Hallo Leo und danke für die flotte Antwort.
Hier die logs: Code:
ComboFix 13-02-22.01 - fritz 22.02.2013 15:38:59.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.1023.546 [GMT 1:00]
ausgeführt von:: c:\dokumente und einstellungen\fritz\Desktop\ComboFix.exe
AV: Computer Security *Disabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-01-22 bis 2013-02-22 ))))))))))))))))))))))))))))))
.
.
2013-02-22 11:20 . 2013-02-22 11:20 -------- d-----w- c:\programme\Gemeinsame Dateien\Java
2013-02-22 11:19 . 2013-02-22 11:19 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-22 11:19 . 2013-02-22 11:19 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-02-22 11:19 . 2013-02-22 11:19 -------- d-----w- c:\programme\Java
2013-02-11 19:47 . 2013-02-21 20:22 -------- d-----w- c:\programme\Diablo II
2013-02-11 19:47 . 2013-02-11 20:04 -------- d-----w- c:\programme\Gemeinsame Dateien\Blizzard Entertainment
2013-02-06 00:17 . 2013-02-08 12:55 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Tarma Installer
2013-01-31 18:43 . 2013-01-31 20:16 -------- d-----w- c:\programme\Diablo II Shareware
2013-01-30 22:19 . 2013-01-30 22:23 -------- d-----w- c:\programme\Diablo-HYBRID
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-22 11:19 . 2012-09-07 13:31 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-22 11:19 . 2012-09-07 13:31 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-26 03:55 . 2008-04-14 07:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-11 21:00 . 2012-09-18 22:44 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-11 21:00 . 2012-09-18 22:44 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-07 07:24 . 2008-04-14 07:30 2072064 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-07 07:24 . 2008-04-14 07:00 2195328 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 10:09 . 2008-04-14 07:00 1867392 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2008-04-14 07:00 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2008-04-14 07:00 1297920 ----a-w- c:\windows\system32\quartz.dll
2012-12-26 20:06 . 2008-04-14 07:00 916480 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:06 . 2008-04-14 07:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-12-26 20:06 . 2008-04-14 07:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2008-04-14 07:00 385024 ------w- c:\windows\system32\html.iec
2012-12-16 12:23 . 2008-04-14 07:00 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-12-14 15:49 . 2012-09-10 15:43 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-19 21:48 . 2013-02-19 21:48 263064 ----a-w- c:\programme\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programme\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"IntelZeroConfig"="c:\programme\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\programme\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"F-Secure Manager"="c:\programme\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE" [2012-07-03 310992]
"Adobe ARM"="c:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"F-Secure Hoster (666)"="c:\programme\F-Secure\fshoster32.exe" [2012-08-27 167632]
"HD Tune"="c:\progra~1\HDTUNE~1\HDTune.exe" [2008-02-09 401408]
"SunJavaUpdateSched"="c:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programme\\StarMoney 8.0 S-Edition\\ouservice\\StarMoneyOnlineUpdate.exe"=
"c:\\Programme\\StarMoney 8.0 S-Edition\\app\\StarMoney.exe"=
"c:\\Programme\\Java\\jre7\\bin\\javaw.exe"=
.
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [07.09.2012 14:19 44240]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\programme\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys [16.01.2013 13:31 73208]
R2 fshoster;F-Secure Dll Hoster;c:\programme\F-Secure\fshoster32.exe -hosterid:0 --> c:\programme\F-Secure\fshoster32.exe -hosterid:0 [?]
R2 FSORSPClient;F-Secure ORSP Client;c:\programme\F-Secure\apps\CCF_Reputation\fsorsp.exe [25.05.2012 11:00 61152]
R2 StarMoney 8.0 OnlineUpdate;StarMoney 8.0 OnlineUpdate;c:\programme\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [08.02.2013 11:57 699680]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\programme\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [07.09.2012 14:18 144952]
R3 fsni;fsni;c:\programme\F-Secure\apps\CCF_Scanning\fsnixp32.sys [30.01.2013 15:18 49720]
R3 fsnitdi;fsnitdi;c:\programme\F-Secure\apps\CCF_Scanning\fsnitdi32.sys [30.01.2013 15:18 23096]
S0 cerc6;cerc6; [x]
.
Inhalt des "geplante Tasks" Ordners
.
2013-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1390067357-1177238915-1003Core.job
- c:\dokumente und einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2012-09-10 15:47]
.
2013-02-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1390067357-1177238915-1003UA.job
- c:\dokumente und einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2012-09-10 15:47]
.
.
------- Zusätzlicher Suchlauf -------
.
uInternet Connection Wizard,ShellNext = "c:\programme\Outlook Express\msimn.exe" //mailurl:mailto:lleroc@lleroc.com
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\dokumente und einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: network.proxy.type - 2
FF - ExtSQL: 2012-12-30 13:47; groovesharkUnlocker@overlord1337; c:\dokumente und einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\groovesharkUnlocker@overlord1337.xpi
FF - ExtSQL: 2013-01-03 14:17; jid1-QpHD8URtZWJC2A@jetpack; c:\dokumente und einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi
FF - ExtSQL: 2013-02-22 13:36; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; c:\dokumente und einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - ExtSQL: 2013-02-22 13:36; {73a6fe31-595d-460b-a920-fcc0f8843232}; c:\dokumente und einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-02-22 15:45
Windows 5.1.2600 Service Pack 3 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fshoster]
"ImagePath"="c:\programme\F-Secure\fshoster32.exe -hosterid:0"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\F-Secure\My Services Agent\Protected]
@Denied: ) (Everyone)
"AgentIdentifier"="35118382-b0f7-46c6-be89-08affe5bd427"
"AuthorizationCode"="4*l7hQ0xGFecTTBgzUYv7r2CR2q-iS3cMBEPTjN9N7Z*hqFLfCEf9g"
"666_AgentIdentifier"="35118382-b0f7-46c6-be89-08affe5bd427"
"666_AuthorizationCode"="4*l7hQ0xGFecTTBgzUYv7r2CR2q-iS3cMBEPTjN9N7Z*hqFLfCEf9g"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]
"7040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\Ati2evxx.dll
c:\programme\f-secure\apps\computersecurity\hips\fshook32.dll
.
- - - - - - - > 'explorer.exe'(860)
c:\programme\f-secure\apps\computersecurity\hips\fshook32.dll
c:\programme\F-Secure\apps\ComputerSecurity\Spam Control\fsscoepl.dll
c:\windows\system32\webcheck.dll
.
Zeit der Fertigstellung: 2013-02-22 15:47:49
ComboFix-quarantined-files.txt 2013-02-22 14:47
.
Vor Suchlauf: 22 Verzeichnis(se), 106.536.308.736 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 106.780.499.968 Bytes frei
.
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 663F9737BDC16BDCB4A14AF3F14E706C Code:
OTL logfile created on: 22.02.2013 15:59:37 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Dokumente und Einstellungen\fritz\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1023,37 Mb Total Physical Memory | 469,98 Mb Available Physical Memory | 45,92% Memory free
1,90 Gb Paging File | 1,46 Gb Available in Paging File | 76,49% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme
Drive C: | 149,04 Gb Total Space | 99,48 Gb Free Space | 66,74% Space Free | Partition Type: NTFS
Computer Name: KINGFRITZ | User Name: fritz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.02.22 13:19:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\fritz\Desktop\OTL.com
PRC - [2013.02.22 12:19:17 | 000,170,912 | ---- | M] (Oracle Corporation) -- C:\Programme\Java\jre7\bin\jqs.exe
PRC - [2013.01.08 11:57:33 | 001,019,448 | ---- | M] (F-Secure Corporation) -- C:\Programme\F-Secure\apps\ComputerSecurity\Anti-Virus\fssm32.exe
PRC - [2013.01.08 11:57:33 | 000,618,040 | ---- | M] (F-Secure Corporation) -- C:\Programme\F-Secure\apps\ComputerSecurity\Anti-Virus\fsgk32.exe
PRC - [2012.12.18 15:28:22 | 000,038,112 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Adobe\Reader 10.0\Reader\reader_sl.exe
PRC - [2012.08.27 15:06:56 | 000,167,632 | ---- | M] (F-Secure Corporation) -- C:\Programme\F-Secure\fshoster32.exe
PRC - [2012.07.03 17:40:00 | 000,310,992 | ---- | M] (F-Secure Corporation) -- C:\Programme\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE
PRC - [2012.07.03 17:40:00 | 000,212,688 | ---- | M] (F-Secure Corporation) -- C:\Programme\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE
PRC - [2012.07.03 09:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
PRC - [2012.05.25 11:00:44 | 000,061,152 | ---- | M] (F-Secure Corporation) -- C:\Programme\F-Secure\apps\CCF_Reputation\fsorsp.exe
PRC - [2008.04.14 08:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.02.21 10:19:58 | 000,819,200 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2007.02.21 10:19:40 | 000,294,912 | ---- | M] (Intel(R) Corporation) -- C:\Programme\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2007.02.21 10:17:42 | 000,970,752 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2007.02.21 10:13:26 | 000,487,424 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2007.01.31 13:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Programme\Canon\CAL\CALMAIN.exe
========== Modules (No Company Name) ==========
MOD - [2013.01.08 11:57:33 | 000,221,752 | ---- | M] () -- \\?\c:\programme\f-secure\apps\computersecurity\hips\fsumi.dll
MOD - [2012.12.18 15:28:26 | 000,301,056 | ---- | M] () -- C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.DEU
MOD - [2012.09.07 14:26:18 | 000,030,888 | ---- | M] () -- C:\Programme\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\hashlib_x86.dll
MOD - [2012.09.07 14:13:22 | 003,051,200 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtXmlPatterns4.dll
MOD - [2012.09.07 14:13:21 | 010,706,624 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtWebKit4.dll
MOD - [2012.09.07 14:13:21 | 000,372,416 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtXml4.dll
MOD - [2012.09.07 14:13:20 | 000,622,272 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtSql4.dll
MOD - [2012.09.07 14:13:19 | 008,347,328 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtGui4.dll
MOD - [2012.09.07 14:13:19 | 002,256,576 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtCore4.dll
MOD - [2012.09.07 14:13:19 | 000,986,816 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtNetwork4.dll
MOD - [2012.09.07 14:13:19 | 000,450,240 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtHelp4.dll
MOD - [2012.09.07 14:13:18 | 001,076,928 | ---- | M] () -- C:\WINDOWS\WinSxS\x86_F-Secure.Qt462_2e112a926211c0a3_4.6.2.680_x-ww_5bf632f0\QtCLucene4.dll
MOD - [2012.08.27 15:06:54 | 000,143,056 | ---- | M] () -- C:\Programme\F-Secure\imageformats\qjpeg4.dll
MOD - [2012.07.03 17:40:02 | 000,200,400 | ---- | M] () -- C:\Programme\F-Secure\apps\ComputerSecurity\Spam Control\fsas.dll
MOD - [2012.07.03 17:39:54 | 000,147,456 | ---- | M] () -- C:\Programme\F-Secure\apps\ComputerSecurity\FSGUI\flyerres.eng
MOD - [2012.07.03 17:39:54 | 000,086,016 | ---- | M] () -- C:\Programme\F-Secure\apps\ComputerSecurity\FSGUI\strres.eng
MOD - [2012.07.03 17:39:54 | 000,049,152 | ---- | M] () -- C:\Programme\F-Secure\apps\ComputerSecurity\FSGUI\fsavures.eng
MOD - [2012.07.03 17:39:48 | 000,038,400 | ---- | M] () -- C:\Programme\F-Secure\apps\ComputerSecurity\Anti-Virus\fsavhres.eng
MOD - [2012.06.21 12:29:36 | 000,241,360 | ---- | M] () -- C:\Programme\F-Secure\imageformats\qmng4.dll
MOD - [2012.06.21 12:29:36 | 000,216,784 | ---- | M] () -- C:\Programme\F-Secure\daas2.dll
MOD - [2012.06.21 12:29:36 | 000,036,048 | ---- | M] () -- C:\Programme\F-Secure\imageformats\qico4.dll
MOD - [2012.06.21 12:29:36 | 000,034,000 | ---- | M] () -- C:\Programme\F-Secure\imageformats\qgif4.dll
MOD - [2007.02.21 10:13:02 | 000,118,784 | ---- | M] () -- C:\Programme\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006.10.17 15:13:20 | 001,167,360 | ---- | M] () -- C:\Programme\Intel\Wireless\Bin\acAuth.dll
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2013.02.22 12:19:17 | 000,170,912 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Programme\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013.02.19 22:48:38 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.12.21 14:48:08 | 000,699,680 | ---- | M] (Star Finanz - Software Entwicklung und Vertriebs GmbH) [Auto | Stopped] -- C:\Programme\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe -- (StarMoney 8.0 OnlineUpdate)
SRV - [2012.08.27 15:06:56 | 000,167,632 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Programme\F-Secure\fshoster32.exe -- (fshoster)
SRV - [2012.07.03 17:40:00 | 000,212,688 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Programme\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE -- (FSMA)
SRV - [2012.05.25 11:00:44 | 000,061,152 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Programme\F-Secure\apps\CCF_Reputation\fsorsp.exe -- (FSORSPClient)
SRV - [2007.02.21 10:19:40 | 000,294,912 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2007.01.31 13:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Programme\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2003.07.28 11:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | Boot | Stopped] -- -- (cerc6)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOKUME~1\fritz\LOKALE~1\Temp\catchme.sys -- (catchme)
DRV - [2013.01.30 15:18:46 | 000,049,720 | ---- | M] (F-Secure Corporation) [Kernel | On_Demand | Running] -- C:\Programme\F-Secure\apps\CCF_Scanning\fsnixp32.sys -- (fsni)
DRV - [2013.01.30 15:18:46 | 000,023,096 | ---- | M] (F-Secure Corporation) [Kernel | On_Demand | Running] -- C:\Programme\F-Secure\apps\CCF_Scanning\fsnitdi32.sys -- (fsnitdi)
DRV - [2013.01.08 11:59:18 | 000,144,952 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Programme\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys -- (F-Secure Gatekeeper)
DRV - [2013.01.08 11:57:33 | 000,073,208 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Programme\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys -- (F-Secure HIPS)
DRV - [2012.10.06 18:29:41 | 000,044,240 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\fsbts.sys -- (fsbts)
DRV - [2012.06.03 09:45:50 | 000,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2007.02.21 10:16:12 | 000,012,416 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007.02.08 12:51:16 | 002,209,408 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51)
DRV - [2005.08.03 22:10:18 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005.03.10 15:56:06 | 000,273,168 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1844237615-1390067357-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: groovesharkUnlocker%40overlord1337:1.3
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130129
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0
FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*'))%20%7B%20return%20'PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us04.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us03.personalitycores.com%3A8000'%3B%7D%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF - prefs.js..network.proxy.type: 2
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Programme\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Programme\Mozilla Firefox\components [2013.02.19 22:48:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Programme\Mozilla Firefox\plugins [2013.02.21 15:35:18 | 000,000,000 | ---D | M]
[2012.09.07 14:23:59 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Mozilla\Extensions
[2013.02.22 13:36:34 | 000,000,000 | ---D | M] (No name found) -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions
[2013.02.22 13:36:33 | 000,000,000 | ---D | M] (WOT) -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012.12.30 13:47:36 | 000,029,022 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\groovesharkUnlocker@overlord1337.xpi
[2013.01.22 01:35:25 | 000,315,066 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi
[2013.02.22 13:36:33 | 000,530,982 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013.02.14 19:57:09 | 000,817,280 | ---- | M] () (No name found) -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Mozilla\Firefox\Profiles\hplxco34.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.02.19 22:48:13 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.02.19 22:48:40 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Programme\mozilla firefox\components\browsercomps.dll
[2012.08.25 03:49:52 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.25 03:49:52 | 000,002,465 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml
[2012.08.25 03:49:52 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.25 03:49:52 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.25 03:49:52 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.25 03:49:52 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage: hxxp://www.google.de/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: hxxp://www.google.de/
CHR - plugin: Shockwave Flash (Enabled) = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Programme\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programme\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programme\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U7 (Enabled) = C:\Programme\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.10 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Programme\VideoLAN\VLC\npvlc.dll
CHR - Extension: YouTube = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AdBlock = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.44_0\
CHR - Extension: Google Mail = C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2008.04.14 08:00:00 | 000,000,820 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [F-Secure Hoster (666)] C:\Programme\F-Secure\fshoster32.exe (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure Manager] C:\Programme\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [HD Tune] C:\Programme\HD Tune\HDTune.exe (EFD Software)
O4 - HKLM..\Run: [IntelWireless] C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1844237615-1390067357-1177238915-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-1390067357-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1844237615-1390067357-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1844237615-1390067357-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{325B613D-4D53-4461-82B8-A2BF6327413F}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Die derzeitige Homepage) - About:Home
O24 - Desktop WallPaper: C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.09.07 13:53:10 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.02.22 15:36:41 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.02.22 15:35:06 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.02.22 15:35:06 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.02.22 15:35:06 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.02.22 15:35:06 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.02.22 15:34:48 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.02.22 15:34:43 | 000,000,000 | R--D | C] -- C:\Dokumente und Einstellungen\fritz\Startmenü\Programme\Verwaltung
[2013.02.22 15:34:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.02.22 15:32:33 | 005,034,222 | R--- | C] (Swearware) -- C:\Dokumente und Einstellungen\fritz\Desktop\ComboFix.exe
[2013.02.22 15:32:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Dokumente und Einstellungen\fritz\Desktop\OTL.com
[2013.02.22 14:15:28 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\fritz\Desktop\scan
[2013.02.22 12:20:29 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Java
[2013.02.22 12:19:07 | 000,000,000 | ---D | C] -- C:\Programme\Java
[2013.02.19 22:48:10 | 000,000,000 | ---D | C] -- C:\Programme\Mozilla Firefox
[2013.02.17 00:11:42 | 000,000,000 | RH-D | C] -- C:\Dokumente und Einstellungen\fritz\Recent
[2013.02.11 21:07:41 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Diablo II
[2013.02.11 20:47:14 | 000,000,000 | ---D | C] -- C:\Programme\Diablo II
[2013.02.11 20:47:14 | 000,000,000 | ---D | C] -- C:\Programme\Gemeinsame Dateien\Blizzard Entertainment
[2013.02.06 01:17:39 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer
[2013.01.31 19:43:08 | 000,000,000 | ---D | C] -- C:\Programme\Diablo II Shareware
[2013.01.30 23:19:45 | 000,000,000 | ---D | C] -- C:\Programme\Diablo-HYBRID
[2013.01.25 13:52:04 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\fritz\Desktop\tb
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.02.22 16:02:32 | 000,001,210 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1390067357-1177238915-1003UA.job
[2013.02.22 15:58:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.02.22 15:58:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.02.22 15:36:52 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013.02.22 15:32:06 | 005,034,222 | R--- | M] (Swearware) -- C:\Dokumente und Einstellungen\fritz\Desktop\ComboFix.exe
[2013.02.22 13:54:01 | 000,000,000 | ---- | M] () -- C:\Dokumente und Einstellungen\fritz\defogger_reenable
[2013.02.22 13:51:46 | 000,050,477 | ---- | M] () -- C:\Dokumente und Einstellungen\fritz\Desktop\Defogger(1).exe
[2013.02.22 13:34:43 | 000,376,832 | ---- | M] () -- C:\Dokumente und Einstellungen\fritz\Desktop\gmer_2.1.19081.exe
[2013.02.22 13:19:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Dokumente und Einstellungen\fritz\Desktop\OTL.com
[2013.02.21 19:02:58 | 000,001,158 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1390067357-1177238915-1003Core.job
[2013.02.21 15:00:27 | 000,001,065 | ---- | M] () -- C:\WINDOWS\winamp.ini
[2013.02.17 00:12:24 | 000,030,680 | ---- | M] () -- C:\Dokumente und Einstellungen\fritz\Eigene Dateien\cc_20130217_001219.reg
[2013.02.13 16:07:54 | 000,194,568 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.02.13 14:35:42 | 000,456,044 | ---- | M] () -- C:\WINDOWS\System32\perfh007.dat
[2013.02.13 14:35:42 | 000,439,072 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013.02.13 14:35:42 | 000,083,316 | ---- | M] () -- C:\WINDOWS\System32\perfc007.dat
[2013.02.13 14:35:42 | 000,070,462 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013.02.11 21:14:28 | 000,000,790 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Diablo II - Lord of Destruction.lnk
[2013.02.08 13:39:27 | 000,000,756 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.31 00:01:01 | 000,002,364 | ---- | M] () -- C:\Dokumente und Einstellungen\fritz\Desktop\Google Chrome.lnk
[2013.01.30 19:03:33 | 000,001,460 | ---- | M] () -- C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\recently-used.xbel
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.02.22 15:36:51 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013.02.22 15:36:46 | 000,262,448 | RHS- | C] () -- C:\cmldr
[2013.02.22 15:35:06 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.02.22 15:35:06 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.02.22 15:35:06 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.02.22 15:35:06 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.02.22 15:35:06 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.02.22 15:32:33 | 000,050,477 | ---- | C] () -- C:\Dokumente und Einstellungen\fritz\Desktop\Defogger(1).exe
[2013.02.22 14:05:01 | 000,376,832 | ---- | C] () -- C:\Dokumente und Einstellungen\fritz\Desktop\gmer_2.1.19081.exe
[2013.02.22 13:54:01 | 000,000,000 | ---- | C] () -- C:\Dokumente und Einstellungen\fritz\defogger_reenable
[2013.02.17 00:12:22 | 000,030,680 | ---- | C] () -- C:\Dokumente und Einstellungen\fritz\Eigene Dateien\cc_20130217_001219.reg
[2013.02.11 21:07:41 | 000,000,790 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Desktop\Diablo II - Lord of Destruction.lnk
[2013.02.08 11:59:59 | 000,176,128 | ---- | C] () -- C:\Dokumente und Einstellungen\fritz\Desktop\TaskbarRepairToolPlus!.exe
[2013.01.30 19:03:33 | 000,001,460 | ---- | C] () -- C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\recently-used.xbel
[2013.01.10 15:30:07 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2013.01.09 13:43:42 | 000,390,880 | ---- | C] () -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\FontCache3.0.0.0.dat
[2012.10.29 15:04:28 | 000,000,397 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2012.10.29 14:56:23 | 000,001,534 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ss.ini
[2012.10.08 13:52:45 | 000,000,400 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012.09.14 16:52:07 | 000,001,065 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2012.09.09 06:29:29 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.09.08 17:04:54 | 000,005,632 | ---- | C] () -- C:\Dokumente und Einstellungen\fritz\Lokale Einstellungen\Anwendungsdaten\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.07 14:42:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012.09.07 14:41:08 | 000,194,568 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.09.07 14:30:05 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.09.07 14:19:05 | 000,044,240 | ---- | C] () -- C:\WINDOWS\System32\drivers\fsbts.sys
[2012.09.07 14:18:32 | 000,019,571 | ---- | C] () -- C:\WINDOWS\prodsett_copy.ini
[2012.09.07 14:02:36 | 000,095,617 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2012.09.07 14:01:44 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2012.09.07 13:56:17 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012.09.07 13:49:13 | 000,021,740 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
========== ZeroAccess Check ==========
[2012.09.11 11:47:14 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2012.06.28 22:32:24 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 11:51:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 08:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.01.10 15:30:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Canneverbe Limited
[2012.09.07 14:23:42 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\F-Secure
[2012.10.29 14:54:36 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\FreeRIP
[2012.12.19 17:49:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\StarMoney 8.0
[2013.02.08 13:55:10 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Tarma Installer
[2013.01.10 15:30:41 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Canneverbe Limited
[2013.02.20 18:59:39 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\FileZilla
[2012.12.30 13:29:01 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Groovedown_Uninstall
[2012.09.11 19:56:23 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\fritz\Anwendungsdaten\Scribus
========== Purity Check ==========
< End of report > |