Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Lüfter dreht hoch - Ilivid? (https://www.trojaner-board.de/123301-luefter-dreht-hoch-ilivid.html)

v-man0815 02.09.2012 11:11

Lüfter dreht hoch - Ilivid?
 
Lüfter dreht hoch - Ilivid?

Der Lüfter von meinem Nootbook (HP Pavilion dv7-6101eg, mit Windows 7) schaltet hoch, sobald ich den browser öffne – obwohl keinerlei offensichtliche Anwendung läuft. Das finde ich erst einmal verdächtig: was arbeitet da?

Dann habe ich gestern auf kinox.to einen Film ansehen wollen und bin bei den verschiedenen host-plattformen immer wieder zu einem ilivid download gekommen. Den habe ich beim ersten Mal auch gestartet, aber nach einiger Zeit abgebrochen und im Internet nach „ilivid“ gesucht. Nachdem ich einige postings dazu gelesen hatte, führte ich mit „Malwarebytes Anti-Malware“ einen Suchlauf aus, bei dem einige verdächtige Elemente gefunden und gelöst wurden. Gleichzeitig meldete Antivir das Auffinden von fünf verdächtigen Objekten, die ich ebenfalls gelöscht habe. Schließlich habe ich, wie in diesem board beschrieben, noch einen Scan mit OTL durchgeführt. Die beiden Log-Files poste ich hier.
Ich habe darüber hinaus noch mit dem RegCleaner von Antivir einen scan durchgeführt – wenn ich wüsste, wie man hier einen screenshot postet, würde ich auch das tun.

Kann mir anhand der Log-Files jemand sagen, ob da etwas im Busch ist?
Wie könnte ich der Frage auf den Grund gehen, warum der Lüfter so hoch dreht (und auch die Temperatur: Intel Core5-1: 61 / Core5-2: 61 / HP-3389 THRM: 62) bei derzeit kaum Anwendungen so hoch ist.

Danke Martin

cosinus 03.09.2012 21:57

Zitat:

führte ich mit „ Malwarebytes Anti-Malware “ einen Suchlauf aus, bei dem einige verdächtige Elemente gefunden und gelöst wurden. Gleichzeitig meldete Antivir das Auffinden von fünf verdächtigen Objekten, die ich ebenfalls gelöscht habe.
Und wo sind die Logs dieser beiden Scanner? :confused:

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

v-man0815 04.09.2012 08:59

Erstmal danke, dass du dir die Sache ansiehst!

Meinst du diese Infos:


Code:


Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.09.01.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
superaze :: SUPERAZE-HP [Administrator]

Schutz: Aktiviert

01.09.2012 18:36:26
mbam-log-2012-09-01 (18-36-26).txt

Art des Suchlaufs: Vollständiger Suchlauf (B:\|C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 462950
Laufzeit: 1 Stunde(n), 35 Minute(n), 6 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 6
HKCR\CrossriderApp0005060.BHO (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt.
HKCR\CrossriderApp0005060.FBApi (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt.
HKCR\CrossriderApp0005060.FBApi.1 (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt.
HKCR\CrossriderApp0005060.Sandbox (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt.
HKCR\CrossriderApp0005060.Sandbox.1 (PUP.CrossFire.Gen) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 1
HKCU\Software\InstalledBrowserExtensions\215 Apps|5060 (PUP.CrossFire.SA) -> Daten: Savings Sidekick -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Antivir-Meldungen:

Die Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_567\uninstall.exe'
enthielt einen Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware].
….
Die Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_514\uninstall.exe'
enthielt einen Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware].

Die Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_569\uninstall.exe'
enthielt einen Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware].

Die Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_342\uninstall.exe'
enthielt einen Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware].

Die Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_383\uninstall.exe'
enthielt einen Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware].

In allen Fällen > Durchgeführte Aktion(en):
Eine Sicherungskopie wurde unter dem Namen XXX .qua erstellt ( QUARANTÄNE ).
Die Datei wurde ins Quarantäneverzeichnis ….  verschoben!



In der Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_569\uninstall.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware]

In der Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_383\uninstall.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware] gefunden.

In der Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_514\uninstall.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware]

In der Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_567\uninstall.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware] gefunden.

In der Datei 'C:\Program Files (x86)\Uninstall Information\ib_uninst_342\uninstall.exe'
wurde ein Virus oder unerwünschtes Programm 'ADWARE/InstallBrain.Gen' [adware] gefunden.
In allen Fällen > Ausgeführte Aktion: Zugriff verweigern


cosinus 04.09.2012 15:42

Zitat:

Keine Aktion durchgeführt.
-> No action taken.
Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! Bitte nachholen falls noch nicht getan!

NICHTS voreilig aus der Quarantäne löschen!

v-man0815 04.09.2012 19:17

in der Quarantäne, ok! ... aber nicht löschen?

cosinus 04.09.2012 19:55

Führ bitte auch ESET aus, danach sehen wir weiter.

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Im als Administrator geöffneten Browser diesen Link aufrufen => ESET Online Scanner
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Haken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher das bei Remove Found Threats kein Hacken gesetzt ist.
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen Fenster.
Code:

"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
Poste nun den Inhalt der log.txt.


Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

v-man0815 05.09.2012 11:35

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7a0e45050fd3c8438bbd9101be17a5a2
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-09-05 10:32:19
# local_time=2012-09-05 12:32:19 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 24704868 24704868 0 0
# compatibility_mode=5893 16776573 100 94 93064 98464221 0 0
# compatibility_mode=8192 67108863 100 0 164 164 0 0
# scanned=273022
# found=7
# cleaned=0
# scan_time=6767
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe        a variant of Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\FPDownloadManager.exe        Win32/Toolbar.Babylon application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\PDFCreator-1_2_3_setup.exe        Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\SoftonicDownloader_fuer_ibm-spss-statistics-standard.exe        a variant of Win32/SoftonicDownloader.D application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\c8681f3.msi        a variant of Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
${Memory}        a variant of Win32/Toolbar.Widgi application        00000000000000000000000000000000        I


cosinus 05.09.2012 15:00

Code:

C:\Users\superaze\Downloads\SoftonicDownloader_fuer_ibm-spss-statistics-standard.exe
Vermüllte Software von Softonic scheint gerade stark in Mode zu sein! :stirn:

Finger weg von Softonic!! :pfui:

Softonic ist eine Toolbar- und Adwareschleuder! Finger weg! Software lädt man sich mit oberster Priorität direkt vom Hersteller und nicht von solchen Toolbarklitschen wie Softonic! Im Notfall würde natürlich chip.de gehen


adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

v-man0815 05.09.2012 15:37

Code:

# AdwCleaner v1.801 - Logfile created 09/05/2012 at 16:34:56
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : superaze - SUPERAZE-HP
# Boot Mode : Normal
# Running from : C:\Users\superaze\Downloads\adwCleaner1801.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\superaze\AppData\Local\AskToolbar
Folder Found : C:\Users\superaze\AppData\Local\Conduit
Folder Found : C:\Users\superaze\AppData\LocalLow\appbario8
Folder Found : C:\Users\superaze\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\superaze\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\superaze\AppData\LocalLow\Conduit
Folder Found : C:\Users\superaze\AppData\LocalLow\pdfforge
Folder Found : C:\Users\superaze\AppData\LocalLow\PriceGong
Folder Found : C:\Users\superaze\AppData\LocalLow\Search Settings
Folder Found : C:\Users\superaze\AppData\Roaming\pdfforge
Folder Found : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\ConduitCommon
Folder Found : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\CT3227982
Folder Found : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\extensions\{0cc09160-108c-4759-bab1-5c12c216e005}
Folder Found : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
Folder Found : C:\ProgramData\IBUpdaterService
Folder Found : C:\ProgramData\pc performer manager
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
Folder Found : C:\Program Files (x86)\appbario8
Folder Found : C:\Program Files (x86)\Application Updater
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\Crawler
Folder Found : C:\Program Files (x86)\Free Offers from Freeze.com
Folder Found : C:\Program Files (x86)\PriceGong
Folder Found : C:\Program Files (x86)\Common Files\spigot
Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Found : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\searchplugins\Conduit.xml
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\crawlersrch.xml

***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3227982
Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\Ask.com.tmp
Key Found : HKCU\Software\AskToolbar
Key Found : HKCU\Software\bProtector
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Cr_Installer
Key Found : HKCU\Software\CToolbar
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\pdfforge
Key Found : HKCU\Software\Search Settings
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\APN
Key Found : HKLM\SOFTWARE\appbario8
Key Found : HKLM\SOFTWARE\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
Key Found : HKLM\SOFTWARE\Classes\ctbcommon.Buttons
Key Found : HKLM\SOFTWARE\Classes\ctbr.R404Pro
Key Found : HKLM\SOFTWARE\Classes\CToolbar.TB4Client
Key Found : HKLM\SOFTWARE\Classes\CToolbar.TB4Script
Key Found : HKLM\SOFTWARE\Classes\CToolbar.TB4Server
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO
Key Found : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO.1
Key Found : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl
Key Found : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl.1
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tbr
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\CToolbar
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\Freeze.com
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\appbario8 Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong
Key Found : HKLM\SOFTWARE\pdfforge
Key Found : HKLM\SOFTWARE\Search Settings
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchSettings]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
[x64] Key Found : HKCU\Software\APN
[x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
[x64] Key Found : HKCU\Software\AppDataLow\Software\Conduit
[x64] Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
[x64] Key Found : HKCU\Software\AppDataLow\Software\PriceGong
[x64] Key Found : HKCU\Software\AppDataLow\Software\SmartBar
[x64] Key Found : HKCU\Software\AppDataLow\Toolbar
[x64] Key Found : HKCU\Software\Ask.com
[x64] Key Found : HKCU\Software\Ask.com.tmp
[x64] Key Found : HKCU\Software\AskToolbar
[x64] Key Found : HKCU\Software\bProtector
[x64] Key Found : HKCU\Software\Conduit
[x64] Key Found : HKCU\Software\Cr_Installer
[x64] Key Found : HKCU\Software\CToolbar
[x64] Key Found : HKCU\Software\DataMngr
[x64] Key Found : HKCU\Software\DataMngr_Toolbar
[x64] Key Found : HKCU\Software\InstalledBrowserExtensions
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
[x64] Key Found : HKCU\Software\pdfforge
[x64] Key Found : HKCU\Software\Search Settings
[x64] Key Found : HKCU\Software\Softonic
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
[x64] Key Found : HKLM\SOFTWARE\Classes\ctbcommon.Buttons
[x64] Key Found : HKLM\SOFTWARE\Classes\ctbr.R404Pro
[x64] Key Found : HKLM\SOFTWARE\Classes\CToolbar.TB4Client
[x64] Key Found : HKLM\SOFTWARE\Classes\CToolbar.TB4Script
[x64] Key Found : HKLM\SOFTWARE\Classes\CToolbar.TB4Server
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO
[x64] Key Found : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO.1
[x64] Key Found : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl
[x64] Key Found : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl.1
[x64] Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tbr
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{0CC09160-108C-4759-BAB1-5C12C216E005}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566}
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88C52ECB-DE9F-4F9D-B1DE-304527565B23}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4577701A-D06B-4C1C-BA46-FFADC94D7494}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CC09160-108C-4759-BAB1-5C12C216E005}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0CC09160-108C-4759-BAB1-5C12C216E005}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CC09160-108C-4759-BAB1-5C12C216E005}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0CC09160-108C-4759-BAB1-5C12C216E005}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CC09160-108C-4759-BAB1-5C12C216E005}
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{0CC09160-108C-4759-BAB1-5C12C216E005}]
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
[x64] Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227982
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60747
[HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227980

-\\ Mozilla Firefox v16.0 (de)

Profile name : default
File : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\prefs.js

Found : user_pref("CT3227982..clientLogIsEnabled", false);
Found : user_pref("CT3227982..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT3227982..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT3227982.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT3227982.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT3227982.BrowserCompStateIsOpen_1000515", true);
Found : user_pref("CT3227982.BrowserCompStateIsOpen_9221552460232570768", true);
Found : user_pref("CT3227982.CT3227982", "CT3227982");
Found : user_pref("CT3227982.CurrentServerDate", "5-9-2012");
Found : user_pref("CT3227982.DSChangedManually", true);
Found : user_pref("CT3227982.DSInstall", true);
Found : user_pref("CT3227982.DialogsAlignMode", "LTR");
Found : user_pref("CT3227982.DialogsGetterLastCheckTime", "Wed Sep 05 2012 11:57:02 GMT+0200");
Found : user_pref("CT3227982.DownloadReferralCookieData", "");
Found : user_pref("CT3227982.EMailNotifierPollDate", "Thu Aug 23 2012 19:39:17 GMT+0200");
Found : user_pref("CT3227982.FirstServerDate", "22-8-2012");
Found : user_pref("CT3227982.FirstTime", true);
Found : user_pref("CT3227982.FirstTimeFF3", true);
Found : user_pref("CT3227982.FirstTimeHiddenVer", true);
Found : user_pref("CT3227982.FixPageNotFoundErrors", true);
Found : user_pref("CT3227982.GroupingServerCheckInterval", 1440);
Found : user_pref("CT3227982.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT3227982.HPInstall", true);
Found : user_pref("CT3227982.HasUserGlobalKeys", true);
Found : user_pref("CT3227982.HomePageProtectorEnabled", true);
Found : user_pref("CT3227982.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=[...]
Found : user_pref("CT3227982.Initialize", true);
Found : user_pref("CT3227982.InitializeCommonPrefs", true);
Found : user_pref("CT3227982.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT3227982.InstallationType", "Unknown");
Found : user_pref("CT3227982.InstalledDate", "Wed Aug 22 2012 20:40:55 GMT+0200");
Found : user_pref("CT3227982.InvalidateCache", false);
Found : user_pref("CT3227982.IsAlertDBUpdated", true);
Found : user_pref("CT3227982.IsGrouping", false);
Found : user_pref("CT3227982.IsInitSetupIni", true);
Found : user_pref("CT3227982.IsMulticommunity", false);
Found : user_pref("CT3227982.IsOpenThankYouPage", true);
Found : user_pref("CT3227982.IsOpenUninstallPage", true);
Found : user_pref("CT3227982.IsProtectorsInit", true);
Found : user_pref("CT3227982.LanguagePackLastCheckTime", "Tue Sep 04 2012 19:44:00 GMT+0200");
Found : user_pref("CT3227982.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT3227982.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT3227982.LastLogin_3.15.1.0", "Wed Sep 05 2012 09:16:38 GMT+0200");
Found : user_pref("CT3227982.LatestVersion", "3.15.1.0");
Found : user_pref("CT3227982.Locale", "en");
Found : user_pref("CT3227982.MCDetectTooltipHeight", "83");
Found : user_pref("CT3227982.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT3227982.MCDetectTooltipWidth", "295");
Found : user_pref("CT3227982.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT3227982.OriginalFirstVersion", "3.15.1.0");
Found : user_pref("CT3227982.RadioIsPodcast", false);
Found : user_pref("CT3227982.RadioLastCheckTime", "Thu Aug 23 2012 19:39:23 GMT+0200");
Found : user_pref("CT3227982.RadioLastUpdateIPServer", "3");
Found : user_pref("CT3227982.RadioLastUpdateServer", "3");
Found : user_pref("CT3227982.RadioMediaID", "9962");
Found : user_pref("CT3227982.RadioMediaType", "Media Player");
Found : user_pref("CT3227982.RadioMenuSelectedID", "EBRadioMenu_CT32279829962");
Found : user_pref("CT3227982.RadioShrinkedFromSetup", false);
Found : user_pref("CT3227982.RadioStationName", "California%20Rock");
Found : user_pref("CT3227982.RadioStationURL", "hxxp://feedlive.net/california.asx");
Found : user_pref("CT3227982.SavedHomepage", "about:home");
Found : user_pref("CT3227982.SearchCaption", "appbario8 Customized Web Search");
Found : user_pref("CT3227982.SearchEngineBeforeUnload", "Google");
Found : user_pref("CT3227982.SearchFromAddressBarIsInit", true);
Found : user_pref("CT3227982.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...]
Found : user_pref("CT3227982.SearchInNewTabEnabled", true);
Found : user_pref("CT3227982.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT3227982.SearchInNewTabLastCheckTime", "Wed Sep 05 2012 09:36:20 GMT+0200");
Found : user_pref("CT3227982.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT3227982.SearchProtectorEnabled", false);
Found : user_pref("CT3227982.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT3227982.SendProtectorDataViaLogin", true);
Found : user_pref("CT3227982.ServiceMapLastCheckTime", "Wed Sep 05 2012 09:36:22 GMT+0200");
Found : user_pref("CT3227982.SettingsLastCheckTime", "Wed Sep 05 2012 09:36:20 GMT+0200");
Found : user_pref("CT3227982.SettingsLastUpdate", "1346671355");
Found : user_pref("CT3227982.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13");
Found : user_pref("CT3227982.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT3227982.ThirdPartyComponentsLastCheck", "Wed Aug 22 2012 15:03:10 GMT+0200");
Found : user_pref("CT3227982.ThirdPartyComponentsLastUpdate", "1331805997");
Found : user_pref("CT3227982.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT3227982.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3227982");
Found : user_pref("CT3227982.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT3227982.UserID", "UN05558750173541349");
Found : user_pref("CT3227982.WeatherNetwork", "");
Found : user_pref("CT3227982.WeatherPollDate", "Thu Aug 23 2012 19:39:24 GMT+0200");
Found : user_pref("CT3227982.WeatherUnit", "C");
Found : user_pref("CT3227982.alertChannelId", "1663751");
Found : user_pref("CT3227982.autoDisableScopes", -1);
Found : user_pref("CT3227982.backendstorage.bday_installdate", "32332D37");
Found : user_pref("CT3227982.backendstorage.bday_installfromtoolbar", "796573");
Found : user_pref("CT3227982.backendstorage.ct3227982ads1", "25374225323261647325323225334125354225374225323[...]
Found : user_pref("CT3227982.backendstorage.ct3227982current_term", "74656C65666F6E627563682E6465");
Found : user_pref("CT3227982.backendstorage.ct3227982sdate", "3233");
Found : user_pref("CT3227982.components.1000034", true);
Found : user_pref("CT3227982.components.1000234", true);
Found : user_pref("CT3227982.components.1000515", true);
Found : user_pref("CT3227982.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT3227982.globalFirstTimeInfoLastCheckTime", "Wed Aug 22 2012 15:03:11 GMT+0200");
Found : user_pref("CT3227982.homepageProtectorEnableByLogin", true);
Found : user_pref("CT3227982.initDone", true);
Found : user_pref("CT3227982.isAppTrackingManagerOn", false);
Found : user_pref("CT3227982.isFirstRadioInstallation", false);
Found : user_pref("CT3227982.myStuffEnabled", true);
Found : user_pref("CT3227982.myStuffPublihserMinWidth", 400);
Found : user_pref("CT3227982.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT3227982.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT3227982.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT3227982.navigateToUrlOnSearch", false);
Found : user_pref("CT3227982.revertSettingsEnabled", true);
Found : user_pref("CT3227982.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT3227982.searchProtectorEnableByLogin", true);
Found : user_pref("CT3227982.testingCtid", "");
Found : user_pref("CT3227982.toolbarAppMetaDataLastCheckTime", "Wed Sep 05 2012 09:36:23 GMT+0200");
Found : user_pref("CT3227982.toolbarContextMenuLastCheckTime", "Wed Aug 22 2012 15:03:12 GMT+0200");
Found : user_pref("CT3227982.usagesFlag", 1);
Found : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227982&Search[...]
Found : user_pref("CommunityToolbar.ConduitSearchList", "appbario8 Customized Web Search");
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3227982/CT3227982[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1663751/1656277/AT", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3227982", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3227982",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"5f3[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\superaze\\AppData\\Roaming\\Mozilla[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.15.1.0");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.asp[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT3227982");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT3227982");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT3227982");
Found : user_pref("CommunityToolbar.globalUserId", "3c14d022-e635-4cf0-bf1e-6824773db8a3");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3227982");
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Aug 22 2012 15:03:1[...]
Found : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Aug 23 2012 19:39:35 GMT+020[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Aug 23 2012 19:39:26 GMT+0200");
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "805bad1b-84f0-4970-a6a6-ffbc3eb34220");
Found : user_pref("CommunityToolbar.originalHomepage", "about:home");
Found : user_pref("CommunityToolbar.originalSearchEngine", "Google");
Found : user_pref("browser.search.defaultenginename", "appbario8 Customized Web Search");
Found : user_pref("browser.search.defaultthis.engineName", "appbario8 Customized Web Search");
Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&Sea[...]
Found : user_pref("browser.search.order.1", "appbario8 Customized Web Search");
Found : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13");
Found : user_pref("extensions.crossriderapp5060.5060.InstallationThankYouPage", true);
Found : user_pref("extensions.crossriderapp5060.5060.InstallationTime", 1344716376);
Found : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.searchUserConifrmation", false[...]
Found : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setHomepage", false);
Found : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setNewTab", false);
Found : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setSearch", false);
Found : user_pref("extensions.crossriderapp5060.5060.active", true);
Found : user_pref("extensions.crossriderapp5060.5060.addressbar", "");
Found : user_pref("extensions.crossriderapp5060.5060.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG&&appA[...]
Found : user_pref("extensions.crossriderapp5060.5060.backgroundver", 5);
Found : user_pref("extensions.crossriderapp5060.5060.can_run_bg_code", true);
Found : user_pref("extensions.crossriderapp5060.5060.certdomaininstaller", "");
Found : user_pref("extensions.crossriderapp5060.5060.changeprevious", false);
Found : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.value", "1344716376");
Found : user_pref("extensions.crossriderapp5060.5060.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 [...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.value", "1344716376");
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.expiration", "Wed Sep 05 2012 13:[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.value", "%5B%22nonexistantdomain.[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.expiration", "Mon Sep 10 2012 [...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.value", "%22AT%22");
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 [...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.value", "1346843194");
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 [...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.value", "%221%22");
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.value", "%7B%22source_id%2[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.value", "%2214019%22");
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.value", "1346219133545");
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.value", "%221224%22");
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.value", "%2266354%22");
Found : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[...]
Found : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.value", "1346047899383");
Found : user_pref("extensions.crossriderapp5060.5060.description", "Savings Sidekick");
Found : user_pref("extensions.crossriderapp5060.5060.domain", "");
Found : user_pref("extensions.crossriderapp5060.5060.enablesearch", false);
Found : user_pref("extensions.crossriderapp5060.5060.fbremoteurl", "");
Found : user_pref("extensions.crossriderapp5060.5060.group", 0);
Found : user_pref("extensions.crossriderapp5060.5060.homepage", "");
Found : user_pref("extensions.crossriderapp5060.5060.iframe", false);
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.expiration", "Fri Feb 0[...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.value", "%7B%22installe[...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.value", "28");
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.expiration", "Fri Feb [...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.value", "0");
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.value", "%7B%7D");
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.expiration", "Wed Sep 05[...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.value", "true");
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.value", "%7B%7D");
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.expiration", "Fri[...]
Found : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.value", "%7B%22re[...]
Found : user_pref("extensions.crossriderapp5060.5060.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...]
Found : user_pref("extensions.crossriderapp5060.5060.manifesturl", "");
Found : user_pref("extensions.crossriderapp5060.5060.name", "Savings Sidekick");
Found : user_pref("extensions.crossriderapp5060.5060.newtab", "");
Found : user_pref("extensions.crossriderapp5060.5060.opensearch", "");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.code", "appAPI._cr_config={appID:funct[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.name", "base");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.ver", 3);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.ver", 4);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.name", "GPL Background (BG)");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.ver", 2);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.code", "(function(a){a.selectedText=f[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.name", "CrossriderAppUtils");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.ver", 2);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.name", "CrossriderUtils");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.ver", 2);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.code", "(function(f){var u={};var e=M[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.name", "FacebookFFIE");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.ver", 1);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.code", "(function(f,b){if(typeof(b)==[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.name", "FFAppAPIWrapper");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.ver", 3);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.code", "if(typeof window!==\"undefine[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.name", "jQuery");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.ver", 3);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.code", "var CrossriderDebugManager=(f[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.name", "debug");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.ver", 3);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.code", "(function(a){appAPI.queueMana[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.name", "resources");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.ver", 2);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.code", "var CrossriderInitializerPlug[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.name", "initializer");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.ver", 2);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.code", "/*! jQuery v1.7.1 jquery.com |[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.name", "jquery_1_7_1");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.ver", 3);
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.code", "(function(){appAPI.ready=func[...]
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.name", "resources_background");
Found : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.ver", 1);
Found : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_0", "17,14,16,47,1000015");
Found : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_1", "17,14,13,16,15,4,1,21,22,100[...]
Found : user_pref("extensions.crossriderapp5060.5060.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...]
Found : user_pref("extensions.crossriderapp5060.5060.pluginsversion", 10);
Found : user_pref("extensions.crossriderapp5060.5060.publisher", "215 Apps");
Found : user_pref("extensions.crossriderapp5060.5060.searchstatus", 0);
Found : user_pref("extensions.crossriderapp5060.5060.setnewtab", false);
Found : user_pref("extensions.crossriderapp5060.5060.settingsurl", "");
Found : user_pref("extensions.crossriderapp5060.5060.thankyou", "");
Found : user_pref("extensions.crossriderapp5060.5060.updateinterval", 360);
Found : user_pref("extensions.crossriderapp5060.5060.ver", 28);
Found : user_pref("extensions.crossriderapp5060.adsOldValue", -1);
Found : user_pref("extensions.crossriderapp5060.apps", "5060");
Found : user_pref("extensions.crossriderapp5060.bic", "13917586ec4693a548be35d47b1da244");
Found : user_pref("extensions.crossriderapp5060.cid", 5060);
Found : user_pref("extensions.crossriderapp5060.firstrun", false);
Found : user_pref("extensions.crossriderapp5060.hadappinstalled", true);
Found : user_pref("extensions.crossriderapp5060.installationdate", 1344716435);
Found : user_pref("extensions.crossriderapp5060.lastcheck", 22447167);
Found : user_pref("extensions.crossriderapp5060.lastcheckitem", 22447387);
Found : user_pref("extensions.crossriderapp5060.modetype", "production");
Found : user_pref("extensions.enabledAddons", "{0cc09160-108c-4759-bab1-5c12c216e005}:3.15.1.0,crossriderapp[...]
Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&SearchSource=2&q=[...]

-\\ Google Chrome v21.0.1180.89

File : C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [44759 octets] - [05/09/2012 16:34:56]

########## EOF - C:\AdwCleaner[R1].txt - [44888 octets] ##########


cosinus 05.09.2012 15:41

Ich hab extra einen Downloadlink zum adwCleaner mitgegeben aber dennoch hast du eine alte von irgenwo anders benutzt!

v-man0815 05.09.2012 15:54

… weil im Explorer, in dem ich diese Forum-Seite geöffnet habe, ein SmartScreen-Filter die Ausführung blockiert hat. Im FireFox ging es, dafür habe ich dann eben selbst nach dem Programm gesucht.

cosinus 06.09.2012 10:15

Und nun willst du kein neues Log mit der aktuellen Version machen? :wtf:

v-man0815 06.09.2012 11:05

Wie meinst du das? Womit will ich kein kein neues Log machen?

Meinst du einen Scan mit AdwCleaner? Die Log-Datei habe ich jedenfalls im Beitrag #9 geposted.

cosinus 06.09.2012 15:15

Liest du eigentlich meine Beiträge? :(
Natürlich sollst du ein neues Log mit der aktuellen Version machen!

v-man0815 06.09.2012 15:39

wenn du nicht die Die Log-Datei meinst die ich im Beitrag #9 geposted habe, dann weiß ich tatsächlich nicht, was du meinst.
Das ist die Log-Datei, die ich mit der aktuellen AdwCleaner-Version gemacht habe: „Logfile created 09/05/2012 at 16:34:56“. Wenn ich die jetzt nochmal poste, wird sie auch nicht aktueller. Wenn du eine Log-Datei von einem anderen Programm meinst, da sag' es mir bitte.

cosinus 06.09.2012 16:03

Was verstehst du an meinem Text nicht!

Du hast eine alte Version vom adwCleaner benutzt!

Und das obwohl ich extra auf die aktuelle Version verlinkt habe! Du sollst den adwCleaner endlich in aktueller Version runterladen und ein neues Log machen!

v-man0815 06.09.2012 17:40

... sorry, dass ich wirklich eine veraltete Version benutzt habe, hatte ich nicht gescheckt!

hier die Log-Datei der hoffentlich aktuellen Version:
Code:




# AdwCleaner v2.000 - Datei am 09/06/2012 um 18:31:33 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : superaze - SUPERAZE-HP
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\superaze\Downloads\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****

Gefunden : PC Performer Manager

***** [Dateien / Ordner] *****

Datei Gefunden : C:\Program Files (x86)\Mozilla Firefox\searchplugins\crawlersrch.xml
Datei Gefunden : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\searchplugins\Conduit.xml
Ordner Gefunden : C:\Program Files (x86)\appbario8
Ordner Gefunden : C:\Program Files (x86)\Application Updater
Ordner Gefunden : C:\Program Files (x86)\Ask.com
Ordner Gefunden : C:\Program Files (x86)\Common Files\spigot
Ordner Gefunden : C:\Program Files (x86)\Conduit
Ordner Gefunden : C:\Program Files (x86)\Crawler
Ordner Gefunden : C:\Program Files (x86)\Free Offers from Freeze.com
Ordner Gefunden : C:\Program Files (x86)\PriceGong
Ordner Gefunden : C:\ProgramData\IBUpdaterService
Ordner Gefunden : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
Ordner Gefunden : C:\ProgramData\pc performer manager
Ordner Gefunden : C:\Users\superaze\AppData\Local\AskToolbar
Ordner Gefunden : C:\Users\superaze\AppData\Local\Conduit
Ordner Gefunden : C:\Users\superaze\AppData\LocalLow\appbario8
Ordner Gefunden : C:\Users\superaze\AppData\LocalLow\AskToolbar
Ordner Gefunden : C:\Users\superaze\AppData\LocalLow\boost_interprocess
Ordner Gefunden : C:\Users\superaze\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\superaze\AppData\LocalLow\pdfforge
Ordner Gefunden : C:\Users\superaze\AppData\LocalLow\PriceGong
Ordner Gefunden : C:\Users\superaze\AppData\LocalLow\Search Settings
Ordner Gefunden : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\ConduitCommon
Ordner Gefunden : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\CT3227982
Ordner Gefunden : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\extensions\{0cc09160-108c-4759-bab1-5c12c216e005}
Ordner Gefunden : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
Ordner Gefunden : C:\Users\superaze\AppData\Roaming\pdfforge
Ordner Gefunden : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registrierungsdatenbank] *****

Daten Gefunden : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\pcperf~1\22558~1.177\{16cdf~1\%prote~1.dll
Schlüssel Gefunden : HKCU\Software\APN
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\appbario8
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gefunden : HKCU\Software\Ask.com
Schlüssel Gefunden : HKCU\Software\Ask.com.tmp
Schlüssel Gefunden : HKCU\Software\AskToolbar
Schlüssel Gefunden : HKCU\Software\bProtector
Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKCU\Software\Cr_Installer
Schlüssel Gefunden : HKCU\Software\CToolbar
Schlüssel Gefunden : HKCU\Software\DataMngr
Schlüssel Gefunden : HKCU\Software\DataMngr_Toolbar
Schlüssel Gefunden : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gefunden : HKCU\Software\pdfforge
Schlüssel Gefunden : HKCU\Software\Search Settings
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gefunden : HKLM\Software\APN
Schlüssel Gefunden : HKLM\Software\appbario8
Schlüssel Gefunden : HKLM\Software\AskToolbar
Schlüssel Gefunden : HKLM\Software\bProtector
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ctbcommon.Buttons
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\ctbr.R404Pro
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CToolbar.TB4Client
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CToolbar.TB4Script
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CToolbar.TB4Server
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tbr
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT3227982
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566}
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\CToolbar
Schlüssel Gefunden : HKLM\Software\DataMngr
Schlüssel Gefunden : HKLM\Software\Freeze.com
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler
Schlüssel Gefunden : HKLM\Software\pdfforge
Schlüssel Gefunden : HKLM\Software\Search Settings
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4577701A-D06B-4C1C-BA46-FFADC94D7494}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88C52ECB-DE9F-4F9D-B1DE-304527565B23}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\appbario8 Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gefunden : HKU\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gefunden : HKU\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [{b64982b1-d112-42b5-b1e4-d3867c4533f8}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchSettings]
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Wert Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Wert Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227982
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60747
[HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227980

-\\ Mozilla Firefox v16.0 (de)

Profilname : default
Datei : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\prefs.js

Gefunden : user_pref("CT3227982..clientLogIsEnabled", false);
Gefunden : user_pref("CT3227982..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Gefunden : user_pref("CT3227982..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Gefunden : user_pref("CT3227982.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Gefunden : user_pref("CT3227982.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Gefunden : user_pref("CT3227982.BrowserCompStateIsOpen_1000515", true);
Gefunden : user_pref("CT3227982.BrowserCompStateIsOpen_9221552460232570768", true);
Gefunden : user_pref("CT3227982.CT3227982", "CT3227982");
Gefunden : user_pref("CT3227982.CurrentServerDate", "6-9-2012");
Gefunden : user_pref("CT3227982.DSChangedManually", true);
Gefunden : user_pref("CT3227982.DSInstall", true);
Gefunden : user_pref("CT3227982.DialogsAlignMode", "LTR");
Gefunden : user_pref("CT3227982.DialogsGetterLastCheckTime", "Wed Sep 05 2012 11:57:02 GMT+0200");
Gefunden : user_pref("CT3227982.DownloadReferralCookieData", "");
Gefunden : user_pref("CT3227982.EMailNotifierPollDate", "Thu Aug 23 2012 19:39:17 GMT+0200");
Gefunden : user_pref("CT3227982.FirstServerDate", "22-8-2012");
Gefunden : user_pref("CT3227982.FirstTime", true);
Gefunden : user_pref("CT3227982.FirstTimeFF3", true);
Gefunden : user_pref("CT3227982.FirstTimeHiddenVer", true);
Gefunden : user_pref("CT3227982.FixPageNotFoundErrors", true);
Gefunden : user_pref("CT3227982.GroupingServerCheckInterval", 1440);
Gefunden : user_pref("CT3227982.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Gefunden : user_pref("CT3227982.HPInstall", true);
Gefunden : user_pref("CT3227982.HasUserGlobalKeys", true);
Gefunden : user_pref("CT3227982.HomePageProtectorEnabled", true);
Gefunden : user_pref("CT3227982.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=[...]
Gefunden : user_pref("CT3227982.Initialize", true);
Gefunden : user_pref("CT3227982.InitializeCommonPrefs", true);
Gefunden : user_pref("CT3227982.InstallationAndCookieDataSentCount", 3);
Gefunden : user_pref("CT3227982.InstallationType", "Unknown");
Gefunden : user_pref("CT3227982.InstalledDate", "Wed Aug 22 2012 20:40:55 GMT+0200");
Gefunden : user_pref("CT3227982.InvalidateCache", false);
Gefunden : user_pref("CT3227982.IsAlertDBUpdated", true);
Gefunden : user_pref("CT3227982.IsGrouping", false);
Gefunden : user_pref("CT3227982.IsInitSetupIni", true);
Gefunden : user_pref("CT3227982.IsMulticommunity", false);
Gefunden : user_pref("CT3227982.IsOpenThankYouPage", true);
Gefunden : user_pref("CT3227982.IsOpenUninstallPage", true);
Gefunden : user_pref("CT3227982.IsProtectorsInit", true);
Gefunden : user_pref("CT3227982.LanguagePackLastCheckTime", "Wed Sep 05 2012 19:44:00 GMT+0200");
Gefunden : user_pref("CT3227982.LanguagePackReloadIntervalMM", 1440);
Gefunden : user_pref("CT3227982.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Gefunden : user_pref("CT3227982.LastLogin_3.15.1.0", "Thu Sep 06 2012 15:54:07 GMT+0200");
Gefunden : user_pref("CT3227982.LatestVersion", "3.15.1.0");
Gefunden : user_pref("CT3227982.Locale", "en");
Gefunden : user_pref("CT3227982.MCDetectTooltipHeight", "83");
Gefunden : user_pref("CT3227982.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Gefunden : user_pref("CT3227982.MCDetectTooltipWidth", "295");
Gefunden : user_pref("CT3227982.MyStuffEnabledAtInstallation", true);
Gefunden : user_pref("CT3227982.OriginalFirstVersion", "3.15.1.0");
Gefunden : user_pref("CT3227982.RadioIsPodcast", false);
Gefunden : user_pref("CT3227982.RadioLastCheckTime", "Thu Aug 23 2012 19:39:23 GMT+0200");
Gefunden : user_pref("CT3227982.RadioLastUpdateIPServer", "3");
Gefunden : user_pref("CT3227982.RadioLastUpdateServer", "3");
Gefunden : user_pref("CT3227982.RadioMediaID", "9962");
Gefunden : user_pref("CT3227982.RadioMediaType", "Media Player");
Gefunden : user_pref("CT3227982.RadioMenuSelectedID", "EBRadioMenu_CT32279829962");
Gefunden : user_pref("CT3227982.RadioShrinkedFromSetup", false);
Gefunden : user_pref("CT3227982.RadioStationName", "California%20Rock");
Gefunden : user_pref("CT3227982.RadioStationURL", "hxxp://feedlive.net/california.asx");
Gefunden : user_pref("CT3227982.SavedHomepage", "about:home");
Gefunden : user_pref("CT3227982.SearchCaption", "appbario8 Customized Web Search");
Gefunden : user_pref("CT3227982.SearchEngineBeforeUnload", "Google");
Gefunden : user_pref("CT3227982.SearchFromAddressBarIsInit", true);
Gefunden : user_pref("CT3227982.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...]
Gefunden : user_pref("CT3227982.SearchInNewTabEnabled", true);
Gefunden : user_pref("CT3227982.SearchInNewTabIntervalMM", 1440);
Gefunden : user_pref("CT3227982.SearchInNewTabLastCheckTime", "Thu Sep 06 2012 11:16:33 GMT+0200");
Gefunden : user_pref("CT3227982.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Gefunden : user_pref("CT3227982.SearchProtectorEnabled", false);
Gefunden : user_pref("CT3227982.SearchProtectorToolbarDisabled", false);
Gefunden : user_pref("CT3227982.SendProtectorDataViaLogin", true);
Gefunden : user_pref("CT3227982.ServiceMapLastCheckTime", "Thu Sep 06 2012 11:16:35 GMT+0200");
Gefunden : user_pref("CT3227982.SettingsLastCheckTime", "Thu Sep 06 2012 18:27:58 GMT+0200");
Gefunden : user_pref("CT3227982.SettingsLastUpdate", "1346943349");
Gefunden : user_pref("CT3227982.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13");
Gefunden : user_pref("CT3227982.ThirdPartyComponentsInterval", 504);
Gefunden : user_pref("CT3227982.ThirdPartyComponentsLastCheck", "Wed Aug 22 2012 15:03:10 GMT+0200");
Gefunden : user_pref("CT3227982.ThirdPartyComponentsLastUpdate", "1331805997");
Gefunden : user_pref("CT3227982.ToolbarShrinkedFromSetup", false);
Gefunden : user_pref("CT3227982.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3227982");
Gefunden : user_pref("CT3227982.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Gefunden : user_pref("CT3227982.UserID", "UN05558750173541349");
Gefunden : user_pref("CT3227982.WeatherNetwork", "");
Gefunden : user_pref("CT3227982.WeatherPollDate", "Thu Aug 23 2012 19:39:24 GMT+0200");
Gefunden : user_pref("CT3227982.WeatherUnit", "C");
Gefunden : user_pref("CT3227982.alertChannelId", "1663751");
Gefunden : user_pref("CT3227982.autoDisableScopes", -1);
Gefunden : user_pref("CT3227982.backendstorage.bday_installdate", "32332D37");
Gefunden : user_pref("CT3227982.backendstorage.bday_installfromtoolbar", "796573");
Gefunden : user_pref("CT3227982.backendstorage.ct3227982ads1", "25374225323261647325323225334125354225374225323[...]
Gefunden : user_pref("CT3227982.backendstorage.ct3227982current_term", "74656C65666F6E627563682E6465");
Gefunden : user_pref("CT3227982.backendstorage.ct3227982sdate", "3233");
Gefunden : user_pref("CT3227982.components.1000034", true);
Gefunden : user_pref("CT3227982.components.1000234", true);
Gefunden : user_pref("CT3227982.components.1000515", true);
Gefunden : user_pref("CT3227982.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Gefunden : user_pref("CT3227982.globalFirstTimeInfoLastCheckTime", "Wed Aug 22 2012 15:03:11 GMT+0200");
Gefunden : user_pref("CT3227982.homepageProtectorEnableByLogin", true);
Gefunden : user_pref("CT3227982.initDone", true);
Gefunden : user_pref("CT3227982.isAppTrackingManagerOn", false);
Gefunden : user_pref("CT3227982.isFirstRadioInstallation", false);
Gefunden : user_pref("CT3227982.myStuffEnabled", true);
Gefunden : user_pref("CT3227982.myStuffPublihserMinWidth", 400);
Gefunden : user_pref("CT3227982.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Gefunden : user_pref("CT3227982.myStuffServiceIntervalMM", 1440);
Gefunden : user_pref("CT3227982.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Gefunden : user_pref("CT3227982.navigateToUrlOnSearch", false);
Gefunden : user_pref("CT3227982.revertSettingsEnabled", true);
Gefunden : user_pref("CT3227982.searchProtectorDialogDelayInSec", 10);
Gefunden : user_pref("CT3227982.searchProtectorEnableByLogin", true);
Gefunden : user_pref("CT3227982.testingCtid", "");
Gefunden : user_pref("CT3227982.toolbarAppMetaDataLastCheckTime", "Thu Sep 06 2012 10:11:41 GMT+0200");
Gefunden : user_pref("CT3227982.toolbarContextMenuLastCheckTime", "Wed Aug 22 2012 15:03:12 GMT+0200");
Gefunden : user_pref("CT3227982.usagesFlag", 1);
Gefunden : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227982&Search[...]
Gefunden : user_pref("CommunityToolbar.ConduitSearchList", "appbario8 Customized Web Search");
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3227982/CT3227982[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1663751/1656277/AT", "\"0\"[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3227982", [...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3227982",[...]
Gefunden : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"5f3[...]
Gefunden : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\superaze\\AppData\\Roaming\\Mozilla[...]
Gefunden : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.15.1.0");
Gefunden : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.asp[...]
Gefunden : user_pref("CommunityToolbar.ToolbarsList", "CT3227982");
Gefunden : user_pref("CommunityToolbar.ToolbarsList2", "CT3227982");
Gefunden : user_pref("CommunityToolbar.ToolbarsList4", "CT3227982");
Gefunden : user_pref("CommunityToolbar.globalUserId", "3c14d022-e635-4cf0-bf1e-6824773db8a3");
Gefunden : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Gefunden : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Gefunden : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3227982");
Gefunden : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Aug 22 2012 15:03:1[...]
Gefunden : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Gefunden : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Gefunden : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Aug 23 2012 19:39:35 GMT+020[...]
Gefunden : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Gefunden : user_pref("CommunityToolbar.notifications.locale", "en");
Gefunden : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Gefunden : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Aug 23 2012 19:39:26 GMT+0200");
Gefunden : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Gefunden : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Gefunden : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Gefunden : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Gefunden : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Gefunden : user_pref("CommunityToolbar.notifications.userId", "805bad1b-84f0-4970-a6a6-ffbc3eb34220");
Gefunden : user_pref("CommunityToolbar.originalHomepage", "about:home");
Gefunden : user_pref("CommunityToolbar.originalSearchEngine", "Google");
Gefunden : user_pref("browser.search.defaultenginename", "appbario8 Customized Web Search");
Gefunden : user_pref("browser.search.defaultthis.engineName", "appbario8 Customized Web Search");
Gefunden : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&Sea[...]
Gefunden : user_pref("browser.search.order.1", "appbario8 Customized Web Search");
Gefunden : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13");
Gefunden : user_pref("extensions.crossriderapp5060.5060.InstallationThankYouPage", true);
Gefunden : user_pref("extensions.crossriderapp5060.5060.InstallationTime", 1344716376);
Gefunden : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.searchUserConifrmation", false[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setHomepage", false);
Gefunden : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setNewTab", false);
Gefunden : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setSearch", false);
Gefunden : user_pref("extensions.crossriderapp5060.5060.active", true);
Gefunden : user_pref("extensions.crossriderapp5060.5060.addressbar", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG&&appA[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.backgroundver", 5);
Gefunden : user_pref("extensions.crossriderapp5060.5060.can_run_bg_code", true);
Gefunden : user_pref("extensions.crossriderapp5060.5060.certdomaininstaller", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.changeprevious", false);
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.value", "1344716376");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 [...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.value", "1344716376");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.expiration", "Thu Sep 06 2012 18:[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.value", "%5B%22nonexistantdomain.[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.expiration", "Mon Sep 10 2012 [...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.value", "%22AT%22");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 [...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.value", "1346948878");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 [...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.value", "%221%22");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.value", "%7B%22source_id%2[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.value", "%2214019%22");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.value", "1346219133545");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.value", "%221224%22");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.value", "%2266354%22");
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.value", "1346047899383");
Gefunden : user_pref("extensions.crossriderapp5060.5060.description", "Savings Sidekick");
Gefunden : user_pref("extensions.crossriderapp5060.5060.domain", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.enablesearch", false);
Gefunden : user_pref("extensions.crossriderapp5060.5060.fbremoteurl", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.group", 0);
Gefunden : user_pref("extensions.crossriderapp5060.5060.homepage", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.iframe", false);
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.expiration", "Fri Feb 0[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.value", "%7B%22installe[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.value", "28");
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.expiration", "Fri Feb [...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.value", "0");
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.value", "%7B%7D");
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.expiration", "Thu Sep 06[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.value", "true");
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.value", "%7B%7D");
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.expiration", "Fri[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.value", "%7B%22re[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.manifesturl", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.name", "Savings Sidekick");
Gefunden : user_pref("extensions.crossriderapp5060.5060.newtab", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.opensearch", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.code", "appAPI._cr_config={appID:funct[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.name", "base");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.ver", 3);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.ver", 4);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.name", "GPL Background (BG)");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.ver", 2);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.code", "(function(a){a.selectedText=f[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.name", "CrossriderAppUtils");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.ver", 2);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.name", "CrossriderUtils");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.ver", 2);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.code", "(function(f){var u={};var e=M[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.name", "FacebookFFIE");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.ver", 1);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.code", "(function(f,b){if(typeof(b)==[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.name", "FFAppAPIWrapper");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.ver", 3);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.code", "if(typeof window!==\"undefine[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.name", "jQuery");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.ver", 3);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.code", "var CrossriderDebugManager=(f[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.name", "debug");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.ver", 3);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.code", "(function(a){appAPI.queueMana[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.name", "resources");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.ver", 2);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.code", "var CrossriderInitializerPlug[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.name", "initializer");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.ver", 2);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.code", "/*! jQuery v1.7.1 jquery.com |[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.name", "jquery_1_7_1");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.ver", 3);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.code", "(function(){appAPI.ready=func[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.name", "resources_background");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.ver", 1);
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_0", "17,14,16,47,1000015");
Gefunden : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_1", "17,14,13,16,15,4,1,21,22,100[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...]
Gefunden : user_pref("extensions.crossriderapp5060.5060.pluginsversion", 10);
Gefunden : user_pref("extensions.crossriderapp5060.5060.publisher", "215 Apps");
Gefunden : user_pref("extensions.crossriderapp5060.5060.searchstatus", 0);
Gefunden : user_pref("extensions.crossriderapp5060.5060.setnewtab", false);
Gefunden : user_pref("extensions.crossriderapp5060.5060.settingsurl", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.thankyou", "");
Gefunden : user_pref("extensions.crossriderapp5060.5060.updateinterval", 360);
Gefunden : user_pref("extensions.crossriderapp5060.5060.ver", 28);
Gefunden : user_pref("extensions.crossriderapp5060.adsOldValue", -1);
Gefunden : user_pref("extensions.crossriderapp5060.apps", "5060");
Gefunden : user_pref("extensions.crossriderapp5060.bic", "13917586ec4693a548be35d47b1da244");
Gefunden : user_pref("extensions.crossriderapp5060.cid", 5060);
Gefunden : user_pref("extensions.crossriderapp5060.firstrun", false);
Gefunden : user_pref("extensions.crossriderapp5060.hadappinstalled", true);
Gefunden : user_pref("extensions.crossriderapp5060.installationdate", 1344716435);
Gefunden : user_pref("extensions.crossriderapp5060.lastcheck", 22448878);
Gefunden : user_pref("extensions.crossriderapp5060.lastcheckitem", 22449151);
Gefunden : user_pref("extensions.crossriderapp5060.modetype", "production");
Gefunden : user_pref("extensions.enabledAddons", "{0cc09160-108c-4759-bab1-5c12c216e005}:3.15.1.0,crossriderapp[...]
Gefunden : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&SearchSource=2&q=[...]

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [44734 octets] - [05/09/2012 16:34:56]
AdwCleaner[R2].txt - [42386 octets] - [06/09/2012 18:31:14]
AdwCleaner[R3].txt - [42340 octets] - [06/09/2012 18:31:33]

########## EOF - C:\AdwCleaner[R3].txt - [42401 octets] ##########


cosinus 06.09.2012 20:25

Nun ist es richtig ;)

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

v-man0815 07.09.2012 08:58

Erste Meldung: Avira Browser-Schutz deaktiviert. Um den wieder zu bekommen, müsste ich Avira search-bar installieren. Normalerweise würde ich das sofort tun – soll ich das deiner Meinung nach?


Hier ist mal die Log-Datei:

Code:



# AdwCleaner v2.000 - Datei am 09/07/2012 um 09:00:09 erstellt
# Aktualisiert am 30/08/2012 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : superaze - SUPERAZE-HP
# Normaler Modus : Normal
# Ausgeführt unter : C:\Users\superaze\Desktop\adwcleaner(1).exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : PC Performer Manager

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\crawlersrch.xml
Datei Gelöscht : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\searchplugins\Conduit.xml
Gelöscht mit Neustart : C:\ProgramData\pc performer manager
Ordner Gelöscht : C:\Program Files (x86)\appbario8
Ordner Gelöscht : C:\Program Files (x86)\Application Updater
Ordner Gelöscht : C:\Program Files (x86)\Ask.com
Ordner Gelöscht : C:\Program Files (x86)\Common Files\spigot
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\Crawler
Ordner Gelöscht : C:\Program Files (x86)\Free Offers from Freeze.com
Ordner Gelöscht : C:\Program Files (x86)\PriceGong
Ordner Gelöscht : C:\ProgramData\IBUpdaterService
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
Ordner Gelöscht : C:\Users\superaze\AppData\Local\AskToolbar
Ordner Gelöscht : C:\Users\superaze\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\superaze\AppData\LocalLow\appbario8
Ordner Gelöscht : C:\Users\superaze\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\superaze\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\superaze\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\superaze\AppData\LocalLow\pdfforge
Ordner Gelöscht : C:\Users\superaze\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\superaze\AppData\LocalLow\Search Settings
Ordner Gelöscht : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\ConduitCommon
Ordner Gelöscht : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\CT3227982
Ordner Gelöscht : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\extensions\{0cc09160-108c-4759-bab1-5c12c216e005}
Ordner Gelöscht : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
Ordner Gelöscht : C:\Users\superaze\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registrierungsdatenbank] *****

Daten Gelöscht : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\pcperf~1\22558~1.177\{16cdf~1\%prote~1.dll
Schlüssel Gelöscht : HKCU\Software\APN
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\appbario8
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\Ask.com
Schlüssel Gelöscht : HKCU\Software\Ask.com.tmp
Schlüssel Gelöscht : HKCU\Software\AskToolbar
Schlüssel Gelöscht : HKCU\Software\bProtector
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\Cr_Installer
Schlüssel Gelöscht : HKCU\Software\CToolbar
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\pdfforge
Schlüssel Gelöscht : HKCU\Software\Search Settings
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\Software\APN
Schlüssel Gelöscht : HKLM\Software\appbario8
Schlüssel Gelöscht : HKLM\Software\AskToolbar
Schlüssel Gelöscht : HKLM\Software\bProtector
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ctbcommon.Buttons
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ctbr.R404Pro
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CToolbar.TB4Client
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CToolbar.TB4Script
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CToolbar.TB4Server
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceFactorIE.PriceGongBHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tbr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3227982
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566}
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\CToolbar
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Freeze.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler
Schlüssel Gelöscht : HKLM\Software\pdfforge
Schlüssel Gelöscht : HKLM\Software\Search Settings
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{17FBAC21-3A8E-43BD-AB17-F02E52037EDB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4577701A-D06B-4C1C-BA46-FFADC94D7494}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88C52ECB-DE9F-4F9D-B1DE-304527565B23}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CC09160-108C-4759-BAB1-5C12C216E005}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\appbario8 Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PriceGong
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{b64982b1-d112-42b5-b1e4-d3867c4533f8}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchSettings]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{0CC09160-108C-4759-BAB1-5C12C216E005}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227982 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60747 --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - bProtector Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227980 --> hxxp://www.google.com

-\\ Mozilla Firefox v16.0 (de)

Profilname : default
Datei : C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\zbd7w197.default\prefs.js

Gelöscht : user_pref("CT3227982..clientLogIsEnabled", false);
Gelöscht : user_pref("CT3227982..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Gelöscht : user_pref("CT3227982..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Gelöscht : user_pref("CT3227982.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Gelöscht : user_pref("CT3227982.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Gelöscht : user_pref("CT3227982.BrowserCompStateIsOpen_1000515", true);
Gelöscht : user_pref("CT3227982.BrowserCompStateIsOpen_9221552460232570768", true);
Gelöscht : user_pref("CT3227982.CT3227982", "CT3227982");
Gelöscht : user_pref("CT3227982.CurrentServerDate", "7-9-2012");
Gelöscht : user_pref("CT3227982.DSChangedManually", true);
Gelöscht : user_pref("CT3227982.DSInstall", true);
Gelöscht : user_pref("CT3227982.DialogsAlignMode", "LTR");
Gelöscht : user_pref("CT3227982.DialogsGetterLastCheckTime", "Wed Sep 05 2012 11:57:02 GMT+0200");
Gelöscht : user_pref("CT3227982.DownloadReferralCookieData", "");
Gelöscht : user_pref("CT3227982.EMailNotifierPollDate", "Thu Aug 23 2012 19:39:17 GMT+0200");
Gelöscht : user_pref("CT3227982.FirstServerDate", "22-8-2012");
Gelöscht : user_pref("CT3227982.FirstTime", true);
Gelöscht : user_pref("CT3227982.FirstTimeFF3", true);
Gelöscht : user_pref("CT3227982.FirstTimeHiddenVer", true);
Gelöscht : user_pref("CT3227982.FixPageNotFoundErrors", true);
Gelöscht : user_pref("CT3227982.GroupingServerCheckInterval", 1440);
Gelöscht : user_pref("CT3227982.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Gelöscht : user_pref("CT3227982.HPInstall", true);
Gelöscht : user_pref("CT3227982.HasUserGlobalKeys", true);
Gelöscht : user_pref("CT3227982.HomePageProtectorEnabled", true);
Gelöscht : user_pref("CT3227982.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=[...]
Gelöscht : user_pref("CT3227982.Initialize", true);
Gelöscht : user_pref("CT3227982.InitializeCommonPrefs", true);
Gelöscht : user_pref("CT3227982.InstallationAndCookieDataSentCount", 3);
Gelöscht : user_pref("CT3227982.InstallationType", "Unknown");
Gelöscht : user_pref("CT3227982.InstalledDate", "Wed Aug 22 2012 20:40:55 GMT+0200");
Gelöscht : user_pref("CT3227982.InvalidateCache", false);
Gelöscht : user_pref("CT3227982.IsAlertDBUpdated", true);
Gelöscht : user_pref("CT3227982.IsGrouping", false);
Gelöscht : user_pref("CT3227982.IsInitSetupIni", true);
Gelöscht : user_pref("CT3227982.IsMulticommunity", false);
Gelöscht : user_pref("CT3227982.IsOpenThankYouPage", true);
Gelöscht : user_pref("CT3227982.IsOpenUninstallPage", true);
Gelöscht : user_pref("CT3227982.IsProtectorsInit", true);
Gelöscht : user_pref("CT3227982.LanguagePackLastCheckTime", "Thu Sep 06 2012 20:05:23 GMT+0200");
Gelöscht : user_pref("CT3227982.LanguagePackReloadIntervalMM", 1440);
Gelöscht : user_pref("CT3227982.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Gelöscht : user_pref("CT3227982.LastLogin_3.15.1.0", "Fri Sep 07 2012 07:46:35 GMT+0200");
Gelöscht : user_pref("CT3227982.LatestVersion", "3.15.1.0");
Gelöscht : user_pref("CT3227982.Locale", "en");
Gelöscht : user_pref("CT3227982.MCDetectTooltipHeight", "83");
Gelöscht : user_pref("CT3227982.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Gelöscht : user_pref("CT3227982.MCDetectTooltipWidth", "295");
Gelöscht : user_pref("CT3227982.MyStuffEnabledAtInstallation", true);
Gelöscht : user_pref("CT3227982.OriginalFirstVersion", "3.15.1.0");
Gelöscht : user_pref("CT3227982.RadioIsPodcast", false);
Gelöscht : user_pref("CT3227982.RadioLastCheckTime", "Thu Aug 23 2012 19:39:23 GMT+0200");
Gelöscht : user_pref("CT3227982.RadioLastUpdateIPServer", "3");
Gelöscht : user_pref("CT3227982.RadioLastUpdateServer", "3");
Gelöscht : user_pref("CT3227982.RadioMediaID", "9962");
Gelöscht : user_pref("CT3227982.RadioMediaType", "Media Player");
Gelöscht : user_pref("CT3227982.RadioMenuSelectedID", "EBRadioMenu_CT32279829962");
Gelöscht : user_pref("CT3227982.RadioShrinkedFromSetup", false);
Gelöscht : user_pref("CT3227982.RadioStationName", "California%20Rock");
Gelöscht : user_pref("CT3227982.RadioStationURL", "hxxp://feedlive.net/california.asx");
Gelöscht : user_pref("CT3227982.SavedHomepage", "about:home");
Gelöscht : user_pref("CT3227982.SearchCaption", "appbario8 Customized Web Search");
Gelöscht : user_pref("CT3227982.SearchEngineBeforeUnload", "Google");
Gelöscht : user_pref("CT3227982.SearchFromAddressBarIsInit", true);
Gelöscht : user_pref("CT3227982.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT322[...]
Gelöscht : user_pref("CT3227982.SearchInNewTabEnabled", true);
Gelöscht : user_pref("CT3227982.SearchInNewTabIntervalMM", 1440);
Gelöscht : user_pref("CT3227982.SearchInNewTabLastCheckTime", "Thu Sep 06 2012 11:16:33 GMT+0200");
Gelöscht : user_pref("CT3227982.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Gelöscht : user_pref("CT3227982.SearchProtectorEnabled", false);
Gelöscht : user_pref("CT3227982.SearchProtectorToolbarDisabled", false);
Gelöscht : user_pref("CT3227982.SendProtectorDataViaLogin", true);
Gelöscht : user_pref("CT3227982.ServiceMapLastCheckTime", "Thu Sep 06 2012 11:16:35 GMT+0200");
Gelöscht : user_pref("CT3227982.SettingsLastCheckTime", "Fri Sep 07 2012 07:46:34 GMT+0200");
Gelöscht : user_pref("CT3227982.SettingsLastUpdate", "1346943349");
Gelöscht : user_pref("CT3227982.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13");
Gelöscht : user_pref("CT3227982.ThirdPartyComponentsInterval", 504);
Gelöscht : user_pref("CT3227982.ThirdPartyComponentsLastCheck", "Wed Aug 22 2012 15:03:10 GMT+0200");
Gelöscht : user_pref("CT3227982.ThirdPartyComponentsLastUpdate", "1331805997");
Gelöscht : user_pref("CT3227982.ToolbarShrinkedFromSetup", false);
Gelöscht : user_pref("CT3227982.TrusteLinkUrl", "hxxp://trust.conduit.com/CT3227982");
Gelöscht : user_pref("CT3227982.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Gelöscht : user_pref("CT3227982.UserID", "UN05558750173541349");
Gelöscht : user_pref("CT3227982.WeatherNetwork", "");
Gelöscht : user_pref("CT3227982.WeatherPollDate", "Thu Aug 23 2012 19:39:24 GMT+0200");
Gelöscht : user_pref("CT3227982.WeatherUnit", "C");
Gelöscht : user_pref("CT3227982.alertChannelId", "1663751");
Gelöscht : user_pref("CT3227982.autoDisableScopes", -1);
Gelöscht : user_pref("CT3227982.backendstorage.bday_installdate", "32332D37");
Gelöscht : user_pref("CT3227982.backendstorage.bday_installfromtoolbar", "796573");
Gelöscht : user_pref("CT3227982.backendstorage.ct3227982ads1", "25374225323261647325323225334125354225374225323[...]
Gelöscht : user_pref("CT3227982.backendstorage.ct3227982current_term", "74656C65666F6E627563682E6465");
Gelöscht : user_pref("CT3227982.backendstorage.ct3227982sdate", "3233");
Gelöscht : user_pref("CT3227982.components.1000034", true);
Gelöscht : user_pref("CT3227982.components.1000234", true);
Gelöscht : user_pref("CT3227982.components.1000515", true);
Gelöscht : user_pref("CT3227982.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Gelöscht : user_pref("CT3227982.globalFirstTimeInfoLastCheckTime", "Wed Aug 22 2012 15:03:11 GMT+0200");
Gelöscht : user_pref("CT3227982.homepageProtectorEnableByLogin", true);
Gelöscht : user_pref("CT3227982.initDone", true);
Gelöscht : user_pref("CT3227982.isAppTrackingManagerOn", false);
Gelöscht : user_pref("CT3227982.isFirstRadioInstallation", false);
Gelöscht : user_pref("CT3227982.myStuffEnabled", true);
Gelöscht : user_pref("CT3227982.myStuffPublihserMinWidth", 400);
Gelöscht : user_pref("CT3227982.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Gelöscht : user_pref("CT3227982.myStuffServiceIntervalMM", 1440);
Gelöscht : user_pref("CT3227982.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Gelöscht : user_pref("CT3227982.navigateToUrlOnSearch", false);
Gelöscht : user_pref("CT3227982.revertSettingsEnabled", true);
Gelöscht : user_pref("CT3227982.searchProtectorDialogDelayInSec", 10);
Gelöscht : user_pref("CT3227982.searchProtectorEnableByLogin", true);
Gelöscht : user_pref("CT3227982.testingCtid", "");
Gelöscht : user_pref("CT3227982.toolbarAppMetaDataLastCheckTime", "Thu Sep 06 2012 10:11:41 GMT+0200");
Gelöscht : user_pref("CT3227982.toolbarContextMenuLastCheckTime", "Wed Aug 22 2012 15:03:12 GMT+0200");
Gelöscht : user_pref("CT3227982.usagesFlag", 1);
Gelöscht : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227982&Search[...]
Gelöscht : user_pref("CommunityToolbar.ConduitSearchList", "appbario8 Customized Web Search");
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT3227982/CT3227982[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1663751/1656277/AT", "\"0\"[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT3227982", [...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT3227982",[...]
Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"018[...]
Gelöscht : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\superaze\\AppData\\Roaming\\Mozilla[...]
Gelöscht : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.15.1.0");
Gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.asp[...]
Gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT3227982");
Gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT3227982");
Gelöscht : user_pref("CommunityToolbar.ToolbarsList4", "CT3227982");
Gelöscht : user_pref("CommunityToolbar.globalUserId", "3c14d022-e635-4cf0-bf1e-6824773db8a3");
Gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Gelöscht : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3227982");
Gelöscht : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Aug 22 2012 15:03:1[...]
Gelöscht : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Gelöscht : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Aug 23 2012 19:39:35 GMT+020[...]
Gelöscht : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Gelöscht : user_pref("CommunityToolbar.notifications.locale", "en");
Gelöscht : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Gelöscht : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Aug 23 2012 19:39:26 GMT+0200");
Gelöscht : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Gelöscht : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Gelöscht : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Gelöscht : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Gelöscht : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Gelöscht : user_pref("CommunityToolbar.notifications.userId", "805bad1b-84f0-4970-a6a6-ffbc3eb34220");
Gelöscht : user_pref("CommunityToolbar.originalHomepage", "about:home");
Gelöscht : user_pref("CommunityToolbar.originalSearchEngine", "Google");
Gelöscht : user_pref("browser.search.defaultenginename", "appbario8 Customized Web Search");
Gelöscht : user_pref("browser.search.defaultthis.engineName", "appbario8 Customized Web Search");
Gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&Sea[...]
Gelöscht : user_pref("browser.search.order.1", "appbario8 Customized Web Search");
Gelöscht : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.InstallationThankYouPage", true);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.InstallationTime", 1344716376);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.searchUserConifrmation", false[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setHomepage", false);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setNewTab", false);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.InstallationUserSettings.setSearch", false);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.active", true);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.addressbar", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG&&appA[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.backgroundver", 5);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.can_run_bg_code", true);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.certdomaininstaller", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.changeprevious", false);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.value", "1344716376");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 [...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.value", "1344716376");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.expiration", "Fri Sep 07 2012 09:[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.value", "%5B%22nonexistantdomain.[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.expiration", "Mon Sep 10 2012 [...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.value", "%22AT%22");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 [...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.value", "1347001124");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 [...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.value", "%221%22");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.value", "%7B%22source_id%2[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.value", "%2214019%22");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.value", "1346219133545");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.value", "%221224%22");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.value", "%2266354%22");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.value", "1346047899383");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.description", "Savings Sidekick");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.domain", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.enablesearch", false);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.fbremoteurl", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.group", 0);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.homepage", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.iframe", false);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.expiration", "Fri Feb 0[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.InstallerIdentifiers.value", "%7B%22installe[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.value", "28");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.expiration", "Fri Feb [...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.value", "0");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.value", "%7B%7D");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.expiration", "Fri Sep 07[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.value", "true");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.value", "%7B%7D");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.expiration", "Fri[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.value", "%7B%22re[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.manifesturl", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.name", "Savings Sidekick");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.newtab", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.opensearch", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.code", "appAPI._cr_config={appID:funct[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.name", "base");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.ver", 3);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.ver", 4);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.name", "GPL Background (BG)");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.ver", 2);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.code", "(function(a){a.selectedText=f[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.name", "CrossriderAppUtils");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.ver", 2);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.name", "CrossriderUtils");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.ver", 2);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.code", "(function(f){var u={};var e=M[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.name", "FacebookFFIE");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.ver", 1);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.code", "(function(f,b){if(typeof(b)==[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.name", "FFAppAPIWrapper");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.ver", 3);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.code", "if(typeof window!==\"undefine[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.name", "jQuery");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.ver", 3);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.code", "var CrossriderDebugManager=(f[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.name", "debug");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.ver", 3);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.code", "(function(a){appAPI.queueMana[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.name", "resources");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.ver", 2);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.code", "var CrossriderInitializerPlug[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.name", "initializer");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.ver", 2);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.code", "/*! jQuery v1.7.1 jquery.com |[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.name", "jquery_1_7_1");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.ver", 3);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.code", "(function(){appAPI.ready=func[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.name", "resources_background");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.ver", 1);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_0", "17,14,16,47,1000015");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_1", "17,14,13,16,15,4,1,21,22,100[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...]
Gelöscht : user_pref("extensions.crossriderapp5060.5060.pluginsversion", 10);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.publisher", "215 Apps");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.searchstatus", 0);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.setnewtab", false);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.settingsurl", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.thankyou", "");
Gelöscht : user_pref("extensions.crossriderapp5060.5060.updateinterval", 360);
Gelöscht : user_pref("extensions.crossriderapp5060.5060.ver", 28);
Gelöscht : user_pref("extensions.crossriderapp5060.adsOldValue", -1);
Gelöscht : user_pref("extensions.crossriderapp5060.apps", "5060");
Gelöscht : user_pref("extensions.crossriderapp5060.bic", "13917586ec4693a548be35d47b1da244");
Gelöscht : user_pref("extensions.crossriderapp5060.cid", 5060);
Gelöscht : user_pref("extensions.crossriderapp5060.firstrun", false);
Gelöscht : user_pref("extensions.crossriderapp5060.hadappinstalled", true);
Gelöscht : user_pref("extensions.crossriderapp5060.installationdate", 1344716435);
Gelöscht : user_pref("extensions.crossriderapp5060.lastcheck", 22449947);
Gelöscht : user_pref("extensions.crossriderapp5060.lastcheckitem", 22450019);
Gelöscht : user_pref("extensions.crossriderapp5060.modetype", "production");
Gelöscht : user_pref("extensions.enabledAddons", "{0cc09160-108c-4759-bab1-5c12c216e005}:3.15.1.0,crossriderapp[...]
Gelöscht : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&SearchSource=2&q=[...]

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [44734 octets] - [05/09/2012 16:34:56]
AdwCleaner[R2].txt - [42386 octets] - [06/09/2012 18:31:14]
AdwCleaner[R3].txt - [42447 octets] - [06/09/2012 18:31:33]
AdwCleaner[R4].txt - [42391 octets] - [07/09/2012 08:59:34]
AdwCleaner[S1].txt - [42602 octets] - [07/09/2012 09:00:09]

########## EOF - C:\AdwCleaner[S1].txt - [42663 octets] ##########


cosinus 07.09.2012 12:59

Lass das sein! Dieser Browser-Schutz ist völlig überbewertet!

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

v-man0815 07.09.2012 13:59

... die Antwort auf 1): ja, auf 2): nein!

cosinus 10.09.2012 11:54

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


v-man0815 12.09.2012 12:34

OK. … soll ich eigentlich nach dem scan auch „cleanen“?


OTL Logfile:
Code:

OTL logfile created on: 12.09.2012 11:18:56 - Run 1
OTL by OldTimer - Version 3.2.61.3    Folder = C:\Users\superaze\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
5,95 Gb Total Physical Memory | 4,24 Gb Available Physical Memory | 71,26% Memory free
11,90 Gb Paging File | 9,22 Gb Available in Paging File | 77,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 291,24 Gb Total Space | 242,36 Gb Free Space | 83,22% Space Free | Partition Type: NTFS
Drive D: | 15,18 Gb Total Space | 1,65 Gb Free Space | 10,90% Space Free | Partition Type: NTFS
 
Computer Name: SUPERAZE-HP | User Name: superaze | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\superaze\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (HP)
PRC - C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP)
PRC - C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (HP)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS)
PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS)
PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\b1acb6d21dd13ae76f360354dc8f8de3\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e2ed613308593613ac154671c7549c26\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (!SASCORE) -- C:\Programme\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (vpnagent) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (STacSV) -- C:\Programme\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (FPLService) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (HP)
SRV - (hpCMSrv) -- C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (HPWMISVC) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (HPClientSvc) -- C:\Programme\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) -- C:\Programme\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (vpnva) -- C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (intelkmd) -- C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (cpuz135) -- C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SynasUSB) -- C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft)
DRV - (SASDIFSV) -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Programme\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCON/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{098733A3-52AE-4F51-8936-59A44140F3EB}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCON/1
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{098733A3-52AE-4F51-8936-59A44140F3EB}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCON/1
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes,bProtectorDefaultScope = {847150B3-D27F-486D-BA04-F79F117F4C5C}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{098733A3-52AE-4F51-8936-59A44140F3EB}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{847150B3-D27F-486D-BA04-F79F117F4C5C}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3227980
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{B3659E37-90D9-41E5-952F-3512AC16808F}: "URL" = hxxp://at.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/"
FF - prefs.js..extensions.enabledAddons: crossriderapp5060@crossrider.com:0.83.28
FF - prefs.js..extensions.enabledAddons: specialsavings@superfish.com:1.2.0.14
FF - prefs.js..keyword.URL: "hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q="
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.2.72: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.2.72: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.2.72: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.26 15:16:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.03.31 21:51:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.04.01 21:42:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.08 10:41:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.09.08 10:41:52 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.26 15:16:11 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\specialsavings@superfish.com: C:\Users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles/zbd7w197.default\extensions\specialsavings@superfish.com [2012.09.12 10:51:50 | 000,000,000 | ---D | M]
 
[2011.11.24 12:59:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\superaze\AppData\Roaming\mozilla\Extensions
[2012.01.17 12:22:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\dxvxtbh3.default\extensions
[2012.07.01 09:48:33 | 000,000,000 | ---D | M] (@@toolbarname@@) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\dxvxtbh3.default\extensions\toolbar@ask.com
[2012.09.08 10:11:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\zbd7w197.default\extensions
[2012.09.02 11:07:02 | 000,000,000 | ---D | M] ("Savings Sidekick") -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\zbd7w197.default\extensions\crossriderapp5060@crossrider.com
[2012.09.12 10:51:50 | 000,000,000 | ---D | M] (SpecialSavings) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\zbd7w197.default\extensions\specialsavings@superfish.com
[2012.08.21 11:53:26 | 000,000,921 | ---- | M] () -- C:\Users\superaze\AppData\Roaming\mozilla\firefox\profiles\zbd7w197.default\searchplugins\bProtect.xml
[2012.09.07 19:27:38 | 000,002,401 | ---- | M] () -- C:\Users\superaze\AppData\Roaming\mozilla\firefox\profiles\zbd7w197.default\searchplugins\Web Search.xml
[2012.09.08 10:41:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.08 10:41:51 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.09.08 10:41:51 | 000,000,000 | ---D | M] (TrueSuite Website Logon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com
[2012.09.08 10:41:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2012.09.08 10:41:54 | 000,260,576 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.06.21 12:16:10 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2000.01.01 04:00:00 | 000,170,080 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2012.08.24 20:37:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.24 20:37:18 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.24 20:37:18 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.24 20:37:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.24 20:37:18 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.24 20:37:18 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Simple Pass 2011 (Enabled) = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe\1.0_0\npwebsitelogon.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Website Logon = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe\1.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SpecialSavings) - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O2 - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0cc09160-108c-4759-bab1-5c12c216e005} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SpywareTerminatorShield] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe File not found
O4:64bit: - HKLM..\Run: [SpywareTerminatorUpdater] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe File not found
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-684552159-775688101-1027930909-1001..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: SpecialSavings - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} https://vpn.uibk.ac.at/CACHE/stc/1/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A6FFB0A5-E400-4E52-A883-EB102CF9A644}: DhcpNameServer = 10.0.0.138 10.0.0.138
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~3\pcperf~1\22558~1.177\{16cdf~1\%prote~1.dll) -  File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.09.12 10:51:10 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\superaze\Desktop\OTL-neu.exe
[2012.09.12 08:35:37 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{32627817-D74F-44C7-B922-6E1395E6C40C}
[2012.09.11 19:41:40 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{E61DDEBF-6ADB-432F-BAFB-890C00364716}
[2012.09.11 07:06:18 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{31FA53F8-6C7E-40F0-858A-5BCE7F3FE03B}
[2012.09.10 08:59:29 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{6DE5FA07-2891-43E0-AB0D-A8AE7B542256}
[2012.09.09 20:59:18 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{8068CF4D-7B2B-4D36-8F33-E09BEFA07AED}
[2012.09.09 08:59:07 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{14CF631A-9D3E-4657-A2A4-718DB77789F3}
[2012.09.08 10:41:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012.09.08 09:00:36 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{B5D1C3EB-096F-4FE4-BE71-9271F5AB567A}
[2012.09.07 19:26:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pdfforge
[2012.09.07 19:26:26 | 000,000,000 | ---D | C] -- C:\Program Files\pdfforge
[2012.09.07 16:31:43 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Roaming\pdfforge
[2012.09.07 08:05:52 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{8FA9938C-EAF5-4C14-AA13-E065EEE09CEB}
[2012.09.06 20:05:28 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{223ABC41-2C78-46F7-8CFE-7AD354159EC4}
[2012.09.06 07:54:47 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{C7A4316A-8639-423C-9DB5-5079A3E57E58}
[2012.09.05 10:36:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.09.05 09:16:44 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{D08A272C-FC4C-4B4D-B332-0019F7BB72DF}
[2012.09.04 08:37:30 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{C13170D1-6CA7-4323-9EB5-BF0312CCF523}
[2012.09.03 09:38:05 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{7F10ED1E-14DD-4DBA-8178-1E197DABC9F5}
[2012.09.03 07:50:19 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012.09.02 20:30:20 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{FC22BC8E-24B4-4254-928E-4C2BE495F2AF}
[2012.09.02 11:22:31 | 000,021,992 | ---- | C] (CPUID) -- C:\Windows\SysNative\drivers\cpuz135_x64.sys
[2012.09.02 11:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2012.09.02 11:22:30 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2012.09.02 08:29:56 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{B1A9C564-B317-4BA1-B80A-1143C53A6E9D}
[2012.09.01 20:29:45 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{D0412745-2FD7-40E5-A0B9-49298B616659}
[2012.09.01 08:28:48 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{268C95FC-A701-496A-AF44-19E62E6F59E2}
[2012.08.31 08:31:07 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{A9131340-6364-427B-BB78-D8420BD089AA}
[2012.08.30 19:59:27 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{AD02EA2C-29E9-4BCE-B5F4-CB37C7C33EBA}
[2012.08.30 07:46:19 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{CA3FB100-2ECF-459F-97C7-4DD8CC8CF751}
[2012.08.29 19:45:55 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{DDA40914-6259-4B80-BD25-D9B41EEB0DB9}
[2012.08.29 07:43:32 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{099D1874-6A8C-4053-8335-7AB7EAAF71DC}
[2012.08.28 07:43:41 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{AEB1327C-A65D-4DBC-8DC5-7994C77F0602}
[2012.08.27 10:09:31 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{A8ECC894-B186-451B-BBA5-BAA14F5EAA43}
[2012.08.26 20:56:18 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{02365A84-6785-4D89-8C1F-44D8464386A8}
[2012.08.26 08:56:06 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{C302DF96-B036-42C8-9B6C-6FAF8E145B68}
[2012.08.25 08:33:53 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{78AADC20-5BFF-41CE-8E29-EE425819C433}
[2012.08.24 19:52:35 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{6ECADD43-2910-428F-9482-B6B64F4944B8}
[2012.08.24 07:52:23 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{1D839C5E-372E-4BAF-BF92-CC1AA145333F}
[2012.08.23 12:39:16 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{BF097EC1-1180-4698-97DE-C06B5B30E410}
[2012.08.22 12:59:59 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{1DDA42FD-D7FD-41D3-B7AD-EA88FDD1794A}
[2012.08.21 22:23:27 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{49D28650-43E7-4A6B-A661-088207045534}
[2012.08.19 21:57:43 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{7526FCFF-B263-4D5D-B2C9-F9757FC0056E}
[2012.08.17 21:44:32 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{5530647D-6D83-44B7-917C-89DFD8CAC8D5}
[2012.08.17 21:44:20 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{24704F23-C68F-4FFA-A548-2CAD380B7618}
[2012.08.14 14:59:49 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{6F25BC42-F8BE-42AE-B8EB-8BA3D21363F0}
[2012.08.14 14:59:38 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{99FFF2DF-096D-4396-BE73-4C35ADC29CD2}
[2012.08.13 16:26:55 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{59399C36-D307-4260-83E4-90D838491078}
[2012.08.13 16:26:45 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{1518C25A-F4D7-4561-9D91-5178CFF7F102}
 
========== Files - Modified Within 30 Days ==========
 
[2012.09.12 10:53:00 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.12 10:51:34 | 000,000,126 | ---- | M] () -- C:\Users\superaze\Desktop\OTL.url
[2012.09.12 10:51:10 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\superaze\Desktop\OTL-neu.exe
[2012.09.12 10:26:41 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.09.12 10:26:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.09.11 19:41:55 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.10 17:30:33 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.10 17:30:33 | 000,654,400 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.10 17:30:33 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.10 17:30:33 | 000,130,240 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.10 17:30:33 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.09 16:22:39 | 000,951,544 | ---- | M] () -- C:\Users\superaze\Desktop\Brain's Modality-Specific Systems Dr_ Lawrence Barsalou - YouTube.mht
[2012.09.09 09:04:44 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.09.09 09:04:44 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.09.09 08:55:10 | 495,865,855 | -HS- | M] () -- C:\hiberfil.sys
[2012.09.07 19:26:27 | 000,000,991 | ---- | M] () -- C:\Users\Public\Desktop\PDFArchitect.lnk
[2012.09.07 08:59:18 | 000,511,265 | ---- | M] () -- C:\Users\superaze\Desktop\adwcleaner(1).exe
[2012.09.02 11:22:31 | 000,000,930 | ---- | M] () -- C:\Users\Public\Desktop\CPUID HWMonitor.lnk
[2012.09.01 16:00:12 | 000,428,410 | ---- | M] () -- C:\Users\superaze\Desktop\Marinoa &  Gallesea & Buccinoc & Riggio - Language sensorimotor specificity modulates the motor system_2012.pdf
[2012.09.01 08:57:19 | 004,093,131 | ---- | M] () -- C:\Users\superaze\Desktop\Claxton - Progression in Creativity - developing new forms of assessment_2012.pdf
[2012.08.31 16:51:09 | 000,006,443 | ---- | M] () -- C:\Users\superaze\Desktop\Studienbestätigungen für Martin Woznica.pdf
[2012.08.26 12:07:01 | 001,196,870 | ---- | M] () -- C:\Users\superaze\Desktop\Dekubitus--Entstehung-Prophylaxe-und-Versorgung.pdf
[2012.08.17 22:02:45 | 000,442,792 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.08.13 21:37:45 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForsuperaze.job
 
========== Files Created - No Company Name ==========
 
[2012.09.12 10:51:34 | 000,000,126 | ---- | C] () -- C:\Users\superaze\Desktop\OTL.url
[2012.09.09 16:22:37 | 000,951,544 | ---- | C] () -- C:\Users\superaze\Desktop\Brain's Modality-Specific Systems Dr_ Lawrence Barsalou - YouTube.mht
[2012.09.07 19:26:27 | 000,000,991 | ---- | C] () -- C:\Users\Public\Desktop\PDFArchitect.lnk
[2012.09.07 08:59:13 | 000,511,265 | ---- | C] () -- C:\Users\superaze\Desktop\adwcleaner(1).exe
[2012.09.02 11:22:31 | 000,000,930 | ---- | C] () -- C:\Users\Public\Desktop\CPUID HWMonitor.lnk
[2012.09.01 09:15:29 | 000,428,410 | ---- | C] () -- C:\Users\superaze\Desktop\Marinoa &  Gallesea & Buccinoc & Riggio - Language sensorimotor specificity modulates the motor system_2012.pdf
[2012.09.01 08:57:14 | 004,093,131 | ---- | C] () -- C:\Users\superaze\Desktop\Claxton - Progression in Creativity - developing new forms of assessment_2012.pdf
[2012.08.31 16:51:09 | 000,006,443 | ---- | C] () -- C:\Users\superaze\Desktop\Studienbestätigungen für Martin Woznica.pdf
[2012.08.26 12:07:01 | 001,196,870 | ---- | C] () -- C:\Users\superaze\Desktop\Dekubitus--Entstehung-Prophylaxe-und-Versorgung.pdf
[2012.08.11 22:18:39 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2012.08.11 22:18:39 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2012.08.11 22:18:39 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2012.08.11 22:18:39 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\serauth2.dll
[2012.08.11 22:18:39 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\serauth1.dll
[2012.08.11 22:18:39 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\nsprs.dll
[2012.08.11 21:54:38 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2012.08.11 21:54:38 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2012.04.14 22:02:11 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012.02.26 15:23:01 | 000,000,575 | ---- | C] () -- C:\Windows\hpwmdl21.dat.temp
[2012.02.26 15:12:40 | 000,251,947 | ---- | C] () -- C:\Windows\hpwins21.dat
[2012.02.26 15:12:40 | 000,000,575 | ---- | C] () -- C:\Windows\hpwmdl21.dat
[2011.12.09 10:13:33 | 000,000,051 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe.cfg
[2011.12.04 10:15:33 | 000,002,892 | ---- | C] () -- C:\Windows\SysWow64\audcon.sys
[2011.12.04 10:14:25 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe
[2011.12.01 11:22:00 | 000,000,176 | ---- | C] () -- C:\Users\superaze\AppData\Roaming\burnaware.ini
[2011.10.07 11:53:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.10.07 11:44:02 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2011.10.07 11:42:45 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.10.07 11:42:42 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.10.07 11:42:42 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.10.07 11:42:41 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.10.07 11:38:02 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.06.21 12:14:44 | 000,000,068 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2011.02.22 16:40:34 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL
[2010.12.17 04:26:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
 
========== LOP Check ==========
 
[2012.06.26 20:50:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\calibre
[2012.06.22 08:34:08 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Canneverbe Limited
[2012.08.31 20:22:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\FileZilla
[2011.11.30 13:12:55 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\ImgBurn
[2012.07.25 14:17:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\KompoZer
[2011.11.25 11:35:02 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\OpenOffice.org
[2012.09.07 16:31:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\pdfforge
[2011.12.27 19:23:11 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Scribus
[2011.11.24 12:52:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Synaptics
[2011.12.13 22:37:59 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Waves Audio
[2011.11.24 15:56:24 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Windows Live Writer
[2012.03.15 11:02:08 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.04.23 10:46:17 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Adobe
[2011.12.04 12:53:15 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\AdobeAUM
[2011.12.04 12:53:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\AdobeUM
[2011.11.24 20:13:51 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Apple Computer
[2011.11.24 12:53:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\ATI
[2011.11.24 13:15:50 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Avira
[2012.06.26 20:50:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\calibre
[2012.06.22 08:34:08 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Canneverbe Limited
[2012.02.10 14:05:33 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\CyberLink
[2012.06.01 14:04:25 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\DivX
[2012.08.31 20:22:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\FileZilla
[2012.06.16 12:07:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Hewlett-Packard
[2012.04.08 16:20:19 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\HP
[2011.11.24 12:52:51 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\hpqlog
[2012.05.14 07:57:46 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\HpUpdate
[2011.11.24 12:52:20 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Identities
[2011.11.30 13:12:55 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\ImgBurn
[2011.11.24 12:52:44 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Intel Corporation
[2012.07.25 14:17:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\KompoZer
[2011.11.24 12:54:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Macromedia
[2011.11.24 13:42:18 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Malwarebytes
[2011.10.07 21:33:40 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Media Center Programs
[2012.08.31 20:22:44 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Media Player Classic
[2012.09.08 10:11:24 | 000,000,000 | --SD | M] -- C:\Users\superaze\AppData\Roaming\Microsoft
[2011.11.24 12:59:16 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Mozilla
[2012.05.29 11:35:29 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\NCH Software
[2011.11.25 11:35:02 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\OpenOffice.org
[2012.09.07 16:31:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\pdfforge
[2012.05.25 09:56:30 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Real
[2011.11.30 13:44:27 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\RealNetworks
[2011.12.27 19:23:11 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Scribus
[2012.08.31 20:22:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Skype
[2011.11.24 13:37:57 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\SUPERAntiSpyware.com
[2011.11.24 12:52:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Synaptics
[2011.12.13 22:37:59 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Waves Audio
[2011.11.24 15:56:24 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Windows Live Writer
 
< %APPDATA%\*.exe /s >
[2011.11.26 09:52:39 | 000,617,472 | ---- | M] () -- C:\Users\superaze\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\uno_packages\3FDB.tmp_\oracle-pdfimport.oxt\xpdfimport.exe
[2012.07.18 21:11:14 | 000,315,544 | ---- | M] (RealNetworks, Inc.) -- C:\Users\superaze\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.11\rnupgagent.exe
 
< %SYSTEMDRIVE%\*.exe >
[2008.04.11 08:03:48 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\SWSetup\Drivers\IRST\Drivers\x64\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\drivers\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_a36325196df56f7d\iaStor.sys
[2011.01.13 03:44:08 | 000,355,352 | ---- | M] (Intel Corporation) MD5=F989555F1662581032CCE1578A8FF28E -- C:\SWSetup\Drivers\IRST\Drivers\x32\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 670 bytes -> C:\Users\superaze\Desktop\Verteiler Dienstplan.eml:OECustomProperty

< End of report >

--- --- ---

[/code]

cosinus 12.09.2012 14:34

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - user.js - File not found
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{847150B3-D27F-486D-BA04-F79F117F4C5C}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3227980
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes,bProtectorDefaultScope = {847150B3-D27F-486D-BA04-F79F117F4C5C}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{098733A3-52AE-4F51-8936-59A44140F3EB}: "URL" = http://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{B3659E37-90D9-41E5-952F-3512AC16808F}: "URL" = http://at.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
FF - prefs.js..extensions.enabledAddons: specialsavings@superfish.com:1.2.0.14
FF - prefs.js..keyword.URL: "http://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q="
[2012.07.01 09:48:33 | 000,000,000 | ---D | M] (@@toolbarname@@) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\dxvxtbh3.default\extensions\toolbar@ask.com
[2012.09.12 10:51:50 | 000,000,000 | ---D | M] (SpecialSavings) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\zbd7w197.default\extensions\specialsavings@superfish.com
[2012.08.21 11:53:26 | 000,000,921 | ---- | M] () -- C:\Users\superaze\AppData\Roaming\mozilla\firefox\profiles\zbd7w197.default\searchplugins\bProtect.xml
[2012.09.07 19:27:38 | 000,002,401 | ---- | M] () -- C:\Users\superaze\AppData\Roaming\mozilla\firefox\profiles\zbd7w197.default\searchplugins\Web Search.xml
[2012.09.08 10:41:51 | 000,000,000 | ---D | M] (TrueSuite Website Logon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0cc09160-108c-4759-bab1-5c12c216e005} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [SpywareTerminatorShield] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe File not found
O4:64bit: - HKLM..\Run: [SpywareTerminatorUpdater] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe File not found
O4 - HKLM..\Run: []  File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O20 - AppInit_DLLs: (c:\progra~3\pcperf~1\22558~1.177\{16cdf~1\%prote~1.dll) -  File not found
O32 - HKLM CDRom: AutoRun - 1
:Files
C:\Program Files (x86)\Common Files\Spigot
C:\Users\superaze\Downloads\FPDownloadManager.exe
C:\Users\superaze\Downloads\PDFCreator-1_2_3_setup.exe
C:\Users\superaze\Downloads\SoftonicDownloader_fuer_ibm-spss-statistics-standard.exe
C:\Users\superaze\Downloads\SweetImSetup.exe
c:\progra~3\pcperf~1
C:\Users\superaze\AppData\Local\{*
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

v-man0815 12.09.2012 17:12

… „wenn Du nach dem Fixen auf ok klickst“ – ich habe nirgends nach dem Fixen auf OK klicken können?
Der Rechner wurde (von selbst/OldTimer) neu gestartet.

Hier die Datei:

Code:



Files\Folders moved on Reboot...
C:\Users\superaze\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


War das jetzt alles so weit richtig?

Kann es sein, FireFox jetzt nicht mehr richtig funktioniert? Manche Seiten (z.B. die der FAZ) werden im FireFox nur noch unvollständig angezeigt - während im Explorer alles funktioniert.

cosinus 12.09.2012 20:17

Das Log ist leider unvollständig

v-man0815 13.09.2012 17:15

Diesmal musste ich nach dem Fixen tatsächlich auf ok klicken, bevor das System neu gestartet wurde.
Das war beim ersten Mal nicht der Fall – irgendwie hatte sich System von selbst neu gestartet (oder abgestürzt?).
Jedenfalls sieht die Log-Datei nun anders aus:

Code:



All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{847150B3-D27F-486D-BA04-F79F117F4C5C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{847150B3-D27F-486D-BA04-F79F117F4C5C}\ not found.
HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ not found.
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{098733A3-52AE-4F51-8936-59A44140F3EB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{098733A3-52AE-4F51-8936-59A44140F3EB}\ not found.
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{B3659E37-90D9-41E5-952F-3512AC16808F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3659E37-90D9-41E5-952F-3512AC16808F}\ not found.
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found.
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found.
Registry key HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.
Prefs.js: specialsavings@superfish.com:1.2.0.14 removed from extensions.enabledAddons
Prefs.js: "hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=AT&userid=df50e6c2-0f5f-4baf-8b6f-b2696b0b6399&searchtype=ds&q=" removed from keyword.URL
Folder C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\dxvxtbh3.default\extensions\toolbar@ask.com\ not found.
Folder C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\zbd7w197.default\extensions\specialsavings@superfish.com\ not found.
File C:\Users\superaze\AppData\Roaming\mozilla\firefox\profiles\zbd7w197.default\searchplugins\bProtect.xml not found.
File C:\Users\superaze\AppData\Roaming\mozilla\firefox\profiles\zbd7w197.default\searchplugins\Web Search.xml not found.
C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\components folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\chrome\skin folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\chrome\content folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\chrome folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com folder moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0cc09160-108c-4759-bab1-5c12c216e005} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0cc09160-108c-4759-bab1-5c12c216e005}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}\ not found.
Registry value HKEY_USERS\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorShield not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorUpdater not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\EnableShellExecuteHooks not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~3\pcperf~1\22558~1.177\{16cdf~1\%prote~1.dll deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
========== FILES ==========
File\Folder C:\Program Files (x86)\Common Files\Spigot not found.
File\Folder C:\Users\superaze\Downloads\FPDownloadManager.exe not found.
File\Folder C:\Users\superaze\Downloads\PDFCreator-1_2_3_setup.exe not found.
File\Folder C:\Users\superaze\Downloads\SoftonicDownloader_fuer_ibm-spss-statistics-standard.exe not found.
File\Folder C:\Users\superaze\Downloads\SweetImSetup.exe not found.
File\Folder c:\progra~3\pcperf~1 not found.
C:\Users\superaze\AppData\Local\{8B9FD3F5-AB86-462B-AA33-928FE8C9DBF0} folder moved successfully.
C:\Users\superaze\AppData\Local\{CE18E388-EE8B-44CF-88D4-112123960701} folder moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\superaze\Desktop\cmd.bat deleted successfully.
C:\Users\superaze\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: superaze
->Temp folder emptied: 1839116 bytes
->Temporary Internet Files folder emptied: 72219476 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 141219559 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 3218 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 27699712 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67899 bytes
RecycleBin emptied: 150723148 bytes
 
Total Files Cleaned = 376,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.61.3 log created on 09132012_180438

Files\Folders moved on Reboot...
C:\Users\superaze\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\superaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1D2URVSD\123301-luefter-dreht-hoch-ilivid-3[2].htm moved successfully.
C:\Users\superaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1D2URVSD\ads[6].htm moved successfully.
C:\Users\superaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\superaze\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Es bleibt die Frage nach FireFox. Kann es sein, es jetzt nicht mehr richtig funktioniert? Manche Seiten (z.B. die der FAZ) werden im FireFox nur noch unvollständig angezeigt - während im Explorer alles funktioniert.

cosinus 14.09.2012 10:53

Zitat:

Es bleibt die Frage nach FireFox. Kann es sein, es jetzt nicht mehr richtig funktioniert? Manche Seiten (z.B. die der FAZ) werden im FireFox nur noch unvollständig angezeigt - während im Explorer alles funktioniert.
Erstell dir mal ein neues Profil und teste => Firefox-Profile erstellen und löschen | Anleitung | Firefox-Hilfe

Aber mit oberster Prio sollten wir erstmal sichergehen, dass der Rechner wieder sauber ist - dann kannst du dich um FF und anderer Probleme kümmern

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

v-man0815 14.09.2012 19:33

Das mit dem FireFox habe ich durch einen Neuinstallation geregelt …


Hier die TDSS-Killer Datei:

Code:



20:28:31.0671 3192  TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
20:28:31.0811 3192  ============================================================
20:28:31.0811 3192  Current date / time: 2012/09/14 20:28:31.0811
20:28:31.0811 3192  SystemInfo:
20:28:31.0811 3192 
20:28:31.0811 3192  OS Version: 6.1.7601 ServicePack: 1.0
20:28:31.0811 3192  Product type: Workstation
20:28:31.0811 3192  ComputerName: SUPERAZE-HP
20:28:31.0811 3192  UserName: superaze
20:28:31.0811 3192  Windows directory: C:\Windows
20:28:31.0811 3192  System windows directory: C:\Windows
20:28:31.0811 3192  Running under WOW64
20:28:31.0811 3192  Processor architecture: Intel x64
20:28:31.0811 3192  Number of processors: 4
20:28:31.0811 3192  Page size: 0x1000
20:28:31.0811 3192  Boot type: Normal boot
20:28:31.0811 3192  ============================================================
20:28:32.0264 3192  Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:28:32.0264 3192  ============================================================
20:28:32.0264 3192  \Device\Harddisk0\DR0:
20:28:32.0264 3192  MBR partitions:
20:28:32.0264 3192  Initialize success
20:28:32.0264 3192  ============================================================
20:29:31.0325 3940  ============================================================
20:29:31.0325 3940  Scan started
20:29:31.0325 3940  Mode: Manual; SigCheck; TDLFS;
20:29:31.0325 3940  ============================================================
20:29:31.0372 3940  ================ Scan system memory ========================
20:29:31.0372 3940  System memory - ok
20:29:31.0372 3940  ================ Scan services =============================
20:29:31.0388 3940  !SASCORE - ok
20:29:31.0450 3940  1394ohci - ok
20:29:31.0466 3940  Accelerometer - ok
20:29:31.0466 3940  ACPI - ok
20:29:31.0466 3940  AcpiPmi - ok
20:29:31.0513 3940  AdobeFlashPlayerUpdateSvc - ok
20:29:31.0528 3940  adp94xx - ok
20:29:31.0528 3940  adpahci - ok
20:29:31.0544 3940  adpu320 - ok
20:29:31.0559 3940  AeLookupSvc - ok
20:29:31.0559 3940  AESTFilters - ok
20:29:31.0575 3940  AFD - ok
20:29:31.0591 3940  agp440 - ok
20:29:31.0591 3940  ALG - ok
20:29:31.0606 3940  aliide - ok
20:29:31.0622 3940  AMD External Events Utility - ok
20:29:31.0622 3940  amdide - ok
20:29:31.0637 3940  AmdK8 - ok
20:29:31.0637 3940  amdkmdag - ok
20:29:31.0669 3940  amdkmdap - ok
20:29:31.0669 3940  AmdPPM - ok
20:29:31.0669 3940  amdsata - ok
20:29:31.0684 3940  amdsbs - ok
20:29:31.0684 3940  amdxata - ok
20:29:31.0684 3940  AntiVirSchedulerService - ok
20:29:31.0700 3940  AntiVirService - ok
20:29:31.0715 3940  AntiVirWebService - ok
20:29:31.0715 3940  AppID - ok
20:29:31.0731 3940  AppIDSvc - ok
20:29:31.0731 3940  Appinfo - ok
20:29:31.0731 3940  arc - ok
20:29:31.0747 3940  arcsas - ok
20:29:31.0762 3940  AsyncMac - ok
20:29:31.0762 3940  atapi - ok
20:29:31.0778 3940  AudioEndpointBuilder - ok
20:29:31.0778 3940  AudioSrv - ok
20:29:31.0793 3940  avgntflt - ok
20:29:31.0793 3940  avipbb - ok
20:29:31.0793 3940  avkmgr - ok
20:29:31.0809 3940  AxInstSV - ok
20:29:31.0825 3940  b06bdrv - ok
20:29:31.0825 3940  b57nd60a - ok
20:29:31.0840 3940  BCM43XX - ok
20:29:31.0840 3940  BDESVC - ok
20:29:31.0840 3940  Beep - ok
20:29:31.0871 3940  BFE - ok
20:29:31.0871 3940  BITS - ok
20:29:31.0871 3940  blbdrive - ok
20:29:31.0871 3940  bowser - ok
20:29:31.0887 3940  BrFiltLo - ok
20:29:31.0887 3940  BrFiltUp - ok
20:29:31.0887 3940  Browser - ok
20:29:31.0903 3940  Brserid - ok
20:29:31.0903 3940  BrSerWdm - ok
20:29:31.0903 3940  BrUsbMdm - ok
20:29:31.0903 3940  BrUsbSer - ok
20:29:31.0918 3940  BTHMODEM - ok
20:29:31.0934 3940  bthserv - ok
20:29:31.0934 3940  cdfs - ok
20:29:31.0934 3940  cdrom - ok
20:29:31.0949 3940  CertPropSvc - ok
20:29:31.0965 3940  circlass - ok
20:29:31.0965 3940  CLFS - ok
20:29:31.0965 3940  clr_optimization_v2.0.50727_32 - ok
20:29:31.0965 3940  clr_optimization_v2.0.50727_64 - ok
20:29:32.0012 3940  clr_optimization_v4.0.30319_32 - ok
20:29:32.0012 3940  clr_optimization_v4.0.30319_64 - ok
20:29:32.0027 3940  clwvd - ok
20:29:32.0043 3940  CmBatt - ok
20:29:32.0043 3940  cmdide - ok
20:29:32.0059 3940  CNG - ok
20:29:32.0059 3940  Compbatt - ok
20:29:32.0074 3940  CompositeBus - ok
20:29:32.0074 3940  COMSysApp - ok
20:29:32.0121 3940  cpuz135 - ok
20:29:32.0137 3940  crcdisk - ok
20:29:32.0152 3940  CryptSvc - ok
20:29:32.0152 3940  DcomLaunch - ok
20:29:32.0152 3940  defragsvc - ok
20:29:32.0168 3940  DfsC - ok
20:29:32.0168 3940  Dhcp - ok
20:29:32.0168 3940  discache - ok
20:29:32.0199 3940  Disk - ok
20:29:32.0199 3940  Dnscache - ok
20:29:32.0199 3940  dot3svc - ok
20:29:32.0230 3940  Dot4 - ok
20:29:32.0230 3940  Dot4Print - ok
20:29:32.0230 3940  dot4usb - ok
20:29:32.0246 3940  DPS - ok
20:29:32.0246 3940  drmkaud - ok
20:29:32.0246 3940  DXGKrnl - ok
20:29:32.0246 3940  EapHost - ok
20:29:32.0246 3940  ebdrv - ok
20:29:32.0261 3940  EFS - ok
20:29:32.0277 3940  ehRecvr - ok
20:29:32.0277 3940  ehSched - ok
20:29:32.0293 3940  elxstor - ok
20:29:32.0293 3940  ErrDev - ok
20:29:32.0308 3940  EventSystem - ok
20:29:32.0308 3940  exfat - ok
20:29:32.0324 3940  ezSharedSvc - ok
20:29:32.0339 3940  fastfat - ok
20:29:32.0339 3940  Fax - ok
20:29:32.0339 3940  fdc - ok
20:29:32.0355 3940  fdPHost - ok
20:29:32.0355 3940  FDResPub - ok
20:29:32.0355 3940  FileInfo - ok
20:29:32.0355 3940  Filetrace - ok
20:29:32.0371 3940  flpydisk - ok
20:29:32.0371 3940  FltMgr - ok
20:29:32.0371 3940  FontCache - ok
20:29:32.0386 3940  FontCache3.0.0.0 - ok
20:29:32.0402 3940  FPLService - ok
20:29:32.0402 3940  FsDepends - ok
20:29:32.0402 3940  Fs_Rec - ok
20:29:32.0402 3940  fvevol - ok
20:29:32.0417 3940  gagp30kx - ok
20:29:32.0417 3940  gpsvc - ok
20:29:32.0433 3940  gupdate - ok
20:29:32.0433 3940  gupdatem - ok
20:29:32.0449 3940  hcw85cir - ok
20:29:32.0449 3940  HdAudAddService - ok
20:29:32.0464 3940  HDAudBus - ok
20:29:32.0464 3940  HidBatt - ok
20:29:32.0464 3940  HidBth - ok
20:29:32.0480 3940  HidIr - ok
20:29:32.0480 3940  hidserv - ok
20:29:32.0495 3940  HidUsb - ok
20:29:32.0495 3940  hkmsvc - ok
20:29:32.0495 3940  HomeGroupListener - ok
20:29:32.0495 3940  HomeGroupProvider - ok
20:29:32.0511 3940  HP Health Check Service - ok
20:29:32.0511 3940  HPClientSvc - ok
20:29:32.0527 3940  hpCMSrv - ok
20:29:32.0527 3940  HPDrvMntSvc.exe - ok
20:29:32.0542 3940  hpdskflt - ok
20:29:32.0558 3940  hpqcxs08 - ok
20:29:32.0558 3940  hpqddsvc - ok
20:29:32.0573 3940  hpqwmiex - ok
20:29:32.0589 3940  HpSAMD - ok
20:29:32.0605 3940  HPSLPSVC - ok
20:29:32.0605 3940  hpsrv - ok
20:29:32.0620 3940  HPWMISVC - ok
20:29:32.0620 3940  HTTP - ok
20:29:32.0636 3940  hwpolicy - ok
20:29:32.0636 3940  i8042prt - ok
20:29:32.0651 3940  iaStor - ok
20:29:32.0683 3940  IAStorDataMgrSvc - ok
20:29:32.0683 3940  iaStorV - ok
20:29:32.0729 3940  IDriverT - ok
20:29:32.0729 3940  idsvc - ok
20:29:32.0745 3940  iirsp - ok
20:29:32.0761 3940  IKEEXT - ok
20:29:32.0761 3940  IntcDAud - ok
20:29:32.0761 3940  intelide - ok
20:29:32.0776 3940  intelkmd - ok
20:29:32.0776 3940  intelppm - ok
20:29:32.0792 3940  IPBusEnum - ok
20:29:32.0792 3940  IpFilterDriver - ok
20:29:32.0807 3940  iphlpsvc - ok
20:29:32.0807 3940  IPMIDRV - ok
20:29:32.0807 3940  IPNAT - ok
20:29:32.0823 3940  IRENUM - ok
20:29:32.0823 3940  isapnp - ok
20:29:32.0823 3940  iScsiPrt - ok
20:29:32.0823 3940  kbdclass - ok
20:29:32.0823 3940  kbdhid - ok
20:29:32.0839 3940  KeyIso - ok
20:29:32.0839 3940  KSecDD - ok
20:29:32.0839 3940  KSecPkg - ok
20:29:32.0839 3940  ksthunk - ok
20:29:32.0839 3940  KtmRm - ok
20:29:32.0854 3940  LanmanServer - ok
20:29:32.0854 3940  LanmanWorkstation - ok
20:29:32.0870 3940  lltdio - ok
20:29:32.0870 3940  lltdsvc - ok
20:29:32.0870 3940  lmhosts - ok
20:29:32.0901 3940  LMS - ok
20:29:32.0917 3940  LSI_FC - ok
20:29:32.0917 3940  LSI_SAS - ok
20:29:32.0917 3940  LSI_SAS2 - ok
20:29:32.0932 3940  LSI_SCSI - ok
20:29:32.0932 3940  luafv - ok
20:29:32.0932 3940  MBAMProtector - ok
20:29:32.0948 3940  MBAMScheduler - ok
20:29:32.0963 3940  MBAMService - ok
20:29:32.0963 3940  Mcx2Svc - ok
20:29:32.0963 3940  megasas - ok
20:29:32.0963 3940  MegaSR - ok
20:29:32.0963 3940  MEIx64 - ok
20:29:32.0979 3940  Microsoft SharePoint Workspace Audit Service - ok
20:29:32.0979 3940  MMCSS - ok
20:29:32.0979 3940  Modem - ok
20:29:32.0995 3940  monitor - ok
20:29:32.0995 3940  mouclass - ok
20:29:33.0010 3940  mouhid - ok
20:29:33.0010 3940  mountmgr - ok
20:29:33.0026 3940  MozillaMaintenance - ok
20:29:33.0026 3940  mpio - ok
20:29:33.0026 3940  mpsdrv - ok
20:29:33.0026 3940  MpsSvc - ok
20:29:33.0026 3940  MRxDAV - ok
20:29:33.0026 3940  mrxsmb - ok
20:29:33.0041 3940  mrxsmb10 - ok
20:29:33.0041 3940  mrxsmb20 - ok
20:29:33.0041 3940  msahci - ok
20:29:33.0041 3940  msdsm - ok
20:29:33.0041 3940  MSDTC - ok
20:29:33.0057 3940  Msfs - ok
20:29:33.0057 3940  mshidkmdf - ok
20:29:33.0057 3940  msisadrv - ok
20:29:33.0057 3940  MSiSCSI - ok
20:29:33.0057 3940  msiserver - ok
20:29:33.0073 3940  MSKSSRV - ok
20:29:33.0073 3940  MSPCLOCK - ok
20:29:33.0073 3940  MSPQM - ok
20:29:33.0073 3940  MsRPC - ok
20:29:33.0073 3940  mssmbios - ok
20:29:33.0088 3940  MSTEE - ok
20:29:33.0088 3940  MTConfig - ok
20:29:33.0088 3940  Mup - ok
20:29:33.0088 3940  napagent - ok
20:29:33.0088 3940  NativeWifiP - ok
20:29:33.0104 3940  NDIS - ok
20:29:33.0104 3940  NdisCap - ok
20:29:33.0104 3940  NdisTapi - ok
20:29:33.0104 3940  Ndisuio - ok
20:29:33.0119 3940  NdisWan - ok
20:29:33.0119 3940  NDProxy - ok
20:29:33.0119 3940  Net Driver HPZ12 - ok
20:29:33.0119 3940  NetBIOS - ok
20:29:33.0119 3940  NetBT - ok
20:29:33.0135 3940  Netlogon - ok
20:29:33.0151 3940  Netman - ok
20:29:33.0151 3940  netprofm - ok
20:29:33.0151 3940  NetTcpPortSharing - ok
20:29:33.0166 3940  nfrd960 - ok
20:29:33.0166 3940  NlaSvc - ok
20:29:33.0182 3940  Npfs - ok
20:29:33.0182 3940  nsi - ok
20:29:33.0182 3940  nsiproxy - ok
20:29:33.0197 3940  Ntfs - ok
20:29:33.0197 3940  Null - ok
20:29:33.0213 3940  nusb3hub - ok
20:29:33.0213 3940  nusb3xhc - ok
20:29:33.0213 3940  NVENETFD - ok
20:29:33.0229 3940  nvraid - ok
20:29:33.0229 3940  nvstor - ok
20:29:33.0244 3940  nv_agp - ok
20:29:33.0244 3940  ohci1394 - ok
20:29:33.0260 3940  ose - ok
20:29:33.0275 3940  osppsvc - ok
20:29:33.0275 3940  p2pimsvc - ok
20:29:33.0275 3940  p2psvc - ok
20:29:33.0275 3940  Parport - ok
20:29:33.0291 3940  partmgr - ok
20:29:33.0291 3940  PcaSvc - ok
20:29:33.0291 3940  pci - ok
20:29:33.0291 3940  pciide - ok
20:29:33.0291 3940  pcmcia - ok
20:29:33.0291 3940  pcw - ok
20:29:33.0307 3940  PEAUTH - ok
20:29:33.0307 3940  PerfHost - ok
20:29:33.0307 3940  pla - ok
20:29:33.0322 3940  PlugPlay - ok
20:29:33.0353 3940  Pml Driver HPZ12 - ok
20:29:33.0369 3940  PNRPAutoReg - ok
20:29:33.0369 3940  PNRPsvc - ok
20:29:33.0385 3940  PolicyAgent - ok
20:29:33.0385 3940  Power - ok
20:29:33.0400 3940  PptpMiniport - ok
20:29:33.0400 3940  Processor - ok
20:29:33.0400 3940  ProfSvc - ok
20:29:33.0416 3940  ProtectedStorage - ok
20:29:33.0431 3940  Psched - ok
20:29:33.0431 3940  ql2300 - ok
20:29:33.0447 3940  ql40xx - ok
20:29:33.0447 3940  QWAVE - ok
20:29:33.0447 3940  QWAVEdrv - ok
20:29:33.0463 3940  RasAcd - ok
20:29:33.0463 3940  RasAgileVpn - ok
20:29:33.0463 3940  RasAuto - ok
20:29:33.0478 3940  Rasl2tp - ok
20:29:33.0478 3940  RasMan - ok
20:29:33.0494 3940  RasPppoe - ok
20:29:33.0494 3940  RasSstp - ok
20:29:33.0494 3940  rdbss - ok
20:29:33.0494 3940  rdpbus - ok
20:29:33.0509 3940  RDPCDD - ok
20:29:33.0509 3940  RDPENCDD - ok
20:29:33.0509 3940  RDPREFMP - ok
20:29:33.0509 3940  RDPWD - ok
20:29:33.0525 3940  rdyboost - ok
20:29:33.0525 3940  RemoteAccess - ok
20:29:33.0525 3940  RemoteRegistry - ok
20:29:33.0525 3940  RpcEptMapper - ok
20:29:33.0525 3940  RpcLocator - ok
20:29:33.0525 3940  RpcSs - ok
20:29:33.0541 3940  RSPCIESTOR - ok
20:29:33.0541 3940  rspndr - ok
20:29:33.0556 3940  RTL8167 - ok
20:29:33.0556 3940  SamSs - ok
20:29:33.0556 3940  SASDIFSV - ok
20:29:33.0556 3940  SASKUTIL - ok
20:29:33.0556 3940  sbp2port - ok
20:29:33.0572 3940  SCardSvr - ok
20:29:33.0572 3940  scfilter - ok
20:29:33.0572 3940  Schedule - ok
20:29:33.0572 3940  SCPolicySvc - ok
20:29:33.0572 3940  sdbus - ok
20:29:33.0587 3940  SDRSVC - ok
20:29:33.0587 3940  secdrv - ok
20:29:33.0587 3940  seclogon - ok
20:29:33.0587 3940  SENS - ok
20:29:33.0603 3940  SensrSvc - ok
20:29:33.0603 3940  Serenum - ok
20:29:33.0603 3940  Serial - ok
20:29:33.0619 3940  sermouse - ok
20:29:33.0619 3940  SessionEnv - ok
20:29:33.0619 3940  sffdisk - ok
20:29:33.0634 3940  sffp_mmc - ok
20:29:33.0634 3940  sffp_sd - ok
20:29:33.0634 3940  sfloppy - ok
20:29:33.0634 3940  SharedAccess - ok
20:29:33.0634 3940  ShellHWDetection - ok
20:29:33.0650 3940  SiSRaid2 - ok
20:29:33.0650 3940  SiSRaid4 - ok
20:29:33.0665 3940  Skype C2C Service - ok
20:29:33.0665 3940  SkypeUpdate - ok
20:29:33.0681 3940  Smb - ok
20:29:33.0712 3940  SNMPTRAP - ok
20:29:33.0712 3940  spldr - ok
20:29:33.0712 3940  Spooler - ok
20:29:33.0712 3940  sppsvc - ok
20:29:33.0712 3940  sppuinotify - ok
20:29:33.0712 3940  srv - ok
20:29:33.0728 3940  srv2 - ok
20:29:33.0728 3940  SrvHsfHDA - ok
20:29:33.0728 3940  SrvHsfV92 - ok
20:29:33.0743 3940  SrvHsfWinac - ok
20:29:33.0743 3940  srvnet - ok
20:29:33.0759 3940  SSDPSRV - ok
20:29:33.0759 3940  SstpSvc - ok
20:29:33.0759 3940  STacSV - ok
20:29:33.0759 3940  stexstor - ok
20:29:33.0759 3940  STHDA - ok
20:29:33.0775 3940  stisvc - ok
20:29:33.0790 3940  swenum - ok
20:29:33.0790 3940  swprv - ok
20:29:33.0806 3940  SynasUSB - ok
20:29:33.0821 3940  SynTP - ok
20:29:33.0837 3940  SysMain - ok
20:29:33.0853 3940  TabletInputService - ok
20:29:33.0853 3940  TapiSrv - ok
20:29:33.0868 3940  TBS - ok
20:29:33.0868 3940  Tcpip - ok
20:29:33.0868 3940  TCPIP6 - ok
20:29:33.0868 3940  tcpipreg - ok
20:29:33.0884 3940  TDPIPE - ok
20:29:33.0884 3940  TDTCP - ok
20:29:33.0884 3940  tdx - ok
20:29:33.0884 3940  TermDD - ok
20:29:33.0899 3940  TermService - ok
20:29:33.0899 3940  Themes - ok
20:29:33.0899 3940  THREADORDER - ok
20:29:33.0899 3940  TrkWks - ok
20:29:33.0899 3940  TrustedInstaller - ok
20:29:33.0915 3940  tssecsrv - ok
20:29:33.0915 3940  TsUsbFlt - ok
20:29:33.0915 3940  TsUsbGD - ok
20:29:33.0931 3940  tunnel - ok
20:29:33.0931 3940  uagp35 - ok
20:29:33.0946 3940  udfs - ok
20:29:33.0946 3940  UI0Detect - ok
20:29:33.0962 3940  uliagpkx - ok
20:29:33.0962 3940  umbus - ok
20:29:33.0962 3940  UmPass - ok
20:29:33.0962 3940  UNS - ok
20:29:33.0962 3940  upnphost - ok
20:29:33.0977 3940  usbccgp - ok
20:29:33.0993 3940  usbcir - ok
20:29:33.0993 3940  usbehci - ok
20:29:33.0993 3940  usbhub - ok
20:29:33.0993 3940  usbohci - ok
20:29:33.0993 3940  usbprint - ok
20:29:33.0993 3940  USBSTOR - ok
20:29:34.0009 3940  usbuhci - ok
20:29:34.0009 3940  usbvideo - ok
20:29:34.0009 3940  UxSms - ok
20:29:34.0024 3940  VaultSvc - ok
20:29:34.0040 3940  VBoxDrv - ok
20:29:34.0055 3940  VBoxNetAdp - ok
20:29:34.0055 3940  VBoxNetFlt - ok
20:29:34.0071 3940  VBoxUSBMon - ok
20:29:34.0071 3940  vdrvroot - ok
20:29:34.0071 3940  vds - ok
20:29:34.0087 3940  vga - ok
20:29:34.0087 3940  VgaSave - ok
20:29:34.0102 3940  vhdmp - ok
20:29:34.0102 3940  viaide - ok
20:29:34.0118 3940  volmgr - ok
20:29:34.0118 3940  volmgrx - ok
20:29:34.0118 3940  volsnap - ok
20:29:34.0118 3940  vpnagent - ok
20:29:34.0133 3940  vpnva - ok
20:29:34.0149 3940  vsmraid - ok
20:29:34.0149 3940  VSS - ok
20:29:34.0149 3940  vwifibus - ok
20:29:34.0149 3940  vwififlt - ok
20:29:34.0165 3940  W32Time - ok
20:29:34.0165 3940  WacomPen - ok
20:29:34.0165 3940  WANARP - ok
20:29:34.0165 3940  Wanarpv6 - ok
20:29:34.0165 3940  WatAdminSvc - ok
20:29:34.0180 3940  wbengine - ok
20:29:34.0180 3940  WbioSrvc - ok
20:29:34.0180 3940  wcncsvc - ok
20:29:34.0180 3940  WcsPlugInService - ok
20:29:34.0180 3940  Wd - ok
20:29:34.0180 3940  Wdf01000 - ok
20:29:34.0196 3940  WdiServiceHost - ok
20:29:34.0196 3940  WdiSystemHost - ok
20:29:34.0196 3940  WebClient - ok
20:29:34.0196 3940  Wecsvc - ok
20:29:34.0196 3940  wercplsupport - ok
20:29:34.0211 3940  WerSvc - ok
20:29:34.0211 3940  WfpLwf - ok
20:29:34.0211 3940  WIMMount - ok
20:29:34.0211 3940  WinDefend - ok
20:29:34.0211 3940  WinHttpAutoProxySvc - ok
20:29:34.0227 3940  Winmgmt - ok
20:29:34.0227 3940  WinRM - ok
20:29:34.0243 3940  WinUsb - ok
20:29:34.0243 3940  Wlansvc - ok
20:29:34.0243 3940  wlcrasvc - ok
20:29:34.0258 3940  wlidsvc - ok
20:29:34.0258 3940  WmiAcpi - ok
20:29:34.0258 3940  wmiApSrv - ok
20:29:34.0274 3940  WMPNetworkSvc - ok
20:29:34.0274 3940  WPCSvc - ok
20:29:34.0274 3940  WPDBusEnum - ok
20:29:34.0289 3940  ws2ifsl - ok
20:29:34.0289 3940  wscsvc - ok
20:29:34.0305 3940  WSDPrintDevice - ok
20:29:34.0305 3940  WSearch - ok
20:29:34.0305 3940  wuauserv - ok
20:29:34.0305 3940  WudfPf - ok
20:29:34.0321 3940  WUDFRd - ok
20:29:34.0321 3940  wudfsvc - ok
20:29:34.0321 3940  WwanSvc - ok
20:29:34.0336 3940  ================ Scan global ===============================
20:29:34.0336 3940  [Global] - ok
20:29:34.0336 3940  ================ Scan MBR ==================================
20:29:34.0352 3940  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
20:29:34.0695 3940  \Device\Harddisk0\DR0 - ok
20:29:34.0695 3940  ================ Scan VBR ==================================
20:29:34.0695 3940  ============================================================
20:29:34.0695 3940  Scan finished
20:29:34.0695 3940  ============================================================
20:29:34.0711 5656  Detected object count: 0
20:29:34.0711 5656  Actual detected object count: 0


cosinus 14.09.2012 23:06

Wundert mich, denn über 90% der Probleme mit dem Firefox liegen am Benutzerprofil und nicht am Firefox selbst.

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

v-man0815 15.09.2012 10:10

OK, hier die ComboFix-Datei:

Combofix Logfile:
Code:

ComboFix 12-09-14.03 - superaze 15.09.2012  10:48:46.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.43.1031.18.6092.4340 [GMT 2:00]
ausgeführt von:: c:\users\superaze\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\Savings Sidekick
c:\program files (x86)\Savings Sidekick\Savings Sidekick.ico
c:\program files (x86)\Savings Sidekick\Savings Sidekick.ini
c:\program files (x86)\Savings Sidekick\Savings SidekickInstaller.log
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
c:\users\superaze\AppData\Local\Savings Sidekick
c:\users\superaze\AppData\Local\Savings Sidekick\Chrome\Savings Sidekick.crx
c:\windows\IsUn0407.exe
c:\windows\SysWow64\lsprst7.dll
c:\windows\SysWow64\nsprs.dll
c:\windows\SysWow64\serauth1.dll
c:\windows\SysWow64\serauth2.dll
c:\windows\SysWow64\ssprs.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-08-15 bis 2012-09-15  ))))))))))))))))))))))))))))))
.
.
2012-09-15 08:54 . 2012-09-15 08:54        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-09-07 17:26 . 2012-09-07 17:26        --------        d-----w-        c:\program files\pdfforge
2012-09-07 14:31 . 2012-09-07 14:31        --------        d-----w-        c:\users\superaze\AppData\Roaming\pdfforge
2012-09-05 08:36 . 2012-09-05 08:36        --------        d-----w-        c:\program files (x86)\ESET
2012-09-02 09:22 . 2010-11-09 13:35        21992        ----a-w-        c:\windows\system32\drivers\cpuz135_x64.sys
2012-09-02 09:22 . 2012-09-02 09:22        --------        d-----w-        c:\program files\CPUID
2012-08-17 19:45 . 2012-05-05 08:36        503808        ----a-w-        c:\windows\system32\srcore.dll
2012-08-17 19:45 . 2012-05-05 07:46        43008        ----a-w-        c:\windows\SysWow64\srclient.dll
2012-08-17 19:45 . 2012-02-11 06:43        751104        ----a-w-        c:\windows\system32\win32spl.dll
2012-08-17 19:45 . 2012-02-11 06:36        559104        ----a-w-        c:\windows\system32\spoolsv.exe
2012-08-17 19:45 . 2012-02-11 06:36        67072        ----a-w-        c:\windows\splwow64.exe
2012-08-17 19:45 . 2012-02-11 05:43        492032        ----a-w-        c:\windows\SysWow64\win32spl.dll
2012-08-17 19:45 . 2012-07-04 22:13        59392        ----a-w-        c:\windows\system32\browcli.dll
2012-08-17 19:45 . 2012-07-04 22:13        136704        ----a-w-        c:\windows\system32\browser.dll
2012-08-17 19:45 . 2012-07-04 22:16        73216        ----a-w-        c:\windows\system32\netapi32.dll
2012-08-17 19:45 . 2012-07-04 21:14        41984        ----a-w-        c:\windows\SysWow64\browcli.dll
2012-08-17 19:45 . 2012-07-18 18:15        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-08-17 19:45 . 2012-05-14 05:26        956928        ----a-w-        c:\windows\system32\localspl.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-15 08:54 . 2012-09-15 08:54        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{32AF5F4A-E115-4317-B5C8-EF43D522C888}\offreg.dll
2012-09-13 05:39 . 2012-01-26 08:10        64462936        ----a-w-        c:\windows\system32\MRT.exe
2012-09-07 15:04 . 2011-11-24 11:42        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-08-17 20:26 . 2012-04-02 06:28        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-17 20:26 . 2012-01-14 11:30        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-09-08 5663616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-13 283160]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-15 336384]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-02-15 94264]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-11-09 586296]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-15 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2011-03-16 61112]
"HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-01-27 318520]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-03-31 296056]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24 135664]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-17 250056]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24 135664]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-06 114144]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynUSB64.sys [2006-11-16 31248]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2011-11-27 1255736]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-10-19 27760]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-11-04 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-11-04 130864]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-08 140672]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-03-15 203776]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
S2 AntiVirWebService;Avira Browser Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2012-05-08 465360]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992]
S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe [x]
S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-02-17 265544]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-02-28 92216]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-01-26 30520]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-09 26680]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-13 13336]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-22 2656280]
S2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2011-09-22 645048]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-03-15 9259520]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-03-15 301056]
S3 hpCMSrv;HP Connection Manager 4.0 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-02-15 1071160]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-01-27 12273408]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-01-13 333928]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-02-17 428136]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-11-04 146736]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-11-04 165680]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-09-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 20:26]
.
2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24 19:44]
.
2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-24 19:44]
.
2012-09-13 c:\windows\Tasks\HPCeeScheduleForsuperaze.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13 20:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-27 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-27 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-27 418328]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-03-11 1128448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.at/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant =
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\SpecialSavings\SpecialSavingsSinged.dll
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 10.0.0.138 10.0.0.138
DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} - hxxps://vpn.uibk.ac.at/CACHE/stc/1/binaries/vpnweb.cab
FF - ProfilePath - c:\users\superaze\AppData\Roaming\Mozilla\Firefox\Profiles\9od2n9tg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Photoshop 6.0 - c:\windows\ISUN0407.EXE
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-{E92D47A1-D27D-430A-8368-0BAFD956507D} - c:\program files (x86)\InstallShield Installation Information\{E92D47A1-D27D-430A-8368-0BAFD956507D}\setup.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-09-15  10:56:02
ComboFix-quarantined-files.txt  2012-09-15 08:56
.
Vor Suchlauf: 14 Verzeichnis(se), 258.978.545.664 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 258.856.591.360 Bytes frei
.
- - End Of File - - 4F9807CA45C474C289FB7260F5CCBB91

--- --- ---

cosinus 16.09.2012 11:53

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

v-man0815 17.09.2012 21:14

Bei GMER war das Fester leer, wenn ich im Reiter (wie beschrieben) Rootkit/Maleware gewählt hatte. Auch konnte ich längst nicht bei allen Kästchen rechts ein Häkchen setzen.
Anschließend kam die Meldung, dass nichts gefunden wurde – ich kann hierzu also auch keine Log-Datei posten.

>>>
hier das OSAM-Log:
Code:

OSAM Logfile:

       
Code:

       
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 22:10:47 on 17.09.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 15.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"HPCeeScheduleForsuperaze.job" - "Hewlett-Packard" - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"mlcfg32.cpl" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\MLCFG32.CPL
"QuickTime" - "Apple Inc." - C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"cpuz135" (cpuz135) - "CPUID" - C:\Windows\system32\drivers\cpuz135_x64.sys
"CyberLink WebCam Virtual Driver" (clwvd) - ? - C:\Windows\System32\DRIVERS\clwvd.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"SASDIFSV" (SASDIFSV) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
"SASKUTIL" (SASKUTIL) - "SUPERAdBlocker.com and SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
"SynasUSB" (SynasUSB) - "SIA Syncrosoft" - C:\Windows\System32\drivers\SynUSB64.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{B2F55D43-C7A4-4B7C-90D7-7A860DFA9F2A} "PXCInfoShlExt Class" - "Tracker Software Products (Canada) Ltd." - C:\Program Files\Tracker Software\Shell Extensions\win32\XCShInfo.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807573E5-5146-11D5-A672-00B0D022E945} "Microsoft Office InfoPath XML Mime Filter" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{314111c7-a502-11d2-bbca-00c04f8ec294} "HxProtocol Class" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks )-----
{E54729E8-BB3D-4270-9D49-7389EA579090} "EasyBits ShellExecute Hook" - "EasyBits Software Corp." - C:\Windows\SysWow64\EZUPBH~1.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} "Arbeitsbereiche" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{5E2121EE-0300-11D4-8D3B-444553540000} "Catalyst Context Menu extension" - ? -   (File not found | COM-object registry key not found)
{D66DC78C-4F61-447F-942B-3FB6980118CF} "CInfoTipShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll
{83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
{99FD978C-D287-4F50-827F-B2C658EDA8E7} "Groove Explorer Icon Overlay 1 (GFS Unread Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} "Groove Explorer Icon Overlay 2 (GFS Stub)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{920E6DB1-9907-4370-B3A0-BAFC03D81399} "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{16F3DD56-1AF5-4347-846D-7C10C4192619} "Groove Explorer Icon Overlay 3 (GFS Folder)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} "Groove Explorer Icon Overlay 4 (GFS Unread Mark)" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} "Groove Folder Synchronization" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{6C467336-8281-4E60-8204-430CED96822D} "Groove GFS Context Menu Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "Groove GFS Stub Execution Hook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{A449600E-1DC6-4232-B948-9BD794D62056} "Groove GFS Stub Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{387E725D-DC16-4D76-B310-2C93ED4752A0} "Groove XML Icon Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} "ImageExtractorShellExt Class" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} "Microsoft OneNote Namespace Extension for Windows Desktop Search" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL
{00020D75-0000-0000-C000-000000000046} "Microsoft Outlook" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\MLSHEXT.DLL
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{0006F045-0000-0000-C000-000000000046} "Outlook File Icon Extension" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL
{CF822AB4-6DB5-4FDA-BC28-E61DF36D2583} "PDF-XChange PDF Preview Provider" - "Tracker Software Products (Canada) Ltd." - C:\Program Files\Tracker Software\Shell Extensions\win32\XCShInfo.dll
{67EB453C-1BE1-48EC-AAF3-23B10277FCC1} "PDF-XChange PDF Property Handler" - "Tracker Software Products (Canada) Ltd." - C:\Program Files\Tracker Software\Shell Extensions\win32\XCShInfo.dll
{EBD0B8F4-A9A0-41B7-9695-030CD264D9C8} "PDF-XChange PDF Thumbnail Provider" - "Tracker Software Products (Canada) Ltd." - C:\Program Files\Tracker Software\Shell Extensions\win32\XCShInfo.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - c:\program files (x86)\real\realplayer\rpshell.dll
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -   (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
XCShInfo "{B2F55D43-C7A4-4B7C-90D7-7A860DFA9F2A}" - ? -   (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars )-----
{555D4D79-4BD2-4094-A395-CFC534424A05} "HP Smart Web Printing" - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
ITBar7Height64 "ITBar7Height64" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CC679CB8-DC4B-458B-B817-D447B3B6AC31} "Cisco AnyConnect VPN Client Web Control" - "Cisco Systems, Inc." - C:\Windows\SysWow64\vpnweb.ocx / https://vpn.uibk.ac.at/CACHE/stc/1/binaries/vpnweb.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_24" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_24.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101" - ? - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204  (File not found)
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
{48E73304-E1D6-4330-914C-F5F514E3486C} "An OneNote senden" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
{DDE87865-83C5-48c4-8357-2F5B1AA84522} "HP Smart Web Printing ein- oder ausblenden" - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} "SpecialSavings" - "SpecialSavings" - C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll
{FFFDC614-B694-4AE6-AB38-5D6374584B52} "Verknüpfte &OneNote-Notizen" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} "Groove GFS Browser Helper" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
{0347C33E-8762-4905-BF09-768834316C61} "HP Print Enhancer" - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} "HP Smart BHO Class" - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{B4F3A835-0E21-4959-BA22-42B3008E02FF} "Office Document Cache Handler" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
{3049C3E9-B461-4BC5-8870-4C09146192CA} "RealPlayer Download and Record Plugin for Internet Explorer" - "RealPlayer" - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{74F475FA-6C75-43BD-AAB9-ECDA6184F600} "SpecialSavings" - "SpecialSavings" - C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll
{8590886E-EC8C-43C1-A32C-E4C2B0B6395B} "TrueSuite Website Log On" - "HP" - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"HP Digital Imaging Monitor.lnk" - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"SUPERAntiSpyware" - "SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"BCSSync" - "Microsoft Corporation" - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"DivXUpdate" - ? - "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Easybits Recovery" - "EasyBits Software AS" - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
"HP Quick Launch" - "Hewlett-Packard Development Company, L.P." - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
"HP Software Update" - "Hewlett-Packard" - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
"HPConnectionManager" - "Hewlett-Packard Development Company L.P." - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
"HPOSD" - "Hewlett-Packard Development Company, L.P." - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
"IAStorIcon" - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
"NUSB3MON" - "Renesas Electronics Corporation" - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"QuickTime Task" - "Apple Inc." - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"TkBellExe" - "RealNetworks, Inc." - "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe"  -osboot

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"pdfcmon" - "pdfforge GbR" - C:\Windows\system32\pdfcmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
"Avira Browser Schutz" (AntiVirWebService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
"Cisco AnyConnect VPN Agent" (vpnagent) - "Cisco Systems, Inc." - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
"Easybits Services for Windows" (ezSharedSvc) - ? - C:\Windows\System32\ezSharedSvcHost.exe  (File not found)
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
"HP Client Services" (HPClientSvc) - "Hewlett-Packard Company" - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
"HP Connection Manager 4.0 Service" (hpCMSrv) - "Hewlett-Packard Development Company L.P." - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
"HP CUE DeviceDiscovery Service" (hpqddsvc) - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
"HP Health Check Service" (HP Health Check Service) - "Hewlett-Packard Company" - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
"HP Network Devices Support" (HPSLPSVC) - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
"HP Quick Synchronization Service" (HPDrvMntSvc.exe) - "Hewlett-Packard Company" - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
"HP Software Framework Service" (hpqwmiex) - "Hewlett-Packard Company" - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
"hpqcxs08" (hpqcxs08) - "Hewlett-Packard Co." - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
"HPWMISVC" (HPWMISVC) - "Hewlett-Packard Development Company, L.P." - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Management and Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Intel(R) Rapid Storage Technology" (IAStorDataMgrSvc) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
"MBAMScheduler" (MBAMScheduler) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft SharePoint Workspace Audit Service" (Microsoft SharePoint Workspace Audit Service) - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Office  Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Office Software Protection Platform" (osppsvc) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"SAS Core Service" (!SASCORE) - "SUPERAntiSpyware.com" - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
"Skype C2C Service" (Skype C2C Service) - "Skype Technologies S.A." - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"TrueSuiteService" (FPLService) - "HP" - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winlogon]
-----( HKCU\Control Panel\Desktop )-----
"SCRNSAVE.EXE" - "EasyBits Software AS" - C:\Windows\SysWOW64\ezScrSvr.scr

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries )-----
"AVSDA" - "Avira Operations GmbH & Co. KG" - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll

===[ Logfile end ]=========================================[ Logfile end ]===


--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru


cosinus 19.09.2012 08:38

Ja gMER läuft nicht immer - aber was ist mit aswMBR?

v-man0815 20.09.2012 07:44

Code:


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-20 08:34:02
-----------------------------
08:34:02.466    OS Version: Windows x64 6.1.7601 Service Pack 1
08:34:02.466    Number of processors: 4 586 0x2A07
08:34:02.467    ComputerName: SUPERAZE-HP  UserName: superaze
08:34:04.039    Initialize success
08:35:42.963    AVAST engine defs: 12091901
08:39:54.448    The log file has been saved successfully to "C:\Users\superaze\Desktop\aswMBR-Log - 20-9-2012.txt"

Kann ich aswMBR jetzt schließen, ohne irgendwelche weiteren Schritte (z.B. Fix) unternommen zu haben?

cosinus 20.09.2012 14:52

aswMBR lief nicht richtig. Erstell damit bitte richtig nach meiner Anleitung nochmal ein Log

v-man0815 21.09.2012 06:43

Code:


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-21 07:38:48
-----------------------------
07:38:48.927    OS Version: Windows x64 6.1.7601 Service Pack 1
07:38:48.927    Number of processors: 4 586 0x2A07
07:38:48.927    ComputerName: SUPERAZE-HP  UserName: superaze
07:38:50.222    Initialize success
07:39:07.321    AVAST engine download error: 0
07:39:07.321    AVAST engine defs: 12091901
07:39:20.613    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
07:39:20.628    Disk 0 Vendor: Hitachi_ JEDO Size: 610480MB BusType: 3
07:39:20.659    Disk 0 MBR read successfully
07:39:20.659    Disk 0 MBR scan
07:39:20.659    Disk 0 Windows 7 default MBR code
07:39:20.675    Disk 0 Partition 1 00    42          SFS                0 MB offset 63
07:39:20.675    Disk 0 Partition 2 80 (A) 42          SFS NTFS          199 MB offset 2048
07:39:20.691    Disk 0 Partition 3 00    42          SFS NTFS      298229 MB offset 409600
07:39:20.706    Disk 0 Partition 4 00    42          SFS NTFS      312050 MB offset 611182592
07:39:20.722    Disk 0 scanning C:\Windows\system32\drivers
07:39:20.722    Service scanning
07:39:50.970    Modules scanning
07:39:51.501    Disk 0 trace - called modules:
07:39:51.891    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
07:39:51.891    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800845b060]
07:39:51.906    3 CLASSPNP.SYS[fffff88000c0143f] -> nt!IofCallDriver -> [0xfffffa80082ccb10]
07:39:51.906    5 hpdskflt.sys[fffff880017f2361] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006550050]
07:39:52.905    AVAST engine scan C:\Windows
07:39:52.905    AVAST engine scan C:\Windows\system32
07:39:52.920    AVAST engine scan C:\Windows\system32\drivers
07:39:52.936    AVAST engine scan C:\Users\superaze
07:39:52.951    AVAST engine scan C:\ProgramData
07:39:52.951    Scan finished successfully
07:40:35.674    Disk 0 MBR has been saved successfully to "C:\Users\superaze\Desktop\MBR.dat"
07:40:35.674    The log file has been saved successfully to "C:\Users\superaze\Desktop\aswMBR-Log - 21-9-2012.txt"


cosinus 21.09.2012 15:04

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

v-man0815 22.09.2012 13:48

Code:


Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.09.22.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
superaze :: SUPERAZE-HP [Administrator]

22.09.2012 10:26:56
mbam-log-2012-09-22 (10-26-56).txt

Art des Suchlaufs: Vollständiger Suchlauf (B:\|C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 485205
Laufzeit: 1 Stunde(n), 40 Minute(n), 15 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:



 SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/22/2012 at 02:45 PM

Application Version : 5.5.1016

Core Rules Database Version : 7986
Trace Rules Database Version: 5798

Scan type      : Complete Scan
Total Scan Time : 01:17:22

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 843
Memory threats detected  : 0
Registry items scanned    : 73491
Registry threats detected : 0
File items scanned        : 142359
File threats detected    : 91

Adware.Tracking Cookie
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\2TKOJ4BQ.txt [ /apmebf.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\AP8FG43X.txt [ /fastclick.net ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\0A3BWYYW.txt [ /tracking.quisma.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\L220ZCZE.txt [ /zanox.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\96QQA5Z6.txt [ /ad.zanox.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\5UMRS6EM.txt [ /mediaplex.com ]
        C:\USERS\SUPERAZE\Cookies\2TKOJ4BQ.txt [ Cookie:superaze@apmebf.com/ ]
        C:\USERS\SUPERAZE\Cookies\0A3BWYYW.txt [ Cookie:superaze@tracking.quisma.com/ ]
        C:\USERS\SUPERAZE\Cookies\96QQA5Z6.txt [ Cookie:superaze@ad.zanox.com/ ]
        C:\USERS\SUPERAZE\Cookies\5UMRS6EM.txt [ Cookie:superaze@mediaplex.com/ ]
        .doubleclick.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        server.adformdsp.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adformdsp.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        tradefx.advertserve.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        www.ardmediathek.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        forexyard.advertserve.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        gsadserver.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]


cosinus 22.09.2012 18:46

Code:

UAC On - Limited User
Wie hast du sasw gestartet? Einfach per Doppelklick?

v-man0815 23.09.2012 08:03

Ich habe SUPERAntiSpyware geöffnet und dann den Button „Scan your Computer …“ angeklickt.

cosinus 23.09.2012 16:51

Danach hab ich nicht gefragt! Mit ist schon klar, dass du sasw gestartet hast aberich wollte wissen wie genau!

v-man0815 23.09.2012 20:10

Liste der Anhänge anzeigen (Anzahl: 1)
…tut mir leid: jetzt weiß ich wirklich nicht, was du meinst. Ich habe sasw so gestartet, wie man das eben macht (und wie ich es beschrieben habe). Was für andere Möglichkeiten gibt es denn sonst noch?

cosinus 24.09.2012 12:33

Lesen der Anleitung hilft!!

Benutzer mit Windows Vista und Windows 7 starten das Tool bitte wieder per Rechtsklick => als Administrator ausführen!

v-man0815 24.09.2012 15:21

Lesen der Anleitung hilft …

Ich weiß deine Mühe wirklich zu schätzen und verstehe ja, dass es ärgerlich ist, wenn jemand die Instruktionen nicht richtig befolgt.

Aber wie wäre es gewesen, wenn du klar gefragt hättest, ob ich sasw als Administrator gestartet habe (anstatt: „einfach mit Doppelklick“)?

Da meine Benutzerkontenenstellung so eingerichtet ist, dass ich vor Programmen wie sasw um „Erlaubnis“ gefragt werde, dachte ich, dies sei dann dasselbe, wie wenn ich per Rechtsklick als Administrator ausführe. Nun kannst du wieder sagen, dass ich das doch wissen müsste … wie kann man nur so blöd sein …
In jedem Fall habe ich die Anleitung gelesen, war aber in dem Glauben, mein Vorgehen sei gleichwertig.

Ich finde, nicht nur Lesen der Anleitung hilft, sondern auch ein klares Formulieren der Frage.

Code:



SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 09/24/2012 at 03:32 PM

Application Version : 5.5.1016

Core Rules Database Version : 7986
Trace Rules Database Version: 5798

Scan type      : Complete Scan
Total Scan Time : 01:17:59

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 838
Memory threats detected  : 0
Registry items scanned    : 73509
Registry threats detected : 0
File items scanned        : 145066
File threats detected    : 113

Adware.Tracking Cookie
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\8VSXHHO7.txt [ /apmebf.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\5792BQWO.txt [ /tracking.quisma.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\N5Y8TIYM.txt [ /zanox.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\EBNWE3G6.txt [ /mediathek.daserste.de ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\4S4DAWEC.txt [ /atdmt.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\NJEZUF02.txt [ /ad.zanox.com ]
        C:\Users\superaze\AppData\Roaming\Microsoft\Windows\Cookies\2WL8BAXT.txt [ /mediaplex.com ]
        C:\USERS\SUPERAZE\Cookies\8VSXHHO7.txt [ Cookie:superaze@apmebf.com/ ]
        C:\USERS\SUPERAZE\Cookies\5792BQWO.txt [ Cookie:superaze@tracking.quisma.com/ ]
        C:\USERS\SUPERAZE\Cookies\4S4DAWEC.txt [ Cookie:superaze@atdmt.com/ ]
        C:\USERS\SUPERAZE\Cookies\NJEZUF02.txt [ Cookie:superaze@ad.zanox.com/ ]
        C:\USERS\SUPERAZE\Cookies\2WL8BAXT.txt [ Cookie:superaze@mediaplex.com/ ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        www.findhorn.org [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        www.findhorn.org [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .findhorn.org [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .findhorn.org [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .findhorn.org [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        adx2.chip.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .managementcircleag.122.2o7.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        gsadserver.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        tradefx.advertserve.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\SUPERAZE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9OD2N9TG.DEFAULT\COOKIES.SQLITE ]


cosinus 24.09.2012 19:40

Zitat:

Ich finde, nicht nur Lesen der Anleitung hilft, sondern auch ein klares Formulieren der Frage.
Was bitte war an meiner Frage nicht klar formuliert? Es ist eine einfache Frage, ja oder nein kann als Antwort kommen :pfeiff:
Ist aber auch nun wurscht, denn sasw hat offensichtlich einen Bug und zeigt das nicht immer richtig an. Du hast es doch diesmal richtig per Rechtsklick als Admin ausgeführt oder? ;)

v-man0815 25.09.2012 09:43

… ob ich das Programm nun wirklich richtig ausgeführt habe, weiß ich natürlich nicht. Jedenfalls habe ich es per Rechtsklick als Admin gestartet.

Was bedeutet es für mich, dass sasw „offensichtlich einen Bug hat“? Hat das Programm einen Bug bei mir gefunden, … hat es einen Bug und funktioniert nicht richtig … oder hat es ein Bug, wodurch es egal ist, wie man es startet?

cosinus 25.09.2012 13:15

Du hast es als Admin per Rechtsklick gestartet und trotzdem zeigt es UAC On - Limited User - DAS ist der Bug!

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

v-man0815 26.09.2012 18:21

Nein, es gibt keine anderen Funde oder Probleme. Danke jedenfalls für die ausführliche Unterstützung, auch wenn es nicht immer einfach war.

Gruß
Martin

cosinus 27.09.2012 14:19

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

v-man0815 05.10.2012 17:22

Hy cosinus,

gestern wollte ich dann zu guter letzt, wie von dir empfohlen, die Programme entfernen, die im Laufe der Aktionen zum Einsatz kamen. Ich habe OTL gestartet und auf Bereinigung (cleaning) geklickt. Doch ab da lässt sich Windows nicht mehr hoch fahren und ich lande beim Windows-Start-Manager!

Wenn ich im Windows-Start-Manager „normal starten“ wähle, funktioniert das nicht:
Fehler bei der Startauswahl. Zugriff auf ein erforderliches Gerät nicht möglich. (Status 0xc0000225)
Es bleibt das abgesicherte Hochfahren. Dafür soll ich aber die Windows-CD/DVD einlegen und „computer reparieren“ wählen.

Abgesehen davon, dass ich keine solche Windows-CD/DVD habe (mich also erst an HP wenden muss), würde ich gerne wissen, ob
(1) dabei meine Daten auf der Festplatte verlorengehen? (… weil alles neu formatiert wird?)
(2) ob ich auch noch andere Möglichkeiten habe, Windows wieder normal zu starten?

Kannst du mir hier nen Tip geben?

Martin

cosinus 05.10.2012 18:24

Funktioniert noch der abgesicherte Modus? Mit Netzwerktreibern? Wenn ja wäre ein Wiederherstellungspunkt eine Option
OTL steht im Verdacht diesen Mist auslösen :(

v-man0815 06.10.2012 08:24

… wie gesagt: im Moment kann ich gar nichts machen, auch keine älteren Wiederherstellungspunkt aktivieren. Dafür benötige ich erst eine Windows-CD/DVD (Offensichtlich habe ich nach dem Kauf versäumt, eine solche selbst zu erstellen. Eine entsprechende Anfrage an HP läuft schon ..)

Wenn ich die Option „ Windows normal starten“ wähle, erscheint erst noch kurz das Windows Logo, es wird auch kurz eine Internetverbindung hergestellt (Funknetz-Taste leuchtet), doch dann erscheint auf blauem Bildschirmhintergrund in weißer Schrift: „Session manager initialization system progress terminated unexpectedly with a status of 0xc0000022 (0x00000000 0x00000000). The system has been shut down. Dann geht wirklich gar nichts mehr – ich kann nur noch den Stecker ziehen.

Es bleiben meine Fragen:
(1) ob bei einem eventuellen Einsatz der Windows-CD/DVD im abgesicherten Modus zwangsläufig meine Daten auf der Festplatte verlorengehen? (… weil alles neu formatiert wird?)
(2) ob ich auch noch andere Möglichkeiten habe, Windows wieder normal zu starten? (z.B. indem ich irgendwas beim booten (Bios?) verändern kann?

cosinus 07.10.2012 05:49

EIne Windows7-DVD kannst du runterladen und selber brennen => http://www.trojaner-board.de/100776-...tml#post676887

Wenn du ein Inplace Upgrade machst, sollte eigentlich nichts an Daten gelöscht werden, verlassen würde mich aber niemals drauf, deswegen sichere vorher alle Daten über eine Linux-Live-CD auf eine externe Platte.

v-man0815 07.10.2012 16:20

… ufff, das war ein Akt (für den ganzen Sonntag) – aber es hat geklappt!
Daten mit Live-CD gesichert, Windows-7-ISO gedownloaded und mit dieser CD eine Wiederherstellung gestartet.

Jetzt stellt sich mir allerdings die Frage, ob ich die gesamte Prozedur wiederholen muss, durch die du mich in diesem Thread geführt hast?

cosinus 07.10.2012 20:02

Wie ist denn jetzt der Stand der Dinge?
Windows repariert? Ja? Auch noch alles da? :dummguck:

v-man0815 08.10.2012 07:26

… ja, Windows ist repariert und alles ist noch da!

Muss ich jetzt noch einmal die gesamte Prozedur wiederholen und erneut nach „Schädlingen“ suchen?

cosinus 08.10.2012 11:41

Mach zuerst mal einen Vollscan mit Malwarebytes, dann sehen wir weiter

v-man0815 08.10.2012 13:45

Code:



Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.08.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
superaze :: SUPERAZE-HP [Administrator]

08.10.2012 12:53:48
mbam-log-2012-10-08 (12-53-48).txt

Art des Suchlaufs: Vollständiger Suchlauf (B:\|C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 512555
Laufzeit: 1 Stunde(n), 49 Minute(n), 57 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 08.10.2012 15:44

Ok, dann machnochmal einen Scan mit ESET, aber ich denke nicht, dass da noch was ist ;)

v-man0815 09.10.2012 10:08

... schon wieder 5 threats, und sogar einer von saft-tronic - wo der herkommt, weiß ich nicht, aber ich bin auch nicht der einzige an diesem Notebook. Also nicht gleich wieder schimpfen!

Code:




ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7a0e45050fd3c8438bbd9101be17a5a2
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-09-05 10:32:19
# local_time=2012-09-05 12:32:19 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 24704868 24704868 0 0
# compatibility_mode=5893 16776573 100 94 93064 98464221 0 0
# compatibility_mode=8192 67108863 100 0 164 164 0 0
# scanned=273022
# found=7
# cleaned=0
# scan_time=6767
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe        a variant of Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\FPDownloadManager.exe        Win32/Toolbar.Babylon application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\PDFCreator-1_2_3_setup.exe        Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\SoftonicDownloader_fuer_ibm-spss-statistics-standard.exe        a variant of Win32/SoftonicDownloader.D application (unable to clean)        00000000000000000000000000000000        I
C:\Users\superaze\Downloads\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\c8681f3.msi        a variant of Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
${Memory}        a variant of Win32/Toolbar.Widgi application        00000000000000000000000000000000        I
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7a0e45050fd3c8438bbd9101be17a5a2
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-10-09 08:58:34
# local_time=2012-10-09 10:58:34 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 27635091 27635091 0 0
# compatibility_mode=5893 16776573 100 94 1051 101394444 0 0
# compatibility_mode=8192 67108863 100 0 2930387 2930387 0 0
# scanned=318049
# found=5
# cleaned=0
# scan_time=8519
C:\Windows\Installer\c8681f3.msi        a variant of Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\09122012_175516\C_Users\superaze\Downloads\FPDownloadManager.exe        Win32/Toolbar.Babylon application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\09122012_175516\C_Users\superaze\Downloads\PDFCreator-1_2_3_setup.exe        Win32/Toolbar.Widgi application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\09122012_175516\C_Users\superaze\Downloads\SoftonicDownloader_fuer_ibm-spss-statistics-standard.exe        a variant of Win32/SoftonicDownloader.E application (unable to clean)        00000000000000000000000000000000        I
C:\_OTL\MovedFiles\09122012_175516\C_Users\superaze\Downloads\SweetImSetup.exe        a variant of Win32/SweetIM.B application (unable to clean)        00000000000000000000000000000000        I

Ist es eigentlich kein Problem, wenn der online-Virenschutz fast zwei Stunden abgestellt ist und der Internetzugang offen? Da kann ich mir doch während des scans neue Schädlinge einfangen, die dann gar nicht mehr erfasst werden, oder?

cosinus 09.10.2012 10:28

Zitat:

Ist es eigentlich kein Problem, wenn der online-Virenschutz fast zwei Stunden abgestellt ist und der Internetzugang offen?
Wie stellst du dir das vor? DIe Schädlinge warten vor dem Eingang deiner Internetverbindung und schlagen zu wenn der Türsteher schläft? :rofl:

Überleg mal was so ein Virenscanner im Hintergrund macht, er durchsucht jede Datei vor dem eigentlichen Zugriff, die Internetverbindung ohne aktiven Virenscanner im Hintergrund hattest du nur wegen des ESET-OnlineScanners!

v-man0815 09.10.2012 15:46

… in der Tat, so ähnlich hatte mir das vorgestellt: die Schädlinge warten vor dem Eingang … Allerdings war mir schon klar, dass sie erst dann auf meine Haustüre aufmerksam werden, wenn ich irgendwie aktiv werde. Deswegen hatte ich alle Internetaktivitäten während des scans unterlassen. Aber immerhin war ja ESET aktiv, und ob dadurch irgendwelche Schädlinge auf mich aufmerksam werden (können) oder nicht, war mir nicht so ohne weiteres verständlich. Ich bin da einfach nur ein Laie …

Jedenfalls habe ich nun noch einmal den adwcleaner „cleanen“ gelassen (mit neuestem update und so, wie von dir beschrieben) und dann noch einmal den OldTimer drüber gejagt. Hier die Log-Datei

OTL Logfile:
Code:

OTL logfile created on: 09.10.2012 16:24:53 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\superaze\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
5,95 Gb Total Physical Memory | 4,03 Gb Available Physical Memory | 67,72% Memory free
11,90 Gb Paging File | 9,54 Gb Available in Paging File | 80,23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 291,24 Gb Total Space | 229,68 Gb Free Space | 78,86% Space Free | Partition Type: NTFS
Drive D: | 15,18 Gb Total Space | 1,65 Gb Free Space | 10,90% Space Free | Partition Type: NTFS
 
Computer Name: SUPERAZE-HP | User Name: superaze | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\superaze\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (HP)
PRC - C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP)
PRC - C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (HP)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS)
PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS)
PRC - C:\Windows\SysWOW64\ezSharedSvcHost.exe (EasyBits Software AS)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\b1acb6d21dd13ae76f360354dc8f8de3\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e2ed613308593613ac154671c7549c26\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (!SASCORE) -- C:\Programme\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (vpnagent) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (STacSV) -- C:\Programme\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (FPLService) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (HP)
SRV - (hpCMSrv) -- C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (HPWMISVC) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (HPSLPSVC) -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (HPClientSvc) -- C:\Programme\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AESTFilters) -- C:\Programme\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (vpnva) -- C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (intelkmd) -- C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (cpuz135) -- C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SynasUSB) -- C:\Windows\SysNative\drivers\synUSB64.sys (SIA Syncrosoft)
DRV - (SASDIFSV) -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Programme\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCON/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{098733A3-52AE-4F51-8936-59A44140F3EB}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCON/1
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{098733A3-52AE-4F51-8936-59A44140F3EB}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.at/
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes,bProtectorDefaultScope = {847150B3-D27F-486D-BA04-F79F117F4C5C}
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-684552159-775688101-1027930909-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/"
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.2.72: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.2.72: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.2.72: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.26 15:16:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012.10.07 16:41:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.04.01 21:42:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.14 14:32:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.09.17 19:00:33 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.26 15:16:11 | 000,000,000 | ---D | M]
 
[2012.09.14 14:33:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\superaze\AppData\Roaming\mozilla\Extensions
[2012.09.22 15:21:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\9od2n9tg.default\extensions
[2012.09.12 17:55:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\superaze\AppData\Roaming\mozilla\Firefox\Profiles\dxvxtbh3.default\extensions
[2012.09.14 14:32:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.08 10:41:51 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.09.13 18:06:46 | 000,000,000 | ---D | M] (TrueSuite Website Logon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com
[2012.09.06 03:26:03 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.06.21 12:16:10 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.08.14 17:49:30 | 000,171,136 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2012.09.06 04:07:37 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.09.06 04:07:37 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.09.06 04:07:37 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.09.06 04:07:37 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.09.06 04:07:37 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.09.06 04:07:37 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Simple Pass 2011 (Enabled) = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe\1.0_0\npwebsitelogon.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)  (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Website Logon = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe\1.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\superaze\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
 
O1 HOSTS File: ([2012.09.15 10:54:26 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SpecialSavings) - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O2 - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-684552159-775688101-1027930909-1001..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-684552159-775688101-1027930909-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-684552159-775688101-1027930909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: SpecialSavings - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O16:64bit: - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} https://vpn.uibk.ac.at/CACHE/stc/1/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A6FFB0A5-E400-4E52-A883-EB102CF9A644}: DhcpNameServer = 10.0.0.138 10.0.0.138
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
MsConfig:64bit - StartUpFolder: C:^Users^superaze^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: !SASCORE - C:\Programme\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: !SASCORE - C:\Programme\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.09 16:22:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\superaze\Desktop\OTL(1).exe
[2012.10.09 08:20:57 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{FF0AE410-31BD-4147-97F9-D870A135A7A2}
[2012.10.08 20:20:34 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{D9F9B67B-FD1F-48F6-822E-05C2703CBB75}
[2012.10.08 20:16:26 | 000,000,000 | ---D | C] -- C:\Users\superaze\Desktop\online-Befragung - Längsschnitt-Dateien
[2012.10.08 08:20:10 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{5BE81E3D-13B1-42C6-A77F-4EF0551668CA}
[2012.10.07 17:26:23 | 000,000,000 | ---D | C] -- C:\Users\superaze\Desktop\Rechnungen - BackUp
[2012.10.07 15:49:13 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{B6BB66A3-585F-45E3-B05D-A2A304FF6EE0}
[2012.10.02 19:06:49 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\Secunia PSI
[2012.10.02 19:06:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
[2012.10.02 17:37:04 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{8D526314-1113-4712-8FDF-DA45FA768F1B}
[2012.10.01 21:00:28 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{3CE7C67F-8949-4996-9CD8-BEACFC5AEB04}
[2012.10.01 09:00:16 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{B1815942-B009-4240-B907-1DB378B99C2F}
[2012.09.30 20:41:05 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{2C962D93-0B26-4E3C-B410-28698F2AFE66}
[2012.09.29 20:35:54 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{52354ADA-E5FA-4688-BB17-834E862CB7D5}
[2012.09.28 21:46:51 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{3D8BA033-8CA9-4C6E-A33E-3124213D1216}
[2012.09.28 07:41:32 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{35531156-3315-4743-A8C0-8EBBF498381A}
[2012.09.27 08:22:33 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{08D14B06-E80C-4EF8-A226-738C00C317D0}
[2012.09.26 17:16:04 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1
[2012.09.26 08:56:06 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{46AF8BCE-231E-477C-B1DB-F49333E94581}
[2012.09.25 08:25:56 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{9112C579-BD6A-45E8-9911-AF4A740F153E}
[2012.09.24 08:57:27 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{22CFCF7D-9256-4C81-B4C5-E673C163323D}
[2012.09.23 20:57:16 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{95AAF0D8-ECDA-429A-BB26-BDA08BEE7156}
[2012.09.23 08:56:52 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{F31BAFEA-2C72-47B7-B695-F5631E9BC71E}
[2012.09.22 13:21:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012.09.22 13:20:53 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.09.22 10:26:07 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{D0A757BB-7600-4209-8F5A-B0B20C218619}
[2012.09.21 09:53:38 | 000,000,000 | R--D | C] -- C:\Users\superaze\Documents\Scanned Documents
[2012.09.21 09:53:38 | 000,000,000 | ---D | C] -- C:\Users\superaze\Documents\Fax
[2012.09.21 08:29:50 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{412781A2-C0A3-4E5F-9399-CB3638184537}
[2012.09.20 20:29:26 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{23C1B498-08AF-4C85-9DE8-3B0FBDCC8A25}
[2012.09.20 08:29:02 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{02537F88-7CF6-42C8-AC39-AF8538199874}
[2012.09.19 20:28:50 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{BDA7ABE7-A869-42D9-8A0C-2F57AD301FBB}
[2012.09.19 08:28:40 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{FB5B33FC-22C7-4B5B-9F87-49B7609A5DD0}
[2012.09.18 09:30:58 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{ED95A259-04E1-4E16-A220-BE20BF8E032E}
[2012.09.17 21:30:35 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{EA9E11FB-09C7-4F9F-8E75-7BB70B451834}
[2012.09.17 09:30:09 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{B58B5B21-721C-4F57-83BD-6825D260DC9B}
[2012.09.16 21:06:15 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{62D2A27D-B700-49DC-B6F0-AD43CEB70FA6}
[2012.09.16 09:06:04 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{F61BC56C-74E9-430E-A4A0-9FC56E5EF4BF}
[2012.09.15 11:41:12 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\Tracker Software
[2012.09.15 11:15:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.09.15 10:47:02 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.09.15 10:47:02 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.09.15 10:47:02 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.09.15 10:46:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.09.15 10:46:41 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.09.15 10:21:05 | 000,000,000 | ---D | C] -- C:\Users\superaze\Desktop\Downloaden - Hörbilder - Geschäftsadresse  Gaddafi-Clan-Dateien
[2012.09.15 08:42:29 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{F637183A-D2EB-4818-92D2-8F7E199090BC}
[2012.09.14 19:39:21 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{84B8C39D-3C4B-4010-9244-A761C98EF855}
[2012.09.14 14:32:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012.09.14 07:31:12 | 000,000,000 | ---D | C] -- C:\Users\superaze\AppData\Local\{2B84A781-42B3-4675-A8E9-9D6847774A22}
[2012.09.12 17:55:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\%LOCALAPPDATA%
[2012.09.12 17:55:16 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.09.12 10:51:10 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\superaze\Desktop\OldTimer - Müll u Feide - Scanner.exe
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.09 16:26:53 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.09 16:26:53 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.09 16:26:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.10.09 16:22:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\superaze\Desktop\OTL(1).exe
[2012.10.09 16:19:57 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.10.09 16:19:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.09 16:19:20 | 495,865,855 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.09 16:15:02 | 000,538,327 | ---- | M] () -- C:\Users\superaze\Desktop\adwcleaner(1).exe
[2012.10.09 15:59:00 | 000,001,114 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.10.08 20:16:31 | 000,021,643 | ---- | M] () -- C:\Users\superaze\Desktop\online-Befragung - Längsschnitt.htm
[2012.10.08 11:29:19 | 000,251,939 | ---- | M] () -- C:\Windows\hpwins21.dat
[2012.10.08 11:05:02 | 002,061,339 | ---- | M] () -- C:\Users\superaze\Desktop\sinus701S - Bedienungsanleitung.pdf
[2012.10.07 17:44:40 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.07 17:44:40 | 000,654,400 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.07 17:44:40 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.07 17:44:40 | 000,130,240 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.07 17:44:40 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.07 15:43:22 | 000,442,408 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.28 09:27:41 | 000,039,397 | ---- | M] () -- C:\Users\superaze\Desktop\OE1 - Kontext - download - Der falsche Feind.pdf
[2012.09.26 17:52:10 | 000,000,016 | -H-- | M] () -- C:\Windows\SysWow64\servdat.slm
[2012.09.23 20:07:11 | 000,001,062 | ---- | M] () -- C:\Users\superaze\Desktop\PDF-Viewer.lnk
[2012.09.22 13:21:09 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.09.17 19:00:26 | 000,001,805 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012.09.15 10:54:26 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.09.15 10:21:07 | 000,046,062 | ---- | M] () -- C:\Users\superaze\Desktop\Downloaden - Hörbilder - Geschäftsadresse  Gaddafi-Clan.htm
[2012.09.14 14:32:40 | 000,001,090 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.09.13 08:01:41 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForsuperaze.job
[2012.09.12 14:36:13 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.09.12 10:51:10 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\superaze\Desktop\OldTimer - Müll u Feide - Scanner.exe
 
========== Files Created - No Company Name ==========
 
[2012.10.08 20:16:25 | 000,021,643 | ---- | C] () -- C:\Users\superaze\Desktop\online-Befragung - Längsschnitt.htm
[2012.10.08 11:04:58 | 002,061,339 | ---- | C] () -- C:\Users\superaze\Desktop\sinus701S - Bedienungsanleitung.pdf
[2012.10.08 10:34:08 | 000,251,947 | ---- | C] () -- C:\Windows\hpwins21.dat.temp
[2012.09.28 09:27:19 | 000,039,397 | ---- | C] () -- C:\Users\superaze\Desktop\OE1 - Kontext - download - Der falsche Feind.pdf
[2012.09.22 13:21:09 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012.09.15 10:47:02 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.09.15 10:47:02 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.09.15 10:47:02 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.09.15 10:47:02 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.09.15 10:47:02 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.09.15 10:21:05 | 000,046,062 | ---- | C] () -- C:\Users\superaze\Desktop\Downloaden - Hörbilder - Geschäftsadresse  Gaddafi-Clan.htm
[2012.09.14 14:32:40 | 000,001,102 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.09.14 14:32:40 | 000,001,090 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.08.11 22:18:39 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2012.08.11 22:18:39 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2012.08.11 21:54:38 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2012.04.14 22:02:11 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012.02.26 15:23:01 | 000,000,575 | ---- | C] () -- C:\Windows\hpwmdl21.dat.temp
[2012.02.26 15:12:40 | 000,251,939 | ---- | C] () -- C:\Windows\hpwins21.dat
[2012.02.26 15:12:40 | 000,000,575 | ---- | C] () -- C:\Windows\hpwmdl21.dat
[2011.12.09 10:13:33 | 000,000,051 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe.cfg
[2011.12.04 10:15:33 | 000,002,892 | ---- | C] () -- C:\Windows\SysWow64\audcon.sys
[2011.12.04 10:14:25 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe
[2011.12.01 11:22:00 | 000,000,176 | ---- | C] () -- C:\Users\superaze\AppData\Roaming\burnaware.ini
[2011.10.07 11:53:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.10.07 11:44:02 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2011.10.07 11:42:45 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.10.07 11:42:42 | 000,213,332 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.10.07 11:42:42 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.10.07 11:42:41 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.10.07 11:38:02 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011.06.21 12:14:44 | 000,000,068 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2011.02.22 16:40:34 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL
[2010.12.17 04:26:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll
 
========== LOP Check ==========
 
[2012.06.26 20:50:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\calibre
[2012.06.22 08:34:08 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Canneverbe Limited
[2012.08.31 20:22:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\FileZilla
[2011.11.30 13:12:55 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\ImgBurn
[2012.07.25 14:17:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\KompoZer
[2011.11.25 11:35:02 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\OpenOffice.org
[2011.12.27 19:23:11 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Scribus
[2011.11.24 12:52:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Synaptics
[2011.12.13 22:37:59 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Waves Audio
[2011.11.24 15:56:24 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.04.23 10:46:17 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Adobe
[2011.12.04 12:53:15 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\AdobeAUM
[2011.12.04 12:53:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\AdobeUM
[2011.11.24 20:13:51 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Apple Computer
[2011.11.24 12:53:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\ATI
[2011.11.24 13:15:50 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Avira
[2012.06.26 20:50:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\calibre
[2012.06.22 08:34:08 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Canneverbe Limited
[2012.02.10 14:05:33 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\CyberLink
[2012.06.01 14:04:25 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\DivX
[2012.08.31 20:22:43 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\FileZilla
[2012.06.16 12:07:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Hewlett-Packard
[2012.04.08 16:20:19 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\HP
[2011.11.24 12:52:51 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\hpqlog
[2012.05.14 07:57:46 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\HpUpdate
[2011.11.24 12:52:20 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Identities
[2011.11.30 13:12:55 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\ImgBurn
[2011.11.24 12:52:44 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Intel Corporation
[2012.07.25 14:17:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\KompoZer
[2011.11.24 12:54:13 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Macromedia
[2011.11.24 13:42:18 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Malwarebytes
[2011.10.07 21:33:40 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Media Center Programs
[2012.08.31 20:22:44 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Media Player Classic
[2012.09.08 10:11:24 | 000,000,000 | --SD | M] -- C:\Users\superaze\AppData\Roaming\Microsoft
[2012.09.14 14:33:21 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Mozilla
[2012.05.29 11:35:29 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\NCH Software
[2011.11.25 11:35:02 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\OpenOffice.org
[2012.05.25 09:56:30 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Real
[2011.11.30 13:44:27 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\RealNetworks
[2011.12.27 19:23:11 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Scribus
[2012.09.20 08:31:28 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Skype
[2011.11.24 13:37:57 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\SUPERAntiSpyware.com
[2011.11.24 12:52:41 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Synaptics
[2011.12.13 22:37:59 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Waves Audio
[2011.11.24 15:56:24 | 000,000,000 | ---D | M] -- C:\Users\superaze\AppData\Roaming\Windows Live Writer
 
< %APPDATA%\*.exe /s >
[2011.11.26 09:52:39 | 000,617,472 | ---- | M] () -- C:\Users\superaze\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\uno_packages\3FDB.tmp_\oracle-pdfimport.oxt\xpdfimport.exe
[2012.09.25 17:57:49 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\superaze\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe
[2012.09.25 17:57:49 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Users\superaze\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe
[2012.07.18 21:11:14 | 000,315,544 | ---- | M] (RealNetworks, Inc.) -- C:\Users\superaze\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\9.11\rnupgagent.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\erdnt\cache64\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\erdnt\cache86\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\erdnt\cache64\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\SWSetup\Drivers\IRST\Drivers\x64\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\drivers\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_a36325196df56f7d\iaStor.sys
[2011.01.13 03:44:08 | 000,355,352 | ---- | M] (Intel Corporation) MD5=F989555F1662581032CCE1578A8FF28E -- C:\SWSetup\Drivers\IRST\Drivers\x32\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\erdnt\cache64\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\erdnt\cache86\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\erdnt\cache86\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\erdnt\cache64\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\erdnt\cache86\user32.dll
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\erdnt\cache64\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache86\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\erdnt\cache64\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\erdnt\cache64\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\erdnt\cache86\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\erdnt\cache64\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 07:08:49 | 000,032,624 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.11.24 21:44:51 | 000,001,110 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2011.11.24 21:44:53 | 000,001,114 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.04.02 08:28:18 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012.07.14 08:27:38 | 000,000,344 | ---- | C] () -- C:\Windows\Tasks\HPCeeScheduleForsuperaze.job

< End of report >

--- --- ---


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:01 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131