Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Live Security Befall - Asus Notebook Formatierung? (https://www.trojaner-board.de/121067-live-security-befall-asus-notebook-formatierung.html)

brainInfect 02.08.2012 16:49

Live Security Befall - Asus Notebook Formatierung?
 
Hey, leider ist mein Notebook vom Live Security Virus befallen. Es klappt einfach nichts mehr, auch nicht, wenn ichs über "Als Administrator starten" versuche.

Meint ihr, es lohnt sich den Virus zu entfernen oder wäre es angebrachter, das Notebook sofort zu formatieren? Diese Option bevorzuge ich nämlich ehrlich gesagt, was mich zu meinem nächsten Problem bringt: Ich weiss nicht, wie! Ich habe ein Asus Notebook, welches bereits vorinstalliert war. Ehrlich gesagt kenne ich nichtmal die Bezeichnung meines Notebooks. Ich weiss einfach nicht weiter. -.-

Wäre euch für Hilfe echt dankbar, bin ein wenig verzweifelt.

lg
Brain

cosinus 05.08.2012 12:15

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

brainInfect 05.08.2012 17:12

Malware-Log vom 24.07.2012

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.24.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
smoking caterpillar :: SMOKINGCATERPIL [Administrator]

24.07.2012 16:47:45
mbam-log-2012-07-24 (16-47-45).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 190381
Laufzeit: 2 Minute(n), 39 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|LicenseValidator (Trojan.BTSoft.Gen) -> Daten: C:\Users\smoking caterpillar\AppData\Roaming\Identities\{D93F8CF7-17DC-487A-8E11-E8C8222F6912}\LicenseValidator.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 20
C:\Users\smoking caterpillar\AppData\Roaming\Identities\{D93F8CF7-17DC-487A-8E11-E8C8222F6912}\LicenseValidator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Dropbox\{9AE5A9CE-9EE6-484E-ACAF-49A266E826A9}\Upgrade.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Google Inc\{62CEF272-CEA0-4A3B-B3E4-6119CBC0AC4F}\UpgradeChecker.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Google Inc\{71BE8F5C-8B4F-4D94-9B1A-3A18C568DE9E}\UpgradeHelper.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\ICQ\{D18BED3C-3459-46DC-AD82-1A4F38ED3045}\Upgrade.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Identities\{01E2D5AA-2CA9-4966-96CB-91A8A4AF946E}\LicenseValidator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Identities\{DFB35EAD-B0E3-4DA7-97FA-E91BF3D0266C}\LicenseValidator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\{1B26BBDD-28A3-4E26-A15D-DBED71990BB9}\UpgradeChecker.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Opera\{162703E9-604F-4FD1-ABE5-101ABBCE364A}\Upgrade.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Opera\{F5B1C104-5DF9-467D-B18D-72DBE38FA7C5}\Validator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Skype\{E2E78658-7838-4A03-850D-449099CC3EAA}\LicenseValidator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Sun\{D1D11219-7E39-460A-8E9F-5B5535AB51FE}\Validator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Sun\{F428A2DC-F651-4779-9FB6-6218EEB0F9FD}\UpgradeChecker.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\TeamViewer\{4D719943-1F6D-4C65-AB47-D1DB8F9F2D2B}\UpgradeChecker.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\TeamViewer\{6959CA12-456E-41A8-A3AA-8636D6D10422}\UpgradeHelper.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\TeamViewer\{EBFAA0B8-7644-4F46-A6D0-2696616EE0D0}\Validator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\vlc\{5545D2BA-31DA-4BD9-976D-44642277FA6F}\Upgrade.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Windows Desktop Search\{C3E966FD-6392-42F9-83C8-D229DB31ECC8}\LicenseValidator.exe (Trojan.BTSoft.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\n (Trojan.Sirefef) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\U\800000cb.@ (Rootkit.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Malware-Log vom 25.07.2012

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.07.24.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
smoking caterpillar :: SMOKINGCATERPIL [Administrator]

25.07.2012 09:22:16
mbam-log-2012-07-25 (09-22-16).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 349355
Laufzeit: 1 Stunde(n), 5 Minute(n), 5 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 6
F:\RECYCLER\S-1-5-21-854245398-823518204-725345543-1004\De1.exe (PUP.RemoveWGA) -> Keine Aktion durchgeführt.
C:\Users\smoking caterpillar\AppData\Local\fzezwppvr.exe (Trojan.Lameshield) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Local\rlnuvk.exe (Trojan.LameShield) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IUMBP903\soft3[1].exe (RootKit.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IUMBP903\soft4[1].exe (Trojan.LameShield) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\n (Trojan.Sirefef) -> Löschen bei Neustart.

(Ende)

Malware-Log vom 05.08.2012

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.05.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
smoking caterpillar :: SMOKINGCATERPIL [Administrator]

05.08.2012 16:44:54
mbam-log-2012-08-05 (16-44-54).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 343447
Laufzeit: 1 Stunde(n), 3 Minute(n), 56 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 1
C:\Users\smoking caterpillar\AppData\Roaming\ncarn.dll (Trojan.Midhos) -> Löschen bei Neustart.

Infizierte Registrierungsschlüssel: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum (Trojan.LameShield) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 3
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bösartig: (1) Gut: (0) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 1
C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum (Rogue.LiveSecurityPlatinum) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 9
C:\$Recycle.Bin\S-1-5-21-1377819090-1488837102-2095713333-1001\$RCI5S2Z.exe (PUP.Adbundler) -> Keine Aktion durchgeführt.
C:\Users\smoking caterpillar\AppData\Roaming\ncarn.dll (Trojan.Midhos) -> Löschen bei Neustart.
C:\ProgramData\zzouqsor.exe (Trojan.Ransom) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\7531CCA9CA4D593B2B7FCCBCF875F002\7531CCA9CA4D593B2B7FCCBCF875F002.exe (Trojan.LameShield) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\0.9311672931793852.exe (Trojan.Ransom) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\n (Rootkit.0Access) -> Löschen bei Neustart.
C:\Users\smoking caterpillar\AppData\Roaming\KB01265628.exe (Trojan.Cridex) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\xsecva\xsecva.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum\Live Security Platinum.lnk (Rogue.LiveSecurityPlatinum) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Mit dem ESET Online Scanner hab ich irgendwie Probleme. Der Firefox lässt sich nicht öffnen (auch nicht per "Als Administrator starten") und der IE öffnet die ESET Homepage nicht.

Deswegen habe ich das Programm auf einem anderen PC runtergeladen und es dann per Stick auf meinen Laptop gezogen. Nachdem ich die "Terms" akzeptiert habe und auf START klicke kommt folgendes:

Can not get update. Is proxy configured?

Wie kann ich dieses Problem lösen?!

lg
brainInfect

cosinus 05.08.2012 17:34

Bitte prüfen:


Falsche Proxy Einstellungen entfernen
  • Klicke im Start-Menü unter "Einstellungen" auf "Systemsteuerung" -> "Internetoptionen".
  • Wähle die Karteikarte "Verbindungen->Lan-Einstellungen“ und überprüfe ob bei Proxyserver ein Häkchen steht,
    wenn ja -> Entfernen, dann -> OK (sofern nicht richtige Eintragung)



brainInfect 05.08.2012 19:15

Okay, also nachdem Malware Scan ging der Firefox auf einmal wieder, habe ESET runtergeladen und alles ging Problemlos. Hier der Log. :)

Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=1f20a472f272094c81f7295446fd3509
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-08-05 06:08:15
# local_time=2012-08-05 08:08:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=512 16777215 100 0 41520902 41520902 0 0
# compatibility_mode=5893 16776574 66 94 1106629 95813828 0 0
# compatibility_mode=8192 67108863 100 0 1568 1568 0 0
# scanned=158493
# found=41
# cleaned=0
# scan_time=6119
C:\$Recycle.Bin\S-1-5-21-1377819090-1488837102-2095713333-1001\$RCI5S2Z.exe        Win32/Toggle application (unable to clean)        00000000000000000000000000000000        I
C:\ProgramData\ymiyyjwzywphaxu\main.html        HTML/Ransom.B trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\All Users\ymiyyjwzywphaxu\main.html        HTML/Ransom.B trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IUMBP903\%2e_files_build02[1].exe        Win32/Injector.URC trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\Local\Temp\sgwe3t.exe        a variant of Win32/Injector.USA trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\Local\Temp\~!#8E8B.tmp        a variant of Win32/Kryptik.AJHU trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\Local\Temp\tmpd1c5c85e\build02.exe        Win32/Injector.URC trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\11f2e450-17cb4a95        a variant of Win32/Injector.USA trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\74231951-2c1c4008        a variant of Java/Exploit.CVE-2011-3544.AO trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\cc7b851-1b23fa1a        Java/Exploit.Blacole.DW trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\4ad8d3d7-4a47f3d9        a variant of Java/Exploit.CVE-2011-3544.AA trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\66caa8d8-6f32d31f        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\1779e89c-4bc09bea        Java/Exploit.CVE-2012-1723.R trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\19f4031d-4d8fb3f2        Java/Exploit.CVE-2011-3544.AF trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\4c6d7fe0-7bef0eb4        Java/Exploit.CVE-2012-0507.CI trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\8360020-6431778d        Java/Exploit.CVE-2011-3544.AU trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\59871be2-60b5ce50        Java/Exploit.Agent.NBE trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\9f961e6-66e4e2f5        a variant of Java/Exploit.CVE-2011-3544.AI trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\73d1c62e-77e4f8bf        Java/Exploit.CVE-2012-1723.Z trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\40d39af2-25e2eb90        Java/Exploit.CVE-2012-1723.R trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\6947bcb3-2ef729fa        Java/Exploit.Agent.NBR trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\72e195b7-255cdbb5        Java/Exploit.CVE-2012-0507.BT trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\30c9379-68c7efec        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\1c23d47a-76f6c763        Java/Exploit.Agent.NAW trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\9e60fa-461d7952        Java/Exploit.CVE-2012-0507.CF trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\3eb8827c-5149b99f        Java/Exploit.CVE-2012-0507.CU trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\3c0a4d7f-72686568        Java/Exploit.Agent.NCB trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\78dde689-5edcf65d        Java/Exploit.Agent.NAY trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\Roaming\Albyc\edfui.exe        a variant of Win32/Kryptik.AJHU trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\Roaming\Paxyka\caqy.exe        Win32/Injector.URC trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\AppData\Roaming\vlc\{96FD72B9-3877-4F4A-9591-A6E08D4D18B2}\Upgrade.exe        a variant of Win32/Injector.TSL trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\smoking caterpillar\Downloads\Mipony153-Installer.exe        Win32/Toolbar.Babylon application (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\U\80000000.@        Win64/Sirefef.AL trojan (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-10 145729\Backup Files 2012-07-10 145729\Backup files 1.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-10 145729\Backup Files 2012-07-10 145729\Backup files 2.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-15 190001\Backup Files 2012-07-15 190001\Backup files 1.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-15 190001\Backup Files 2012-07-15 190001\Backup files 2.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-22 190002\Backup Files 2012-07-22 190002\Backup files 1.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-22 190002\Backup Files 2012-07-22 190002\Backup files 2.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-22 190002\Backup Files 2012-07-29 190001\Backup files 1.zip        Java/Exploit.CVE-2012-1723.R trojan (unable to clean)        00000000000000000000000000000000        I
D:\SMOKINGCATERPIL\Backup Set 2012-07-22 190002\Backup Files 2012-08-05 190004\Backup files 1.zip        multiple threats (unable to clean)        00000000000000000000000000000000        I

Bis hierher schonmal Danke für die Mühe!!

cosinus 05.08.2012 19:29

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

brainInfect 05.08.2012 19:36

Code:

# AdwCleaner v1.800 - Logfile created 08/05/2012 at 20:35:56
# Updated 01/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : smoking caterpillar - SMOKINGCATERPIL
# Running from : C:\Users\smoking caterpillar\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\smoking caterpillar\AppData\LocalLow\BabylonToolbar
Folder Found : C:\Users\smoking caterpillar\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\smoking caterpillar\AppData\Roaming\loadtbs
Folder Found : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\Conduit
Folder Found : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\ConduitCommon
Folder Found : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\CT2431245
Folder Found : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\CT2849855
Folder Found : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}
Folder Found : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}
Folder Found : C:\ProgramData\InstallMate
File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml

***** [Registry] *****

Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\bhoclass.bho.bhoclass.bho
Key Found : HKLM\SOFTWARE\Classes\bhoclass.bho.bhoclass.bho.1.0
Key Found : HKLM\SOFTWARE\Conduit
[x64] Key Found : HKCU\Software\Conduit
[x64] Key Found : HKCU\Software\Softonic
[x64] Key Found : HKLM\SOFTWARE\Classes\bhoclass.bho.bhoclass.bho
[x64] Key Found : HKLM\SOFTWARE\Classes\bhoclass.bho.bhoclass.bho.1.0

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2CF0D01-7657-48AA-98C9-AE5E64757FCC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2CF0D01-7657-48AA-98C9-AE5E64757FCC}
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : Daniel [Profil par défaut]
File : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\prefs.js

Found : user_pref("CT2431245..clientLogIsEnabled", false);
Found : user_pref("CT2431245..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2431245..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2431245.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT2431245.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2431245.BrowserCompStateIsOpen_129453394044193841", true);
Found : user_pref("CT2431245.BrowserCompStateIsOpen_129659302539581540", true);
Found : user_pref("CT2431245.BrowserCompStateIsOpen_129682601309982614", true);
Found : user_pref("CT2431245.BrowserCompStateIsOpen_129780209672379590", true);
Found : user_pref("CT2431245.BrowserCompStateIsOpen_129790544018252482", true);
Found : user_pref("CT2431245.CTID", "CT2431245");
Found : user_pref("CT2431245.CurrentServerDate", "5-8-2012");
Found : user_pref("CT2431245.DialogsAlignMode", "LTR");
Found : user_pref("CT2431245.DialogsGetterLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Found : user_pref("CT2431245.DownloadReferralCookieData", "");
Found : user_pref("CT2431245.EMailNotifierPollDate", "Sun Apr 29 2012 17:56:32 GMT+0200");
Found : user_pref("CT2431245.FeedLastCount129009402595187825", 505);
Found : user_pref("CT2431245.FeedPollDate7470634014180506963", "Mon Apr 30 2012 01:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634014269327586", "Sun Apr 29 2012 17:56:33 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634014329599698", "Mon Apr 30 2012 01:56:35 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634014537505092", "Sun Apr 29 2012 17:56:33 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634014970726540", "Mon Apr 30 2012 01:56:36 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634015410831318", "Sun Apr 29 2012 22:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634015483395460", "Mon Apr 30 2012 01:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634015636754705", "Mon Apr 30 2012 01:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634015768347545", "Mon Apr 30 2012 01:56:36 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634015855543602", "Mon Apr 30 2012 01:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634016030710453", "Sun Apr 29 2012 17:56:33 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634016114705611", "Mon Apr 30 2012 01:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634016129205152", "Sun Apr 29 2012 22:56:36 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634016143724791", "Sun Apr 29 2012 22:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634016271239162", "Sun Apr 29 2012 22:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634016568520719", "Mon Apr 30 2012 01:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634016726993788", "Sun Apr 29 2012 17:56:33 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017109031809", "Mon Apr 30 2012 01:56:36 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017132743740", "Mon Apr 30 2012 01:56:36 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017299547668", "Mon Apr 30 2012 01:56:38 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017302327846", "Mon Apr 30 2012 01:56:36 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017344111490", "Mon Apr 30 2012 01:56:35 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017478360748", "Sun Apr 29 2012 22:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017732797593", "Sun Apr 29 2012 17:56:33 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634017821686064", "Sun Apr 29 2012 22:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedPollDate7470634018090228721", "Mon Apr 30 2012 01:56:37 GMT+0200");
Found : user_pref("CT2431245.FeedTTL7470634014269327586", 5);
Found : user_pref("CT2431245.FeedTTL7470634014537505092", 5);
Found : user_pref("CT2431245.FeedTTL7470634014970726540", 2);
Found : user_pref("CT2431245.FeedTTL7470634015636754705", 5);
Found : user_pref("CT2431245.FeedTTL7470634015855543602", 30);
Found : user_pref("CT2431245.FeedTTL7470634016568520719", 30);
Found : user_pref("CT2431245.FeedTTL7470634017109031809", 2);
Found : user_pref("CT2431245.FeedTTL7470634017299547668", 2);
Found : user_pref("CT2431245.FirstServerDate", "5-6-2010");
Found : user_pref("CT2431245.FirstTime", true);
Found : user_pref("CT2431245.FirstTimeFF3", true);
Found : user_pref("CT2431245.FixPageNotFoundErrors", true);
Found : user_pref("CT2431245.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2431245.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2431245.HasUserGlobalKeys", true);
Found : user_pref("CT2431245.HomePageProtectorEnabled", false);
Found : user_pref("CT2431245.HomepageBeforeUnload", "hxxp://www.google.de/");
Found : user_pref("CT2431245.Initialize", true);
Found : user_pref("CT2431245.InitializeCommonPrefs", true);
Found : user_pref("CT2431245.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2431245.InstallationType", "Unknown");
Found : user_pref("CT2431245.InstalledDate", "Sat Jun 05 2010 22:45:45 GMT+0200");
Found : user_pref("CT2431245.InvalidateCache", false);
Found : user_pref("CT2431245.IsAlertDBUpdated", true);
Found : user_pref("CT2431245.IsGrouping", false);
Found : user_pref("CT2431245.IsMulticommunity", false);
Found : user_pref("CT2431245.IsOpenThankYouPage", false);
Found : user_pref("CT2431245.IsOpenUninstallPage", true);
Found : user_pref("CT2431245.LanguagePackLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Found : user_pref("CT2431245.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2431245.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2431245.LastLogin_2.5.8.6", "Sat Jun 05 2010 22:45:46 GMT+0200");
Found : user_pref("CT2431245.LastLogin_3.11.0.3", "Sun Apr 29 2012 17:56:34 GMT+0200");
Found : user_pref("CT2431245.LastLogin_3.12.2.3", "Sun May 20 2012 22:27:48 GMT+0200");
Found : user_pref("CT2431245.LastLogin_3.13.0.6", "Wed Jul 25 2012 20:25:22 GMT+0200");
Found : user_pref("CT2431245.LastLogin_3.14.1.0", "Sun Aug 05 2012 18:14:47 GMT+0200");
Found : user_pref("CT2431245.LatestVersion", "3.14.1.0");
Found : user_pref("CT2431245.Locale", "de-de");
Found : user_pref("CT2431245.LoginCache", 4);
Found : user_pref("CT2431245.MCDetectTooltipHeight", "83");
Found : user_pref("CT2431245.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2431245.MCDetectTooltipWidth", "295");
Found : user_pref("CT2431245.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT2431245.RadioIsPodcast", false);
Found : user_pref("CT2431245.RadioLastCheckTime", "Sun Apr 29 2012 17:56:33 GMT+0200");
Found : user_pref("CT2431245.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2431245.RadioLastUpdateServer", "129167771525870000");
Found : user_pref("CT2431245.RadioMediaID", "20503672");
Found : user_pref("CT2431245.RadioMediaType", "Media Player");
Found : user_pref("CT2431245.RadioMenuSelectedID", "EBRadioMenu_CT243124520503672");
Found : user_pref("CT2431245.RadioShrinkedFromSetup", false);
Found : user_pref("CT2431245.RadioStationName", "Team%20Radio%20Deutschland");
Found : user_pref("CT2431245.RadioStationURL", "hxxp://trd.stream.w-u-s.org:6666/dsl.m3u");
Found : user_pref("CT2431245.SHRINK_TOOLBAR", 1);
Found : user_pref("CT2431245.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Found : user_pref("CT2431245.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Found : user_pref("CT2431245.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2431245.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...]
Found : user_pref("CT2431245.SearchInNewTabEnabled", true);
Found : user_pref("CT2431245.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2431245.SearchInNewTabLastCheckTime", "Sun Aug 05 2012 18:14:46 GMT+0200");
Found : user_pref("CT2431245.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2431245.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2431245.SearchInNewTabUserEnabled", false);
Found : user_pref("CT2431245.SearchProtectorEnabled", false);
Found : user_pref("CT2431245.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT2431245.ServiceMapLastCheckTime", "Sun Aug 05 2012 18:14:46 GMT+0200");
Found : user_pref("CT2431245.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2431245.SettingsLastCheckTime", "Sun Aug 05 2012 18:14:46 GMT+0200");
Found : user_pref("CT2431245.SettingsLastUpdate", "1339926569");
Found : user_pref("CT2431245.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2431245.ThirdPartyComponentsLastCheck", "Sun Apr 29 2012 17:56:32 GMT+0200");
Found : user_pref("CT2431245.ThirdPartyComponentsLastUpdate", "1275408427");
Found : user_pref("CT2431245.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2431245");
Found : user_pref("CT2431245.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT2431245.UserID", "UN50208063598108291");
Found : user_pref("CT2431245.ValidationData_Toolbar", 2);
Found : user_pref("CT2431245.WeatherNetwork", "");
Found : user_pref("CT2431245.WeatherPollDate", "Sun Apr 29 2012 17:56:35 GMT+0200");
Found : user_pref("CT2431245.WeatherUnit", "C");
Found : user_pref("CT2431245.alertChannelId", "825452");
Found : user_pref("CT2431245.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Found : user_pref("CT2431245.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Found : user_pref("CT2431245.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Found : user_pref("CT2431245.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...]
Found : user_pref("CT2431245.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Found : user_pref("CT2431245.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Found : user_pref("CT2431245.backendstorage./9b+7e06cg5el8:", "6E6D6D72727373707273");
Found : user_pref("CT2431245.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737378787979767879242F4B4947[...]
Found : user_pref("CT2431245.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Found : user_pref("CT2431245.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Found : user_pref("CT2431245.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Found : user_pref("CT2431245.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Found : user_pref("CT2431245.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Found : user_pref("CT2431245.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Found : user_pref("CT2431245.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Found : user_pref("CT2431245.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Found : user_pref("CT2431245.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Found : user_pref("CT2431245.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Found : user_pref("CT2431245.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Found : user_pref("CT2431245.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Found : user_pref("CT2431245.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Found : user_pref("CT2431245.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Found : user_pref("CT2431245.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Found : user_pref("CT2431245.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Found : user_pref("CT2431245.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Found : user_pref("CT2431245.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Found : user_pref("CT2431245.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Found : user_pref("CT2431245.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Found : user_pref("CT2431245.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Found : user_pref("CT2431245.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Found : user_pref("CT2431245.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Found : user_pref("CT2431245.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Found : user_pref("CT2431245.backendstorage./9b-0?3g>d", "3C3D3D70713E44767A7743477920474B7A78254D237E7E2A26[...]
Found : user_pref("CT2431245.backendstorage./9b-0?3g@6:5;", "");
Found : user_pref("CT2431245.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Found : user_pref("CT2431245.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Found : user_pref("CT2431245.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Found : user_pref("CT2431245.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D464[...]
Found : user_pref("CT2431245.backendstorage./9b5ba==9cjag", "6F6D6E6B6F7171437A767674724A47794B794F4F21");
Found : user_pref("CT2431245.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D72727373707278717575");
Found : user_pref("CT2431245.backendstorage./9b9643g3/9e", "6A");
Found : user_pref("CT2431245.backendstorage./9b<:222h64<", "393F352F3E");
Found : user_pref("CT2431245.backendstorage./9b=+03eh8h8j?:", "4443");
Found : user_pref("CT2431245.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Found : user_pref("CT2431245.backendstorage./9b?b0d:8aj62<h", "6D");
Found : user_pref("CT2431245.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Found : user_pref("CT2431245.backendstorage.autocompletepro_enable_auto", "31");
Found : user_pref("CT2431245.backendstorage.ct2431245ads1", "25374225323261647325323225334125354225374225323[...]
Found : user_pref("CT2431245.backendstorage.ct2431245current_term", "");
Found : user_pref("CT2431245.backendstorage.ct2431245isadsdisabled", "74727565");
Found : user_pref("CT2431245.backendstorage.ct2431245sdate", "3230");
Found : user_pref("CT2431245.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E");
Found : user_pref("CT2431245.backendstorage.printitgreenstatus", "74727565");
Found : user_pref("CT2431245.backendstorage.shoppingapp.gk.exipres", "53756E204A756E20323420323031322031353A[...]
Found : user_pref("CT2431245.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79");
Found : user_pref("CT2431245.clientLogIsEnabled", true);
Found : user_pref("CT2431245.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT2431245.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT2431245.globalFirstTimeInfoLastCheckTime", "Sun Apr 29 2012 17:56:34 GMT+0200");
Found : user_pref("CT2431245.homepageProtectorEnableByLogin", true);
Found : user_pref("CT2431245.initDone", true);
Found : user_pref("CT2431245.isAppTrackingManagerOn", true);
Found : user_pref("CT2431245.isFirstRadioInstallation", false);
Found : user_pref("CT2431245.myStuffEnabled", true);
Found : user_pref("CT2431245.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2431245.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2431245.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2431245.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2431245.oldAppsList", "129009402577063104,129009402577844366,111,129790544018252482,129[...]
Found : user_pref("CT2431245.revertSettingsEnabled", true);
Found : user_pref("CT2431245.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT2431245.searchProtectorEnableByLogin", true);
Found : user_pref("CT2431245.testingCtid", "");
Found : user_pref("CT2431245.toolbarAppMetaDataLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Found : user_pref("CT2431245.toolbarContextMenuLastCheckTime", "Sun Apr 29 2012 17:56:34 GMT+0200");
Found : user_pref("CT2431245.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CT2431245.usagesFlag", 2);
Found : user_pref("CT2849855..clientLogIsEnabled", false);
Found : user_pref("CT2849855..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2849855..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2849855.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT2849855.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2849855.BrowserCompStateIsOpen_129640009348738015", true);
Found : user_pref("CT2849855.CTID", "CT2849855");
Found : user_pref("CT2849855.CurrentServerDate", "5-8-2012");
Found : user_pref("CT2849855.DialogsAlignMode", "LTR");
Found : user_pref("CT2849855.DialogsGetterLastCheckTime", "Sun Aug 05 2012 18:14:56 GMT+0200");
Found : user_pref("CT2849855.DownloadReferralCookieData", "");
Found : user_pref("CT2849855.EMailNotifierPollDate", "Sat Feb 19 2011 21:39:38 GMT+0100");
Found : user_pref("CT2849855.FeedLastCount129349796701375473", 74);
Found : user_pref("CT2849855.FeedPollDate129313974171006416", "Sat Feb 19 2011 21:39:38 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313975698350231", "Sat Feb 19 2011 21:39:38 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313976370850190", "Sat Feb 19 2011 21:39:38 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313976648818968", "Sat Feb 19 2011 21:39:39 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313977444757117", "Sat Feb 19 2011 21:39:39 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313980389131455", "Sat Feb 19 2011 21:39:39 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313980655381977", "Sat Feb 19 2011 21:39:39 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313980886163259", "Sat Feb 19 2011 21:39:39 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313981234756535", "Sat Feb 19 2011 21:39:39 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313983226631720", "Sat Feb 19 2011 21:39:40 GMT+0100");
Found : user_pref("CT2849855.FeedPollDate129313983607725691", "Sat Feb 19 2011 21:39:40 GMT+0100");
Found : user_pref("CT2849855.FeedTTL129313974171006416", 10);
Found : user_pref("CT2849855.FeedTTL129313977444757117", 15);
Found : user_pref("CT2849855.FeedTTL129313980655381977", 5);
Found : user_pref("CT2849855.FeedTTL129313981234756535", 5);
Found : user_pref("CT2849855.FirstServerDate", "19-2-2011");
Found : user_pref("CT2849855.FirstTime", true);
Found : user_pref("CT2849855.FirstTimeFF3", true);
Found : user_pref("CT2849855.FixPageNotFoundErrors", false);
Found : user_pref("CT2849855.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2849855.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2849855.HasUserGlobalKeys", true);
Found : user_pref("CT2849855.Initialize", true);
Found : user_pref("CT2849855.InitializeCommonPrefs", true);
Found : user_pref("CT2849855.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2849855.InstallationType", "UnknownIntegration");
Found : user_pref("CT2849855.InstalledDate", "Sat Feb 19 2011 21:39:38 GMT+0100");
Found : user_pref("CT2849855.IsGrouping", false);
Found : user_pref("CT2849855.IsMulticommunity", false);
Found : user_pref("CT2849855.IsOpenThankYouPage", true);
Found : user_pref("CT2849855.IsOpenUninstallPage", false);
Found : user_pref("CT2849855.LanguagePackLastCheckTime", "Sun Aug 05 2012 18:14:56 GMT+0200");
Found : user_pref("CT2849855.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2849855.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2849855.LastLogin_3.12.0.7", "Wed Apr 25 2012 11:23:30 GMT+0200");
Found : user_pref("CT2849855.LastLogin_3.12.2.3", "Wed May 30 2012 17:21:55 GMT+0200");
Found : user_pref("CT2849855.LastLogin_3.13.0.6", "Wed Jul 25 2012 20:38:22 GMT+0200");
Found : user_pref("CT2849855.LastLogin_3.14.1.0", "Sun Aug 05 2012 18:14:56 GMT+0200");
Found : user_pref("CT2849855.LastLogin_3.2.5.2", "Sat Feb 19 2011 21:39:38 GMT+0100");
Found : user_pref("CT2849855.LatestVersion", "3.14.1.0");
Found : user_pref("CT2849855.Locale", "de");
Found : user_pref("CT2849855.MCDetectTooltipHeight", "83");
Found : user_pref("CT2849855.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2849855.MCDetectTooltipWidth", "295");
Found : user_pref("CT2849855.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT2849855.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2849855.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT284[...]
Found : user_pref("CT2849855.SearchInNewTabEnabled", true);
Found : user_pref("CT2849855.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2849855.SearchInNewTabLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Found : user_pref("CT2849855.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2849855.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2849855.SearchInNewTabUserEnabled", false);
Found : user_pref("CT2849855.ServiceMapLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Found : user_pref("CT2849855.SettingsLastCheckTime", "Sun Aug 05 2012 18:14:47 GMT+0200");
Found : user_pref("CT2849855.SettingsLastUpdate", "1342353836");
Found : user_pref("CT2849855.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2849855.ThirdPartyComponentsLastCheck", "Sat Feb 19 2011 21:39:34 GMT+0100");
Found : user_pref("CT2849855.ThirdPartyComponentsLastUpdate", "1255348257");
Found : user_pref("CT2849855.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT2849855.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2849855");
Found : user_pref("CT2849855.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT2849855.UserID", "UN72140786784973512");
Found : user_pref("CT2849855.ValidationData_Toolbar", 1);
Found : user_pref("CT2849855.WeatherNetwork", "");
Found : user_pref("CT2849855.WeatherPollDate", "Sat Feb 19 2011 21:39:41 GMT+0100");
Found : user_pref("CT2849855.WeatherUnit", "C");
Found : user_pref("CT2849855.alertChannelId", "1241896");
Found : user_pref("CT2849855.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Found : user_pref("CT2849855.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Found : user_pref("CT2849855.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Found : user_pref("CT2849855.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...]
Found : user_pref("CT2849855.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Found : user_pref("CT2849855.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Found : user_pref("CT2849855.backendstorage./9b+7e06cg5el8:", "6E6D6D72727074727272");
Found : user_pref("CT2849855.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473737878767A787878242F4B4947[...]
Found : user_pref("CT2849855.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Found : user_pref("CT2849855.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Found : user_pref("CT2849855.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Found : user_pref("CT2849855.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Found : user_pref("CT2849855.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Found : user_pref("CT2849855.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Found : user_pref("CT2849855.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Found : user_pref("CT2849855.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Found : user_pref("CT2849855.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Found : user_pref("CT2849855.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Found : user_pref("CT2849855.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Found : user_pref("CT2849855.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Found : user_pref("CT2849855.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Found : user_pref("CT2849855.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Found : user_pref("CT2849855.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Found : user_pref("CT2849855.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Found : user_pref("CT2849855.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Found : user_pref("CT2849855.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Found : user_pref("CT2849855.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Found : user_pref("CT2849855.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Found : user_pref("CT2849855.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Found : user_pref("CT2849855.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Found : user_pref("CT2849855.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Found : user_pref("CT2849855.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Found : user_pref("CT2849855.backendstorage./9b-0?3g>d", "6F3E6A6E6F7340457A717445452079484C77257C237E7E2A53[...]
Found : user_pref("CT2849855.backendstorage./9b-0?3g@6:5;", "");
Found : user_pref("CT2849855.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Found : user_pref("CT2849855.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Found : user_pref("CT2849855.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Found : user_pref("CT2849855.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Found : user_pref("CT2849855.backendstorage./9b5ba==9cjag", "6E3B6E3D6C3E43447A6F44764675764A78207D7B7A");
Found : user_pref("CT2849855.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D72727074727277777876");
Found : user_pref("CT2849855.backendstorage./9b9643g3/9e", "6A");
Found : user_pref("CT2849855.backendstorage./9b<:222h64<", "393F352F3E");
Found : user_pref("CT2849855.backendstorage./9b=+03eh8h8j?:", "4443");
Found : user_pref("CT2849855.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Found : user_pref("CT2849855.backendstorage./9b?b0d:8aj62<h", "6D");
Found : user_pref("CT2849855.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Found : user_pref("CT2849855.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT2849855.homepageProtectorEnableByLogin", true);
Found : user_pref("CT2849855.initDone", true);
Found : user_pref("CT2849855.myStuffEnabled", true);
Found : user_pref("CT2849855.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2849855.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2849855.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2849855.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2849855.revertSettingsEnabled", true);
Found : user_pref("CT2849855.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT2849855.searchProtectorEnableByLogin", true);
Found : user_pref("CT2849855.testingCtid", "");
Found : user_pref("CT2849855.toolbarAppMetaDataLastCheckTime", "Sun Aug 05 2012 18:14:56 GMT+0200");
Found : user_pref("CT2849855.toolbarContextMenuLastCheckTime", "Sat Feb 19 2011 21:39:42 GMT+0100");
Found : user_pref("CT2849855.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2431245/CT2431245[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1241896/1237569/DE", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/DE", "\"1-218[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849855", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.11[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2431245",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849855",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"d12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...]
Found : user_pref("CommunityToolbar.EngineOwner", "");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "bittorrentbar_de");
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Dokumente und Einstellungen\\Administrator[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.11.0.3");
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Found : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2849855");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "bittorrentbar_de");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2431245,CT2849855");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2431245,ConduitEngine,CT2849855");
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Dec 14 2011 20:05:49 GMT+0100");
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Dec 14 2011 20:05:49 GMT+0100");
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "6b1ebbe2-eee1-4afe-b21e-bc3c4e851b33");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Feb 19 2011 21:39:42 GMT+0100");
Found : user_pref("CommunityToolbar.globalUserId", "e15f13f9-65e8-4a86-92d2-d255058818f5");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.killedEngine", true);
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Apr 29 2012 17:56:3[...]
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Apr 29 2012 18:56:43 GMT+020[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Apr 29 2012 17:56:33 GMT+0200");
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "d7df0c30-2b5d-4d1c-b840-d36b13f2fb23");
Found : user_pref("CommunityToolbar.undefined", "");
Found : user_pref("extensions.DivXWebPlayer@divx.com.install-event-fired", true);
Found : user_pref("extensions.enabledAddons", "DivXWebPlayer@divx.com:2.0.2.039,personas@christopher.beard:1[...]
Found : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Found : user_pref("extensions.facemoods.aflt", "_#w7th2");
Found : user_pref("extensions.facemoods.firstRun", false);
Found : user_pref("extensions.facemoods.lastActv", "19");
Found : user_pref("keyword.URL", "hxxp://start.facemoods.com/results.php?f=5&a=w7th2&q=");

*************************

AdwCleaner[R1].txt - [41723 octets] - [05/08/2012 20:35:56]

########## EOF - C:\AdwCleaner[R1].txt - [41852 octets] ##########

PS: Glückwunsch zum Sieg im Elfmeterschießen vorhin, am 1. Spieltag werden wir ein härterer Gegner für euch. :P

lg

cosinus 05.08.2012 19:53

Zitat:

PS: Glückwunsch zum Sieg im Elfmeterschießen vorhin, am 1. Spieltag werden wir ein härterer Gegner für euch. :P
Wir werden sehen! :aufsmaul: :applaus: :pfeiff:

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

brainInfect 05.08.2012 20:03

Zitat:

Zitat von cosinus (Beitrag 884538)
Wir werden sehen! :aufsmaul: :applaus: :pfeiff:

Bin gespannt. Zumindest erwarte ich euch stärker als Hamburg letzte Saison zum Auftakt. http://forum.express.de/images/smili...nvorlachen.gif http://www.ugly-smilies.de/data/ugly.gif

Code:

# AdwCleaner v1.800 - Logfile created 08/05/2012 at 20:55:57
# Updated 01/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : smoking caterpillar - SMOKINGCATERPIL
# Running from : C:\Users\smoking caterpillar\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\smoking caterpillar\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\smoking caterpillar\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\smoking caterpillar\AppData\Roaming\loadtbs
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\Conduit
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\ConduitCommon
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\CT2431245
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\CT2849855
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}
Folder Deleted : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}
Folder Deleted : C:\ProgramData\InstallMate
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml

***** [Registry] *****

Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\bhoclass.bho.bhoclass.bho
Key Deleted : HKLM\SOFTWARE\Classes\bhoclass.bho.bhoclass.bho.1.0
Key Deleted : HKLM\SOFTWARE\Conduit

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2CF0D01-7657-48AA-98C9-AE5E64757FCC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BBA74401-6D6F-4BBD-9F65-E8623814F3BB}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2F39980-399F-492E-8D88-5FF7CCB3B47F}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (de)

Profile name : Daniel [Profil par défaut]
File : C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\prefs.js

C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\user.js ... Deleted !

Deleted : user_pref("CT2431245..clientLogIsEnabled", false);
Deleted : user_pref("CT2431245..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2431245..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2431245.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2431245.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2431245.BrowserCompStateIsOpen_129453394044193841", true);
Deleted : user_pref("CT2431245.BrowserCompStateIsOpen_129659302539581540", true);
Deleted : user_pref("CT2431245.BrowserCompStateIsOpen_129682601309982614", true);
Deleted : user_pref("CT2431245.BrowserCompStateIsOpen_129780209672379590", true);
Deleted : user_pref("CT2431245.BrowserCompStateIsOpen_129790544018252482", true);
Deleted : user_pref("CT2431245.CTID", "CT2431245");
Deleted : user_pref("CT2431245.CurrentServerDate", "5-8-2012");
Deleted : user_pref("CT2431245.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2431245.DialogsGetterLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Deleted : user_pref("CT2431245.DownloadReferralCookieData", "");
Deleted : user_pref("CT2431245.EMailNotifierPollDate", "Sun Apr 29 2012 17:56:32 GMT+0200");
Deleted : user_pref("CT2431245.FeedLastCount129009402595187825", 505);
Deleted : user_pref("CT2431245.FeedPollDate7470634014180506963", "Mon Apr 30 2012 01:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634014269327586", "Sun Apr 29 2012 17:56:33 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634014329599698", "Mon Apr 30 2012 01:56:35 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634014537505092", "Sun Apr 29 2012 17:56:33 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634014970726540", "Mon Apr 30 2012 01:56:36 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634015410831318", "Sun Apr 29 2012 22:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634015483395460", "Mon Apr 30 2012 01:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634015636754705", "Mon Apr 30 2012 01:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634015768347545", "Mon Apr 30 2012 01:56:36 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634015855543602", "Mon Apr 30 2012 01:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634016030710453", "Sun Apr 29 2012 17:56:33 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634016114705611", "Mon Apr 30 2012 01:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634016129205152", "Sun Apr 29 2012 22:56:36 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634016143724791", "Sun Apr 29 2012 22:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634016271239162", "Sun Apr 29 2012 22:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634016568520719", "Mon Apr 30 2012 01:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634016726993788", "Sun Apr 29 2012 17:56:33 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017109031809", "Mon Apr 30 2012 01:56:36 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017132743740", "Mon Apr 30 2012 01:56:36 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017299547668", "Mon Apr 30 2012 01:56:38 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017302327846", "Mon Apr 30 2012 01:56:36 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017344111490", "Mon Apr 30 2012 01:56:35 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017478360748", "Sun Apr 29 2012 22:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017732797593", "Sun Apr 29 2012 17:56:33 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634017821686064", "Sun Apr 29 2012 22:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedPollDate7470634018090228721", "Mon Apr 30 2012 01:56:37 GMT+0200");
Deleted : user_pref("CT2431245.FeedTTL7470634014269327586", 5);
Deleted : user_pref("CT2431245.FeedTTL7470634014537505092", 5);
Deleted : user_pref("CT2431245.FeedTTL7470634014970726540", 2);
Deleted : user_pref("CT2431245.FeedTTL7470634015636754705", 5);
Deleted : user_pref("CT2431245.FeedTTL7470634015855543602", 30);
Deleted : user_pref("CT2431245.FeedTTL7470634016568520719", 30);
Deleted : user_pref("CT2431245.FeedTTL7470634017109031809", 2);
Deleted : user_pref("CT2431245.FeedTTL7470634017299547668", 2);
Deleted : user_pref("CT2431245.FirstServerDate", "5-6-2010");
Deleted : user_pref("CT2431245.FirstTime", true);
Deleted : user_pref("CT2431245.FirstTimeFF3", true);
Deleted : user_pref("CT2431245.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2431245.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2431245.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2431245.HasUserGlobalKeys", true);
Deleted : user_pref("CT2431245.HomePageProtectorEnabled", false);
Deleted : user_pref("CT2431245.HomepageBeforeUnload", "hxxp://www.google.de/");
Deleted : user_pref("CT2431245.Initialize", true);
Deleted : user_pref("CT2431245.InitializeCommonPrefs", true);
Deleted : user_pref("CT2431245.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2431245.InstallationType", "Unknown");
Deleted : user_pref("CT2431245.InstalledDate", "Sat Jun 05 2010 22:45:45 GMT+0200");
Deleted : user_pref("CT2431245.InvalidateCache", false);
Deleted : user_pref("CT2431245.IsAlertDBUpdated", true);
Deleted : user_pref("CT2431245.IsGrouping", false);
Deleted : user_pref("CT2431245.IsMulticommunity", false);
Deleted : user_pref("CT2431245.IsOpenThankYouPage", false);
Deleted : user_pref("CT2431245.IsOpenUninstallPage", true);
Deleted : user_pref("CT2431245.LanguagePackLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Deleted : user_pref("CT2431245.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2431245.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2431245.LastLogin_2.5.8.6", "Sat Jun 05 2010 22:45:46 GMT+0200");
Deleted : user_pref("CT2431245.LastLogin_3.11.0.3", "Sun Apr 29 2012 17:56:34 GMT+0200");
Deleted : user_pref("CT2431245.LastLogin_3.12.2.3", "Sun May 20 2012 22:27:48 GMT+0200");
Deleted : user_pref("CT2431245.LastLogin_3.13.0.6", "Wed Jul 25 2012 20:25:22 GMT+0200");
Deleted : user_pref("CT2431245.LastLogin_3.14.1.0", "Sun Aug 05 2012 18:14:47 GMT+0200");
Deleted : user_pref("CT2431245.LatestVersion", "3.14.1.0");
Deleted : user_pref("CT2431245.Locale", "de-de");
Deleted : user_pref("CT2431245.LoginCache", 4);
Deleted : user_pref("CT2431245.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2431245.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2431245.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2431245.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2431245.RadioIsPodcast", false);
Deleted : user_pref("CT2431245.RadioLastCheckTime", "Sun Apr 29 2012 17:56:33 GMT+0200");
Deleted : user_pref("CT2431245.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2431245.RadioLastUpdateServer", "129167771525870000");
Deleted : user_pref("CT2431245.RadioMediaID", "20503672");
Deleted : user_pref("CT2431245.RadioMediaType", "Media Player");
Deleted : user_pref("CT2431245.RadioMenuSelectedID", "EBRadioMenu_CT243124520503672");
Deleted : user_pref("CT2431245.RadioShrinkedFromSetup", false);
Deleted : user_pref("CT2431245.RadioStationName", "Team%20Radio%20Deutschland");
Deleted : user_pref("CT2431245.RadioStationURL", "hxxp://trd.stream.w-u-s.org:6666/dsl.m3u");
Deleted : user_pref("CT2431245.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2431245.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2431245.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Deleted : user_pref("CT2431245.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2431245.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...]
Deleted : user_pref("CT2431245.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2431245.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2431245.SearchInNewTabLastCheckTime", "Sun Aug 05 2012 18:14:46 GMT+0200");
Deleted : user_pref("CT2431245.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2431245.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2431245.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT2431245.SearchProtectorEnabled", false);
Deleted : user_pref("CT2431245.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT2431245.ServiceMapLastCheckTime", "Sun Aug 05 2012 18:14:46 GMT+0200");
Deleted : user_pref("CT2431245.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2431245.SettingsLastCheckTime", "Sun Aug 05 2012 18:14:46 GMT+0200");
Deleted : user_pref("CT2431245.SettingsLastUpdate", "1339926569");
Deleted : user_pref("CT2431245.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2431245.ThirdPartyComponentsLastCheck", "Sun Apr 29 2012 17:56:32 GMT+0200");
Deleted : user_pref("CT2431245.ThirdPartyComponentsLastUpdate", "1275408427");
Deleted : user_pref("CT2431245.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2431245");
Deleted : user_pref("CT2431245.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT2431245.UserID", "UN50208063598108291");
Deleted : user_pref("CT2431245.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2431245.WeatherNetwork", "");
Deleted : user_pref("CT2431245.WeatherPollDate", "Sun Apr 29 2012 17:56:35 GMT+0200");
Deleted : user_pref("CT2431245.WeatherUnit", "C");
Deleted : user_pref("CT2431245.alertChannelId", "825452");
Deleted : user_pref("CT2431245.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e06cg5el8:", "6E6D6D72727373707273");
Deleted : user_pref("CT2431245.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737378787979767879242F4B4947[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Deleted : user_pref("CT2431245.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Deleted : user_pref("CT2431245.backendstorage./9b-0?3g>d", "3C3D3D70713E44767A7743477920474B7A78254D237E7E2A26[...]
Deleted : user_pref("CT2431245.backendstorage./9b-0?3g@6:5;", "");
Deleted : user_pref("CT2431245.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Deleted : user_pref("CT2431245.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Deleted : user_pref("CT2431245.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Deleted : user_pref("CT2431245.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484775213F3E484F4E4D464[...]
Deleted : user_pref("CT2431245.backendstorage./9b5ba==9cjag", "6F6D6E6B6F7171437A767674724A47794B794F4F21");
Deleted : user_pref("CT2431245.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D72727373707278717575");
Deleted : user_pref("CT2431245.backendstorage./9b9643g3/9e", "6A");
Deleted : user_pref("CT2431245.backendstorage./9b<:222h64<", "393F352F3E");
Deleted : user_pref("CT2431245.backendstorage./9b=+03eh8h8j?:", "4443");
Deleted : user_pref("CT2431245.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Deleted : user_pref("CT2431245.backendstorage./9b?b0d:8aj62<h", "6D");
Deleted : user_pref("CT2431245.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Deleted : user_pref("CT2431245.backendstorage.autocompletepro_enable_auto", "31");
Deleted : user_pref("CT2431245.backendstorage.ct2431245ads1", "25374225323261647325323225334125354225374225323[...]
Deleted : user_pref("CT2431245.backendstorage.ct2431245current_term", "");
Deleted : user_pref("CT2431245.backendstorage.ct2431245isadsdisabled", "74727565");
Deleted : user_pref("CT2431245.backendstorage.ct2431245sdate", "3230");
Deleted : user_pref("CT2431245.backendstorage.hxxp://cmg1_conduit-widgets_com/pitsi.state", "4F50454E");
Deleted : user_pref("CT2431245.backendstorage.printitgreenstatus", "74727565");
Deleted : user_pref("CT2431245.backendstorage.shoppingapp.gk.exipres", "53756E204A756E20323420323031322031353A[...]
Deleted : user_pref("CT2431245.backendstorage.shoppingapp.gk.geolocation", "6765726D616E79");
Deleted : user_pref("CT2431245.clientLogIsEnabled", true);
Deleted : user_pref("CT2431245.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2431245.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT2431245.globalFirstTimeInfoLastCheckTime", "Sun Apr 29 2012 17:56:34 GMT+0200");
Deleted : user_pref("CT2431245.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2431245.initDone", true);
Deleted : user_pref("CT2431245.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2431245.isFirstRadioInstallation", false);
Deleted : user_pref("CT2431245.myStuffEnabled", true);
Deleted : user_pref("CT2431245.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2431245.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2431245.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2431245.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2431245.oldAppsList", "129009402577063104,129009402577844366,111,129790544018252482,129[...]
Deleted : user_pref("CT2431245.revertSettingsEnabled", true);
Deleted : user_pref("CT2431245.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2431245.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2431245.testingCtid", "");
Deleted : user_pref("CT2431245.toolbarAppMetaDataLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Deleted : user_pref("CT2431245.toolbarContextMenuLastCheckTime", "Sun Apr 29 2012 17:56:34 GMT+0200");
Deleted : user_pref("CT2431245.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2431245.usagesFlag", 2);
Deleted : user_pref("CT2849855..clientLogIsEnabled", false);
Deleted : user_pref("CT2849855..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2849855..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2849855.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2849855.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2849855.BrowserCompStateIsOpen_129640009348738015", true);
Deleted : user_pref("CT2849855.CTID", "CT2849855");
Deleted : user_pref("CT2849855.CurrentServerDate", "5-8-2012");
Deleted : user_pref("CT2849855.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2849855.DialogsGetterLastCheckTime", "Sun Aug 05 2012 18:14:56 GMT+0200");
Deleted : user_pref("CT2849855.DownloadReferralCookieData", "");
Deleted : user_pref("CT2849855.EMailNotifierPollDate", "Sat Feb 19 2011 21:39:38 GMT+0100");
Deleted : user_pref("CT2849855.FeedLastCount129349796701375473", 74);
Deleted : user_pref("CT2849855.FeedPollDate129313974171006416", "Sat Feb 19 2011 21:39:38 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313975698350231", "Sat Feb 19 2011 21:39:38 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313976370850190", "Sat Feb 19 2011 21:39:38 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313976648818968", "Sat Feb 19 2011 21:39:39 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313977444757117", "Sat Feb 19 2011 21:39:39 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313980389131455", "Sat Feb 19 2011 21:39:39 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313980655381977", "Sat Feb 19 2011 21:39:39 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313980886163259", "Sat Feb 19 2011 21:39:39 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313981234756535", "Sat Feb 19 2011 21:39:39 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313983226631720", "Sat Feb 19 2011 21:39:40 GMT+0100");
Deleted : user_pref("CT2849855.FeedPollDate129313983607725691", "Sat Feb 19 2011 21:39:40 GMT+0100");
Deleted : user_pref("CT2849855.FeedTTL129313974171006416", 10);
Deleted : user_pref("CT2849855.FeedTTL129313977444757117", 15);
Deleted : user_pref("CT2849855.FeedTTL129313980655381977", 5);
Deleted : user_pref("CT2849855.FeedTTL129313981234756535", 5);
Deleted : user_pref("CT2849855.FirstServerDate", "19-2-2011");
Deleted : user_pref("CT2849855.FirstTime", true);
Deleted : user_pref("CT2849855.FirstTimeFF3", true);
Deleted : user_pref("CT2849855.FixPageNotFoundErrors", false);
Deleted : user_pref("CT2849855.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2849855.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2849855.HasUserGlobalKeys", true);
Deleted : user_pref("CT2849855.Initialize", true);
Deleted : user_pref("CT2849855.InitializeCommonPrefs", true);
Deleted : user_pref("CT2849855.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2849855.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2849855.InstalledDate", "Sat Feb 19 2011 21:39:38 GMT+0100");
Deleted : user_pref("CT2849855.IsGrouping", false);
Deleted : user_pref("CT2849855.IsMulticommunity", false);
Deleted : user_pref("CT2849855.IsOpenThankYouPage", true);
Deleted : user_pref("CT2849855.IsOpenUninstallPage", false);
Deleted : user_pref("CT2849855.LanguagePackLastCheckTime", "Sun Aug 05 2012 18:14:56 GMT+0200");
Deleted : user_pref("CT2849855.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2849855.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2849855.LastLogin_3.12.0.7", "Wed Apr 25 2012 11:23:30 GMT+0200");
Deleted : user_pref("CT2849855.LastLogin_3.12.2.3", "Wed May 30 2012 17:21:55 GMT+0200");
Deleted : user_pref("CT2849855.LastLogin_3.13.0.6", "Wed Jul 25 2012 20:38:22 GMT+0200");
Deleted : user_pref("CT2849855.LastLogin_3.14.1.0", "Sun Aug 05 2012 18:14:56 GMT+0200");
Deleted : user_pref("CT2849855.LastLogin_3.2.5.2", "Sat Feb 19 2011 21:39:38 GMT+0100");
Deleted : user_pref("CT2849855.LatestVersion", "3.14.1.0");
Deleted : user_pref("CT2849855.Locale", "de");
Deleted : user_pref("CT2849855.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2849855.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2849855.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2849855.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2849855.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2849855.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT284[...]
Deleted : user_pref("CT2849855.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2849855.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2849855.SearchInNewTabLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Deleted : user_pref("CT2849855.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2849855.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2849855.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT2849855.ServiceMapLastCheckTime", "Sun Aug 05 2012 18:14:53 GMT+0200");
Deleted : user_pref("CT2849855.SettingsLastCheckTime", "Sun Aug 05 2012 18:14:47 GMT+0200");
Deleted : user_pref("CT2849855.SettingsLastUpdate", "1342353836");
Deleted : user_pref("CT2849855.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2849855.ThirdPartyComponentsLastCheck", "Sat Feb 19 2011 21:39:34 GMT+0100");
Deleted : user_pref("CT2849855.ThirdPartyComponentsLastUpdate", "1255348257");
Deleted : user_pref("CT2849855.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT2849855.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2849855");
Deleted : user_pref("CT2849855.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT2849855.UserID", "UN72140786784973512");
Deleted : user_pref("CT2849855.ValidationData_Toolbar", 1);
Deleted : user_pref("CT2849855.WeatherNetwork", "");
Deleted : user_pref("CT2849855.WeatherPollDate", "Sat Feb 19 2011 21:39:41 GMT+0100");
Deleted : user_pref("CT2849855.WeatherUnit", "C");
Deleted : user_pref("CT2849855.alertChannelId", "1241896");
Deleted : user_pref("CT2849855.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D4[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C474[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e.:2z527", "247E707571777278333228702A7B797B7B7E30273224262[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e.x305", "247E2A4137374434337A463B3E2B732D7A7D7C213229343F5[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e/x305", "247E2B413536327844393C29712B787C7B773027323E4C434[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e06cg5el8:", "6E6D6D72727074727272");
Deleted : user_pref("CT2849855.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473737878767A787878242F4B4947[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e0x305", "247E2C403A407743383B28702A777C757D2F26313E4129554[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e1x305", "247E2D41313D403279453A3D2A722C7A77797E31283341473[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e2x305", "247E2E3542313D3D393A7B473C3F2C742E79207D322934435[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e31;cjc<=fbj#mm", "247E61393F236B257576737A2A212C6E414F444D[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e3x305", "247E2F413F3B36333F47463F7D493E412E76307E222421352[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A5[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e5x305", "247E3136422B7743383B28702A79757A772F2631434B3D495[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e6x305", "247E322C3E32323238453E7C483D402D752F7E7B2424342B3[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e7x305", "247E333D2C3F3E3F79453A3D2A722C7B7A797A31283347474[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e8x305", "247E343D3F3B35373B3F367C47472C742E7E7823322934495[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e9x305", "247E35332C3F327844393C29712B7B757979302732484C4F4[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e:x305", "247E36333B38327844393C29712B7B76797A3027324948554[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e;x305", "247E373F333F3738422F7B473C3F2C742E7E7A7A22332A354[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e<x305", "247E38343030442F463644377D493E412E7630217D2426352[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e=x305", "247E3933363F41413739357C483D402D752F207E2022342B3[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e>x305", "247E3A41363F323238387B473C3F2C742E7E20217C332A355[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e?x305", "247E3B2D2F2F334134403A3A7D494C2D752F2023207E342B3[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7e@x305", "247E3C40422B7743383B28702A7B767E782F26314E52543D2[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7eax305", "247E3D3D37387743383B28702A7B7A757E2F26314F4F544A5[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7ebx305", "247E3E393141303D33454036327E4A3F422F77317B7D23352[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7ecx305", "247E3F3D303043312E7A463B3E2B732D7B207E31283353515[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7edx305", "247E4035422A363879453A3D2A722C7D202F26315247543C4[...]
Deleted : user_pref("CT2849855.backendstorage./9b+7etx305", "247E6E2F2E3B323342357B44392B732D7A7B7B7C322934215[...]
Deleted : user_pref("CT2849855.backendstorage./9b-0?3g>d", "6F3E6A6E6F7340457A717445452079484C77257C237E7E2A53[...]
Deleted : user_pref("CT2849855.backendstorage./9b-0?3g@6:5;", "");
Deleted : user_pref("CT2849855.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Deleted : user_pref("CT2849855.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Deleted : user_pref("CT2849855.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6A696B7273747576");
Deleted : user_pref("CT2849855.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Deleted : user_pref("CT2849855.backendstorage./9b5ba==9cjag", "6E3B6E3D6C3E43447A6F44764675764A78207D7B7A");
Deleted : user_pref("CT2849855.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6D72727074727277777876");
Deleted : user_pref("CT2849855.backendstorage./9b9643g3/9e", "6A");
Deleted : user_pref("CT2849855.backendstorage./9b<:222h64<", "393F352F3E");
Deleted : user_pref("CT2849855.backendstorage./9b=+03eh8h8j?:", "4443");
Deleted : user_pref("CT2849855.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Deleted : user_pref("CT2849855.backendstorage./9b?b0d:8aj62<h", "6D");
Deleted : user_pref("CT2849855.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Deleted : user_pref("CT2849855.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT2849855.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2849855.initDone", true);
Deleted : user_pref("CT2849855.myStuffEnabled", true);
Deleted : user_pref("CT2849855.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2849855.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2849855.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2849855.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2849855.revertSettingsEnabled", true);
Deleted : user_pref("CT2849855.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2849855.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2849855.testingCtid", "");
Deleted : user_pref("CT2849855.toolbarAppMetaDataLastCheckTime", "Sun Aug 05 2012 18:14:56 GMT+0200");
Deleted : user_pref("CT2849855.toolbarContextMenuLastCheckTime", "Sat Feb 19 2011 21:39:42 GMT+0100");
Deleted : user_pref("CT2849855.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2431245/CT2431245[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1241896/1237569/DE", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825452/821260/DE", "\"1-218[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2431245", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849855", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.11[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2431245",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849855",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2849855/CT2849855[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"d12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"[...]
Deleted : user_pref("CommunityToolbar.EngineOwner", "");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "bittorrentbar_de");
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Dokumente und Einstellungen\\Administrator[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.11.0.3");
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://pgcff.pricegong.com/agreement/agree.html#pg_e[...]
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2849855");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{64ead72b-ffd4-4e01-aa3a-4c71665d73e4}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "bittorrentbar_de");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2431245,CT2849855");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2431245,ConduitEngine,CT2849855");
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Dec 14 2011 20:05:49 GMT+0100");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Dec 14 2011 20:05:49 GMT+0100");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "6b1ebbe2-eee1-4afe-b21e-bc3c4e851b33");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Feb 19 2011 21:39:42 GMT+0100");
Deleted : user_pref("CommunityToolbar.globalUserId", "e15f13f9-65e8-4a86-92d2-d255058818f5");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.killedEngine", true);
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Apr 29 2012 17:56:3[...]
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Apr 29 2012 18:56:43 GMT+020[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Apr 29 2012 17:56:33 GMT+0200");
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "d7df0c30-2b5d-4d1c-b840-d36b13f2fb23");
Deleted : user_pref("CommunityToolbar.undefined", "");
Deleted : user_pref("extensions.DivXWebPlayer@divx.com.install-event-fired", true);
Deleted : user_pref("extensions.enabledAddons", "DivXWebPlayer@divx.com:2.0.2.039,personas@christopher.beard:1[...]
Deleted : user_pref("extensions.engine@conduit.com.install-event-fired", true);
Deleted : user_pref("extensions.facemoods.aflt", "_#w7th2");
Deleted : user_pref("extensions.facemoods.firstRun", false);
Deleted : user_pref("extensions.facemoods.lastActv", "19");
Deleted : user_pref("keyword.URL", "hxxp://start.facemoods.com/results.php?f=5&a=w7th2&q=");

*************************

AdwCleaner[R1].txt - [41836 octets] - [05/08/2012 20:35:56]
AdwCleaner[S1].txt - [42293 octets] - [05/08/2012 20:55:57]

########## EOF - C:\AdwCleaner[S1].txt - [42422 octets] ##########

Gerade beim Neustart öffnete sich dieses Fenster. Hat das was "größeres" zu bedeuten oder kann man das guten Gewissens ignorieren/hinnehmen?

http://s14.directupload.net/images/120805/kvtka46k.png

cosinus 06.08.2012 10:07

Zitat:

Zitat von brainInfect (Beitrag 884555)
Bin gespannt. Zumindest erwarte ich euch stärker als Hamburg letzte Saison zum Auftakt. http://forum.express.de/images/smili...nvorlachen.gif http://www.ugly-smilies.de/data/ugly.gif

Bist du dir da sicher?! :blabla: :lach:

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


brainInfect 06.08.2012 12:59

Zitat:

Zitat von cosinus (Beitrag 884874)
Bist du dir da sicher?! :blabla: :lach:

Ja, ziemlich sogar. Schlechter wäre nur noch Tasmania Berlin in ihren besten Zeiten gewesen. :daumenhoc :applaus:

Habe alles so gemacht, wie dus gesagt hast. Allerdings öffnete sich dann folgendes Fenster, aber keine Log-Datei:

http://s1.directupload.net/images/120806/z3hzytde.png

Was hat das zu bedeuten?

cosinus 06.08.2012 13:30

Du hast OTL per Rechtsklick als Admin ausgeführt?
Wenn ja, probier es nochmal notfalls im abgesicherten Modus

brainInfect 06.08.2012 14:19

Perfekt, jetzt hats geklappt!

OTL-Log

Code:

OTL logfile created on: 06.08.2012 15:01:58 - Run 1
OTL by OldTimer - Version 3.2.56.0    Folder = C:\Users\smoking caterpillar\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,91 Gb Total Physical Memory | 2,94 Gb Available Physical Memory | 75,15% Memory free
7,81 Gb Paging File | 6,85 Gb Available in Paging File | 87,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,24 Gb Total Space | 64,62 Gb Free Space | 54,20% Space Free | Partition Type: NTFS
Drive D: | 153,85 Gb Total Space | 44,41 Gb Free Space | 28,87% Space Free | Partition Type: NTFS
 
Computer Name: SMOKINGCATERPIL | User Name: smoking caterpillar | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.08.06 13:23:41 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\smoking caterpillar\Desktop\OTL.exe
 
 
========== Modules (No Company Name) ==========
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - File not found [Auto | Stopped] -- C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe -- (Amsp)
SRV:64bit: - [2011.01.25 23:11:56 | 000,379,520 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Stopped] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
SRV:64bit: - [2010.09.23 03:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2012.07.29 14:23:05 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.08 21:15:26 | 000,040,960 | ---- | M] () [Auto | Stopped] -- C:\Users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer)
SRV - [2012.01.31 16:09:34 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011.08.24 23:53:22 | 000,092,800 | ---- | M] (ASUS) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe -- (ASUS InstantOn)
SRV - [2010.12.21 03:24:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010.12.21 03:24:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010.09.06 18:56:38 | 000,247,096 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.06.25 19:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.12.15 19:39:38 | 000,096,896 | ---- | M] (ASUS) [Auto | Stopped] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2009.06.16 02:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Stopped] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.03.08 18:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.09.08 20:08:36 | 000,090,096 | ---- | M] (CyberLink) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\CLVirtualDrive.sys -- (CLVirtualDrive)
DRV:64bit: - [2011.07.26 10:22:48 | 012,288,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011.06.02 19:32:50 | 000,401,896 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2011.06.02 19:32:50 | 000,128,488 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2011.05.24 09:24:22 | 002,750,464 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011.05.05 14:32:56 | 001,439,792 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 13:07:06 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.11.05 17:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010.10.20 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010.10.14 19:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010.09.17 10:52:28 | 000,144,464 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\tmcomm.sys -- (tmcomm)
DRV:64bit: - [2010.09.17 10:52:28 | 000,105,552 | ---- | M] (Trend Micro Inc.) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\tmtdi.sys -- (tmtdi)
DRV:64bit: - [2010.09.17 10:52:28 | 000,090,704 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\tmactmon.sys -- (tmactmon)
DRV:64bit: - [2010.09.17 10:52:28 | 000,067,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV:64bit: - [2010.08.24 11:55:44 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010.06.25 19:07:26 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2009.07.20 11:29:40 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SiSG664.sys -- (SiSGbeLH)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008.05.24 02:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2007.06.25 10:42:30 | 000,130,088 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117unic.sys -- (s117unic)
DRV:64bit: - [2007.06.25 10:42:30 | 000,123,432 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117obex.sys -- (s117obex)
DRV:64bit: - [2007.06.25 10:42:30 | 000,031,272 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117nd5.sys -- (s117nd5)
DRV:64bit: - [2007.06.25 10:42:24 | 000,144,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117mdm.sys -- (s117mdm)
DRV:64bit: - [2007.06.25 10:42:24 | 000,125,992 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117mgmt.sys -- (s117mgmt)
DRV:64bit: - [2007.06.25 10:42:24 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117mdfl.sys -- (s117mdfl)
DRV:64bit: - [2007.06.25 10:42:22 | 000,108,072 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117bus.sys -- (s117bus)
DRV - [2011.09.07 18:55:04 | 000,017,536 | ---- | M] (ASUS) [Kernel | System | Stopped] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
DRV - [2010.01.29 11:40:16 | 000,115,600 | ---- | M] (EZB Systems, Inc.) [File_System | System | Stopped] -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys -- (ISODrive)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.07.03 02:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Stopped] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.creaf.com
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{40988352-234F-4506-ADAB-DBB9A1AEE918}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{5022FD8F-89CE-446B-982E-3F8B8EFD2945}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{9D54F150-F5A3-4BE5-84BD-01FEAB4DFBA3}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{B8704F1D-E99A-4FEE-96E2-9C8E09681870}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{C96A9D24-16A0-4D44-8833-24434B114DB3}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{D011AC3A-AC50-4B88-9B1B-A4721FE7986B}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011.12.18 18:14:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.01.08 06:42:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.29 14:23:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.05.27 22:36:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\firejump@firejump.net [2012.04.12 09:39:48 | 000,000,000 | ---D | M]
 
[2011.12.10 16:58:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Extensions
[2012.03.27 20:19:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\C\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\extensions
[2012.03.27 20:19:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\smoking caterpillar\AppData\Roaming\mozilla\Firefox\C\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Mozilla\Firefox\Profiles\smf00mp5.default\extensions\staged
[2012.05.04 10:20:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.07.29 14:23:05 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.03.24 06:23:21 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.05.27 22:36:11 | 000,378,880 | ---- | M] (InfiniAd GmbH) -- C:\Program Files (x86)\mozilla firefox\plugins\npmieze.dll
[2010.12.02 17:58:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.07.29 14:23:03 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.07.29 14:23:03 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.07.29 14:23:03 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.07.29 14:23:03 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.07.29 14:23:03 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.07.29 14:23:03 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.06.14 23:17:56 | 000,441,697 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 im.adtech.de
O1 - Hosts: 127.0.0.1 adserver.adtech.de
O1 - Hosts: 127.0.0.1 adtech.de
O1 - Hosts: 127.0.0.1 ar.atwola.com
O1 - Hosts: 127.0.0.1 atwola.com
O1 - Hosts: 127.0.0.1 adserver.71i.de
O1 - Hosts: 127.0.0.1 adicqserver.71i.de
O1 - Hosts: 127.0.0.1 71i.de
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 15181 more lines...
O2:64bit: - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2:64bit: - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
O2:64bit: - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg32.dll (Trend Micro Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O2 - BHO: (CodecC Class) - {E32FBEA2-F52F-4812-A88F-21FE54FD0AF0} - C:\ProgramData\CodecC\bhoclass.dll (Injector)
O3:64bit: - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [ncarn] rundll32.exe "C:\Users\smoking caterpillar\AppData\Roaming\ncarn.dll",HrIndexOfWeek File not found
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4:64bit: - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files (x86)\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe (ecareme)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files (x86)\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Nuance PDF Reader-reminder] C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (Virage Logic Corporation / Sonic Focus)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUS)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files (x86)\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{979EFD50-C1CE-463C-8E95-C7557714BD8C}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DAB4BAF7-B85E-4E8F-983D-C300CC7D6E92}: DhcpNameServer = 192.168.2.2
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
O18:64bit: - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18:64bit: - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
MsConfig:64bit - StartUpReg: ASUS Screen Saver Protector - hkey= - key= - C:\Windows\AsScrPro.exe (ASUS)
MsConfig:64bit - StartUpReg: CLMLServer - hkey= - key= - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
MsConfig:64bit - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig:64bit - StartUpReg: Power2GoExpress8 - hkey= - key= - C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: RtHDVCpl - hkey= - key= - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
MsConfig:64bit - StartUpReg: Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: BFE - Service
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: MPSSvc - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: BFE - Service
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MPSSvc - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{369FA940-F27E-11D2-B31E-00AA00A110B7}S08718 - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
 
Drivers32:64bit: msacm.ac3filter - ac3filter64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (hxxp://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.08.06 13:23:39 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\smoking caterpillar\Desktop\OTL.exe
[2012.08.05 23:08:20 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{636F9080-CECD-4F7A-93C2-FC7234F1F2FE}
[2012.08.05 23:08:08 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{58E54BBB-D2E2-47E1-9E6A-ADF70FD16212}
[2012.08.05 18:00:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.08.05 18:00:01 | 002,322,184 | ---- | C] (ESET) -- C:\Users\smoking caterpillar\Desktop\esetsmartinstaller_enu.exe
[2012.08.05 16:44:59 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Zinyc
[2012.08.05 16:44:59 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Ugcao
[2012.08.05 16:44:59 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Paxyka
[2012.08.02 16:46:55 | 000,000,000 | ---D | C] -- C:\ProgramData\7531CCA9CA4D593B2B7FCCBCF875F002
[2012.08.02 16:45:49 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Rosuop
[2012.08.02 16:45:49 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Cizo
[2012.08.02 16:45:49 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Albyc
[2012.08.02 16:45:01 | 000,000,000 | -H-D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\C943C2EC
[2012.08.02 16:15:08 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{C588CBEC-640C-410C-B08F-8FAB711030BD}
[2012.08.02 16:14:56 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{897C17F8-4844-494F-B53E-6772C2B99F95}
[2012.07.31 22:05:41 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\dwhelper
[2012.07.31 16:39:36 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\Apps
[2012.07.31 16:39:35 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\Deployment
[2012.07.31 16:39:00 | 000,000,000 | ---D | C] -- C:\Archivos de programa
[2012.07.30 00:25:15 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\xsecva
[2012.07.26 13:05:33 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{08E32DDA-70D2-499A-9C15-B685897959B8}
[2012.07.26 13:05:19 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{D7F0689C-C4FD-463D-A438-4FFBA953BA44}
[2012.07.25 16:20:10 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{559BB5BB-ECE6-4282-89A6-3C1D4AB9CAC1}
[2012.07.25 16:19:58 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{DACC20FE-E7E8-412D-9A4D-49D9052DCA35}
[2012.07.24 16:42:29 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Malwarebytes
[2012.07.24 16:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.24 16:42:19 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.24 16:42:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.24 16:42:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.24 16:18:57 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{CCDF328D-542C-49F1-B27D-DDF83088D9D8}
[2012.07.24 16:18:44 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{07850BB6-4CCC-4B7E-B618-938D48579525}
[2012.07.23 23:37:36 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\Documents\Simply Super Software
[2012.07.23 23:37:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2012.07.23 23:37:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2012.07.23 23:37:23 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Simply Super Software
[2012.07.23 23:37:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2012.07.23 23:05:59 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012.07.23 23:00:58 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{1BD3FFD3-C5D9-4971-A348-43751325AE14}
[2012.07.23 23:00:45 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{D475E403-D1AB-4D5C-BD1B-41766F102131}
[2012.07.22 18:59:31 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{4505BEF0-FE6D-4390-A6B1-BD2F71EA189E}
[2012.07.22 18:59:18 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{D94545D7-F351-474E-92A5-B71E7273BACB}
[2012.07.22 18:10:20 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\ElevatedDiagnostics
[2012.07.22 18:06:37 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{6DFC979A-10DC-4CAB-B549-F306D77CD778}
[2012.07.22 05:59:41 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{12416EC7-D12E-45E1-ACEF-6B8838F96694}
[2012.07.22 03:49:15 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{C225A36B-EBE7-464F-ACAF-53B4467A9582}
[2012.07.21 21:59:01 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{EB4C635D-6A5D-49F1-AC67-4914BF4643AD}
[2012.07.21 07:56:37 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{698999C7-3BCA-4D6C-81AC-564642251195}
[2012.07.20 13:35:36 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{74898C6B-45AC-4889-A427-6DF109724640}
[2012.07.20 07:52:36 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{421B1799-A7A3-4BC4-A88C-2CF201FC8659}
[2012.07.19 19:15:35 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{D352C47E-1C14-4981-BF57-CFCAE32B6F2A}
[2012.07.19 16:53:22 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{536306E6-1BEB-48A2-9ED2-4EB2A55454EA}
[2012.07.19 07:37:55 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{665687F4-B300-4B78-AB40-45D4597A2981}
[2012.07.18 20:42:22 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\Desktop\Guitar pro
[2012.07.18 18:31:33 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{F30BFCCE-2CB1-4A3B-B30C-7AC016E9E798}
[2012.07.18 14:46:02 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{85C15F4C-08EA-4116-801E-738F54468661}
[2012.07.16 23:48:06 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{00E6DA98-14CE-4DF8-A7CA-DAA6B1A79F68}
[2012.07.16 21:40:56 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{BED1B77F-4E13-4B29-A4D3-35FDCFB872AC}
[2012.07.15 10:25:53 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{F170774A-EFA1-4248-8E23-68E77D67E5EE}
[2012.07.14 18:25:59 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{C1AE2F43-5B06-43F7-AA7E-862FE319D063}
[2012.07.12 18:42:13 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{4AD18159-8490-4B5B-A582-6AE17CA1AF47}
[2012.07.12 15:03:30 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{B99986B2-4333-46E5-8F23-291FC1A7DD8B}
[2012.07.11 13:25:14 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{80C60C7E-3C20-4D47-BE6C-3FCDD094ED2A}
[2012.07.11 13:25:01 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{7B263A4B-8EC6-42E8-9D81-72C84B69EED4}
[2012.07.10 20:38:06 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{90D372A1-27FB-4269-B8D0-E8A9CC1DE12D}
[2012.07.10 20:37:44 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{77830F79-1796-4884-B587-EE647FE6BEC3}
[2012.07.10 18:09:33 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Apple
[2012.07.09 23:41:58 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{FDFB9892-8F57-481E-9528-05EE9882121F}
[2012.07.09 23:41:40 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{EEBE63FA-A88E-48C0-8C61-EB289F5B0C00}
[2012.07.09 09:11:33 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{37594653-4C53-4B10-B5B2-BD44D85BD86B}
[2012.07.09 09:11:22 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{FF56CD4E-7711-4345-9889-BDEA79B77D2A}
[2012.07.08 12:57:08 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Dropbox
[2012.07.08 12:55:45 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Windows Desktop Search
[2012.07.08 12:55:33 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Sun
[2012.07.08 12:54:51 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Roaming\Google Inc
[2012.07.08 12:51:49 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{C4BB78F0-3BB4-4033-BD73-F7AFCA36FF56}
[2012.07.08 12:51:26 | 000,000,000 | ---D | C] -- C:\Users\smoking caterpillar\AppData\Local\{86A8724B-81F1-4626-9428-E4B4F3FCFAA5}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.08.06 15:00:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.08.06 15:00:20 | 3145,826,304 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.06 13:27:14 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.08.06 13:27:14 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.08.06 13:23:41 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\smoking caterpillar\Desktop\OTL.exe
[2012.08.06 00:17:45 | 000,000,542 | ---- | M] () -- C:\Windows\WebCamC.ini
[2012.08.05 21:40:03 | 005,352,741 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\Bakkushan - Nur die Nacht [OFFICIAL MUSI.mp3
[2012.08.05 21:39:46 | 007,286,847 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\Green Day - Oh Love [Lyric Video].mp3
[2012.08.05 20:35:38 | 000,614,903 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\adwcleaner.exe
[2012.08.05 18:16:45 | 002,322,184 | ---- | M] (ESET) -- C:\Users\smoking caterpillar\Desktop\esetsmartinstaller_enu.exe
[2012.08.05 18:13:32 | 000,045,056 | ---- | M] () -- C:\Windows\SysWow64\acovcnt.exe
[2012.08.05 16:42:40 | 000,001,118 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.08.02 02:40:15 | 001,529,532 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.08.02 02:40:15 | 000,665,812 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.08.02 02:40:15 | 000,627,654 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.08.02 02:40:15 | 000,133,992 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.08.02 02:40:15 | 000,110,374 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.08.01 01:48:56 | 005,185,208 | ---- | M] () -- C:\Users\smoking caterpillar\Desktop\Pollock - We used to be.mp3
[2012.07.28 17:54:25 | 000,000,051 | ---- | M] () -- C:\ProgramData\beetroueqnymvyc
[2012.07.23 03:22:11 | 000,334,752 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.07.09 15:48:43 | 000,002,240 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.08.05 21:38:49 | 005,352,741 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\Bakkushan - Nur die Nacht [OFFICIAL MUSI.mp3
[2012.08.05 21:38:16 | 007,286,847 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\Green Day - Oh Love [Lyric Video].mp3
[2012.08.05 20:35:36 | 000,614,903 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\adwcleaner.exe
[2012.08.05 16:42:40 | 000,001,118 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.08.01 01:48:55 | 005,185,208 | ---- | C] () -- C:\Users\smoking caterpillar\Desktop\Pollock - We used to be.mp3
[2012.07.28 17:54:20 | 000,000,051 | ---- | C] () -- C:\ProgramData\beetroueqnymvyc
[2012.07.24 16:53:05 | 000,023,552 | ---- | C] () -- C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\U\800000cb.@
[2012.07.23 23:37:25 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2012.07.23 23:37:24 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2012.07.23 23:02:31 | 000,016,896 | ---- | C] () -- C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\U\80000000.@
[2012.07.23 23:02:31 | 000,001,712 | ---- | C] () -- C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\U\00000001.@
[2012.07.06 22:47:46 | 000,000,051 | ---- | C] () -- C:\ProgramData\ecmjzjtqkkbqmhm
[2012.06.22 16:16:00 | 000,003,389 | ---- | C] () -- C:\Users\smoking caterpillar\.recently-used.xbel
[2012.06.10 14:49:20 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini
[2012.04.10 23:40:28 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2012.04.01 17:52:40 | 000,000,542 | ---- | C] () -- C:\Windows\WebCamC.ini
[2012.03.26 14:07:25 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012.03.26 14:07:25 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012.03.26 14:07:25 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012.03.26 14:07:23 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012.03.19 00:31:00 | 000,000,205 | ---- | C] () -- C:\Users\smoking caterpillar\.swfinfo
[2012.03.18 05:30:19 | 000,000,046 | ---- | C] () -- C:\Windows\SysWow64\DonationCoder_urlsnooper_InstallInfo.dat
[2012.02.07 00:52:44 | 000,004,608 | ---- | C] () -- C:\Users\smoking caterpillar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.02.07 00:43:55 | 000,028,672 | ---- | C] () -- C:\Windows\wutil.dll
[2012.02.07 00:41:55 | 000,158,720 | ---- | C] () -- C:\Windows\SysWow64\LFCMP62N.DLL
[2012.02.07 00:41:55 | 000,078,336 | ---- | C] () -- C:\Windows\SysWow64\LTIMG62N.DLL
[2012.02.07 00:41:55 | 000,043,008 | ---- | C] () -- C:\Windows\SysWow64\LTFIL62N.DLL
[2012.02.07 00:41:55 | 000,022,016 | ---- | C] () -- C:\Windows\SysWow64\LFBMP62N.DLL
[2012.01.11 15:16:43 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\@
[2012.01.11 15:16:43 | 000,002,048 | -HS- | C] () -- C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\@
[2011.12.18 20:36:29 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2011.12.17 03:02:11 | 000,000,017 | ---- | C] () -- C:\Users\smoking caterpillar\AppData\Local\resmon.resmoncfg
[2011.12.15 16:39:10 | 000,000,403 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.12.10 16:25:56 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\acovcnt.exe
[2011.09.16 10:21:16 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011.09.16 10:20:27 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.09.16 10:20:19 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011.09.16 10:20:15 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011.09.16 10:20:13 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.09.16 10:20:10 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011.04.13 04:48:48 | 000,131,472 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== LOP Check ==========
 
[2011.12.20 01:46:17 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\1&1 Mail & Media GmbH
[2012.08.02 16:45:49 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Albyc
[2012.04.11 00:05:38 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\AnvSoft
[2011.12.10 16:32:32 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ASUS WebStorage
[2011.12.16 05:16:55 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\AveDesk
[2012.04.10 23:56:05 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\avidemux
[2012.08.02 16:45:01 | 000,000,000 | -H-D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\C943C2EC
[2012.08.05 18:12:06 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Cizo
[2012.07.08 21:15:18 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DesktopIconForAmazon
[2012.03.18 05:30:19 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DonationCoder
[2012.07.11 10:09:47 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Dropbox
[2012.06.03 23:19:16 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DVDVideoSoft
[2012.04.18 16:30:35 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\FileZilla
[2012.06.22 16:16:00 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\gtk-2.0
[2012.08.06 14:34:26 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ICQ
[2011.12.18 20:50:28 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ICQ-Tools.de
[2012.03.23 21:46:22 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Mipony
[2012.04.10 23:45:41 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\mkvtoolnix
[2012.02.24 15:20:38 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Musereo
[2011.12.14 08:02:58 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Nuance
[2011.12.18 20:36:25 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\OCS
[2012.07.08 15:43:35 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Opera
[2012.03.23 21:40:10 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Orbit
[2012.08.05 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Paxyka
[2012.03.18 05:40:07 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ProgSense
[2012.08.02 16:45:49 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Rosuop
[2012.07.23 23:37:23 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Simply Super Software
[2011.12.15 04:11:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Sinvise Systems
[2012.07.08 12:57:00 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\TeamViewer
[2012.08.05 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Ugcao
[2012.07.08 12:55:45 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Windows Desktop Search
[2012.08.05 17:59:11 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\xsecva
[2011.12.14 08:02:54 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Zeon
[2012.08.05 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Zinyc
[2012.07.29 14:01:13 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.12.20 01:46:17 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\1&1 Mail & Media GmbH
[2011.12.10 16:33:29 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Adobe
[2012.08.02 16:45:49 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Albyc
[2012.04.11 00:05:38 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\AnvSoft
[2012.07.10 18:09:33 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Apple
[2011.12.10 16:32:32 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ASUS WebStorage
[2011.12.16 05:16:55 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\AveDesk
[2012.04.10 23:56:05 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\avidemux
[2012.08.02 16:45:01 | 000,000,000 | -H-D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\C943C2EC
[2012.08.05 18:12:06 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Cizo
[2012.04.11 19:45:49 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\CyberLink
[2012.07.08 21:15:18 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DesktopIconForAmazon
[2012.02.21 02:16:22 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DivX
[2012.03.18 05:30:19 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DonationCoder
[2012.07.11 10:09:47 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Dropbox
[2012.05.18 13:25:14 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\dvdcss
[2012.06.03 23:19:16 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\DVDVideoSoft
[2012.04.18 16:30:35 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\FileZilla
[2011.12.14 08:02:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\FLEXnet
[2011.12.10 16:26:24 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Google
[2012.07.11 09:53:13 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Google Inc
[2012.06.22 16:16:00 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\gtk-2.0
[2012.07.04 02:40:07 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Help
[2012.08.06 14:34:26 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ICQ
[2011.12.18 20:50:28 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ICQ-Tools.de
[2012.07.23 17:30:00 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Identities
[2012.07.04 02:36:00 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Macromedia
[2012.07.24 16:42:29 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Malwarebytes
[2009.07.14 09:44:38 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Media Center Programs
[2012.04.01 02:42:25 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Media Player Classic
[2012.08.02 16:46:10 | 000,000,000 | --SD | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Microsoft
[2011.12.19 02:47:32 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Microsoft Web Folders
[2012.03.23 21:46:22 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Mipony
[2012.04.10 23:45:41 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\mkvtoolnix
[2011.12.10 16:58:12 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Mozilla
[2012.02.24 15:20:38 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Musereo
[2012.03.26 14:22:47 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\NCH Software
[2011.12.14 08:02:58 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Nuance
[2011.12.18 20:36:25 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\OCS
[2012.07.08 15:43:35 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Opera
[2012.03.23 21:40:10 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Orbit
[2012.08.05 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Paxyka
[2012.03.18 05:40:07 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\ProgSense
[2012.08.02 16:45:49 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Rosuop
[2012.07.23 23:37:23 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Simply Super Software
[2011.12.15 04:11:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Sinvise Systems
[2012.07.23 17:13:16 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Skype
[2012.07.08 15:43:29 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Sun
[2012.07.08 12:57:00 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\TeamViewer
[2012.08.05 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Ugcao
[2012.07.11 13:45:39 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\vlc
[2012.08.06 14:08:28 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Winamp
[2012.07.08 12:55:45 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Windows Desktop Search
[2011.12.11 20:54:19 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\WinRAR
[2012.08.05 17:59:11 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\xsecva
[2011.12.14 08:02:54 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Zeon
[2012.08.05 16:44:59 | 000,000,000 | ---D | M] -- C:\Users\smoking caterpillar\AppData\Roaming\Zinyc
 
< %APPDATA%\*.exe /s >
[2012.02.24 05:27:11 | 000,250,368 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\Albyc\edfui.exe
[2012.07.08 21:15:17 | 000,753,664 | ---- | M] (Microsoft) -- C:\Users\smoking caterpillar\AppData\Roaming\DesktopIconForAmazon\IconForAmazon.exe
[2007.11.27 08:41:32 | 000,405,504 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\NCH Software\Components\mp3el2\lame.exe
[2012.07.08 21:15:26 | 000,106,496 | ---- | M] (OCS) -- C:\Users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
[2012.07.08 21:15:26 | 000,040,960 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
[2012.04.07 06:25:56 | 000,245,760 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\Paxyka\caqy.exe
[2012.07.09 01:01:20 | 000,370,692 | ---- | M] () -- C:\Users\smoking caterpillar\AppData\Roaming\vlc\{96FD72B9-3877-4F4A-9591-A6E08D4D18B2}\Upgrade.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2010.11.05 17:45:48 | 000,438,808 | ---- | M] (Intel Corporation) MD5=D7921D5A870B11CC1ADAB198A519D50A -- C:\eSupport\eDriver\Software\Others\Intel\IRST\Vista64_Win7_64_10.1.0.1008\iaStor.sys
[2010.11.05 17:45:48 | 000,438,808 | ---- | M] (Intel Corporation) MD5=D7921D5A870B11CC1ADAB198A519D50A -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.11.05 17:45:48 | 000,438,808 | ---- | M] (Intel Corporation) MD5=D7921D5A870B11CC1ADAB198A519D50A -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_710b330fb3531234\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 15:33:40 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 15:33:40 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 08:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 08:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 15:27:24 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 15:27:24 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 14:20:30 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 14:20:30 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 08:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 08:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 15:33:50 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 15:33:50 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 14:21:06 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 14:21:06 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 15:27:26 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 15:27:26 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 14:08:58 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 14:08:58 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 15:27:28 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 15:27:28 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 14:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 14:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\smoking caterpillar\AppData\Local\Temp\RarSFX0\userinit.exe
[2010.11.20 15:25:26 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 15:25:26 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 15:25:32 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 15:25:32 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.05.26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\smoking caterpillar\AppData\Local\Temp\RarSFX0\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >

< End of report >

Extras

Code:

OTL Extras logfile created on: 06.08.2012 15:01:58 - Run 1
OTL by OldTimer - Version 3.2.56.0    Folder = C:\Users\smoking caterpillar\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,91 Gb Total Physical Memory | 2,94 Gb Available Physical Memory | 75,15% Memory free
7,81 Gb Paging File | 6,85 Gb Available in Paging File | 87,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,24 Gb Total Space | 64,62 Gb Free Space | 54,20% Space Free | Partition Type: NTFS
Drive D: | 153,85 Gb Total Space | 44,41 Gb Free Space | 28,87% Space Free | Partition Type: NTFS
 
Computer Name: SMOKINGCATERPIL | User Name: smoking caterpillar | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallDisableNotify" = 0
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{0919C44F-F18A-4E3B-A737-03685272CE72}" = Windows Live Remote Service Resources
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{17A4FD95-A507-43F1-BC92-D8572AF8340A}" = Windows Live Remote Service Resources
"{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources
"{2128559D-BBCD-4744-87F0-7C0CD5CFB464}" = Windows Live Family Safety
"{27B3E5AA-5B75-414A-AC37-F5ADDFA68BDB}" = Windows Live Family Safety
"{287134AD-092F-4BD0-A6F4-911B0B351E87}" = Windows Live Family Safety
"{33B98264-A889-4913-A0CA-C364A75032B3}" = ASUS Power4Gear Hybrid
"{464F7B5E-80BB-4F34-A602-384F0702674A}" = Windows Live Family Safety
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{5ECA80C9-7D7A-49AC-B487-52F1CF47ECEE}" = Windows Live Family Safety
"{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources
"{698EAE05-09DE-47D0-9586-29E41A0934DD}" = Windows Live Family Safety
"{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{74AC7ECE-87E1-41F7-ABA2-5ED9B13CECFA}" = Windows Live Family Safety
"{825C7D3F-D0B3-49D5-A42B-CBB0FBE85E99}" = Windows Live Remote Client Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8832CAA2-4934-4916-A8BF-A9A51C6B58B3}" = Windows Live Family Safety
"{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{944E73EF-857E-4F71-9DC4-CD059D7ADDEF}" = Windows Live Family Safety
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A2862596-B7C3-4D7F-A227-40FEDDF1332B}" = WEB.DE Toolbar MSVC100 CRT x64
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium Internet Security
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium Internet Security
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B0BF8602-EA52-4B0A-A2BD-EDABB0977030}" = Windows Live Remote Client Resources
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{BFBE6E95-5724-47EC-85A0-74D436AD938F}" = Windows Live Family Safety
"{C504EC13-E122-4939-BD6E-EE5A3BAA5FEC}" = Windows Live Remote Client Resources
"{C61D639C-3A1B-4654-901F-08927C804321}" = Windows Live Family Safety
"{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EFB20CF5-1A6D-41F3-8895-223346CE6291}" = Windows Live Remote Service Resources
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FAA3933C-6F0D-4350-B66B-9D7F7031343E}" = Windows Live Remote Service Resources
"{FAD0EC0B-753B-4A97-AD34-32AC1EC8DB69}" = Windows Live Remote Client Resources
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CCleaner" = CCleaner
"DesktopIconAmazon" = Desktop Icon für Amazon
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"SearchAnonymizer" = SearchAnonymizer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{039480EE-6933-4845-88B8-77FD0C3D059D}" = Windows Live Mesh
"{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas
"{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
"{062E4D94-8306-46D5-81B6-45E6AD09C799}" = Windows Live Messenger
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}" = Sonic Focus
"{0A35B15C-9CCD-4C0C-BD5B-34ABF8C95813}_is1" = ICQ 7.2 Build #3525 Banner Remover 1.0
"{0A4C4B29-5A9D-4910-A13C-B920D5758744}" = بريد Windows Live
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0BF1DE3D-31B9-417F-A915-4BCC5AAEE3CD}_is1" = Sothink SWF Editor Version 1.1
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live
"{128133D3-037A-4C62-B1B7-55666A10587A}" = Windows Live UX Platform Language Pack
"{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources
"{168E7302-890A-4138-9109-A225ACAF7AD1}" = Windows Live Photo Common
"{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials
"{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A82AE99-84D3-486D-BAD6-675982603E14}" = Windows Live Writer
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2511AAD7-82DF-4B97-B0B3-E1B933317010}" = Windows Live Writer Resources
"{256DDBE1-4010-4AD4-A62A-CA05F26B7970}_is1" = Anmeldebug Patch
"{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail
"{25F60491-F5AB-4985-9354-37C146783F35}" = Microsoft Works Suite-Add-Ins für Microsoft Word
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{29373E24-AC72-424E-8F2A-FB0F9436F21F}" = Windows Live Photo Common
"{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A6E3140-FF44-11D3-BE64-00104B229E8F}" = PixScreen
"{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"{2C4E06CC-1F04-4C25-8B3C-93A9049EC42C}" = Windows Live UX Platform Language Pack
"{2C865FB0-051E-4D22-AC62-428E035AEAF0}" = Windows Live Mesh
"{2EF17083-57D4-4D64-AE4F-55F32A2C4571}" = CodecC
"{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor 2
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{341697D8-9923-445E-B42A-529E5A99CB7A}" = syncables desktop SE
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack
"{4555BB9E-E715-4260-A178-E8EFD2B653E3}" = Alcor Micro USB Card Reader
"{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh
"{48294D95-EE9A-4377-8213-44FC4265FB27}" = Windows Live Messenger
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer
"{4D83F339-5A5C-4B21-8FD3-5D407B981E72}" = Windows Live Photo Common
"{506FC723-8E6C-4417-9CFF-351F99130425}" = Windows Live UX Platform Language Pack
"{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{622DE1BE-9EDE-49D3-B349-29D64760342A}" = 適用遠端連線的 Windows Live Mesh ActiveX 控制項
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
"{6807427D-8D68-4D30-AF5B-0B38F8F948C8}" = Windows Live Writer Resources
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A4ABCDC-0A49-4132-944E-01FBCCB3465C}" = Windows Live UX Platform Language Pack
"{6CB36609-E3A6-446C-A3C1-C71E311D2B9C}" = Windows Live Movie Maker
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{6E8AFC13-F7B8-41D8-88AB-F1D0CFC56305}" = Windows Live Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
"{7465A996-0FCA-4D2D-A52C-F833B0829B5B}" = Windows Live Movie Maker
"{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh
"{749F674B-2674-47E8-879C-5626A06B2A91}" = InstantOn for NB
"{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack
"{77F69CA1-E53D-4D77-8BA3-FA07606CC851}" = Фотоальбом Windows Live
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{78DBE8CE-61F6-4D6C-806C-A0FFF65F5E1D}" = Windows Live Messenger
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer
"{7FF11E53-C002-4F40-8D68-6BE751E5DD62}" = Windows Live Writer Resources
"{804DE397-F82C-4867-9085-E0AA539A3294}" = Windows Live Writer
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.6.0
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{84A411F9-40A5-4CDA-BF46-E09FBB2BC313}" = Windows Live Essentials
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}" = פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DB90178-B5B0-45BD-B0A7-D40A6A1DF1CA}" = Windows Live Movie Maker
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger
"{ABD534B7-E951-470E-92C2-CD5AF1735726}" = Windows Live Essentials
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail
"{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common
"{AF01B90A-D25C-4F60-AECD-6EEDF509DC11}" = Windows Live Mesh
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B2BCA478-EC0F-45EE-A9E9-5EABE87EA72D}" = Windows Live Photo Common
"{B2E90616-C50D-4B89-A40D-92377AC669E5}" = Windows Live Messenger
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B480904D-F73F-4673-B034-8A5F492C9184}" = Nuance PDF Reader
"{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
"{B63F0CE3-CCD0-490A-9A9C-E1A3B3A17137}" = Почта Windows Live
"{BAEE89D5-6E87-4F89-9603-A1C100479181}" = Windows Live Messenger
"{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}" = Элемент управления Windows Live Mesh ActiveX для удаленных подключений
"{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1" = Sothink SWF Decompiler
"{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker
"{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live
"{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C32CE55C-12BA-4951-8797-0967FDEF556F}" = Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen
"{C4BC5A5F-4A97-47CC-99C3-AB8E10572AFE}" = Wireless Console 3
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}" = ASUS FancyStart
"{C95A5A77-622F-45CA-9540-84468FCB18B1}" = Windows Live Messenger
"{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker
"{CBFD061C-4B27-4A89-ADD8-210316EEFA11}" = Windows Live Messenger
"{CC4BBCBA-89F6-47C3-9B0F-5CE5BB1C316C}" = WEB.DE Toolbar MSVC100 CRT x86
"{CDC39BF2-9697-4959-B893-A2EE05EF6ACB}" = Windows Live Writer
"{CE929F09-3853-4180-BD90-30764BFF7136}" = גלריית התמונות של Windows Live
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D121161E-AD64-4438-97A0-66A1AB7FFDE3}" = Works Suite-Betriebssystem-Pack
"{D299197D-CDEA-41A6-A363-F532DE4114FD}" = Windows Live UX Platform Language Pack
"{D39F0676-163E-4595-A917-E28F99BBD4D2}" = ASUS AI Recovery
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail
"{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack
"{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1" = FireJump 1.0.1.8
"{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker
"{DBAA2B17-D596-4195-A169-BA2166B0D69B}" = Windows Live Mail
"{DC6B4110-394D-45B9-A677-BA495D84CA63}" = Shutdown Timer
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer
"{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E18B30AA-6E2D-480C-B918-AF61009F4010}" = عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer
"{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1" = Game Park Console
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E83DC314-C926-4214-AD58-147691D6FE9F}" = Основные компоненты Windows Live
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
"{ED5EDCD0-5745-4B13-8061-58C9833FD06D}" = Microsoft Works 6.0
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心
"{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2260E94-80F2-4CB1-B6B1-6043D9BFFA47}" = Works-Synchronisierung
"{F52C5BE7-3F57-464E-8A54-908402E43CE8}" = Windows Live Writer Resources
"{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις
"{F7E80BA7-A09D-4DD1-828B-C4A0274D4720}" = Windows Live Mesh
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"{FBCA06D2-4642-4F33-B20A-A7AB3F0D2E69}" = معرض صور Windows Live
"{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}" = Pinnacle VideoSpin
"{FF105207-8423-4E13-B0B1-50753170B245}" = Windows Live Movie Maker
"{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
"1&1 Mail & Media GmbH Toolbar IE8" = WEB.DE Toolbar für Internet Explorer
"5513-1208-7298-9440" = JDownloader 0.9
"AC3Filter_is1" = AC3Filter 1.63b
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AmUStor" = Alcor Micro USB Card Reader
"Any Video Converter_is1" = Any Video Converter 3.3.5
"Apecsoft M2TS to AVI MP4 DVD Converter_is1" = M2TS to AVI MP4 DVD Converter 1.80
"Asus Vibe2.0" = AsusVibe2.0
"ASUS WebStorage" = ASUS WebStorage
"ASUS_Screensaver" = ASUS_Screensaver
"Avidemux 2.5" = Avidemux 2.5 (32-bit)
"Bookworm Deluxe" = Bookworm Deluxe
"Cooking Dash" = Cooking Dash
"Creative Video Blaster WebCam Control" = Creative Video Blaster WebCam Control
"Creative WebCam Monitor" = Creative WebCam Monitor
"DivX Setup" = DivX-Setup
"ESET Online Scanner" = ESET Online Scanner v3
"FileZilla Client" = FileZilla Client 3.3.5.1
"Governor of Poker" = Governor of Poker
"Hotel Dash Suite Success" = Hotel Dash Suite Success
"ICQToolbar" = ICQ Toolbar
"InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor 2
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"Jewel Quest 3" = Jewel Quest 3
"Kalo24 - der Freeware-Kaloreinexperte" = Kalo24 - der Freeware-Kaloreinexperte 1.0.0.0
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 8.6.0
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LastFM_is1" = Last.fm 1.5.4.27091
"loadtbs-2.1" = loadtbs-2.1
"Luxor 3" = Luxor 3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.62.0.1300
"MKV Cutter_is1" = MKV Cutter 1.0
"Mozilla Firefox 14.0.1 (x86 de)" = Mozilla Firefox 14.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Musereo Mono to Stereo Converter_is1" = Musereo Mono to Stereo Converter 2.4
"Plants vs Zombies" = Plants vs Zombies
"Trojan Remover_is1" = Trojan Remover 6.8.4
"UltraISO_is1" = UltraISO Premium V9.52
"VideoPad" = VideoPad Video Editor
"VLC media player" = VLC media player 1.1.11
"WebCam PhotoEditor" = WebCam PhotoEditor
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.2
"WinRAR archiver" = WinRAR
"Works2002Setup" = Microsoft Works 2002-Setup-Start
"World of Goo" = World of Goo
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 11.07.2012 15:28:13 | Computer Name = smokingcaterpil | Source = Application Error | ID = 1000
Error - 11.07.2012 20:17:07 | Computer Name = smokingcaterpil | Source = SideBySide
 | ID = 16842785
 
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\cyberlink\power2go8\CES_AudioCacheAgent.exe.Manifest".
Die abhängige Assemblierung "PDR.X,type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error - 11.07.2012 20:17:07 | Computer Name = smokingcaterpil | Source = SideBySide
 | ID = 16842785
 
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\cyberlink\power2go8\CES_CacheAgent.exe.Manifest".
Die abhängige Assemblierung "PDR.X,type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error - 11.07.2012 20:18:01 | Computer Name = smokingcaterpil | Source = SideBySide
 | ID = 16842815
 
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\spybot - search & destroy\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program files (x86)\spybot - search & destroy\DelZip179.dll" in Zeile 8.
Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig.
Error - 12.07.2012 12:45:47 | Computer Name = smokingcaterpil | Source = Application
 Error | ID = 1000
 
Error - 12.07.2012 16:23:10 | Computer Name = smokingcaterpil | Source = Application Error | ID = 1000
Error - 12.07.2012 18:36:00 | Computer Name = smokingcaterpil | Source = SideBySide
 | ID = 16842785
 
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\cyberlink\power2go8\CES_AudioCacheAgent.exe.Manifest".
Die abhängige Assemblierung "PDR.X,type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error - 12.07.2012 18:36:00 | Computer Name = smokingcaterpil | Source = SideBySide
 | ID = 16842785
 
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\cyberlink\power2go8\CES_CacheAgent.exe.Manifest".
Die abhängige Assemblierung "PDR.X,type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error - 12.07.2012 18:36:50 | Computer Name = smokingcaterpil | Source = SideBySide
 | ID = 16842815
 
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files (x86)\spybot - search & destroy\DelZip179.dll". Fehler in Manifest- oder Richtliniendatei "c:\program files (x86)\spybot - search & destroy\DelZip179.dll" in Zeile 8.
Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig.
Error - 14.07.2012 12:28:52 | Computer Name = smokingcaterpil | Source = Application
 Error | ID = 1000
 
Error - 14.07.2012 15:39:22 | Computer Name = smokingcaterpil | Source = Application Error | ID = 1000
Error - 15.07.2012 13:53:50 | Computer Name = smokingcaterpil | Source = Application
 Error | ID = 1000
 
Error - 15.07.2012 13:56:14 | Computer Name = smokingcaterpil | Source = Application Error | ID = 1000
Error - 15.07.2012 13:57:24 | Computer Name = smokingcaterpil | Source = Application
 Error | ID = 1000
 
Error - 15.07.2012 13:58:40 | Computer Name = smokingcaterpil | Source = Application Error | ID = 1000
Error - 15.07.2012 14:01:34 | Computer Name = smokingcaterpil | Source = Application
 Error | ID = 1000
 
Error - 15.07.2012 14:14:47 | Computer Name = smokingcaterpil | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: vlc.exe, Version: 1.1.11.0, Zeitstempel:
 0x4e1edf37  Name des fehlerhaften Moduls: libavcodec_plugin.dll, Version: 0.0.0.0,
 Zeitstempel: 0x4e1edf39  Ausnahmecode: 0x40000015  Fehleroffset: 0x000c9743  ID des fehlerhaften
 Prozesses: 0x18ac  Startzeit der fehlerhaften Anwendung: 0x01cd62b3a62595fc  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\VideoLAN\VLC\vlc.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files (x86)\VideoLAN\VLC\plugins\libavcodec_plugin.dll  Berichtskennung:
 f5b0c47f-cea8-11e1-bfdb-5404a63486d1
 
Error - 15.07.2012 14:17:14 | Computer Name = smokingcaterpil | Source = Application Error | ID = 1000
Error - 15.07.2012 14:17:14 | Computer Name = smokingcaterpil | Source = Application
 Error | ID = 1000
 
Description = Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725, Zeitstempel: 0x4ec4aa8e
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000c40f2
ID des fehlerhaften Prozesses: 0x95c
Startzeit der fehlerhaften Anwendung: 0x01cd62b3e09aaa09
Pfad der fehlerhaften Anwendung: C:\Windows\explorer.exe
Pfad des fehlerhaften Moduls: C:\Windows\SYSTEM32\ntdll.dll
Berichtskennung: 4d149ae2-cea9-11e1-bfdb-5404a63486d1
Error - 15.07.2012 15:39:00 | Computer Name = smokingcaterpil | Source = Application
 Error | ID = 1000
 
[ System Events ]
Error - 10.05.2012 11:17:03 | Computer Name = smokingcaterpil | Source = Disk | ID = 262151
Description = Fehlerhafter Block bei Gerät \Device\Harddisk1\DR2.
 
Error - 10.05.2012 11:17:03 | Computer Name = smokingcaterpil | Source = Microsoft-Windows-BitLocker-Driver | ID = 24620
Description = Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf
 "F:" können nicht gelesen werden.
 
Error - 10.05.2012 11:17:03 | Computer Name = smokingcaterpil | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
 
Error - 10.05.2012 11:17:44 | Computer Name = smokingcaterpil | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 10.05.2012 11:17:45 | Computer Name = smokingcaterpil | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 10.05.2012 11:17:45 | Computer Name = smokingcaterpil | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 10.05.2012 11:17:46 | Computer Name = smokingcaterpil | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 10.05.2012 11:17:46 | Computer Name = smokingcaterpil | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 10.05.2012 23:18:14 | Computer Name = smokingcaterpil | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
 nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
 
Error - 12.05.2012 08:38:42 | Computer Name = smokingcaterpil | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
 nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
 
 
< End of report >


cosinus 06.08.2012 20:12

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.creaf.com
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{B8704F1D-E99A-4FEE-96E2-9C8E09681870}: "URL" = http://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{C96A9D24-16A0-4D44-8833-24434B114DB3}: "URL" = http://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
IE - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\SearchScopes\{D011AC3A-AC50-4B88-9B1B-A4721FE7986B}: "URL" = http://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=bc8156c2-0a73-426b-a866-d7447be6aa15&pid=icqstyler&mode=bounce&k=0
O2 - BHO: (WEB.DE Toolbar BHO) - {BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3:64bit: - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (WEB.DE Toolbar) - {C424171E-592A-415a-9EB1-DFD6D95D3530} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O3 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\..\Toolbar\WebBrowser: (WEB.DE Toolbar) - {C424171E-592A-415A-9EB1-DFD6D95D3530} - C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
O4:64bit: - HKLM..\Run: [ncarn] rundll32.exe "C:\Users\smoking caterpillar\AppData\Roaming\ncarn.dll",HrIndexOfWeek File not found
O4 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O18:64bit: - Protocol\Handler\webde {8FAF0273-9CA8-4efc-9536-1E35E254D5CD} - C:\Program Files\WEB.DE Toolbar\IE\uitb.dll (1und1 Mail und Media GmbH)
:Files
C:\ProgramData\beetroueqnymvyc
C:\Program Files (x86)\ICQ6Toolbar
C:\Users\smoking caterpillar\AppData\Roaming\Zinyc
C:\Users\smoking caterpillar\AppData\Roaming\Ugcao
C:\Users\smoking caterpillar\AppData\Roaming\Paxyka
C:\ProgramData\7531CCA9CA4D593B2B7FCCBCF875F002
C:\Users\smoking caterpillar\AppData\Roaming\Rosuop
C:\Users\smoking caterpillar\AppData\Roaming\Cizo
C:\Users\smoking caterpillar\AppData\Roaming\Albyc
C:\Users\smoking caterpillar\AppData\Roaming\C943C2EC
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\L
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\U
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\n
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\@
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\L
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\U
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\n
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\@
C:\Users\smoking caterpillar\AppData\Roaming\xsecva
C:\ProgramData\ecmjzjtqkkbqmhm
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache
C:\ProgramData\ymiyyjwzywphaxu
C:\Users\All Users\ymiyyjwzywphaxu
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

brainInfect 06.08.2012 20:34

OTL-Fix

Code:

All processes killed
========== OTL ==========
HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Internet Explorer\SearchScopes\{B8704F1D-E99A-4FEE-96E2-9C8E09681870}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8704F1D-E99A-4FEE-96E2-9C8E09681870}\ not found.
Registry key HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Internet Explorer\SearchScopes\{C96A9D24-16A0-4D44-8833-24434B114DB3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C96A9D24-16A0-4D44-8833-24434B114DB3}\ not found.
Registry key HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Internet Explorer\SearchScopes\{D011AC3A-AC50-4B88-9B1B-A4721FE7986B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D011AC3A-AC50-4B88-9B1B-A4721FE7986B}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF42D4A8-016E-4fcd-B1EB-837659FD77C6}\ deleted successfully.
C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C424171E-592A-415a-9EB1-DFD6D95D3530} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415a-9EB1-DFD6D95D3530}\ deleted successfully.
C:\Program Files\WEB.DE Toolbar\IE\uitb.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C424171E-592A-415a-9EB1-DFD6D95D3530} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415a-9EB1-DFD6D95D3530}\ deleted successfully.
File C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
64bit-Registry value HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ not found.
File C:\Program Files\WEB.DE Toolbar\IE\uitb.dll not found.
Registry value HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C424171E-592A-415A-9EB1-DFD6D95D3530} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C424171E-592A-415A-9EB1-DFD6D95D3530}\ not found.
File C:\Program Files (x86)\WEB.DE Toolbar\IE\uitb.dll not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ncarn deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer deleted successfully.
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe moved successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
File C:\Program Files\WEB.DE Toolbar\IE\uitb.dll not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\webde\ deleted successfully.
File C:\Program Files\WEB.DE Toolbar\IE\uitb.dll not found.
========== FILES ==========
C:\ProgramData\beetroueqnymvyc moved successfully.
C:\Program Files (x86)\ICQ6Toolbar folder moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\Zinyc folder moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\Ugcao folder moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\Paxyka folder moved successfully.
C:\ProgramData\7531CCA9CA4D593B2B7FCCBCF875F002 folder moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\Rosuop folder moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\Cizo folder moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\Albyc folder moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\C943C2EC folder moved successfully.
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\L folder moved successfully.
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\U folder moved successfully.
File\Folder C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\n not found.
C:\Windows\Installer\{8e332967-9d87-6826-99f8-79db66641bd3}\@ moved successfully.
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\L folder moved successfully.
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\U folder moved successfully.
File\Folder C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\n not found.
C:\Users\smoking caterpillar\AppData\Local\{8e332967-9d87-6826-99f8-79db66641bd3}\@ moved successfully.
C:\Users\smoking caterpillar\AppData\Roaming\xsecva folder moved successfully.
C:\ProgramData\ecmjzjtqkkbqmhm moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\smoking caterpillar\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
C:\ProgramData\ymiyyjwzywphaxu folder moved successfully.
File\Folder C:\Users\All Users\ymiyyjwzywphaxu not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: smoking caterpillar
->Temp folder emptied: 383408706 bytes
->Temporary Internet Files folder emptied: 61527428 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 6913 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1281905 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 79067485 bytes
RecycleBin emptied: 22212525 bytes
 
Total Files Cleaned = 522,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Public
 
User: smoking caterpillar
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.56.0 log created on 08062012_212725

Files\Folders moved on Reboot...
C:\Users\smoking caterpillar\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DL1UAOD0\index[1].htm moved successfully.
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CG957XM9\blank[1].htm moved successfully.
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A17JIOHQ\Supplier-Gazelle_1[1].htm not found!

PendingFileRenameOperations files...
File C:\Users\smoking caterpillar\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DL1UAOD0\index[1].htm not found!
File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CG957XM9\blank[1].htm not found!
File C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A17JIOHQ\Supplier-Gazelle_1[1].htm not found!

Registry entries deleted on Reboot...


cosinus 07.08.2012 15:24

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

brainInfect 07.08.2012 20:28

TDSS-Killer Log

Code:

21:25:08.0392 5736        TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
21:25:08.0719 5736        ============================================================
21:25:08.0719 5736        Current date / time: 2012/08/07 21:25:08.0719
21:25:08.0719 5736        SystemInfo:
21:25:08.0719 5736       
21:25:08.0719 5736        OS Version: 6.1.7601 ServicePack: 1.0
21:25:08.0719 5736        Product type: Workstation
21:25:08.0719 5736        ComputerName: SMOKINGCATERPIL
21:25:08.0719 5736        UserName: smoking caterpillar
21:25:08.0719 5736        Windows directory: C:\Windows
21:25:08.0719 5736        System windows directory: C:\Windows
21:25:08.0719 5736        Running under WOW64
21:25:08.0719 5736        Processor architecture: Intel x64
21:25:08.0719 5736        Number of processors: 4
21:25:08.0719 5736        Page size: 0x1000
21:25:08.0719 5736        Boot type: Normal boot
21:25:08.0719 5736        ============================================================
21:25:09.0281 5736        Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:25:09.0281 5736        ============================================================
21:25:09.0281 5736        \Device\Harddisk0\DR0:
21:25:09.0281 5736        MBR partitions:
21:25:09.0281 5736        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3200800, BlocksNum 0xEE79000
21:25:09.0281 5736        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x12079800, BlocksNum 0x133B4800
21:25:09.0281 5736        ============================================================
21:25:09.0312 5736        C: <-> \Device\Harddisk0\DR0\Partition0
21:25:09.0359 5736        D: <-> \Device\Harddisk0\DR0\Partition1
21:25:09.0359 5736        ============================================================
21:25:09.0359 5736        Initialize success
21:25:09.0359 5736        ============================================================
21:25:20.0856 6224        ============================================================
21:25:20.0856 6224        Scan started
21:25:20.0856 6224        Mode: Manual; SigCheck; TDLFS;
21:25:20.0856 6224        ============================================================
21:25:21.0652 6224        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
21:25:21.0792 6224        1394ohci - ok
21:25:21.0854 6224        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
21:25:21.0886 6224        ACPI - ok
21:25:21.0932 6224        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
21:25:22.0073 6224        AcpiPmi - ok
21:25:22.0166 6224        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
21:25:22.0182 6224        adp94xx - ok
21:25:22.0229 6224        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
21:25:22.0260 6224        adpahci - ok
21:25:22.0291 6224        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
21:25:22.0307 6224        adpu320 - ok
21:25:22.0338 6224        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
21:25:22.0478 6224        AeLookupSvc - ok
21:25:22.0541 6224        AFBAgent        (6e79a119b0ce418fe44e0c824bf3f039) C:\Windows\system32\FBAgent.exe
21:25:22.0556 6224        AFBAgent - ok
21:25:22.0634 6224        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
21:25:22.0712 6224        AFD - ok
21:25:22.0759 6224        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
21:25:22.0790 6224        agp440 - ok
21:25:22.0837 6224        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
21:25:22.0915 6224        ALG - ok
21:25:22.0946 6224        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
21:25:22.0978 6224        aliide - ok
21:25:23.0009 6224        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
21:25:23.0009 6224        amdide - ok
21:25:23.0040 6224        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
21:25:23.0102 6224        AmdK8 - ok
21:25:23.0118 6224        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
21:25:23.0165 6224        AmdPPM - ok
21:25:23.0227 6224        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
21:25:23.0258 6224        amdsata - ok
21:25:23.0290 6224        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
21:25:23.0305 6224        amdsbs - ok
21:25:23.0321 6224        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
21:25:23.0336 6224        amdxata - ok
21:25:23.0446 6224        Amsp            (18f64623e76ff58009d6f9cb9dea5d0a) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
21:25:23.0477 6224        Amsp - ok
21:25:23.0524 6224        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
21:25:23.0742 6224        AppID - ok
21:25:23.0789 6224        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
21:25:23.0867 6224        AppIDSvc - ok
21:25:23.0914 6224        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
21:25:23.0992 6224        Appinfo - ok
21:25:24.0023 6224        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
21:25:24.0038 6224        arc - ok
21:25:24.0070 6224        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
21:25:24.0085 6224        arcsas - ok
21:25:24.0194 6224        ASLDRService    (18e5c2f937f9deb8c282df66a3761925) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
21:25:24.0210 6224        ASLDRService - ok
21:25:24.0241 6224        ASMMAP64        (4c016fd76ed5c05e84ca8cab77993961) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
21:25:24.0272 6224        ASMMAP64 - ok
21:25:24.0319 6224        asmthub3        (0aa7a996792fb0287b33a57a8093ae44) C:\Windows\system32\DRIVERS\asmthub3.sys
21:25:24.0382 6224        asmthub3 - ok
21:25:24.0428 6224        asmtxhci        (125dc3abf5bfccfe82ad17d078e0b9ec) C:\Windows\system32\DRIVERS\asmtxhci.sys
21:25:24.0475 6224        asmtxhci - ok
21:25:24.0569 6224        ASUS InstantOn  (9836dda9a33dacc7f40a672c47ad70d0) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
21:25:24.0584 6224        ASUS InstantOn - ok
21:25:24.0616 6224        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
21:25:24.0709 6224        AsyncMac - ok
21:25:24.0740 6224        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
21:25:24.0772 6224        atapi - ok
21:25:24.0943 6224        athr            (de9fb3dade8fd39ae2c587df22d36b8e) C:\Windows\system32\DRIVERS\athrx.sys
21:25:25.0068 6224        athr - ok
21:25:25.0162 6224        ATKGFNEXSrv    (7910158929571214a959d5a6d16dd9c0) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
21:25:25.0177 6224        ATKGFNEXSrv - ok
21:25:25.0286 6224        ATKWMIACPIIO    (41ceaffcf3550785e59e3ec9bee8d97a) C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
21:25:25.0302 6224        ATKWMIACPIIO - ok
21:25:25.0458 6224        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
21:25:25.0567 6224        AudioEndpointBuilder - ok
21:25:25.0567 6224        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
21:25:25.0614 6224        AudioSrv - ok
21:25:25.0692 6224        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
21:25:25.0786 6224        AxInstSV - ok
21:25:25.0864 6224        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
21:25:25.0957 6224        b06bdrv - ok
21:25:25.0988 6224        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
21:25:26.0035 6224        b57nd60a - ok
21:25:26.0082 6224        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
21:25:26.0129 6224        BDESVC - ok
21:25:26.0176 6224        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
21:25:26.0254 6224        Beep - ok
21:25:26.0316 6224        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
21:25:26.0363 6224        blbdrive - ok
21:25:26.0410 6224        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
21:25:26.0488 6224        bowser - ok
21:25:26.0534 6224        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
21:25:26.0644 6224        BrFiltLo - ok
21:25:26.0659 6224        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
21:25:26.0706 6224        BrFiltUp - ok
21:25:26.0768 6224        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
21:25:26.0831 6224        Browser - ok
21:25:26.0862 6224        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
21:25:26.0940 6224        Brserid - ok
21:25:26.0971 6224        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
21:25:27.0002 6224        BrSerWdm - ok
21:25:27.0034 6224        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
21:25:27.0065 6224        BrUsbMdm - ok
21:25:27.0080 6224        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
21:25:27.0112 6224        BrUsbSer - ok
21:25:27.0143 6224        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
21:25:27.0205 6224        BthEnum - ok
21:25:27.0252 6224        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
21:25:27.0299 6224        BTHMODEM - ok
21:25:27.0346 6224        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
21:25:27.0377 6224        BthPan - ok
21:25:27.0439 6224        BTHPORT        (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
21:25:27.0502 6224        BTHPORT - ok
21:25:27.0548 6224        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
21:25:27.0642 6224        bthserv - ok
21:25:27.0658 6224        BTHUSB          (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
21:25:27.0673 6224        BTHUSB - ok
21:25:27.0704 6224        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
21:25:27.0782 6224        cdfs - ok
21:25:27.0814 6224        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
21:25:27.0860 6224        cdrom - ok
21:25:27.0907 6224        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
21:25:28.0001 6224        CertPropSvc - ok
21:25:28.0048 6224        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
21:25:28.0079 6224        circlass - ok
21:25:28.0141 6224        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
21:25:28.0188 6224        CLFS - ok
21:25:28.0250 6224        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:25:28.0282 6224        clr_optimization_v2.0.50727_32 - ok
21:25:28.0328 6224        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:25:28.0344 6224        clr_optimization_v2.0.50727_64 - ok
21:25:28.0453 6224        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:25:28.0484 6224        clr_optimization_v4.0.30319_32 - ok
21:25:28.0547 6224        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:25:28.0562 6224        clr_optimization_v4.0.30319_64 - ok
21:25:28.0640 6224        CLVirtualDrive  (1cce5f4dd276b4b877650437bc5cb31b) C:\Windows\system32\DRIVERS\CLVirtualDrive.sys
21:25:28.0656 6224        CLVirtualDrive - ok
21:25:28.0687 6224        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
21:25:28.0734 6224        CmBatt - ok
21:25:28.0765 6224        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
21:25:28.0781 6224        cmdide - ok
21:25:28.0843 6224        CNG            (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
21:25:28.0890 6224        CNG - ok
21:25:28.0937 6224        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
21:25:28.0968 6224        Compbatt - ok
21:25:29.0015 6224        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
21:25:29.0077 6224        CompositeBus - ok
21:25:29.0093 6224        COMSysApp - ok
21:25:29.0108 6224        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
21:25:29.0124 6224        crcdisk - ok
21:25:29.0171 6224        CryptSvc        (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
21:25:29.0218 6224        CryptSvc - ok
21:25:29.0311 6224        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
21:25:29.0389 6224        DcomLaunch - ok
21:25:29.0467 6224        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
21:25:29.0561 6224        defragsvc - ok
21:25:29.0623 6224        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
21:25:29.0686 6224        DfsC - ok
21:25:29.0748 6224        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
21:25:29.0810 6224        Dhcp - ok
21:25:29.0857 6224        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
21:25:29.0935 6224        discache - ok
21:25:29.0982 6224        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
21:25:30.0013 6224        Disk - ok
21:25:30.0060 6224        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
21:25:30.0122 6224        Dnscache - ok
21:25:30.0169 6224        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
21:25:30.0247 6224        dot3svc - ok
21:25:30.0278 6224        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
21:25:30.0356 6224        DPS - ok
21:25:30.0388 6224        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
21:25:30.0450 6224        drmkaud - ok
21:25:30.0528 6224        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
21:25:30.0575 6224        DXGKrnl - ok
21:25:30.0622 6224        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
21:25:30.0684 6224        EapHost - ok
21:25:30.0856 6224        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
21:25:30.0996 6224        ebdrv - ok
21:25:31.0090 6224        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
21:25:31.0168 6224        EFS - ok
21:25:31.0261 6224        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
21:25:31.0370 6224        ehRecvr - ok
21:25:31.0386 6224        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
21:25:31.0464 6224        ehSched - ok
21:25:31.0558 6224        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
21:25:31.0620 6224        elxstor - ok
21:25:31.0620 6224        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
21:25:31.0667 6224        ErrDev - ok
21:25:31.0714 6224        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
21:25:31.0776 6224        EventSystem - ok
21:25:31.0838 6224        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
21:25:31.0885 6224        exfat - ok
21:25:31.0901 6224        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
21:25:31.0963 6224        fastfat - ok
21:25:32.0026 6224        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
21:25:32.0119 6224        Fax - ok
21:25:32.0135 6224        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
21:25:32.0182 6224        fdc - ok
21:25:32.0213 6224        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
21:25:32.0306 6224        fdPHost - ok
21:25:32.0322 6224        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
21:25:32.0369 6224        FDResPub - ok
21:25:32.0416 6224        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
21:25:32.0431 6224        FileInfo - ok
21:25:32.0447 6224        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
21:25:32.0509 6224        Filetrace - ok
21:25:32.0525 6224        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
21:25:32.0556 6224        flpydisk - ok
21:25:32.0603 6224        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
21:25:32.0618 6224        FltMgr - ok
21:25:32.0712 6224        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
21:25:32.0790 6224        FontCache - ok
21:25:32.0884 6224        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:25:32.0899 6224        FontCache3.0.0.0 - ok
21:25:32.0977 6224        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
21:25:32.0993 6224        FsDepends - ok
21:25:33.0024 6224        fssfltr        (07da62c960ddccc2d35836aeab4fc578) C:\Windows\system32\DRIVERS\fssfltr.sys
21:25:33.0040 6224        fssfltr - ok
21:25:33.0180 6224        fsssvc          (28ddeeec44e988657b732cf404d504cb) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
21:25:33.0227 6224        fsssvc - ok
21:25:33.0336 6224        Fs_Rec          (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
21:25:33.0352 6224        Fs_Rec - ok
21:25:33.0414 6224        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
21:25:33.0445 6224        fvevol - ok
21:25:33.0461 6224        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
21:25:33.0476 6224        gagp30kx - ok
21:25:33.0539 6224        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
21:25:33.0664 6224        gpsvc - ok
21:25:33.0679 6224        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
21:25:33.0695 6224        hcw85cir - ok
21:25:33.0742 6224        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
21:25:33.0788 6224        HdAudAddService - ok
21:25:33.0835 6224        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
21:25:33.0866 6224        HDAudBus - ok
21:25:33.0882 6224        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
21:25:33.0913 6224        HidBatt - ok
21:25:33.0944 6224        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
21:25:33.0976 6224        HidBth - ok
21:25:34.0007 6224        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
21:25:34.0022 6224        HidIr - ok
21:25:34.0038 6224        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
21:25:34.0100 6224        hidserv - ok
21:25:34.0116 6224        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
21:25:34.0147 6224        HidUsb - ok
21:25:34.0178 6224        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
21:25:34.0225 6224        hkmsvc - ok
21:25:34.0256 6224        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
21:25:34.0319 6224        HomeGroupListener - ok
21:25:34.0366 6224        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
21:25:34.0412 6224        HomeGroupProvider - ok
21:25:34.0444 6224        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
21:25:34.0459 6224        HpSAMD - ok
21:25:34.0506 6224        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
21:25:34.0615 6224        HTTP - ok
21:25:34.0646 6224        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
21:25:34.0662 6224        hwpolicy - ok
21:25:34.0693 6224        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
21:25:34.0709 6224        i8042prt - ok
21:25:34.0771 6224        iaStor          (d7921d5a870b11cc1adab198a519d50a) C:\Windows\system32\DRIVERS\iaStor.sys
21:25:34.0787 6224        iaStor - ok
21:25:34.0849 6224        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
21:25:34.0865 6224        iaStorV - ok
21:25:34.0880 6224        ICQ Service - ok
21:25:35.0021 6224        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:25:35.0052 6224        idsvc - ok
21:25:35.0660 6224        igfx            (10bb0dc3361c9420cc1b0b2128bb89db) C:\Windows\system32\DRIVERS\igdkmd64.sys
21:25:36.0097 6224        igfx - ok
21:25:36.0206 6224        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
21:25:36.0222 6224        iirsp - ok
21:25:36.0284 6224        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
21:25:36.0362 6224        IKEEXT - ok
21:25:36.0581 6224        IntcAzAudAddService (cb7dadef3d83fe2c12655a0bdcba99f2) C:\Windows\system32\drivers\RTKVHD64.sys
21:25:36.0628 6224        IntcAzAudAddService - ok
21:25:36.0768 6224        IntcDAud        (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys
21:25:36.0815 6224        IntcDAud - ok
21:25:36.0846 6224        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
21:25:36.0877 6224        intelide - ok
21:25:36.0893 6224        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
21:25:36.0940 6224        intelppm - ok
21:25:36.0986 6224        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
21:25:37.0064 6224        IPBusEnum - ok
21:25:37.0111 6224        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:25:37.0158 6224        IpFilterDriver - ok
21:25:37.0174 6224        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
21:25:37.0205 6224        IPMIDRV - ok
21:25:37.0252 6224        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
21:25:37.0314 6224        IPNAT - ok
21:25:37.0361 6224        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
21:25:37.0470 6224        IRENUM - ok
21:25:37.0486 6224        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
21:25:37.0501 6224        isapnp - ok
21:25:37.0532 6224        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
21:25:37.0564 6224        iScsiPrt - ok
21:25:37.0673 6224        ISODrive        (9c6f3f69163133fb8e56ac4a6e163452) C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys
21:25:37.0688 6224        ISODrive - ok
21:25:37.0735 6224        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
21:25:37.0751 6224        kbdclass - ok
21:25:37.0782 6224        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
21:25:37.0829 6224        kbdhid - ok
21:25:37.0876 6224        kbfiltr        (e63ef8c3271d014f14e2469ce75fecb4) C:\Windows\system32\DRIVERS\kbfiltr.sys
21:25:37.0907 6224        kbfiltr - ok
21:25:37.0938 6224        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:25:37.0954 6224        KeyIso - ok
21:25:38.0000 6224        KSecDD          (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
21:25:38.0032 6224        KSecDD - ok
21:25:38.0047 6224        KSecPkg        (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
21:25:38.0063 6224        KSecPkg - ok
21:25:38.0094 6224        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
21:25:38.0141 6224        ksthunk - ok
21:25:38.0203 6224        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
21:25:38.0266 6224        KtmRm - ok
21:25:38.0328 6224        L1C            (a4a9ca24e54e81c6c3e469eaeb4b3f42) C:\Windows\system32\DRIVERS\L1C62x64.sys
21:25:38.0359 6224        L1C - ok
21:25:38.0406 6224        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
21:25:38.0453 6224        LanmanServer - ok
21:25:38.0484 6224        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
21:25:38.0531 6224        LanmanWorkstation - ok
21:25:38.0578 6224        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
21:25:38.0640 6224        lltdio - ok
21:25:38.0702 6224        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
21:25:38.0780 6224        lltdsvc - ok
21:25:38.0812 6224        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
21:25:38.0843 6224        lmhosts - ok
21:25:38.0983 6224        LMS            (7f32d4c47a50e7223491e8fb9359907d) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
21:25:38.0999 6224        LMS - ok
21:25:39.0061 6224        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
21:25:39.0092 6224        LSI_FC - ok
21:25:39.0108 6224        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
21:25:39.0124 6224        LSI_SAS - ok
21:25:39.0139 6224        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
21:25:39.0155 6224        LSI_SAS2 - ok
21:25:39.0170 6224        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
21:25:39.0186 6224        LSI_SCSI - ok
21:25:39.0217 6224        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
21:25:39.0295 6224        luafv - ok
21:25:39.0342 6224        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
21:25:39.0373 6224        Mcx2Svc - ok
21:25:39.0389 6224        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
21:25:39.0404 6224        megasas - ok
21:25:39.0451 6224        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
21:25:39.0467 6224        MegaSR - ok
21:25:39.0498 6224        MEIx64          (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys
21:25:39.0498 6224        MEIx64 - ok
21:25:39.0529 6224        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
21:25:39.0607 6224        MMCSS - ok
21:25:39.0623 6224        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
21:25:39.0670 6224        Modem - ok
21:25:39.0716 6224        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
21:25:39.0748 6224        monitor - ok
21:25:39.0779 6224        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
21:25:39.0779 6224        mouclass - ok
21:25:39.0810 6224        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
21:25:39.0857 6224        mouhid - ok
21:25:39.0888 6224        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
21:25:39.0919 6224        mountmgr - ok
21:25:40.0013 6224        MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:25:40.0028 6224        MozillaMaintenance - ok
21:25:40.0060 6224        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
21:25:40.0060 6224        mpio - ok
21:25:40.0091 6224        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
21:25:40.0138 6224        mpsdrv - ok
21:25:40.0169 6224        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
21:25:40.0216 6224        MRxDAV - ok
21:25:40.0247 6224        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
21:25:40.0309 6224        mrxsmb - ok
21:25:40.0340 6224        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:25:40.0372 6224        mrxsmb10 - ok
21:25:40.0403 6224        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:25:40.0434 6224        mrxsmb20 - ok
21:25:40.0465 6224        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
21:25:40.0481 6224        msahci - ok
21:25:40.0512 6224        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
21:25:40.0528 6224        msdsm - ok
21:25:40.0574 6224        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
21:25:40.0621 6224        MSDTC - ok
21:25:40.0652 6224        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
21:25:40.0699 6224        Msfs - ok
21:25:40.0730 6224        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
21:25:40.0793 6224        mshidkmdf - ok
21:25:40.0808 6224        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
21:25:40.0808 6224        msisadrv - ok
21:25:40.0855 6224        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
21:25:40.0902 6224        MSiSCSI - ok
21:25:40.0918 6224        msiserver - ok
21:25:40.0949 6224        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
21:25:41.0011 6224        MSKSSRV - ok
21:25:41.0027 6224        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
21:25:41.0074 6224        MSPCLOCK - ok
21:25:41.0105 6224        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
21:25:41.0167 6224        MSPQM - ok
21:25:41.0198 6224        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
21:25:41.0245 6224        MsRPC - ok
21:25:41.0276 6224        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
21:25:41.0276 6224        mssmbios - ok
21:25:41.0308 6224        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
21:25:41.0354 6224        MSTEE - ok
21:25:41.0370 6224        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
21:25:41.0417 6224        MTConfig - ok
21:25:41.0432 6224        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
21:25:41.0432 6224        Mup - ok
21:25:41.0495 6224        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
21:25:41.0573 6224        napagent - ok
21:25:41.0620 6224        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
21:25:41.0682 6224        NativeWifiP - ok
21:25:41.0776 6224        NDIS            (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys
21:25:41.0838 6224        NDIS - ok
21:25:41.0869 6224        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
21:25:41.0900 6224        NdisCap - ok
21:25:41.0916 6224        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
21:25:41.0963 6224        NdisTapi - ok
21:25:41.0994 6224        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
21:25:42.0072 6224        Ndisuio - ok
21:25:42.0088 6224        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
21:25:42.0150 6224        NdisWan - ok
21:25:42.0197 6224        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
21:25:42.0275 6224        NDProxy - ok
21:25:42.0306 6224        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
21:25:42.0353 6224        NetBIOS - ok
21:25:42.0384 6224        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
21:25:42.0431 6224        NetBT - ok
21:25:42.0478 6224        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:25:42.0478 6224        Netlogon - ok
21:25:42.0540 6224        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
21:25:42.0634 6224        Netman - ok
21:25:42.0680 6224        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
21:25:42.0758 6224        netprofm - ok
21:25:42.0868 6224        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:25:42.0883 6224        NetTcpPortSharing - ok
21:25:42.0914 6224        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
21:25:42.0930 6224        nfrd960 - ok
21:25:42.0977 6224        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
21:25:43.0039 6224        NlaSvc - ok
21:25:43.0086 6224        NPF            (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys
21:25:43.0102 6224        NPF - ok
21:25:43.0117 6224        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
21:25:43.0164 6224        Npfs - ok
21:25:43.0180 6224        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
21:25:43.0258 6224        nsi - ok
21:25:43.0304 6224        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
21:25:43.0382 6224        nsiproxy - ok
21:25:43.0492 6224        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
21:25:43.0585 6224        Ntfs - ok
21:25:43.0694 6224        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
21:25:43.0772 6224        Null - ok
21:25:43.0819 6224        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
21:25:43.0850 6224        nvraid - ok
21:25:43.0866 6224        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
21:25:43.0882 6224        nvstor - ok
21:25:43.0913 6224        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
21:25:43.0928 6224        nv_agp - ok
21:25:43.0944 6224        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
21:25:43.0975 6224        ohci1394 - ok
21:25:44.0022 6224        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
21:25:44.0069 6224        p2pimsvc - ok
21:25:44.0084 6224        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
21:25:44.0116 6224        p2psvc - ok
21:25:44.0147 6224        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
21:25:44.0178 6224        Parport - ok
21:25:44.0209 6224        partmgr        (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
21:25:44.0225 6224        partmgr - ok
21:25:44.0256 6224        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
21:25:44.0287 6224        PcaSvc - ok
21:25:44.0334 6224        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
21:25:44.0350 6224        pci - ok
21:25:44.0365 6224        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
21:25:44.0381 6224        pciide - ok
21:25:44.0396 6224        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
21:25:44.0412 6224        pcmcia - ok
21:25:44.0428 6224        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
21:25:44.0443 6224        pcw - ok
21:25:44.0490 6224        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
21:25:44.0568 6224        PEAUTH - ok
21:25:44.0662 6224        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
21:25:44.0693 6224        PerfHost - ok
21:25:44.0802 6224        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
21:25:44.0896 6224        pla - ok
21:25:44.0974 6224        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
21:25:45.0052 6224        PlugPlay - ok
21:25:45.0083 6224        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
21:25:45.0114 6224        PNRPAutoReg - ok
21:25:45.0145 6224        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
21:25:45.0161 6224        PNRPsvc - ok
21:25:45.0223 6224        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
21:25:45.0286 6224        PolicyAgent - ok
21:25:45.0348 6224        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
21:25:45.0410 6224        Power - ok
21:25:45.0488 6224        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
21:25:45.0582 6224        PptpMiniport - ok
21:25:45.0598 6224        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
21:25:45.0629 6224        Processor - ok
21:25:45.0660 6224        ProfSvc        (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
21:25:45.0707 6224        ProfSvc - ok
21:25:45.0722 6224        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:25:45.0754 6224        ProtectedStorage - ok
21:25:45.0800 6224        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
21:25:45.0863 6224        Psched - ok
21:25:45.0956 6224        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
21:25:46.0019 6224        ql2300 - ok
21:25:46.0112 6224        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
21:25:46.0144 6224        ql40xx - ok
21:25:46.0190 6224        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
21:25:46.0222 6224        QWAVE - ok
21:25:46.0237 6224        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
21:25:46.0284 6224        QWAVEdrv - ok
21:25:46.0300 6224        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
21:25:46.0362 6224        RasAcd - ok
21:25:46.0409 6224        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
21:25:46.0456 6224        RasAgileVpn - ok
21:25:46.0487 6224        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
21:25:46.0549 6224        RasAuto - ok
21:25:46.0580 6224        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
21:25:46.0658 6224        Rasl2tp - ok
21:25:46.0721 6224        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
21:25:46.0783 6224        RasMan - ok
21:25:46.0814 6224        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
21:25:46.0861 6224        RasPppoe - ok
21:25:46.0908 6224        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
21:25:46.0986 6224        RasSstp - ok
21:25:47.0017 6224        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
21:25:47.0095 6224        rdbss - ok
21:25:47.0111 6224        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
21:25:47.0158 6224        rdpbus - ok
21:25:47.0173 6224        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
21:25:47.0220 6224        RDPCDD - ok
21:25:47.0267 6224        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
21:25:47.0314 6224        RDPENCDD - ok
21:25:47.0345 6224        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
21:25:47.0407 6224        RDPREFMP - ok
21:25:47.0438 6224        RDPWD          (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
21:25:47.0516 6224        RDPWD - ok
21:25:47.0548 6224        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
21:25:47.0579 6224        rdyboost - ok
21:25:47.0626 6224        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
21:25:47.0704 6224        RemoteAccess - ok
21:25:47.0719 6224        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
21:25:47.0782 6224        RemoteRegistry - ok
21:25:47.0828 6224        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
21:25:47.0875 6224        RFCOMM - ok
21:25:47.0953 6224        rpcapd          (b60f58f175de20a6739194e85b035178) C:\Program Files (x86)\WinPcap\rpcapd.exe
21:25:47.0984 6224        rpcapd - ok
21:25:48.0016 6224        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
21:25:48.0094 6224        RpcEptMapper - ok
21:25:48.0109 6224        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
21:25:48.0140 6224        RpcLocator - ok
21:25:48.0187 6224        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
21:25:48.0234 6224        RpcSs - ok
21:25:48.0265 6224        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
21:25:48.0296 6224        rspndr - ok
21:25:48.0328 6224        s117bus        (6c90231046fb9fc4123c42179832817f) C:\Windows\system32\DRIVERS\s117bus.sys
21:25:48.0328 6224        s117bus - ok
21:25:48.0374 6224        s117mdfl        (3279341c90ef8f226af77623039f4495) C:\Windows\system32\DRIVERS\s117mdfl.sys
21:25:48.0390 6224        s117mdfl - ok
21:25:48.0406 6224        s117mdm        (73e331f555279e753b312675ddaf4516) C:\Windows\system32\DRIVERS\s117mdm.sys
21:25:48.0421 6224        s117mdm - ok
21:25:48.0437 6224        s117mgmt        (d420731fd2880f0f40f20771efaad671) C:\Windows\system32\DRIVERS\s117mgmt.sys
21:25:48.0452 6224        s117mgmt - ok
21:25:48.0468 6224        s117nd5        (98236ca5a9a77d0983ac3f6d6527c796) C:\Windows\system32\DRIVERS\s117nd5.sys
21:25:48.0468 6224        s117nd5 - ok
21:25:48.0515 6224        s117obex        (1dd613909477ae298c98e86617ec356b) C:\Windows\system32\DRIVERS\s117obex.sys
21:25:48.0515 6224        s117obex - ok
21:25:48.0530 6224        s117unic        (9a22df5fe9b6be279d820776a6adb56f) C:\Windows\system32\DRIVERS\s117unic.sys
21:25:48.0546 6224        s117unic - ok
21:25:48.0562 6224        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:25:48.0577 6224        SamSs - ok
21:25:48.0608 6224        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
21:25:48.0640 6224        sbp2port - ok
21:25:48.0686 6224        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
21:25:48.0733 6224        SCardSvr - ok
21:25:48.0749 6224        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
21:25:48.0796 6224        scfilter - ok
21:25:48.0874 6224        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
21:25:48.0952 6224        Schedule - ok
21:25:48.0983 6224        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
21:25:49.0014 6224        SCPolicySvc - ok
21:25:49.0045 6224        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
21:25:49.0092 6224        SDRSVC - ok
21:25:49.0217 6224        SearchAnonymizer (0f4a80438e7286a0e623582f5f2395bd) C:\Users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
21:25:49.0217 6224        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
21:25:49.0217 6224        SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
21:25:49.0295 6224        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
21:25:49.0373 6224        secdrv - ok
21:25:49.0404 6224        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
21:25:49.0451 6224        seclogon - ok
21:25:49.0482 6224        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
21:25:49.0529 6224        SENS - ok
21:25:49.0560 6224        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
21:25:49.0607 6224        SensrSvc - ok
21:25:49.0622 6224        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
21:25:49.0654 6224        Serenum - ok
21:25:49.0700 6224        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
21:25:49.0732 6224        Serial - ok
21:25:49.0778 6224        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
21:25:49.0810 6224        sermouse - ok
21:25:49.0856 6224        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
21:25:49.0919 6224        SessionEnv - ok
21:25:49.0934 6224        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
21:25:49.0997 6224        sffdisk - ok
21:25:50.0028 6224        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
21:25:50.0059 6224        sffp_mmc - ok
21:25:50.0075 6224        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
21:25:50.0106 6224        sffp_sd - ok
21:25:50.0122 6224        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
21:25:50.0153 6224        sfloppy - ok
21:25:50.0200 6224        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
21:25:50.0262 6224        ShellHWDetection - ok
21:25:50.0309 6224        SiSGbeLH        (1bc348cf6baa90ec8e533ef6e6a69933) C:\Windows\system32\DRIVERS\SiSG664.sys
21:25:50.0340 6224        SiSGbeLH - ok
21:25:50.0387 6224        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
21:25:50.0418 6224        SiSRaid2 - ok
21:25:50.0434 6224        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
21:25:50.0434 6224        SiSRaid4 - ok
21:25:50.0543 6224        SkypeUpdate    (17eab7852ff9f15fbaab4e95efc0b812) C:\Program Files (x86)\Skype\Updater\Updater.exe
21:25:50.0558 6224        SkypeUpdate - ok
21:25:50.0605 6224        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
21:25:50.0652 6224        Smb - ok
21:25:50.0699 6224        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
21:25:50.0730 6224        SNMPTRAP - ok
21:25:50.0746 6224        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
21:25:50.0761 6224        spldr - ok
21:25:50.0808 6224        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
21:25:50.0870 6224        Spooler - ok
21:25:51.0042 6224        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
21:25:51.0151 6224        sppsvc - ok
21:25:51.0276 6224        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
21:25:51.0338 6224        sppuinotify - ok
21:25:51.0416 6224        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
21:25:51.0479 6224        srv - ok
21:25:51.0526 6224        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
21:25:51.0557 6224        srv2 - ok
21:25:51.0572 6224        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
21:25:51.0604 6224        srvnet - ok
21:25:51.0650 6224        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
21:25:51.0728 6224        SSDPSRV - ok
21:25:51.0744 6224        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
21:25:51.0806 6224        SstpSvc - ok
21:25:51.0822 6224        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
21:25:51.0838 6224        stexstor - ok
21:25:51.0884 6224        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
21:25:51.0931 6224        stisvc - ok
21:25:51.0947 6224        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
21:25:51.0962 6224        swenum - ok
21:25:52.0009 6224        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
21:25:52.0087 6224        swprv - ok
21:25:52.0212 6224        SynTP          (7e8902f9929a5d9ffd0f545332ce0f10) C:\Windows\system32\DRIVERS\SynTP.sys
21:25:52.0274 6224        SynTP - ok
21:25:52.0462 6224        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
21:25:52.0540 6224        SysMain - ok
21:25:52.0618 6224        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
21:25:52.0664 6224        TabletInputService - ok
21:25:52.0711 6224        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
21:25:52.0789 6224        TapiSrv - ok
21:25:52.0805 6224        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
21:25:52.0867 6224        TBS - ok
21:25:53.0039 6224        Tcpip          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
21:25:53.0132 6224        Tcpip - ok
21:25:53.0304 6224        TCPIP6          (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
21:25:53.0351 6224        TCPIP6 - ok
21:25:53.0444 6224        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
21:25:53.0522 6224        tcpipreg - ok
21:25:53.0554 6224        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
21:25:53.0569 6224        TDPIPE - ok
21:25:53.0600 6224        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
21:25:53.0616 6224        TDTCP - ok
21:25:53.0647 6224        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
21:25:53.0694 6224        tdx - ok
21:25:53.0741 6224        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
21:25:53.0756 6224        TermDD - ok
21:25:53.0819 6224        TermService    (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
21:25:53.0881 6224        TermService - ok
21:25:53.0897 6224        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
21:25:53.0959 6224        Themes - ok
21:25:53.0990 6224        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
21:25:54.0022 6224        THREADORDER - ok
21:25:54.0068 6224        tmactmon        (73aaffdd2ac3c8814b26c440e5dd9dd4) C:\Windows\system32\DRIVERS\tmactmon.sys
21:25:54.0084 6224        tmactmon - ok
21:25:54.0115 6224        tmcomm          (360e61217d4e1e333583d0c721057f70) C:\Windows\system32\DRIVERS\tmcomm.sys
21:25:54.0115 6224        tmcomm - ok
21:25:54.0146 6224        tmevtmgr        (699d34eb7c670139ca23a65372bd5743) C:\Windows\system32\DRIVERS\tmevtmgr.sys
21:25:54.0146 6224        tmevtmgr - ok
21:25:54.0193 6224        tmtdi          (262198efb734012bfcd17e7479ae4a09) C:\Windows\system32\DRIVERS\tmtdi.sys
21:25:54.0209 6224        tmtdi - ok
21:25:54.0256 6224        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
21:25:54.0334 6224        TrkWks - ok
21:25:54.0396 6224        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
21:25:54.0458 6224        TrustedInstaller - ok
21:25:54.0505 6224        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
21:25:54.0536 6224        tssecsrv - ok
21:25:54.0568 6224        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
21:25:54.0614 6224        TsUsbFlt - ok
21:25:54.0630 6224        TsUsbGD        (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
21:25:54.0661 6224        TsUsbGD - ok
21:25:54.0708 6224        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
21:25:54.0786 6224        tunnel - ok
21:25:54.0802 6224        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
21:25:54.0817 6224        uagp35 - ok
21:25:54.0833 6224        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
21:25:54.0911 6224        udfs - ok
21:25:54.0942 6224        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
21:25:54.0989 6224        UI0Detect - ok
21:25:55.0036 6224        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
21:25:55.0051 6224        uliagpkx - ok
21:25:55.0082 6224        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
21:25:55.0129 6224        umbus - ok
21:25:55.0145 6224        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
21:25:55.0176 6224        UmPass - ok
21:25:55.0394 6224        UNS            (2c16648a12999ae69a9ebf41974b0ba2) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
21:25:55.0457 6224        UNS - ok
21:25:55.0582 6224        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
21:25:55.0644 6224        upnphost - ok
21:25:55.0706 6224        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
21:25:55.0769 6224        usbccgp - ok
21:25:55.0816 6224        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
21:25:55.0862 6224        usbcir - ok
21:25:55.0909 6224        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
21:25:55.0925 6224        usbehci - ok
21:25:55.0987 6224        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
21:25:56.0034 6224        usbhub - ok
21:25:56.0065 6224        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
21:25:56.0081 6224        usbohci - ok
21:25:56.0112 6224        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\drivers\usbprint.sys
21:25:56.0128 6224        usbprint - ok
21:25:56.0159 6224        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:25:56.0174 6224        USBSTOR - ok
21:25:56.0221 6224        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
21:25:56.0252 6224        usbuhci - ok
21:25:56.0299 6224        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
21:25:56.0362 6224        usbvideo - ok
21:25:56.0393 6224        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
21:25:56.0440 6224        UxSms - ok
21:25:56.0471 6224        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
21:25:56.0486 6224        VaultSvc - ok
21:25:56.0502 6224        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
21:25:56.0518 6224        vdrvroot - ok
21:25:56.0564 6224        vds            (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
21:25:56.0611 6224        vds - ok
21:25:56.0674 6224        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
21:25:56.0689 6224        vga - ok
21:25:56.0720 6224        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
21:25:56.0752 6224        VgaSave - ok
21:25:56.0783 6224        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
21:25:56.0798 6224        vhdmp - ok
21:25:56.0798 6224        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
21:25:56.0814 6224        viaide - ok
21:25:56.0845 6224        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
21:25:56.0861 6224        volmgr - ok
21:25:56.0892 6224        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
21:25:56.0908 6224        volmgrx - ok
21:25:56.0939 6224        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
21:25:56.0954 6224        volsnap - ok
21:25:56.0986 6224        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
21:25:57.0001 6224        vsmraid - ok
21:25:57.0110 6224        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
21:25:57.0188 6224        VSS - ok
21:25:57.0282 6224        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
21:25:57.0329 6224        vwifibus - ok
21:25:57.0360 6224        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
21:25:57.0391 6224        vwififlt - ok
21:25:57.0422 6224        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
21:25:57.0454 6224        vwifimp - ok
21:25:57.0516 6224        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
21:25:57.0578 6224        W32Time - ok
21:25:57.0594 6224        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
21:25:57.0625 6224        WacomPen - ok
21:25:57.0672 6224        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
21:25:57.0734 6224        WANARP - ok
21:25:57.0734 6224        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
21:25:57.0766 6224        Wanarpv6 - ok
21:25:57.0859 6224        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
21:25:57.0937 6224        wbengine - ok
21:25:58.0031 6224        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
21:25:58.0078 6224        WbioSrvc - ok
21:25:58.0124 6224        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
21:25:58.0187 6224        wcncsvc - ok
21:25:58.0202 6224        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
21:25:58.0249 6224        WcsPlugInService - ok
21:25:58.0312 6224        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
21:25:58.0327 6224        Wd - ok
21:25:58.0374 6224        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
21:25:58.0421 6224        Wdf01000 - ok
21:25:58.0436 6224        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
21:25:58.0546 6224        WdiServiceHost - ok
21:25:58.0561 6224        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
21:25:58.0592 6224        WdiSystemHost - ok
21:25:58.0608 6224        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
21:25:58.0639 6224        WebClient - ok
21:25:58.0686 6224        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
21:25:58.0733 6224        Wecsvc - ok
21:25:58.0764 6224        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
21:25:58.0811 6224        wercplsupport - ok
21:25:58.0858 6224        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
21:25:58.0936 6224        WerSvc - ok
21:25:58.0998 6224        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
21:25:59.0045 6224        WfpLwf - ok
21:25:59.0123 6224        WimFltr        (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
21:25:59.0138 6224        WimFltr - ok
21:25:59.0170 6224        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
21:25:59.0185 6224        WIMMount - ok
21:25:59.0185 6224        WinHttpAutoProxySvc - ok
21:25:59.0248 6224        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
21:25:59.0341 6224        Winmgmt - ok
21:25:59.0466 6224        WinRM          (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
21:25:59.0560 6224        WinRM - ok
21:25:59.0700 6224        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
21:25:59.0731 6224        WinUsb - ok
21:25:59.0809 6224        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
21:25:59.0872 6224        Wlansvc - ok
21:25:59.0965 6224        wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
21:25:59.0981 6224        wlcrasvc - ok
21:26:00.0199 6224        wlidsvc        (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:26:00.0262 6224        wlidsvc - ok
21:26:00.0371 6224        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
21:26:00.0418 6224        WmiAcpi - ok
21:26:00.0480 6224        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
21:26:00.0527 6224        wmiApSrv - ok
21:26:00.0605 6224        WMPNetworkSvc - ok
21:26:00.0636 6224        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
21:26:00.0652 6224        WPCSvc - ok
21:26:00.0683 6224        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
21:26:00.0698 6224        WPDBusEnum - ok
21:26:00.0714 6224        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
21:26:00.0776 6224        ws2ifsl - ok
21:26:00.0776 6224        WSearch - ok
21:26:00.0808 6224        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
21:26:00.0901 6224        WudfPf - ok
21:26:00.0948 6224        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
21:26:00.0995 6224        WUDFRd - ok
21:26:01.0026 6224        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
21:26:01.0057 6224        wudfsvc - ok
21:26:01.0088 6224        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
21:26:01.0120 6224        WwanSvc - ok
21:26:01.0151 6224        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
21:26:01.0541 6224        \Device\Harddisk0\DR0 - ok
21:26:01.0556 6224        Boot (0x1200)  (beb34928e75ada2c2548ece6c5638061) \Device\Harddisk0\DR0\Partition0
21:26:01.0556 6224        \Device\Harddisk0\DR0\Partition0 - ok
21:26:01.0588 6224        Boot (0x1200)  (70968fe7fd8f3e5f6dd865b445461b25) \Device\Harddisk0\DR0\Partition1
21:26:01.0588 6224        \Device\Harddisk0\DR0\Partition1 - ok
21:26:01.0588 6224        ============================================================
21:26:01.0588 6224        Scan finished
21:26:01.0588 6224        ============================================================
21:26:01.0603 6188        Detected object count: 1
21:26:01.0603 6188        Actual detected object count: 1
21:26:14.0848 6188        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
21:26:14.0848 6188        SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 08.08.2012 19:54

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

brainInfect 08.08.2012 20:41

CF-Log

Code:

ComboFix 12-08-08.01 - smoking caterpillar 08.08.2012  21:08:03.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4000.2655 [GMT 2:00]
ausgeführt von:: c:\users\smoking caterpillar\Desktop\ComboFix.exe
AV: Trend Micro Titanium Internet Security *Disabled/Outdated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: Trend Micro Titanium Internet Security *Disabled/Outdated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\users\smoking caterpillar\4.0
c:\users\smoking caterpillar\AppData\Roaming\Help\coredb\storage
c:\windows\msvcr71.dll
.
Infizierte Kopie von c:\windows\system32\Services.exe wurde gefunden und desinfiziert
Kopie von - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe wurde wiederhergestellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-07-08 bis 2012-08-08  ))))))))))))))))))))))))))))))
.
.
2012-08-08 19:16 . 2012-08-08 19:16        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-08-06 19:27 . 2012-08-06 19:27        --------        d-----w-        C:\_OTL
2012-08-05 16:00 . 2012-08-05 16:00        --------        d-----w-        c:\program files (x86)\ESET
2012-07-31 20:05 . 2012-07-31 23:48        --------        d-----w-        c:\users\smoking caterpillar\dwhelper
2012-07-31 14:39 . 2012-07-31 14:39        --------        d-----w-        c:\users\smoking caterpillar\AppData\Local\Apps
2012-07-31 14:39 . 2012-07-31 23:52        --------        d-----w-        c:\users\smoking caterpillar\AppData\Local\Deployment
2012-07-31 14:39 . 2012-07-31 14:39        --------        d-----w-        C:\Archivos de programa
2012-07-24 14:42 . 2012-07-24 14:42        --------        d-----w-        c:\users\smoking caterpillar\AppData\Roaming\Malwarebytes
2012-07-24 14:42 . 2012-08-05 14:42        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-07-24 14:42 . 2012-07-24 14:42        --------        d-----w-        c:\programdata\Malwarebytes
2012-07-24 14:42 . 2012-07-03 11:46        24904        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-07-23 21:37 . 2002-03-05 22:00        75264        ----a-w-        c:\windows\SysWow64\unacev2.dll
2012-07-23 21:37 . 2003-02-02 17:06        153088        ----a-w-        c:\windows\SysWow64\UNRAR3.dll
2012-07-23 21:37 . 2012-07-23 21:38        --------        d-----w-        c:\program files (x86)\Trojan Remover
2012-07-23 21:37 . 2012-07-23 21:37        --------        d-----w-        c:\users\smoking caterpillar\AppData\Roaming\Simply Super Software
2012-07-23 21:37 . 2012-07-23 21:37        --------        d-----w-        c:\programdata\Simply Super Software
2012-07-23 21:05 . 2012-07-23 21:05        --------        d-sh--w-        c:\windows\system32\%APPDATA%
2012-07-23 01:04 . 2012-06-12 03:08        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-07-23 01:00 . 2012-06-02 12:07        887296        ----a-w-        c:\program files\Internet Explorer\iedvtool.dll
2012-07-23 01:00 . 2012-06-02 12:06        499200        ----a-w-        c:\program files\Internet Explorer\jsdbgui.dll
2012-07-23 01:00 . 2012-06-02 12:00        818688        ----a-w-        c:\windows\system32\jscript.dll
2012-07-23 01:00 . 2012-06-02 08:27        678912        ----a-w-        c:\program files (x86)\Internet Explorer\iedvtool.dll
2012-07-23 01:00 . 2012-06-02 08:26        387584        ----a-w-        c:\program files (x86)\Internet Explorer\jsdbgui.dll
2012-07-23 01:00 . 2012-06-02 12:49        17807360        ----a-w-        c:\windows\system32\mshtml.dll
2012-07-23 01:00 . 2012-06-02 12:17        10924032        ----a-w-        c:\windows\system32\ieframe.dll
2012-07-22 16:53 . 2012-06-29 10:04        9133488        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B7F756C-CFE0-4F5E-9413-1ACEF41E77BD}\mpengine.dll
2012-07-22 16:10 . 2012-07-22 16:10        --------        d-----w-        c:\users\smoking caterpillar\AppData\Local\ElevatedDiagnostics
2012-07-11 01:00 . 2010-02-23 08:16        294912        ----a-w-        c:\windows\system32\browserchoice.exe
2012-07-10 16:09 . 2012-07-10 16:09        --------        d-----w-        c:\users\smoking caterpillar\AppData\Roaming\Apple
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-08 11:51 . 2011-12-10 14:25        45056        ----a-w-        c:\windows\SysWow64\acovcnt.exe
2012-07-23 01:01 . 2012-07-07 12:20        59701280        ----a-w-        c:\windows\system32\MRT.exe
2012-06-20 13:04 . 2012-06-20 13:04        19736        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-06-02 22:19 . 2012-06-22 06:12        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-22 06:12        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-22 06:12        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-22 06:12        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-22 06:12        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-22 06:12        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-22 06:12        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-22 06:12        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-22 06:12        36864        ----a-w-        c:\windows\system32\wuapp.exe
2012-05-31 10:25 . 2011-12-12 02:04        279656        ------w-        c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E32FBEA2-F52F-4812-A88F-21FE54FD0AF0}]
2012-03-26 23:41        141312        ----a-w-        c:\programdata\CodecC\bhoclass.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032]
"ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472]
"SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2011-07-21 5716608]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2011-09-09 2317312]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-12-02 74752]
"WorksFUD"="c:\program files (x86)\Microsoft Works\wkfud.exe" [2001-10-09 24576]
"Microsoft Works Portfolio"="c:\program files (x86)\Microsoft Works\WksSb.exe" [2001-10-04 331830]
"Microsoft Works Update Detection"="c:\program files (x86)\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-10-04 28738]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"CLMLServer_For_P2G8"="c:\program files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" [2011-10-28 107816]
"CLVirtualDrive"="c:\program files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2011-10-31 485672]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2012-05-22 160872]
"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2012-07-23 1240848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-4-13 548528]
Erinnerungen in Microsoft Works-Kalender.lnk - c:\program files (x86)\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-10-4 24633]
FancyStart daemon.lnk - c:\windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe [2011-11-2 12862]
Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-01-31 158856]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-29 113120]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
S1 CLVirtualDrive;CLVirtualDrive;c:\windows\system32\DRIVERS\CLVirtualDrive.sys [2011-09-08 90096]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2011-01-25 379520]
S2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\Common Files\InstantOn\InsOnSrv.exe [2011-08-24 92800]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344]
S2 SearchAnonymizer;SearchAnonymizer;c:\users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2012-07-08 40960]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [2010-09-17 67664]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-06-02 128488]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-06-02 401896]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2010-09-02 08:41        220160        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2010-09-02 08:41        220160        ----a-w-        c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Trend Micro Titanium"="c:\program files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" [2011-10-08 1111568]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-07-28 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-07-28 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-07-28 416024]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2011-03-21 361984]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]
"Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2011-02-10 197152]
"Ocs_SM"="c:\users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2012-07-08 106496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.2
FF - ProfilePath -
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{BF42D4A8-016E-4fcd-B1EB-837659FD77C6} - c:\program files\WEB.DE Toolbar\IE\uitb.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SynAsusAcpi - c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
AddRemove-ICQToolbar - c:\program files (x86)\ICQ6Toolbar\ICQUnToolbar.exe
AddRemove-loadtbs-2.1 - c:\users\smoking caterpillar\AppData\Roaming\loadtbs\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*v*i*—ä=t\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*a*v*i*õä=t\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*w±_]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*w±_\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*êùÉ[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1377819090-1488837102-2095713333-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*êùÉ[\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\InstantOn\InsOnWMI.exe
c:\program files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
c:\program files (x86)\ASUS\Splendid\ACMON.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\windows\SysWOW64\ACEngSvr.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\powercfg.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-08-08  21:22:28 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-08-08 19:22
.
Vor Suchlauf: 18 Verzeichnis(se), 68.033.392.640 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 67.689.840.640 Bytes frei
.
- - End Of File - - 6FAF54BEA1E5F27ECE7E89FE471E8A21


cosinus 09.08.2012 15:42

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

brainInfect 09.08.2012 19:19

GMER-Log

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-08-09 19:53:49
Windows 6.1.7601 Service Pack 1
Running: vss6w69j.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e                     
Reg  HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet) 

---- EOF - GMER 1.0.15 ----

osam-Log

Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 19:59:59 on 09.08.2012

OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 64-bit
Default Browser: Mozilla Corporation Firefox 14.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"ASMMAP64" (ASMMAP64) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
"ATKWMIACPI Driver" (ATKWMIACPIIO) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
"catchme" (catchme) - ? - C:\ComboFix\catchme.sys  (File not found)
"FssFltr" (fssfltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\fssfltr.sys
"ISO DVD/CD-ROM Device Driver" (ISODrive) - "EZB Systems, Inc." - C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys
"NetGroup Packet Filter Driver" (NPF) - "CACE Technologies, Inc." - C:\Windows\System32\drivers\npf.sys
"Trend Micro TDI Driver" (tmtdi) - "Trend Micro Inc." - C:\Windows\System32\DRIVERS\tmtdi.sys
"WimFltr" (WimFltr) - "Microsoft Corporation" - C:\Windows\System32\DRIVERS\wimfltr.sys

[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll
{1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} "TmIEPlugInAPP Class" - "Trend Micro Inc." - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
{0E526CB5-7446-41D1-A403-19BFE95E8C23} "TmIEPlugInAPP Class" - "Trend Micro Inc." - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg32.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{79BC0345-1015-11D2-A299-006008312725} "///FAST project settings" - ? - C:\Program Files (x86)\Pinnacle\VideoSpin\Programs\BlueShellExt.dll  (File found, but it contains no detailed information)
{D8D1CE8C-B1EB-4E95-B63B-1531BA60E992} "DivX Property Handler" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll
{83238FAE-D346-4E12-8734-D42F7554B3E6} "DivX Thumbnail Provider" - "DivX, Inc." - C:\Program Files (x86)\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll
{0006F045-0000-0000-C000-000000000046} "Outlook-Dateisymbolerweiterung" - "Microsoft Corporation" - C:\PROGRA~2\MICROS~1\Office\OLKFSTUB.DLL
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~2\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files (x86)\WinRAR\rarext.dll
{B41DB860-64E4-11D2-9906-E49FADC173CA} "WinRAR shell extension" - ? -  (File not found | COM-object registry key not found)
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -  (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
"ICQ7.2" - "ICQ, LLC." - C:\Program Files (x86)\ICQ7.2\ICQ.exe
"Sothink SWF Catcher" - ? - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{E32FBEA2-F52F-4812-A88F-21FE54FD0AF0} "CodecC Class" - "Injector" - C:\ProgramData\CodecC\bhoclass.dll
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} "TmBpIeBHO Class" - "Trend Micro Inc." - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
{1CA1377B-DC1D-4A52-9585-6E06050FAC53} "TmIEPlugInBHO Class" - "Trend Micro Inc." - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg32.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID-Anmelde-Hilfsprogramm" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[LSA Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Lsa )-----
"Security Packages" - "Microsoft Corp." - C:\Windows\system32\livessp.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\smoking caterpillar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"AsusVibeLauncher.lnk" - ? - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe  (Shortcut exists | File exists)
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"FancyStart daemon.lnk" - "ASUSTeK Computer Inc." - C:\Program Files (x86)\ASUS\FancyStart\FancyStart.exe  (Shortcut exists | File exists)
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE  (Shortcut exists | File exists)
"Erinnerungen in Microsoft Works-Kalender.lnk" - "Microsoft® Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe  (Shortcut exists | File exists)
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"ASUSPRP" - "ASUSTek Computer Inc." - "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
"ASUSWebStorage" - "ecareme" - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S
"ATKMEDIA" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
"ATKOSD2" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
"CLMLServer_For_P2G8" - "CyberLink" - "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"CLVirtualDrive" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
"DivXUpdate" - ? - "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"HControlUser" - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
"Microsoft Works Portfolio" - "Microsoft® Corporation" - C:\Program Files (x86)\Microsoft Works\WksSb.exe /AllUsers
"Microsoft Works Update Detection" - "Microsoft® Corporation" - C:\Program Files (x86)\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
"Nuance PDF Reader-reminder" - "Nuance Communications, Inc." - "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
"PDFPrint" - "Geek Software GmbH" - C:\Program Files (x86)\PDF24\pdf24.exe
"SonicMasterTray" - "Virage Logic Corporation / Sonic Focus" - C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"TrojanScanner" - "Simply Super Software" - C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
"UpdateLBPShortCut" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
"UpdateP2GoShortCut" - "CyberLink Corp." - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
"WinampAgent" - "Nullsoft, Inc." - "C:\Program Files (x86)\Winamp\winampa.exe"
"Wireless Console 3" - "ASUS" - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
"WorksFUD" - "Microsoft® Corporation" - C:\Program Files (x86)\Microsoft Works\wkfud.exe

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103" (WinDefend) - ? - C:\Program Files (x86)\Windows Defender\mpsvc.dll  (File not found)
"@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101" (WMPNetworkSvc) - ? - "C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe"  (File not found)
"AFBAgent" (AFBAgent) - "ASUSTeK Computer Inc." - C:\Windows\system32\FBAgent.exe
"ASLDR Service" (ASLDRService) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
"ASUS InstantOn Service" (ASUS InstantOn) - "ASUS" - C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
"ATKGFNEX Service" (ATKGFNEXSrv) - "ASUS" - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
"ICQ Service" (ICQ Service) - ? - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe  (File not found)
"Intel(R) Management and Security Application Local Management Service" (LMS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
"Intel(R) Management and Security Application User Notification Service" (UNS) - "Intel Corporation" - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
"Microsoft .NET Framework NGEN v4.0.30319_X64" (clr_optimization_v4.0.30319_64) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
"Remote Packet Capture Protocol v.0 (experimental)" (rpcapd) - "CACE Technologies, Inc." - C:\Program Files (x86)\WinPcap\rpcapd.exe
"SearchAnonymizer" (SearchAnonymizer) - ? - C:\Users\smoking caterpillar\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files (x86)\Skype\Updater\Updater.exe
"Trend Micro Solution Platform" (Amsp) - "Trend Micro Inc." - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
"Windows Live Family Safety Service" (fsssvc) - "Microsoft Corporation" - C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"WindowsLive Local NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
"WindowsLive NSP" - "Microsoft Corp." - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

aswMBR-Log

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-09 20:01:37
-----------------------------
20:01:37.026    OS Version: Windows x64 6.1.7601 Service Pack 1
20:01:37.027    Number of processors: 4 586 0x2A07
20:01:37.028    ComputerName: SMOKINGCATERPIL  UserName:
20:01:37.565    Initialize success
20:10:13.348    AVAST engine defs: 12080900
20:10:34.516    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:10:34.522    Disk 0 Vendor: ST932032 0003 Size: 305245MB BusType: 3
20:10:34.543    Disk 0 MBR read successfully
20:10:34.548    Disk 0 MBR scan
20:10:34.574    Disk 0 Windows 7 default MBR code
20:10:34.589    Disk 0 Partition 1 00    1C Hidd FAT32 LBA MSDOS5.0    25600 MB offset 2048
20:10:34.609    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      122098 MB offset 52430848
20:10:34.639    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      157545 MB offset 302487552
20:10:34.678    Disk 0 scanning C:\Windows\system32\drivers
20:10:46.844    Service scanning
20:11:08.546    Modules scanning
20:11:08.566    Disk 0 trace - called modules:
20:11:08.637    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
20:11:08.983    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004dbd060]
20:11:08.993    3 CLASSPNP.SYS[fffff88001ba943f] -> nt!IofCallDriver -> [0xfffffa8004b65b20]
20:11:09.003    5 ACPI.sys[fffff88000f897a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004b69050]
20:11:09.955    AVAST engine scan C:\Windows
20:11:12.944    AVAST engine scan C:\Windows\system32
20:13:57.886    AVAST engine scan C:\Windows\system32\drivers
20:14:11.521    AVAST engine scan C:\Users\smoking caterpillar
20:15:18.997    File: C:\Users\smoking caterpillar\AppData\Roaming\vlc\{96FD72B9-3877-4F4A-9591-A6E08D4D18B2}\Upgrade.exe  **INFECTED** Win32:Malware-gen
20:16:00.411    AVAST engine scan C:\ProgramData
20:16:01.250    File: C:\ProgramData\CodecC\bhoclass.dll  **INFECTED** Win32:MultiPlug-B [Adw]
20:17:06.378    Scan finished successfully
20:17:26.673    Disk 0 MBR has been saved successfully to "C:\Users\smoking caterpillar\Desktop\MBR.dat"
20:17:26.678    The log file has been saved successfully to "C:\Users\smoking caterpillar\Desktop\aswMBR.txt"


cosinus 10.08.2012 21:13

Code:

C:\Users\smoking caterpillar\AppData\Roaming\vlc\{96FD72B9-3877-4F4A-9591-A6E08D4D18B2}\Upgrade.exe
C:\ProgramData\CodecC\bhoclass.dll

Bitte diese Dateien bei Virustotal auswerten lassen und von jeder den Ergebnislink posten. Falls Du die Dateien nicht siehst, musst Du sie evtl. vorher sichtbar machen.
Wenn eine Datei schon ausgewerte sein sollte, bitte eine weitere Auswertung starten.

brainInfect 10.08.2012 21:38

1. Datei:

https://www.virustotal.com/file/1ea0d8e86c77f2ccd089d99273ae2bb58ca0a41b3c6376bdfb7e25d5958e9c8a/analysis/

2. Datei:

https://www.virustotal.com/file/1d683fd80f1c0fafd9df83e944c8a33d8bd98a84455a815de003eadecdebf4b5/analysis/

Hey, mein Virenscanner hat gerade etwas gefunden.

http://s1.directupload.net/images/120811/ziuv7ost.png

Soll ich auf "exclude" klicken, oder wie soll ich das behandeln?

lg

cosinus 11.08.2012 16:50

Na kasse, appconf32 ist idR ein BankingTrojaner :stirn:
Machst du OnlineBanking mit diesem Rechner?
Willst du wirklich noch weiter bereinigen? Der muss während der Bereinigung ins System gekommen sein, wahrscheinlich durch Lücken in deiner alten Software wie Java, vorher hab ich keine appconf32 in deinem System gesehen

brainInfect 11.08.2012 17:13

Ja ich mach mit dem Rechner OnlineBanking, aber seitdem wir den Laptop bereinigen hab ichs noch nicht gemacht.

Wieso fragst du, ob ob ich den Laptop weiter bereinigen möchte? Ist der Erfolg nicht gegeben bzw der Aufwand zu groß? Soll ich den Rechner besser ganz neu aufsetzen?

Ansich würd ich ihn gerne weiter bereinigen. Aber ich lasse mich da von dir beraten, ob das Sinn macht.

Und er ha noch einen gefunden. :balla:

http://s7.directupload.net/images/120811/of8iuhce.png

cosinus 11.08.2012 19:31

Man kann ihn bereinigen aber ich würde danach nicht mehr OnlineBanking unter dieser Windows-Installation empfehlen

brainInfect 11.08.2012 19:34

Hmm, also am besten neu aufsetzen. So ein Mist, trotzdem Danke für deine Mühen!! :)

Bin mir gerade schon eine Win7-Iso am runterladen. Ich bin mir allerdings unsicher mit den Treibern. Muss ich da was besonders beachten oder reicht es, wenn ich das System mithilfe dieser Iso neu aufsetze?

cosinus 11.08.2012 21:05

Das kommt ganz auf die Hardware an. Wenn dein Rechner nicht allzu neu ist, wird Windows alles erkennen. Aber idR muss man Treiber wir für den Chipsatz und Grafikkarte immer aktuelle einspielen.
Falls deine Netzwerkkarte nicht erkennt werden sollte, könntest du eine böse Überraschung erleben, gut, dass du nochmal fragst, denn dann hast du keine Möglichkeit übers Internet mal eben was runterzuladen (sofern deine Internetverbindung über deine Netzwerkkarte bzw. WLAN-Adapter geht)

Welchen Rechner genau hast du denn?

brainInfect 11.08.2012 21:17

Also meinen Rechner habe ich mir letztes Jahr im November/Dezember gekauft.

Mein Internet läuft über W-Lan.

Ich tippe dir einfach mal alle Daten aus der Systemsteuerung ab:

Win7 Home Premium
ASUSTek Computer Inc.
4,7 Windows-Leistungsindex
Intel Core i3-2310 CPU @ 2.10 GHz
Arbeitsspeicher 4,00 GB
64 Bit

Kann ich nicht einfach eine ISO von meinem aktuellen System erstellen? Bin mir, wie gesagt, zwar gerade eine am runterladen (aus dem Forum), aber wenn ich ne eigene ISO erstelle hätte ich das eventuelle Problem mit den Treibern nicht, oder?

cosinus 11.08.2012 21:28

Ist leider nicht ganz so hilfreich
Installier mal http://www.chip.de/downloads/HWiNFO64_49799644.html
Da siehst du genau welche Hardware da drin steckt

Zitat:

Kann ich nicht einfach eine ISO von meinem aktuellen System erstellen? Bin mir, wie gesagt, zwar gerade eine am runterladen (aus dem Forum), aber wenn ich ne eigene ISO erstelle hätte ich das eventuelle Problem mit den Treibern nicht, oder?
Eine Image vom jetzigen System ist für das Neuaufsetzen wertlos, denn es ist ja samt seinen Systemendateien kompromittiert (muss man annehmen). Du brauchst garantiert saubere Installationsmedien. Damit ist aber nicht gemeint, dass du dir kein Win7-Iso auf DVD brennen darfst. Das ist zwar nicht optimal, aber die Quelle ist das heruntegeladene ISO-File und es wird 1:1 auf DVD gebrannt

Wenn du Windows neu drauf hast und du zwecks Treibermangel nicht ins Internet kommt, solltest du einen Plan B haben - ist eh empfehlenswert weil du bestimmt noch Daten sichern möchtest oder?

Dazu kann ich das posten, denn mit dem Live-Linux-System kommst du mit ziemlicher Sicherheits ins Internet (auch über WLAN) und kannst dir da die Treiber für Windows runterladen

brainInfect 12.08.2012 00:49

Hm, ja ok. Also wenn das mit den Treibern in trockenen Tüchern ist und ich weiss, wie ich sie installiere und wo ich sie herkriege werd ich das System neu aufsetzen. Alles andere bringt mir nichts.

Ich habe das Programm runtergeladen und dir einen Screenshot vom ersten Fenster gemacht, welches sich geöffnet hat. Ich hoffe, da ist alles bei, was du erfahren musst.^^

http://s7.directupload.net/images/120812/h4k578rj.png

cosinus 12.08.2012 13:25

Du hast ein ASUS K54L Mainboard, damit solltest du eigentlich alle nötigen Infos für die Treiberbeschaffung haben :)

Hab übrigens gestern vergessen die die Anleitung mit der Live-CD zu posten, hier ist sie

Zum Thema Datensicherung von infizierten Systemen; mach das über ne Live-CD wie Knoppix, Ubuntu (zweiter Link in meiner Signatur) oder über PartedMagic. Grund: Bei einem Live-System sind keine Schädlinge des infizierten Windows-Systems aktiv, damit ist dann auch eine negative Beeinflussung des Backups durch Schädlinge ausgeschlossen.

Du brauchst natürlich auch ein Sicherungsmedium, am besten dürfte eine externe Platte sein. Sofern du nicht allzuviel sichern musst, kann auch ein USB-Stick ausreichen.

Hier eine kurze Anleitung zu PartedMagic, funktioniert prinzipell so aber fast genauso mit allen anderen Live-Systemen auch.

1. Lade Dir das ISO-Image von PartedMagic herunter, müssten ca. 180 MB sein
2. Brenn es per Imagebrennfunktion auf CD, geht zB mit ImgBurn unter Windows
3. Boote von der gebrannten CD, im Bootmenü von Option 1 starten und warten bis der Linux-Desktop oben ist

http://partedmagic.com/lib/exe/fetch...ia=desktop.png

4. Du müsstest ein Symbol "Mount Devices" finden, das doppelklicken
5. Mounte die Partitionen wo Windows installiert ist, meistens isses /dev/sda1 und natürlich noch etwaige andere Partitionen, wo noch Daten liegen und die gesichert werden müssen - natürlich auch die der externen Platte (du bekommmst nur Lese- und Schreibzugriffe auf die Dateisysteme, wenn diese gemountet sind)
6. Kopiere die Daten der internen Platte auf die externe Platte - kopiere nur persönliche Dateien, Musik, Videos, etc. auf die Backupplatte, KEINE ausführbaren Dateien wie Programme/Spiele/Setups!!
7. Wenn fertig, starte den Rechner neu, schalte die ext. Platte ab und boote von der Windows-DVD zur Neuinstallation (Anleitung beachten)


Alle Zeitangaben in WEZ +1. Es ist jetzt 19:13 Uhr.

Copyright ©2000-2026, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132