Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Yontoo 1.10.02, RootKitAccess (https://www.trojaner-board.de/132191-yontoo-1-10-02-rootkitaccess.html)

SMC36 13.03.2013 18:27

Yontoo 1.10.02, RootKitAccess
 
Hallo!
Vorab: Bin neu im Forum und ein Computer-Idiot.
Habe bei letzter Programm-Kontrolle Yontoo 1.10.02 gefunden. Recherche bei Chip-Online-Forum ergab: Malware, die über Browser eingeschleust wird, um personalisierte Werbung abzusetzen. Weitere Info dort: PC möglicherweise mit RootKitAccess infiziert. Empfehlung: Neuinstallation.
Habe alle wichtigen Daten extern gespeichert. Dann mehrere Ordner mit Buchstaben/Zahlenkombinationen als Namen entdeckt, zwar vermutet, dass sie mit der Malware in Verbindung stehen, aber leider trotzdem versucht, sie zu löschen.
Resultat: Recycling ...
Habe PC sofort ausgeschaltet. Mir wurde geraten, den PC nicht wieder hochzufahren, weil Malware den Bildschirm zerstören könnte.
Kann ich den PC noch retten und wenn ja, wie?:wtf:

aharonov 13.03.2013 19:10

Hallo SMC36 und :hallo:

Mein Name ist Leo und ich werde dich durch die Bereinigung deines Rechners begleiten.

Eine Bereinigung beinhaltet nebst dem Entfernen von Malware auch das Schliessen von Sicherheitslücken und sollte gründlich durchgeführt werden. Sie erfolgt deshalb in mehreren Schritten und bedeutet einigen Aufwand für dich.
Beachte: Das Verschwinden der offensichtlichen Symptome bedeutet nicht, dass das System schon sauber ist.
Arbeite daher in deinem eigenen Interesse solange mit, bis du das OK bekommst, dass alles erledigt ist.

Hinweise zum Ablauf
  • Du bekommst von mir jeweils eine individuell auf dich abgestimmte schrittweise Anleitung.
    • Lese diese Anweisungen immer zuerst vollständig durch und frag bei Unklarheiten nach, bevor du beginnst.
    • Arbeite die Anleitungen dann sorgfältig und in der angegebenen Reihenfolge ab und poste deine Rückmeldungen und Logfiles gesammelt in einer Antwort.
    • Füge den Inhalt der Logfiles wenn immer möglich innerhalb von Code-Tags in deine Antwort ein.
    • Sollten Probleme auftauchen, dann brich an dieser Stelle ab und schildere sie so gut wie möglich.
  • Es ist wichtig für mich, dass sich der Zustand deines Systems nicht plötzlich unvorhersehbar ändert. Deshalb: Bitte
    • .. lasse keine Scanner oder Tools ohne Aufforderung laufen. Lösche nichts auf eigene Faust.
    • .. installiere oder deinstalliere während der Bereinigung keine Software.
    • .. frag nicht parallel in anderen Foren nach Hilfe (Crossposting).
  • Ich kann dir keine Garantien geben, dass die Bereinigung schlussendlich erfolgreich sein wird und wir alles finden werden.
    • Ein Formatieren und Neuinstallieren ist meist der schnellere und immer der sicherere Weg.
    • Sollte ich eine schwerwiegende Infektion bei dir finden, werde ich dich nochmals darauf hinweisen. Es bleibt aber deine Entscheidung.
Los geht's: Alle Tools immer auf den Desktop speichern und von dort starten.


Zitat:

Yontoo 1.10.02 gefunden. Recherche bei Chip-Online-Forum ergab: Malware, die über Browser eingeschleust wird, um personalisierte Werbung abzusetzen. Weitere Info dort: PC möglicherweise mit RootKitAccess infiziert. Empfehlung: Neuinstallation.
Immer mit der Ruhe. Zuerst schauen wir mal, was da überhaupt drauf ist.

Zitat:

Dann mehrere Ordner mit Buchstaben/Zahlenkombinationen als Namen entdeckt, zwar vermutet, dass sie mit der Malware in Verbindung stehen, aber leider trotzdem versucht, sie zu löschen.
Einfach blind irgendwelche unbekannten Ordner zu löschen, kann bös in's Auge gehen.

Zitat:

Mir wurde geraten, den PC nicht wieder hochzufahren, weil Malware den Bildschirm zerstören könnte.
:balla:

Zitat:

Kann ich den PC noch retten und wenn ja, wie?
Rechner wieder aufstarten und dann folgende Schritte abarbeiten:


Schritt 1

Downloade dir bitte defogger (von jpshortstuff) auf deinen Desktop.
  • Starte das Tool mit Doppelklick.
  • Klicke nun auf den Disable Button.
  • Bestätige diese Sicherheitsabfrage mit Ja.
  • Wenn der Scan beendet wurde (Finished), klicke auf OK.
  • Falls Defogger zu einem Neustart auffordert, bestätige dies mit OK.
  • Defogger erstellt auf dem Desktop eine Logdatei mit dem Namen defogger_disable.txt.
  • Nur falls Probleme aufgetreten sind, poste deren Inhalt mit deiner nächsten Antwort.
Klicke den Re-enable Button nicht ohne Anweisung!



Schritt 2

Lade dir Gmer herunter (auf den Button Download EXE drücken) und speichere das Programm auf den Desktop.
  • Deaktiviere alle Antivirenprogramme und Malware/Spyware Scanner.
  • Trenne alle bestehenden Verbindungen zu einem Netzwerk/Internet (WLAN nicht vergessen).
  • Schliesse bitte alle anderen Programme.
  • Starte gmer.exe (die Datei hat einen zufälligen Dateinamen).
    Vista und Win7 User mit Rechtsklick "als Administrator starten".
  • Sollte sich ein Fenster mit folgender Warnung öffnen
    WARNING !!!
    GMER has found system modification, which might have been caused by ROOTKIT activity.
    Do you want to fully scan your system ?
    dann klicke unbedingt auf No.
  • Entferne rechts den Haken bei:
    • IAT/EAT
    • Show all
  • Setze rechts den Haken bei deiner Systempartition (normalerweise C:\).
  • Starte den Scan mit einem Klick auf Scan.
  • Mache gar nichts am Computer, während der Scan läuft!
  • Wenn der Scan fertig ist, klicke auf Save und speichere das Logfile unter Gmer.txt auf deinen Desktop.
  • Schliesse dann GMER und führe unmittelbar einen Neustart des Computers durch.
  • Füge bitte den Inhalt des Logfiles hier in deine Thread ein.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor du ins Netz gehst.



Schritt 3

Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
  • Doppelklick auf die OTL.exe.
  • Unter Extra Registry, wähle bitte Use SafeList.
  • Setze den Haken bei Scan all Users.
  • Klicke nun auf Run Scan.
  • Wenn der Scan beendet ist, werden 2 Logfiles (OTL.txt und Extras.txt) erstellt.
  • Poste den Inhalt dieser Logfiles hier in den Thread.



Bitte poste in deiner nächsten Antwort:
  • Log von Gmer
  • Logs von OTL

SMC36 14.03.2013 18:50

Danke Leo für deine super-ausführliche Anleitung!
Leider sagt mir der Download-Manager schon beim ersten Schritt Defogger
"Der angeforderte Header wurde nicht gefunden" "Fehler beim Schreiben der Datei, Zugriff verweigert."

aharonov 14.03.2013 19:03

Also du kannst das File gar nicht downloaden?
Dann mach mal mit Schritt 2 weiter.

SMC36 14.03.2013 20:12

Download von Defogger und gmer hat doch geklappt. Aber was meinst du mit "antivirenprogramme und spyware-scanner deaktivieren" - wie?

aharonov 14.03.2013 21:27

Zitat:

was meinst du mit "antivirenprogramme und spyware-scanner deaktivieren" - wie?
Du musst einfach den Echtzeitschutz deines Antivirenprogramms ausschalten für die Zeit während des Scans.
Wenn du nicht weisst, wie das geht: Was hast du für ein Antivirenprogramm?

SMC36 15.03.2013 19:14

Hi!
McAfee und Windows Defender. Deaktivierung des Echtzeitschutzes hab ich gecheckt. Mir hat jemand vor kurzem noch spydig draufgepackt. Muss ich das auch deaktivieren? Durch uninstall?

aharonov 15.03.2013 19:21

Hi,

Zitat:

Muss ich das auch deaktivieren? Durch uninstall?
Ja, dieses auch deaktivieren. Wenn du das nicht findest, kannst du es auch temporär deinstallieren.

SMC36 17.03.2013 19:06

Hi Leo!
Habe 2x versucht, Gmer-Scan durchzuführen.
Beim 1. Versuch hat während des Scans der Bildschirm ausgeschaltet, war nur Neustart möglich, also kein Save.
Beim 2. Versuch hat der Scan zwischendrin von selbst abgebrochen, PC hat sich zum Startmenü zurückgesetzt. Also wieder kein Save.
Soll ich mit OTL weitermachen?
Grüße SMC

aharonov 17.03.2013 19:27

Hi,

Zitat:

Soll ich mit OTL weitermachen?
Ja, überspring Gmer und mach mit OTL weiter.

SMC36 19.03.2013 21:07

Zitat:

Zitat von aharonov (Beitrag 1030567)
Hi,


Ja, überspring Gmer und mach mit OTL weiter.

[thread\]OTL Logfile:
Code:

OTL logfile created on: 19.03.2013 19:50:09 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\EMail und InterNet\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,86 Gb Available Physical Memory | 43,32% Memory free
4,22 Gb Paging File | 2,62 Gb Available in Paging File | 62,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 122,59 Gb Total Space | 56,53 Gb Free Space | 46,11% Space Free | Partition Type: NTFS
Drive D: | 26,45 Gb Total Space | 17,17 Gb Free Space | 64,93% Space Free | Partition Type: FAT32
Drive F: | 232,83 Gb Total Space | 220,67 Gb Free Space | 94,78% Space Free | Partition Type: FAT32
 
Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\EMail und InterNet\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\bProtect.exe ()
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Programme\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Programme\Searchqu Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Programme\T-Online\T-Online_Software_6\Browser\browser.exe (Deutsche Telekom AG)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\profilemgr.exe (Deutsche Telekom AG)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\sc_watch.exe (Deutsche Telekom AG)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\kernel.exe (Deutsche Telekom AG)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Programme\McAfee Online Backup\MOBKstat.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
PRC - C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
PRC - C:\Windows\System32\ccsync.exe (Salfeld Computer)
PRC - C:\Windows\System32\cchservice.exe (Salfeld Computer)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Programme\Common Files\DATA BECKER Shared\DBService.exe (DATA BECKER GmbH & Co KG)
PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\System32\schtasks.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\Marmiko Shared\MInfraIS\MInfraIS.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
PRC - C:\Programme\T-Online\T-Online_Software_6\Notifier\Notifier.exe (fun communications GmbH, hxxp://www.fun.de)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\bProtect.exe ()
MOD - c:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\protector.dll ()
MOD - C:\Windows\System32\CmdLineExt03.dll ()
MOD - C:\Programme\DATA BECKER\TVISTA - Tuning Vista 3.0\tvshc.dll ()
 
 
========== Services (SafeList) ==========
 
SRV - (bProtector) -- C:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\bProtect.exe ()
SRV - (mfevtp) -- C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McODS) -- C:\Programme\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MSK80Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TuneUp.UtilitiesSvc) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (ksupmgr) -- C:\Windows\System32\ksupmgr.exe (Salfeld Computer)
SRV - (MOBKbackup) -- C:\Programme\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (LBTServ) -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (fsssvc) -- C:\Programme\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (DBService) -- C:\Programme\Common Files\DATA BECKER Shared\DBService.exe (DATA BECKER GmbH & Co KG)
SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (XDva401) -- C:\Windows\system32\XDva401.sys File not found
DRV - (XDva400) -- C:\Windows\system32\XDva400.sys File not found
DRV - (XDva399) -- C:\Windows\system32\XDva399.sys File not found
DRV - (XDva398) -- C:\Windows\system32\XDva398.sys File not found
DRV - (XDva397) -- C:\Windows\system32\XDva397.sys File not found
DRV - (XDva383) -- C:\Windows\system32\XDva383.sys File not found
DRV - (XDva380) -- C:\Windows\system32\XDva380.sys File not found
DRV - (XDva375) -- C:\Windows\system32\XDva375.sys File not found
DRV - (RkHit) -- C:\Windows\system32\drivers\RKHit.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (mfeavfk01) --  File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (cdiskdun) -- C:\Users\Stefan\AppData\Local\Temp\cdiskdun.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (cfwids) -- C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfewfpk) -- C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfehidk) -- C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) -- C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (McPvDrv) -- C:\Windows\System32\drivers\McPvDrv.sys (McAfee, Inc.)
DRV - (HipShieldK) -- C:\Windows\System32\drivers\HipShieldK.sys (McAfee, Inc.)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (TuneUpUtilitiesDrv) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (MTOnlPktAlyX) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek                                            )
DRV - (seehcri) -- C:\Windows\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (ggsemc) -- C:\Windows\System32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) -- C:\Windows\System32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (MOBKFilter) -- C:\Windows\System32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (NETw5v32) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (SiFilter) -- C:\Windows\System32\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil) -- C:\Windows\System32\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV - (Si3531) -- C:\Windows\System32\drivers\Si3531.sys (Silicon Image, Inc)
DRV - (acedrv11) -- C:\Windows\System32\drivers\acedrv11.sys (Protect Software GmbH)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (XUIF) -- C:\Windows\System32\drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NETw3v32) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (PLCNDIS5) -- C:\Windows\System32\plcndis5.sys (Intellon, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.shareware-d.com/de/index.php?rvs=hompag
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.chatzum.com/
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=342&systemid=406&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = hxxp://search.iminent.com/?appId=&ref=toolbox&q={searchTerms}
 
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3227975
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.iminent.com/?appid=79f3f7a1-4287-4156-9759-bbdffcf9ee89
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 53 8D A2 7B 42 CD 01  [binary data]
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\URLSearchHook: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No CLSID value found
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - No CLSID value found
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\URLSearchHook: {cdf97ee2-ded0-4369-835e-99dd08225fa5} - No CLSID value found
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes,bProtectorDefaultScope = {404962F6-6290-47B0-9B38-12EDABF8D24E}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes,DefaultScope = {404962F6-6290-47B0-9B38-12EDABF8D24E}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{1E3CF04C-0EFA-4506-BE81-6DC4D939B9E4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{1EC20F40-006D-4A2B-89D6-B3EE35C5A3BE}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3227975
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{404962F6-6290-47B0-9B38-12EDABF8D24E}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = hxxp://search.chatzum.com/?q={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = hxxp://dts.search-results.com/sr?src=ieb&appid=342&systemid=406&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}: "URL" = hxxp://search.chatzum.com/?q={searchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = n*b~µ¸QÆ€'h·8+þ°N±hvªddKyÛ0LˆIK껀*Üîw¯ÓüÍoÂOðJnøÛ¸Iï*NÞtÅs‘¿E|l?ÛmõZîìèˆ×—:Ïm–z8x5ÕÈs¨ài"Å0ížÃ,î*„}:<Ê—¨ôT}»€Z‘exˆÒ*Ä6ƒW÷XŸ»kÕ9ΞÂõ¨&ç0*÷l›xäP™xzêÝzÍÝy*•’ØØ7ÝÒÎ*!:]/S¶Ç·$œN/‚Y.ÂKâש6ác¢:ðð_°Oëgø"EÚÐõØ%˜×)â³Xê¯ò¤Ò¼˜ŽžOÇѶÍ>¥ûdAäŒNÈ!Ü_TúàAŽ·>qJLr+j¬¯‡îrDÚß$q®g‚v9Ê&QŸË¦JpQ°-»N< û|/½…aÏBÈбöüƒ¤,¨ç2 ¹YûC¨Q’¦¢ù
—¿R\xƒ,f«ºÜ!§ØËÀ¶v1N2ˆ°ð¼FŽ~Øm–ØAóÏXÊèj&ÌE)^A)(;<ˆž¼È¿'/‹ÝAt        B
“/"9ÙkÒÌA‰¸ÿã&dUÅ‚î*(v?
£¨š²ÈÍ)κç$‹,£
©²næÒŽ>
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.chatzum.com/
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3B 72 7B C5 50 4E CD 01  [binary data]
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes\{5924EA94-E19B-4EFF-811F-3C21B3E7B5EE}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_deDE438
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2013.01.15 16:49:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2013.03.19 18:24:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013.01.03 22:22:52 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\bProtectorForWindows\2.2.463.83\FirefoxExtension
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL
CHR - Extension: Savings Sidekick = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\crossrider
CHR - Extension: Savings Sidekick = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.18.9_0\
CHR - Extension: Savings Sidekick = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.22.80_0\crossrider
CHR - Extension: Savings Sidekick = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo\1.22.80_0\
CHR - Extension: SiteAdvisor = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\
CHR - Extension: Iminent = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\5.14.1.0_0\
CHR - Extension: Iminent = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\6.9.4.3_0\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Programme\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (SpecialSavings) - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Programme\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common Files\Mcafee\SystemCore\ScriptSn.20120627135043.dll (McAfee, Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Programme\Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (IMinent WebBooster (BHO)) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Programme\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (TBSB09850 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Programme\ChatZum Toolbar\tbunsrCCD5.tmp\tbcore3.dll ()
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Programme\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (ChatZum Toolbar) - {37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1} - C:\Programme\ChatZum Toolbar\tbunsrCCD5.tmp\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Programme\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\Toolbar\WebBrowser: (ChatZum Toolbar) - {37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1} - C:\Programme\ChatZum Toolbar\tbunsrCCD5.tmp\tbcore3.dll ()
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\Toolbar\WebBrowser: (no name) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No CLSID value found.
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\System32\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [DATAMNGR] C:\Programme\Searchqu Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ToADiMon.exe] C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\.DEFAULT..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-19..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [Auslogics BoostSpeed 4] C:\Programme\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe (Auslogics)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [UpdateStar] C:\Users\Stefan\AppData\Roaming\UpdateStar\UpdateStar.exe (UpdateStar GmbH)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\System32\WerFault.exe (Microsoft Corporation)
O4 - Startup: C:\Users\EMail und InterNet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 1
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 1
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: SpecialSavings - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Programme\SpecialSavings\SpecialSavingsSinged.dll (SpecialSavings)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{140C4E26-878B-4F2B-AB13-B1A5B4A59635}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8B1D7E6-209D-4841-8E3D-32BCC0D76347}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Programme\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~2\bprote~1\261125~1.80\{eab34~1\protec~1.dll) - c:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\protector.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{355a7c46-dc40-11df-b42a-0016d386db5c}\Shell\AutoRun\command - "" = F:\TranscendService(JF).exe
O33 - MountPoints2\{4eee796f-a22e-11de-b756-0016d386db5c}\Shell\AutoRun\command - "" = F:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.03.17 16:43:50 | 000,103,680 | ---- | C] (GMER) -- C:\ugdiqpob.sys
[2013.03.16 09:27:09 | 000,064,832 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\McPvDrv.sys
[2013.03.16 09:24:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013.03.15 18:57:48 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.03.15 18:57:43 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.03.15 18:57:43 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.03.15 18:57:43 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.03.15 18:57:42 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.03.15 18:57:40 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.03.15 18:57:40 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.03.15 18:57:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.03.05 19:38:41 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\iLivid
[2013.03.05 18:33:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\devolo
[2013.03.05 18:33:10 | 000,000,000 | ---D | C] -- C:\Program Files\devolo
[2013.02.19 14:33:21 | 002,048,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013.02.19 14:33:15 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2013.02.19 14:32:44 | 003,550,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013.02.19 14:32:43 | 003,602,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011.12.12 14:13:32 | 009,734,240 | ---- | C] (McAfee, Inc.) -- C:\ProgramData\TempMOBK-update-6f587c3c1a49f2fdf5254a3e5ed05791.exe
[2011.11.03 17:33:23 | 005,006,472 | ---- | C] (Electronic Arts                                            ) -- C:\Users\Stefan\setup_659.exe
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.03.19 19:57:08 | 002,432,140 | ---- | M] () -- C:\Windows\System32\ccsync.err
[2013.03.19 19:54:00 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{7E0FFB30-A1EA-45D9-AE1C-BE220B81E5B8}.job
[2013.03.19 19:54:00 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4ACB5E34-87B0-41B7-A8D4-2B06E96F0430}.job
[2013.03.19 19:27:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.03.19 18:36:57 | 000,628,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.03.19 18:36:57 | 000,596,246 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.03.19 18:36:57 | 000,126,510 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.03.19 18:36:57 | 000,104,320 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.03.19 18:36:20 | 000,034,358 | ---- | M] () -- C:\Windows\System32\cchservice.err
[2013.03.19 18:36:01 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.03.19 18:14:43 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.19 18:14:43 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.19 18:14:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.18 23:12:08 | 000,004,268 | ---- | M] () -- C:\Windows\MOBK.blk
[2013.03.18 23:12:07 | 000,000,884 | ---- | M] () -- C:\Windows\MOBK.flt
[2013.03.17 16:43:50 | 000,103,680 | ---- | M] (GMER) -- C:\ugdiqpob.sys
[2013.03.16 09:33:29 | 000,001,975 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.03.14 19:17:11 | 000,377,856 | ---- | M] () -- C:\Users\Stefan\Desktop\3yc6w4vy.exe
[2013.03.14 19:07:00 | 000,000,176 | ---- | M] () -- C:\Users\Stefan\defogger_reenable
[2013.03.14 19:03:42 | 000,050,477 | ---- | M] () -- C:\Users\Stefan\Desktop\Defogger.exe
[2013.02.23 17:03:21 | 000,271,520 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.02.19 14:15:04 | 000,060,920 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\cfwids.sys
[2013.02.19 14:12:24 | 000,210,608 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfewfpk.sys
[2013.02.19 14:12:14 | 000,172,416 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
[2013.02.19 14:11:02 | 000,010,088 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeclnk.sys
[2013.02.19 14:10:52 | 000,092,632 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdet.sys
[2013.02.19 14:09:52 | 000,565,888 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys
[2013.02.19 14:09:02 | 000,363,080 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfefirek.sys
[2013.02.19 14:08:40 | 000,065,928 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys
[2013.02.19 14:08:20 | 000,235,264 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys
[2013.02.19 14:07:50 | 000,133,416 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeapfk.sys
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.03.14 19:17:06 | 000,377,856 | ---- | C] () -- C:\Users\Stefan\Desktop\3yc6w4vy.exe
[2013.03.14 19:06:34 | 000,000,176 | ---- | C] () -- C:\Users\Stefan\defogger_reenable
[2013.03.14 19:03:38 | 000,050,477 | ---- | C] () -- C:\Users\Stefan\Desktop\Defogger.exe
[2012.11.09 18:54:29 | 000,000,025 | ---- | C] () -- C:\Windows\SIERRA.INI
[2012.09.21 20:36:17 | 000,000,088 | ---- | C] () -- C:\ProgramData\94C693EDFD.sys
[2012.09.21 20:36:16 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2012.04.12 16:28:22 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2012.04.12 16:28:21 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2012.02.12 15:45:17 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012.02.12 15:44:43 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.02.12 15:44:39 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.12.25 13:06:44 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.12.25 13:06:44 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011.12.15 17:23:51 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.06.17 10:16:37 | 000,000,307 | ---- | C] () -- C:\Windows\game.ini
[2011.05.02 21:43:32 | 000,000,647 | ---- | C] () -- C:\Windows\et.ini
[2011.05.02 21:19:03 | 000,001,233 | ---- | C] () -- C:\Windows\System32\excltmp~.dat
[2011.05.02 21:18:43 | 000,155,536 | ---- | C] () -- C:\Windows\System32\dllcinx.exe
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.02.09 15:25:09 | 000,000,552 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d8caps.dat
[2010.12.08 20:43:23 | 000,091,022 | ---- | C] () -- C:\Users\Stefan\AppData\Roaming\mdbu.bin
[2010.05.30 18:00:55 | 035,743,536 | ---- | C] () -- C:\Users\Stefan\Update_Service_Setup-2.10.5.11.exe
[2009.06.29 07:44:04 | 000,000,680 | RHS- | C] () -- C:\Users\Stefan\ntuser.pol
[2009.06.21 16:38:51 | 000,004,608 | ---- | C] () -- C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.20 18:52:04 | 000,001,356 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d9caps.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

--- --- ---
[thread\]

Cheers
SMC36

aharonov 19.03.2013 21:10

Hallo,

so geht's weiter:


Schritt 1

Downloade dir bitte AdwCleaner und speichere es auf deinen Desktop.
  • Schliesse alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet, je nach Schwere der Infektion auch mehrmals - das ist normal. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.



Schritt 2

Warnung für Mitleser:
Combofix sollte nur dann ausgeführt werden, wenn dies explizit von einem Teammitglied angewiesen wurde!


Downloade dir bitte Combofix.
  • WICHTIG: Speichere Combofix auf deinen Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft, bitte gar nichts am Computer arbeiten, auch nicht die Maus bewegen!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen (C:\Combofix.txt).
  • Bitte poste den Inhalt dieses Logfiles in deiner nächsten Antwort.

Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.



Schritt 3

Starte bitte die OTL.exe.
  • Setze den Haken bei Scan all Users.
  • Drücke auf den Quick Scan Button.
  • Poste den Inhalt von OTL.txt hier in den Thread.



Bitte poste in deiner nächsten Antwort:
  • Log von AdwCleaner
  • Log von Combofix
  • Log von OTL

SMC36 21.03.2013 17:43

Hi Leo!

AdwCleaner-Logfile hier, Combofix-Lauf abgebrochen bei Warnmeldung, dass Antiviren-Programm noch aktiv ist und Schaden an Programmen entstehen könnten. Wollte dann noch mal checken, ob Echtzeit-Schutz deaktiviert ist, aber ich komme jetzt nicht mehr als Administrator ins McAfee-Programm rein. Ist da was schiefgelaufen?
AdwCleaner Logfile:
Code:

# AdwCleaner v2.115 - Datei am 21/03/2013 um 12:20:22 erstellt
# Aktualisiert am 17/03/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : Stefan - STEFAN-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\EMail und InterNet\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : bProtector

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\EMail und InterNet\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\EMail und InterNet\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Datei Gelöscht : C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Gelöscht mit Neustart : C:\Program Files\Ask.com
Gelöscht mit Neustart : C:\Program Files\Searchqu Toolbar
Gelöscht mit Neustart : C:\ProgramData\bProtectorForWindows
Ordner Gelöscht : C:\Program Files\ChatZum Toolbar
Ordner Gelöscht : C:\Program Files\Conduit
Ordner Gelöscht : C:\Program Files\Ilivid
Ordner Gelöscht : C:\Program Files\Iminent
Ordner Gelöscht : C:\Program Files\Savings Sidekick
Ordner Gelöscht : C:\Program Files\SpecialSavings
Ordner Gelöscht : C:\Program Files\Yontoo
Ordner Gelöscht : C:\ProgramData\IBUpdaterService
Ordner Gelöscht : C:\ProgramData\Iminent
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\Local\Temp\bProtectorForWindows
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\LocalLow\searchquband
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\LocalLow\Searchqutoolbar
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\Roaming\Iminent
Ordner Gelöscht : C:\Users\Daten von Johannes\AppData\Roaming\PerformerSoft
Ordner Gelöscht : C:\Users\Daten von Johannes\bProtectorForWindows
Ordner Gelöscht : C:\Users\Daten von Johannes\Desktop\bProtectorForWindows
Ordner Gelöscht : C:\Users\EMail und InterNet\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\EMail und InterNet\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\EMail und InterNet\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\EMail und InterNet\AppData\LocalLow\Searchqutoolbar
Ordner Gelöscht : C:\Users\EMail und InterNet\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\EMail und InterNet\AppData\Roaming\Iminent
Ordner Gelöscht : C:\Users\EMail und InterNet\bProtectorForWindows
Ordner Gelöscht : C:\Users\EMail und InterNet\Desktop\bProtectorForWindows
Ordner Gelöscht : C:\Users\EMail und InterNet\Documents\bProtectorForWindows
Ordner Gelöscht : C:\Users\Schule Johannes\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Stefan\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo
Ordner Gelöscht : C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl
Ordner Gelöscht : C:\Users\Stefan\AppData\Local\Ilivid
Ordner Gelöscht : C:\Users\Stefan\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\Stefan\AppData\Local\Savings Sidekick
Ordner Gelöscht : C:\Users\Stefan\AppData\Local\Temp\Iminent
Ordner Gelöscht : C:\Users\Stefan\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Stefan\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Stefan\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Stefan\AppData\LocalLow\searchquband
Ordner Gelöscht : C:\Users\Stefan\AppData\LocalLow\Searchqutoolbar
Ordner Gelöscht : C:\Users\Stefan\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\Stefan\AppData\Roaming\Iminent
Ordner Gelöscht : C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpecialSavings
Ordner Gelöscht : C:\Users\Stefan\AppData\Roaming\PerformerSoft
Ordner Gelöscht : C:\Users\Stefan\bProtectorForWindows
Ordner Gelöscht : C:\Users\Stefan\Desktop\bProtectorForWindows
Ordner Gelöscht : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Ordner Gelöscht : C:\Windows\system32\bProtectorForWindows

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\{ADFA33FD-16F5-4355-8504-DF4D664CFE83}
Schlüssel Gelöscht : HKCU\Software\530dbdeb56eea42
Schlüssel Gelöscht : HKCU\Software\APN
Schlüssel Gelöscht : HKCU\Software\AppDataLow\AskToolbarInfo
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Savings Sidekick
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\searchqutoolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SpecialSavings
Schlüssel Gelöscht : HKCU\Software\Ask.com
Schlüssel Gelöscht : HKCU\Software\ChatZum Toolbar
Schlüssel Gelöscht : HKCU\Software\Cr_Installer
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\ilivid
Schlüssel Gelöscht : HKCU\Software\Iminent
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ChatZum Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IMBoosterARP
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Savings Sidekick
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchqu Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SpecialSavings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{58124A0B-DC32-4180-9BFF-E0E21AE34026}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\UpdateStar
Schlüssel Gelöscht : HKLM\SOFTWARE\530dbdeb56eea42
Schlüssel Gelöscht : HKLM\Software\APN
Schlüssel Gelöscht : HKLM\Software\AskToolbar
Schlüssel Gelöscht : HKLM\Software\ChatZum Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\BrowserConnection.Loader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\BrowserConnection.Loader.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{01A602A0-D0B9-445B-8081-719E4177C4A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02C9C7B0-C7C8-4AAC-A9E4-55295BF60F8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0398B101-6DA7-473F-A290-17D2FBC88CC0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CC36196-8589-4B80-A771-D659411D7F90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{143D96F9-EB64-48B3-B192-91C2C41A1F43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{14F7D91F-F669-45C9-9F42-BACBFDB86EAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{187A6488-6E71-4A2A-B118-7BEFBFE58257}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26C9BBE4-6D45-4AB6-A5B4-E068C9F5EF6D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2D065204-A024-4C39-8A38-EE7078EC7ACF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F5476C-677B-4DB0-B397-51F5BFD86840}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3223F2FB-D9B9-45FC-9D66-CD717FFA4EE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{351798B1-C1D2-45AB-92B4-4D6C2D6AB5AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AEA1BEF-6195-46F4-ACA2-0ED14F7EFA1B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D7F9AC3-BAC3-4E51-81D7-D121D79E550A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4498C5E9-93C6-4142-B6BE-F0C6DC48B77A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{492A108F-51D0-4BD8-899D-AD4AB2893064}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60893E02-2E5B-43F9-A93A-BAD60C2DF6EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6D39931F-451E-4BDD-BAF4-37FB96DBBA5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C684D2-C35D-4284-976A-D862F53ADB81}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{79EF3691-EC1A-4705-A01A-D2E36EC11758}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82F41418-8E64-47EB-A7F1-4702A974D289}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{85D920CE-63A7-46DC-8992-41D1D2E07FAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{895ED5E8-ABB4-40C3-A0CA-2571964268E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8AAC123A-1959-4A45-BFC5-E2D50783098A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A07956CD-81F8-4A03-B524-5D87E690DC83}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B5E3B26B-6E5C-4865-A63D-58D04B10E245}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B84D2DC5-42B2-4E5E-BF61-7B48152FF8EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89D5309-0367-4494-A92F-3D4C94F88307}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C014EBF8-8854-448B-B5A4-557C4090EDCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C31191DB-2F64-464C-B97C-6AC81ACB7AAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C342C7A7-F622-4EF3-8B7F-ABB9FBE73F14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C4765B07-BC2F-477B-925C-B2BF24887823}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD126DA6-FF5B-4181-AC13-54A62240D2FA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8F01233-2DE6-4EE7-8988-37263F00651B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E812AE43-7799-4E67-8CF8-4104297A2D16}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F0BAAEC7-9AE0-49FF-9C4B-86E774FF397F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F92193FD-2243-4401-9ACC-49FF30885898}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD21B8A2-910B-45AC-9C10-45E6A8B84984}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0005060.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0005060.FBApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0005060.FBApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0005060.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0005060.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ilivid
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Business.Tinyfying.DownloadArgs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Business.Tinyfying.LinkToPromoteArgs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Business.Tinyfying.RawDataArgs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Business.Tinyfying.TinyUrlArgs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Business.Tinyfying.ViralLinkArgs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.ClientCallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.ContractBase
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.AddToUserContentCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.CheckLoginStatusCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.CleanCacheCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.GameOverCallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.GetCreditCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.GetInstallationContextCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.GetLoginStatusCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.GetLoginStatusResult
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.GetVariableCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.GetVariableResult
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.InstallationContextResult
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.LoadContentCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.LoadContentCommandResult
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.LoginCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.LoginStatusChangedCallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.LogoutCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.MergeIdentityCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.MyAccountCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.PlayContentCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.PostContentCallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.RecycleViewsCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.SetVariableCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.ShowBrowserWindowCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.ShowControlCenterCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.ShowPluginWindowCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.TestContentCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.UserContentChangedCallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.VariableChangedCallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.WarmUpCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.DataContracts.WelcomeCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.ServerCommand
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.Communication.ServerResult
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.LightContent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.LightUri
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent.Mediator.MediatorServiceProxy
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.ActiveContentHandle.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.ActiveContentHandler
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.TinyUrlHandler
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IminentWebBooster.TinyUrlHandler.1
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ACA608DB-A210-4253-B799-3FD24E9A7BF5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TBSB09850.IEToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TBSB09850.IEToolbar.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TBSB09850.TBSB09850
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TBSB09850.TBSB09850.3
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3227975
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.TBSB09850
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar3.TBSB09850.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gelöscht : HKLM\Software\ilivid
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0AF350D9-3916-454B-AC53-0B0B65F41301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0702826FCAC36EE52AC0441EEEEE2170
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1198E28F40C3E185E9958608554D4253
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15A073601B9AEC3549BE4A9314794615
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F7C80F9CE5CDF44E9AADDC99402534C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2310FC151CD4F185798FA0996B3524D7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\28572D2E2DE533256AC6B560EA573C22
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2ABB56EABB920EB59B04BDDD26A62083
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2DABA02DFED47E352A2FA2EBDD6F6187
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311567B4A9A002050BB9423FD73FB880
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\373FCED70D7F84E5FB5F3F7B76BEE024
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3BE992C130B235E53A2937391FDCA35B
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DA5F64B3483DE549947A9164ACBAD21
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3ED93605BB9B6635E9D0D86615AF31F1
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4759B017032BA185F9BA6F7DBC95A2D4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A78ABCBB54E46E5482A3EE0AD66C39E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4F9E947B6B895EB5A86757FC5D3DB862
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FEEA83BF72B97E43A2DF0EE4BE4F261
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\509EC7EFB89B7D942997574AB14037A4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50A730A9A3A61BF5BA70CA8A3B7C133B
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51A95A1D4CDE4F958A9451FBB39BF54A
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\536133807DE80465BA6CD0A9742B7DE5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5E25036E68895D45B95E72D1C3C58C74
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60FD8CD5BE007315CA3B5C7E41F24017
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\618E7D05458C4F257909ED9C8CDC0D66
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\621C21014D3C152529E2460FA6304EE3
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6241FF6F317CABD4EBBEE0DE9076BD94
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\636B9C23C79154B57AB561F39A139BFD
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\65AAF0F0CB7F0B45F900FDF19CEAAF2B
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6879A5E348601C45986308CA84958E94
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A6F3B7A9805E1F5492A1020EEDF2341
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B1F5D204E4EEB342A5AD1D7E60D61BF
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7005A2A4DCF9DD7548137AB17E3A3AF3
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\712EAF07EE73CC65C822CC3BAE3B2483
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7947B301B2446E752A3FE06EAD7D26B5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7987CE52D13E16258B0E1E3DB1BB0974
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7BEED197C514FDA53901AE8DD8EF0891
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DFDCF03D46C34159BDE29FBDBF1ACF5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\890F436B85B790A55A582B7307DA12CE
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C13DA6755F685B529615C8E92B3CA39
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D07CD9CB3E6BE652872BF06A1CCA782
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90841B1FC98200349925C88999866F17
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94194FDD4DF523E53A888D65722A135D
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A72F23B1D745C27508518132197BC982
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A89E2B6FB14D8275DA63D075171DA184
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A9C43CD4001E9E4518B274AF9A0EFDA9
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AABA081CF7F19915FBB80B3BAF47CE63
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC2A0FFD0A1686D53A4E24D6E96949E4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE5BDB2750259915D8442D4591A7717B
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1A79C71D5DC1C150B76B6ED11195DFC
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BAE2ED018083A4C8DA86D6E3F4B024
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B6D497DB33974935488761F7C4C3D755
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B752EF3300008394886C402CC27B474F
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B8C8BCC1206978D51A8B9EECBF806C53
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAD3576CEA646895B962F94754612791
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB4091512C8F4295E99CE2D061ED2020
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEE6BBC9A31531F598794A62120B51C7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C19162788CA4D235E829F88E2F771567
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C71F07DA356B66B5484A8E7F2ADEB7DC
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C96AD15EE8E887B56BAF2136A9088503
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C9E6B66ECC49D155888399C51D05C49E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA360F24F0B214744BE40657FDA0B727
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE85F265816AE2D4E9B73C3E207E679C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5389AEEA4A1E20428D045E86BCF643B
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5B62BB7BC607FB539585E2B7B6AFD16
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB027F01D4D53765C8E4FBE7DB77E07E
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DC2EB492393411F5ABE8ED13C59FBF20
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDCA763D4C48A105086B4CCCEE78043F
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DEF7558C7CD27EF46AF802AFBE402675
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E09F4A6B9D2A08B599AE9E38BFC93CD6
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E45D171E075A5425CBACF6631A45FA39
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E513C2076D90AD04F888BD762143F191
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E8F4C985459564F5B8DCFF2B3C7EBD27
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E96E33222BAC06B57A1FA9D72951C945
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EAA46CE9007F70A5CAFA5F26E5DDEBE5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE43FF091A8714A599F33EF2533FB59A
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE790015CF30DAA569960905FF1651A0
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EEB44C47185BD304D80FDF5A4BBE8F54
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F214EB834D2EC474CA76C1CDE306CF3A
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F25491036D0FA5D5FA6742F5742F151A
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F71371A90E93D605C8B0A71F163F625C
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7507D4D4C310125E9A22BD909A41FB6
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F79C21D785419125595AC59458A6142D
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA15C90F092A60F53A4E0F88CED02968
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA1CF130B3D58B553833ACB6BE8AFAD4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB0F1A18E4F0DBD509A42F4D4C05C02A
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD17ED194F1C2B457B4F6EF4AE8DEAF3
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChatZum Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpecialSavings
Schlüssel Gelöscht : HKLM\Software\SearchquMediabarTb
Schlüssel Gelöscht : HKLM\Software\Tarma Installer
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{84FF7BD6-B47F-46F8-9130-01B2696B36CB}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CA3EB689-8F09-4026-AA10-B9534C691CE0}]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{b64982b1-d112-42b5-b1e4-d3867c4533f8}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16470

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.iminent.com/?appid=79f3f7a1-4287-4156-9759-bbdffcf9ee89 --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.chatzum.com/ --> hxxp://www.google.com
Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.chatzum.com/ --> hxxp://www.google.com

-\\ Google Chrome v25.0.1364.172

Datei : C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

Datei : C:\Users\EMail und InterNet\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

Datei : C:\Users\Daten von Johannes\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [49981 octets] - [21/03/2013 12:20:22]

########## EOF - \AdwCleaner[S1].txt - [50042 octets] ##########

--- --- ---

aharonov 21.03.2013 17:56

Hi,

Zitat:

Ist da was schiefgelaufen?
Ich seh nicht, was da hätte schieflaufen können bis jetzt.

Zitat:

aber ich komme jetzt nicht mehr als Administrator ins McAfee-Programm rein.
Dann starte den Rechner neu, versuche dann nochmals, den Echtzeitschutz zu deaktivieren und starte Combofix.
(Wenn der Echtzeitschutz dann deaktiviert ist und Combofix trotzdem noch meckert, kannst du die Warnung übergehen.)

aharonov 24.03.2013 17:18

Hi,

ich hab schon länger keine Antwort mehr von dir erhalten. Brauchst du weiterhin noch Hilfe?

Wenn ich in den nächsten 24 Stunden nichts von dir höre, gehe ich davon aus, dass sich das Thema erledigt hat und lösche es aus meinen Abos.

Hinweis: Wir sind noch nicht fertig! Auch wenn die Symptome verschwunden sein sollten, kann dein System weiterhin infiziert sein und über Sicherheitslücken verfügen, welche eine erneute Infektion möglich machen.

SMC36 24.03.2013 22:47

Hi!
Tschuldige späte Antwort. Alle 3 Scans durchgelaufen, Logfiles von AdwCleaner und OTL im Anhang. Combofix Logfile einfach nicht zu finden. Soll ich Scan nochmal laufen lassen?
Windows Defender meldet Fehler, kann Dienst nicht bereitstellen.
Anhang 52109

Anhang 52110

aharonov 24.03.2013 23:01

Hi,

existiert also kein Log unter C:\Combofix.txt?
Findest du ein Logfile in den Ordnern C:\Qoobox\ oder C:\Combofix\ ?

SMC36 25.03.2013 11:01

Zitat:

Zitat von aharonov (Beitrag 1034604)
Hi,

existiert also kein Log unter C:\Combofix.txt?
Findest du ein Logfile in den Ordnern C:\Qoobox\ oder C:\Combofix\ ?

Unter Combofix kein Suchergebnis.
Unter Qoobox existieren drei Ordner BackEnv, LastRun und Quarantine. Darunter aber keine txt-Datei.
Grüße
SMC36

aharonov 25.03.2013 14:07

Dann lass Combofix bitte nochmals durchlaufen nach obiger Anleitung.
Die alte combofix.exe zuerst vom Desktop löschen und eine neue herunterladen.

SMC36 25.03.2013 20:10

Hi Leo!
Hier der Combofix-Logfile.
Anhang 52155

SMC36

SMC36 25.03.2013 20:17

Und der letzte OTL-Scan.
Anhang 52156
Grüße
SMC36

aharonov 25.03.2013 20:35

Hallo SMC36,

dann machen wir so weiter:
(Die Logfiles bitte nicht anhängen (das erschwert mir das Auswerten massiv), sondern deren Inhalt direkt innerhalb von Codetags einfügen: [code]Inhalt Logfile[/code].)


Schritt 1

Lade bitte folgendermassen Dateien zur Analyse hoch:
  • Deaktiviere bitte temporär deinen Virenscanner.
  • Suche folgenden Ordner
    C:\Qoobox
    und packe ihn in ein zip-Archiv (Rechtsklick darauf -> Senden an -> zip-komprimierten Ordner).
  • Gehe nun zum Trojaner-Board Upload-Channel:
    1. Drücke auf Durchsuchen..., wähle das erstellte zip-File aus und klicke Öffnen.
    2. Füge den Link deines Themas im Forum in das entsprechende Feld ein.
    3. Gib deinen Benutzernamen ein.
    4. Drücke auf den Button Hochladen.
  • Du kannst jetzt deinen Virenscanner wieder aktivieren.
    (bebilderte Anleitung)



Schritt 2
  • Starte bitte die OTL.exe.
  • Kopiere nun den folgenden Inhalt aus der Codebox in die http://larusso.trojaner-board.de/Images/otlfix.jpg Textbox.
    Wichtig: Falls du deinen Benutzernamen im Log unkenntlich gemacht hast (z.B. durch ***), dann mach das hier wieder rückgängig.
Code:

:OTL
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{1EC20F40-006D-4A2B-89D6-B3EE35C5A3BE}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3227975
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
O20 - AppInit_DLLs: (c:\PROGRA~2\BPROTE~1\261125~1.80\{EAB34~1\protector.dll) - c:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\protector.dll ()

:commands
[emptytemp]

  • Schliesse nun bitte alle anderen Programme.
  • Klicke jetzt auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Diesen bitte zulassen.
  • Nach dem Neustart findest du ein Textdokument auf deinem Desktop.
    (Auch zu finden unter C:\_OTL\MovedFiles\<date_time>.log)
  • Kopiere nun dessen Inhalt hier in deinen Thread.



Schritt 3

Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinen Desktop.
  • Entpacke das Archiv auf deinem Desktop.
  • Im neu erstellten Ordner starte bitte die mbar.exe.
  • Wenn eine Warnung "Registry value AppInit_Dlls has been found, .." erscheint, drücke Nein.
  • Folge dann den Anweisungen, führe das Update aus und drücke dann Scan.
Falls Funde angezeigt werden:
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während des Neustarts wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut und wiederhole den Scan.
  • Sollte nochmals was gefunden werden, führe erneut den CleanUp-Prozess durch.
Das Tool wird im erstellten Ordner Logfiles (mbar-log-<Jahr-Monat-Tag>.txt) erzeugen. Bitte poste deren Inhalt hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers.



Schritt 4

Starte bitte die OTL.exe.
  • Setze den Haken bei Scan all Users.
  • Drücke auf den Quick Scan Button.
  • Poste den Inhalt von OTL.txt hier in den Thread.



Bitte poste in deiner nächsten Antwort:
  • Fixlog von OTL
  • Log von MBAR
  • Log von OTL

SMC36 26.03.2013 18:59

Hi Leo!
Zitat:

Füge den Link deines Themas im Forum in das entsprechende Feld ein.
Tschuldige die dämliche Frage: Was muss im Link enthalten sein?
mfg
SMC36

aharonov 26.03.2013 19:03

Hallo,

einfach nur diesen Link kopieren und in das entsprechende Feld einfügen:
Code:

http://www.trojaner-board.de/132191-yontoo-1-10-02-rootkitaccess.html

SMC36 28.03.2013 17:43

Hi Leo!
Hier die Logfiles von MBAR und OTL.
FixLog von OTL habe ich 2mal versucht. Hatte beide Male nach kurzer Zeit den Eindruck, dass der Prozess hängt, hab' den Prozess trotzdem erst nach Stunden mit Neustart abgebrochen und dann mit Schritt 3 und 4 weitergemacht.

1. Scan:
Code:

Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org

Database version: v2013.03.28.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Stefan :: STEFAN-PC [administrator]

28.03.2013 15:48:32
mbar-log-2013-03-28 (15-48-32).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 26900
Time elapsed: 19 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
c:\Users\Stefan\Downloads\BestCodecsPack (1).exe (PUP.BundleInstaller.IB) -> Delete on reboot.
c:\Users\Stefan\Downloads\BestCodecsPack.exe (PUP.BundleInstaller.IB) -> Delete on reboot.

(end)

2. Scan:
Code:

Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org

Database version: v2013.03.28.08

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Stefan :: STEFAN-PC [administrator]

28.03.2013 16:51:04
mbar-log-2013-03-28 (16-51-04).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 26851
Time elapsed: 15 minute(s), 50 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

OTL-Scan:
Code:

OTL logfile created on: 28.03.2013 17:10:37 - Run 7
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Stefan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,11 Gb Available Physical Memory | 55,75% Memory free
4,21 Gb Paging File | 2,90 Gb Available in Paging File | 68,90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 122,59 Gb Total Space | 64,27 Gb Free Space | 52,42% Space Free | Partition Type: NTFS
Drive D: | 26,45 Gb Total Space | 17,17 Gb Free Space | 64,93% Space Free | Partition Type: FAT32
 
Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Stefan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
PRC - C:\Programme\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\profilemgr.exe (Deutsche Telekom AG)
PRC - C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Users\Stefan\AppData\Roaming\UpdateStar\UpdateStar.exe (UpdateStar GmbH)
PRC - C:\Programme\McAfee Online Backup\MOBKstat.exe (McAfee, Inc.)
PRC - C:\Programme\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
PRC - C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
PRC - C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
PRC - C:\Windows\System32\ccsync.exe (Salfeld Computer)
PRC - C:\Windows\System32\cchservice.exe (Salfeld Computer)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\DATA BECKER Shared\DBService.exe (DATA BECKER GmbH & Co KG)
PRC - C:\Programme\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe (Auslogics)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Programme\DATA BECKER\TVISTA - Tuning Vista 3.0\tvshc.dll ()
MOD - C:\Programme\Auslogics\AusLogics BoostSpeed\madBasic_.bpl ()
MOD - C:\Programme\Auslogics\AusLogics BoostSpeed\madDisAsm_.bpl ()
MOD - C:\Programme\Auslogics\AusLogics BoostSpeed\madExcept_.bpl ()
 
 
========== Services (SafeList) ==========
 
SRV - (mfevtp) -- C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (McODS) -- C:\Programme\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MSK80Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (TuneUp.UtilitiesSvc) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (ksupmgr) -- C:\Windows\System32\ksupmgr.exe (Salfeld Computer)
SRV - (MOBKbackup) -- C:\Programme\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (LBTServ) -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (fsssvc) -- C:\Programme\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (DBService) -- C:\Programme\Common Files\DATA BECKER Shared\DBService.exe (DATA BECKER GmbH & Co KG)
SRV - (ServiceLayer) -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (XDva401) -- C:\Windows\system32\XDva401.sys File not found
DRV - (XDva400) -- C:\Windows\system32\XDva400.sys File not found
DRV - (XDva399) -- C:\Windows\system32\XDva399.sys File not found
DRV - (XDva398) -- C:\Windows\system32\XDva398.sys File not found
DRV - (XDva397) -- C:\Windows\system32\XDva397.sys File not found
DRV - (XDva383) -- C:\Windows\system32\XDva383.sys File not found
DRV - (XDva380) -- C:\Windows\system32\XDva380.sys File not found
DRV - (XDva375) -- C:\Windows\system32\XDva375.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (mfeavfk01) --  File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (cdiskdun) -- C:\Users\Stefan\AppData\Local\Temp\cdiskdun.sys File not found
DRV - (catchme) -- C:\Users\Stefan\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (cfwids) -- C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfewfpk) -- C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfehidk) -- C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) -- C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (McPvDrv) -- C:\Windows\System32\drivers\McPvDrv.sys (McAfee, Inc.)
DRV - (HipShieldK) -- C:\Windows\System32\drivers\HipShieldK.sys (McAfee, Inc.)
DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (atksgt) -- C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (TuneUpUtilitiesDrv) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (MTOnlPktAlyX) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek                                            )
DRV - (seehcri) -- C:\Windows\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (ggsemc) -- C:\Windows\System32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) -- C:\Windows\System32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (MOBKFilter) -- C:\Windows\System32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ss_bmdm) -- C:\Windows\System32\drivers\ss_bmdm.sys (MCCI Corporation)
DRV - (ss_bbus) -- C:\Windows\System32\drivers\ss_bbus.sys (MCCI)
DRV - (ss_bmdfl) -- C:\Windows\System32\drivers\ss_bmdfl.sys (MCCI Corporation)
DRV - (NETw5v32) -- C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (SiFilter) -- C:\Windows\System32\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil) -- C:\Windows\System32\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV - (Si3531) -- C:\Windows\System32\drivers\Si3531.sys (Silicon Image, Inc)
DRV - (acedrv11) -- C:\Windows\System32\drivers\acedrv11.sys (Protect Software GmbH)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (XUIF) -- C:\Windows\System32\drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NETw3v32) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (PLCNDIS5) -- C:\Windows\System32\plcndis5.sys (Intellon, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 53 8D A2 7B 42 CD 01  [binary data]
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes,bProtectorDefaultScope = {404962F6-6290-47B0-9B38-12EDABF8D24E}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes,DefaultScope = {404962F6-6290-47B0-9B38-12EDABF8D24E}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{1E3CF04C-0EFA-4506-BE81-6DC4D939B9E4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{404962F6-6290-47B0-9B38-12EDABF8D24E}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2013.01.15 16:49:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2013.03.28 16:36:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013.03.24 20:28:38 | 000,000,000 | ---D | M]
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL
CHR - default_search_provider: McAfee (Enabled)
CHR - default_search_provider: search_url = hxxp://de.search.yahoo.com/search?fr=mcafee&p={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Daten von Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.123.1_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - Extension: SiteAdvisor = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\
 
O1 HOSTS File: ([2013.03.25 19:07:45 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Programme\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common Files\Mcafee\SystemCore\ScriptSn.20120627135043.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [ChicoSys] C:\Windows\System32\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ToADiMon.exe] C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\.DEFAULT..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [Auslogics BoostSpeed 4] C:\Programme\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe (Auslogics)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [UpdateStar] C:\Users\Stefan\AppData\Roaming\UpdateStar\UpdateStar.exe (UpdateStar GmbH)
O4 - HKLM..\RunOnce: [Z1] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\EMail und InterNet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{140C4E26-878B-4F2B-AB13-B1A5B4A59635}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8B1D7E6-209D-4841-8E3D-32BCC0D76347}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Programme\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\PROGRA~2\BPROTE~1\261125~1.80\{EAB34~1\protector.dll) - c:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\protector.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\...com [@ = ComFile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.03.28 15:27:06 | 000,000,000 | ---D | C] -- C:\Users\Stefan\Desktop\mbar-1.01.0.1021
[2013.03.27 20:38:33 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.03.27 20:33:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
[2013.03.25 19:11:05 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.03.25 19:11:04 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\temp
[2013.03.25 18:41:00 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013.03.24 18:30:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.03.24 18:30:55 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.03.21 19:19:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.03.21 19:19:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.03.21 19:19:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.03.21 17:01:20 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013.03.21 13:21:02 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\McAfee Anti-Theft
[2013.03.21 13:15:09 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.21 13:14:14 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.03.17 16:43:50 | 000,103,680 | ---- | C] (GMER) -- C:\ugdiqpob.sys
[2013.03.16 09:27:09 | 000,064,832 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\McPvDrv.sys
[2013.03.16 09:24:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013.03.05 18:33:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\devolo
[2013.03.05 18:33:10 | 000,000,000 | ---D | C] -- C:\Program Files\devolo
[2011.12.12 14:13:32 | 009,734,240 | ---- | C] (McAfee, Inc.) -- C:\ProgramData\TempMOBK-update-6f587c3c1a49f2fdf5254a3e5ed05791.exe
[2011.11.03 17:33:23 | 005,006,472 | ---- | C] (Electronic Arts                                            ) -- C:\Users\Stefan\setup_659.exe
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.03.28 17:14:00 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{7E0FFB30-A1EA-45D9-AE1C-BE220B81E5B8}.job
[2013.03.28 17:14:00 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4ACB5E34-87B0-41B7-A8D4-2B06E96F0430}.job
[2013.03.28 17:13:56 | 004,031,469 | ---- | M] () -- C:\Windows\System32\ccsync.err
[2013.03.28 16:32:40 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.03.28 16:32:24 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.28 16:32:24 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.28 16:32:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.28 16:27:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.03.28 15:25:49 | 013,786,977 | ---- | M] () -- C:\Users\Stefan\Desktop\mbar-1.01.0.1021.zip
[2013.03.27 22:07:16 | 000,004,344 | ---- | M] () -- C:\Windows\MOBK.blk
[2013.03.27 22:07:16 | 000,000,884 | ---- | M] () -- C:\Windows\MOBK.flt
[2013.03.27 20:33:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
[2013.03.26 18:43:17 | 036,166,110 | ---- | M] () -- C:\Users\Stefan\Desktop\Qoobox.zip
[2013.03.25 19:07:45 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.03.21 12:26:56 | 000,000,192 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.03.21 12:14:45 | 000,035,189 | ---- | M] () -- C:\Windows\System32\cchservice.err
[2013.03.19 18:36:57 | 000,628,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.03.19 18:36:57 | 000,596,246 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.03.19 18:36:57 | 000,126,510 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.03.19 18:36:57 | 000,104,320 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.03.17 16:43:50 | 000,103,680 | ---- | M] (GMER) -- C:\ugdiqpob.sys
[2013.03.16 09:33:29 | 000,001,975 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013.03.14 19:17:11 | 000,377,856 | ---- | M] () -- C:\Users\Stefan\Desktop\3yc6w4vy.exe
[2013.03.14 19:07:00 | 000,000,176 | ---- | M] () -- C:\Users\Stefan\defogger_reenable
[2013.03.14 19:03:42 | 000,050,477 | ---- | M] () -- C:\Users\Stefan\Desktop\Defogger.exe
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.03.28 15:25:22 | 013,786,977 | ---- | C] () -- C:\Users\Stefan\Desktop\mbar-1.01.0.1021.zip
[2013.03.26 18:43:02 | 036,166,110 | ---- | C] () -- C:\Users\Stefan\Desktop\Qoobox.zip
[2013.03.21 19:19:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.03.21 19:19:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.03.21 19:19:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.03.21 19:19:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.03.21 19:19:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.03.21 12:20:34 | 000,000,192 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013.03.14 19:17:06 | 000,377,856 | ---- | C] () -- C:\Users\Stefan\Desktop\3yc6w4vy.exe
[2013.03.14 19:06:34 | 000,000,176 | ---- | C] () -- C:\Users\Stefan\defogger_reenable
[2013.03.14 19:03:38 | 000,050,477 | ---- | C] () -- C:\Users\Stefan\Desktop\Defogger.exe
[2012.11.09 18:54:29 | 000,000,025 | ---- | C] () -- C:\Windows\SIERRA.INI
[2012.09.21 20:36:16 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2012.04.12 16:28:22 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2012.04.12 16:28:21 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2012.02.12 15:45:17 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012.02.12 15:44:43 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.02.12 15:44:39 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.12.25 13:06:44 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.12.25 13:06:44 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011.12.15 17:23:51 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.06.17 10:16:37 | 000,000,307 | ---- | C] () -- C:\Windows\game.ini
[2011.05.02 21:43:32 | 000,000,647 | ---- | C] () -- C:\Windows\et.ini
[2011.05.02 21:19:03 | 000,001,233 | ---- | C] () -- C:\Windows\System32\excltmp~.dat
[2011.05.02 21:18:43 | 000,155,536 | ---- | C] () -- C:\Windows\System32\dllcinx.exe
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.02.09 15:25:09 | 000,000,552 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d8caps.dat
[2010.12.08 20:43:23 | 000,091,022 | ---- | C] () -- C:\Users\Stefan\AppData\Roaming\mdbu.bin
[2009.06.29 07:44:04 | 000,000,680 | RHS- | C] () -- C:\Users\Stefan\ntuser.pol
[2009.06.21 16:38:51 | 000,004,608 | ---- | C] () -- C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.20 18:52:04 | 000,001,356 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d9caps.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2011.06.17 10:20:11 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\Activision
[2011.11.08 18:21:35 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\Need for Speed World
[2011.12.25 15:50:32 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\PC Suite
[2012.11.14 19:44:54 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\PeerNetworking
[2009.06.29 12:59:05 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\Petroglyph
[2009.06.27 17:58:42 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\T-Online
[2012.03.20 17:17:28 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\Teeworlds
[2012.04.20 16:00:03 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\TuneUp Software
[2010.12.09 17:41:47 | 000,000,000 | ---D | M] -- C:\Users\Daten von Johannes\AppData\Roaming\WB Games
[2013.01.05 13:47:36 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\Canneverbe Limited
[2012.09.29 14:32:23 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\Canon
[2011.10.31 13:40:57 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\Petroglyph
[2009.06.24 18:05:07 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\T-Online
[2012.04.30 11:41:07 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\TuneUp Software
[2011.12.25 13:24:37 | 000,000,000 | ---D | M] -- C:\Users\Schule Johannes\AppData\Roaming\PC Suite
[2010.12.26 19:00:58 | 000,000,000 | ---D | M] -- C:\Users\Schule Johannes\AppData\Roaming\Petroglyph
[2010.11.07 18:19:32 | 000,000,000 | ---D | M] -- C:\Users\Schule Johannes\AppData\Roaming\T-Online
[2012.05.27 16:00:02 | 000,000,000 | ---D | M] -- C:\Users\Schule Johannes\AppData\Roaming\TuneUp Software
[2010.12.23 14:05:09 | 000,000,000 | ---D | M] -- C:\Users\Schule Johannes\AppData\Roaming\WB Games
[2010.01.02 17:16:02 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Auslogics
[2012.04.20 13:47:51 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite
[2011.01.02 21:34:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Leadertech
[2011.11.03 20:18:07 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Need for Speed World
[2011.12.25 15:38:03 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\PC Suite
[2011.06.23 09:53:25 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\ProtectDisc
[2011.12.25 13:06:27 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Samsung
[2009.06.20 22:51:33 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\T-Online
[2012.04.20 13:24:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Teeworlds
[2012.04.20 13:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\TuneUp Software
[2012.01.27 18:42:37 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\UpdateStar
 
========== Purity Check ==========
 
 

< End of report >


aharonov 28.03.2013 17:48

Hallo,

ja, das kann schon mal vorkommen beim Fix.
Wie läuft der Rechner jetzt?


Schritt 1
  • Starte bitte die OTL.exe.
  • Kopiere nun den folgenden Inhalt aus der Codebox in die http://larusso.trojaner-board.de/Images/otlfix.jpg Textbox.
    Wichtig: Falls du deinen Benutzernamen im Log unkenntlich gemacht hast (z.B. durch ***), dann mach das hier wieder rückgängig.
Code:

:commands
[emptytemp]

  • Schliesse nun bitte alle anderen Programme.
  • Klicke jetzt auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Diesen bitte zulassen.
  • Nach dem Neustart findest du ein Textdokument auf deinem Desktop.
    (Auch zu finden unter C:\_OTL\MovedFiles\<date_time>.log)
  • Kopiere nun dessen Inhalt hier in deinen Thread.



Schritt 2

Downloade dir bitte Malwarebytes Anti-Malware.
  • Installiere das Programm in den vorgegebenen Pfad.
  • Starte nun Malwarebytes Anti-Malware.
    Vista und Win7 User mit Rechtsklick "als Administrator starten".
  • Klicke auf Aktualisierung --> Suche nach Aktualisierung.
  • Wenn das Update beendet wurde, aktiviere im Reiter Suchlauf die Option Quick-Scan durchführen und drücke auf Scannen.
  • Wenn der Scan fertig ist, klicke auf Ergebnisse anzeigen.
  • Versichere dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter dem Reiter Logdateien finden.



Schritt 3

Lade das Setup des ESET Online Scanners herunter und speichere es auf den Desktop.
  • Schliesse evtl. vorhandene externe Festplatten und USB-Sticks an den Rechner an.
  • Deaktiviere jetzt temporär für diesen Scan dein Antivirenprogramm und die Firewall.
    (Danach nicht vergessen, sie wieder einzuschalten.)
  • Starte nun die heruntergeladene esetsmartinstaller_enu.exe.
  • Setze den Haken bei Yes, I accept the Terms of Use und drücke Start.
  • Warte bis die Komponenten heruntergeladen sind.
  • Setze den Haken bei Scan archives.
  • Gehe sicher, dass bei Remove found Threats kein Haken gesetzt ist.
  • Drücke dann auf Start.
  • Die Signaturen werden heruntergeladen und der Scan startet automatisch.
    Hinweis: Dieser Scan kann unter Umständen ziemlich lange dauern!
  • Falls nach Beendigung des Scans Funde angezeigt werden, dann:
    • Drücke auf List of found threats.
    • Klicke dann auf Export to text file... und speichere die Textdatei als ESET.txt auf den Desktop.
    • Drücke danach auf << Back.
  • Schliesse nun den Scanner mit einem Klick auf Finish.
Poste bitte den Inhalt der ESET.txt oder teile mir mit, wenn es keine Funde gegeben hat.



Schritt 4

Downloade dir bitte SecurityCheck (Link 1, Link 2).
  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Wenn der Scan beendet wurde, sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.



Bitte poste in deiner nächsten Antwort:
  • Fixlog von OTL
  • Log von MBAM
  • Log von ESET
  • Log von SecurityCheck

SMC36 29.03.2013 19:00

Hi Leo!

Der Rechner läuft besser, zumal Yontoo und bProtector for Windows wohl bereinigt sind (letzterer wurde vor Monaten in Quarantäne gesteckt, aber nicht ordentlich gekillt).
Eine Frage: Ordner searchplugins wurde von den Scans und Cleans nicht als Virus erkannt. Keine Aktion erforderlich?

Hier die empfohlenen Scans (ESET meldete keine Funde)

OTLFixLog:
Code:

All processes killed
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Daten von Johannes
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 539177869 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 244113199 bytes
->Flash cache emptied: 29241 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: EMail und InterNet
->Temp folder emptied: 218495 bytes
->Temporary Internet Files folder emptied: 169018613 bytes
->Google Chrome cache emptied: 264044566 bytes
->Flash cache emptied: 4992 bytes
 
User: Gast
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: MusikSpieleJojo
->Temp folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: Schule Johannes
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 160602290 bytes
->Flash cache emptied: 1347 bytes
 
User: Stefan
->Temp folder emptied: 1737838 bytes
->Temporary Internet Files folder emptied: 188037922 bytes
->Java cache emptied: 61791222 bytes
->Google Chrome cache emptied: 225008997 bytes
->Flash cache emptied: 5472 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 178226981 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 192308156 bytes
RecycleBin emptied: 637718504 bytes
 
Total Files Cleaned = 2.729,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 03292013_122121

Files\Folders moved on Reboot...
File\Folder C:\Windows\temp\mca9A7C.tmp\avvclean.dat not found!
File\Folder C:\Windows\temp\mca9A7C.tmp\avvscan.dat not found!
File\Folder C:\Windows\temp\mca9A7C.tmp\gdeltaavv.ini not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


[code]
Malwarebytes Anti-Malware (Test) 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.03.29.03

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Stefan :: STEFAN-PC [Administrator]

Schutz: Aktiviert

29.03.2013 12:44:26
mbam-log-2013-03-29 (12-44-26).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 304993
Laufzeit: 7 Minute(n), 40 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
[\code]

SecurityCeck:
Code:

Results of screen317's Security Check version 0.99.61 
 Windows Vista Service Pack 2 x86 (UAC is enabled) 
 Internet Explorer 9 
``````````````Antivirus/Firewall Check:``````````````
McAfee  Anti-Virus und Anti-Spyware 
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware Version 1.70.0.1100 
 TuneUp Utilities 2011 
 TuneUp Utilities Language Pack (de-DE)
 CCleaner   
 Java(TM) 6 Update 16 
 Java version out of Date!
 Adobe Reader 10.1.6 Adobe Reader out of Date! 
 Google Chrome 25.0.1364.152 
 Google Chrome 25.0.1364.172 
````````Process Check: objlist.exe by Laurent```````` 
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbamgui.exe 
 Malwarebytes' Anti-Malware mbamscheduler.exe 
 T-Online T-Online_Software_6 Basis-Software Basis1\ToADiMon.exe
 McAfee Online Backup MOBKstat.exe 
 McAfee Online Backup MOBKbackup.exe 
 T-Online T-ONLI~1 BASIS-~1 Basis2\PROFIL~1.EXE
 T-Online T-Online_Software_6 Basis-Software Basis2\kernel.exe
 T-Online T-Online_Software_6 Basis-Software Basis2\sc_watch.exe
 T-Online T-ONLI~1 Notifier Notifier.exe
 T-ONLINE T-ONLINE_SOFTWARE_6 BROWSER BROWSER.EXE
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````


aharonov 30.03.2013 00:55

Hallo,

das sieht soweit gut aus. Nur noch das Java updaten und dann aufräumen.


Hinweis: Registry Cleaner

Ich sehe, dass du sogenannte Registry Cleaner installiert hast.
In deinem Fall CCleaner und TuneUp Utilities 2011.

Wir raten von der Verwendung jeglicher Art von Registry Cleaner ab.

Der Grund ist ganz einfach:
Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich.
Man sollte nicht unnötigerweise an der Registry rumbasteln. Schon ein kleiner Fehler kann gravierende Folgen haben und auch Programme machen manchmal Fehler.
Zerstörst du die Registry, zerstörst du Windows.

Zudem ist der Nutzen zur Performancesteigerung umstritten und meist kaum im wahrnehmbaren Bereich.

Ich würde dir empfehlen, Registry Cleaner nicht weiterhin zu verwenden und über
Start --> Systemsteuerung --> Software (bei Windows XP)
Start --> Systemsteuerung --> Programme und Funktionen (bei Vista / Win 7)
zu deinstallieren.



Schritt 1

Dein Java ist nicht mehr aktuell. Ältere Versionen enthalten Sicherheitslücken, die von Malware zur Infizierung per Drive-by Download missbraucht werden können.

Die aktuelle Version ist Java 7 Update 17.
  • Gehe zu
    Start --> Systemsteuerung --> Programme und Funktionen (bei Vista / Win 7)
    Start --> Systemsteuerung --> Software (bei Win XP)
    und deinstalliere alle älteren Java-Versionen.
In wenigen Fällen wird Java wirklich benötigt. Auch werden immer wieder neue, noch nicht geschlossene Sicherheitslücken ausgenutzt.
Überleg dir also, ob du eine Java-Installation wirklich brauchst.
Falls du Java weiterhin verwenden möchtest, dann:
  • Lade dir die neueste Java-Version herunter.
  • Schliesse alle laufenden Programme, speziell den Browser.
  • Starte die heruntergeladene jxpiinstall.exe und folge den Anweisungen.
  • Entferne während der Installation den Haken bei "Installieren Sie die Ask-Toolbar ...".

Überprüfe dann mit diesem Plugin-Check, ob nun alle deine verwendeten Versionen aktuell sind und update sie anderenfalls.
(Hinweis: Dein Adobe Reader ist bereits aktuell, auch wenn dies anders angezeigt werden sollte. Für Vista gibt es keine Version 11.)



Schritt 2

Starte defogger und drücke den Button Re-enable.



Schritt 3

Bitte deaktiviere jetzt temporär das Antiviren-Programm, evtl. vorhandenes Skript-Blocking und Antimalware-Programme.

Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste, kopiere folgenden Text in das Ausführen Fenster
Code:

Combofix /Uninstall
und drücke OK.
Du kannst die eben deaktivierten Programme nun wieder einschalten.



Schritt 4

Den ESET Online Scanner kannst du behalten, um ab und zu für eine Zweitmeinung dein System damit zu scannen.
Falls du ESET aber deinstallieren möchtest, dann:

Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste, kopiere folgenden Text in das Ausführen Fenster
Code:

"%ProgramFiles%\Eset\Eset Online Scanner\OnlineScannerUninstaller.exe"
und drücke OK.



Schritt 5

Downloade dir bitte delfix auf deinen Desktop.
  • Schliesse alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Klicke auf Start.
  • DelFix entfernt alle von uns verwendeten Programme und löscht sich anschliessend selbst.
    Sollte denoch etwas übrig bleiben, kannst du es manuell löschen.




>> OK <<
Wir sind durch, deine Logs sehen für mich im Moment sauber aus. :daumenhoc

Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst.

Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann.




Epilog: Tipps, Dos & Don'ts

Aktualität von System und Software

Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
  • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
  • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren

Auch die installierte Software sollte immer in der aktuellsten Version vorliegen.
Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
  • Mit diesem kleinen Plugin-Check kannst du regelmässig diese Komponenten auf deren Aktualität überprüfen.
  • Achte auch darauf, dass alte, nicht mehr verwendete Versionen deinstalliert sind.
  • Optional: Das Programm Secunia Personal Software Inspector kann dich dabei unterstützen, stets die aktuellen Versionen sämtlicher installierter Software zu nutzen.

Sicherheits-Software

Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt).
Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
  • Nutze einen Virenscanner mit Hintergrundwächter mit stets aktueller Datenbank. Welches Produkt gewählt wird, spielt keine so entscheidende Rolle. Es gibt kommerzielle Versionen, aber ein kostenloser Scanner mit den Grundfunktionen wie beispielsweise Avast! Free Antivirus sollte ausreichen. Betreibe aber keinesfalls zwei Wächter parallel, die würden sich gegenseitig behindern.
  • Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.
  • Zusätzlich zum Virenscanner kannst du dein System regelmässig mit einem On-Demand Antimalwareprogramm scannen. Empfehlenswert ist die Free-Version von Malwarebytes Anti-Malware. Vor jedem Scan die Datenbank updaten.
  • Optional: Das Programm Sandboxie führt Anwendungen in einer isolierten Umgebung ("Sandkasten") aus, so dass keine Änderungen am System vorgenommen werden können. Wenn du deinen Browser darin startest, vermindert sich die Chance, dass beim Surfen eingefangene Malware sich dauerhaft im System festsetzen kann.
  • Optional: Das Addon WOT (web of trust) warnt dich vor einer als schädlich gemeldeten Website, bevor sie geladen wird. Für verschiedene Browser erhältlich.

Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt.
Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
  • NoScript verhindert standardmässig das Ausführen von aktiven Inhalten (Java, JavaScript, Flash, ..) für sämtliche Websites. Du kannst selber nach dem Prinzip einer Whitelist festlegen, welchen Seiten du vertrauen und Scripts erlauben willst, auch temporär.
  • Adblock Plus blockt die meisten Werbebanner weg. Solche Banner können nebst ihrer störenden Erscheinung auch als Infektionsherde fungieren.

(Un-)Sicheres Verhalten im Internet

Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert.

Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
  • Illegale Cracks, Keygens und Serials sind ein ausgesprochen einfacher (und ein beliebter) Weg, um Malware zu verbreiten.
  • Bei Dateien aus Peer-to-Peer- und Filesharingprogrammen oder von Filehostern kannst du dir nie sicher sein, ob auch wirklich drin ist, was drauf steht.

Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
  • Surfe mit Vorsicht und lass dich nicht von irgendwie interessant erscheinenden Elementen zu einem vorschnellen Klick verleiten. Lass dich nicht von Popups täuschen, die aussehen wie System- oder Virenmeldungen.
  • Sei skeptisch bei unerwarteten E-Mails, insbesondere wenn sie Anhänge enthalten. Auch wenn sie auf den ersten Blick authentisch wirken, persönliche Daten von dir enthalten oder vermeintlich von einem bekannten Absender stammen: Lieber nochmals in Ruhe überdenken oder nachfragen, anstatt einfach mal Links oder ausführbare Anhänge öffnen oder irgendwo deine Daten eingeben.
  • Auch in sozialen Netzwerken oder über Instant Messaging Systeme können schädliche Links oder Dateien die Runde machen. Erhältst du von einem deiner Freunde eine Nachricht, die merkwürdig ist oder so sensationell interessant oder skandalös tönt, dass man einfach draufklicken muss, dann hat bei ihm/ihr wahrscheinlich Neugier über Verstand gesiegt und du solltest nicht denselben Fehler machen.
  • Lass die Dateiendungen anzeigen, so dass du dich nicht täuschen lässt, wenn eine ausführbare Datei über ein doppelte Dateiendung kaschiert wird, z.B. Nacktfoto.jpg.exe.

Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
  • Lade Software in erster Priorität immer direkt vom Hersteller herunter. Viele Softwareportale (z.B. Softonic) packen noch unnützes Zeug mit in die Installation. Alternativ dazu wähle ein sauberes Portal wie Filepony oder heise.
  • Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen fürs Programm irrelevanten Ergänzungen.

Allgemeine Hinweise

Abschliessend noch ein paar grundsätzliche Bemerkungen:
  • Dein Benutzerkonto für den alltäglichen Gebrauch sollte nicht über Administratorenrechte verfügen. Nutze ein Konto mit eingeschränkten Rechten (Windows XP) bzw. aktiviere die Benutzerkontensteuerung (UAC) auf der höchsten Stufe (Windows Vista / 7).
  • Erstelle regelmässig Backups deiner Daten und Dokumente auf externen Datenträgern, bei wichtigen Dateien mindestens zweifach. Nicht nur ein Malwarebefall kann schmerzhaften Datenverlust nach sich ziehen sondern auch ein gewöhnlicher Festplattendefekt.
  • Die Autorun/Autoplay-Funktion stellt ein Risiko dar, denn sie ermöglicht es, dass beispielsweise beim Einstecken eines entsprechend infizierten USB-Sticks der Befall auf den Rechner überspringt. Überlege dir, ob du diese Funktion nicht besser deaktivieren möchtest.
  • Wähle deine Passwörter gemäss den gängigen Regeln, um besser gegen Brute-Force- und Wörterbuchattacken gewappnet zu sein. Benutze jedes deiner Passwörter nur einmal und ändere sie regelmässig.
  • Der Nutzen von Registry-Cleanern zur Performancesteigerung ist umstritten. Auf jeden Fall lässt sich damit grosser Schaden anrichten, wenn man nicht weiss, was man tut. Wir empfehlen deshalb, die Finger von der Registry zu lassen. Um von Zeit zu Zeit die temporären Dateien zu löschen, genügt TFC.

Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen.
Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen. ;)

SMC36 30.03.2013 12:42

Hi Leo!

Erstmal vielen Dank für deine Hilfe und deine Tipps!
Dann Rückmeldung für deine letzten Instruktionen:
  1. Alles erledigt ausser: Combofix lässt sich nicht löschen, wird nicht gefunden - auch nicht unter Schreibweise ComboFix. Ordner ist vorhanden, aber offensichtlich leer. Was ist mit Qoobox-Ordner?
  2. Windows-Defender meldet nach wie vor: "Fehler bei Anwendungsinitialisierung 0x800106ba. Der Dienst kann aufgrund eines Problems nicht gestartet werden. Versuchen Sie Neustart oder wenden Sie sich an ...." Neustart bringt aber nichts.
  3. Ordner "searchplugins": Soll ich den ignorieren oder muss der bereinigt werden?
  4. Habe DATABeckerTuningVista auf dem Rechner. Wenn du Tunern gegenüber kritisch bist, was hältst du von dem?

Servus
SMC36

aharonov 30.03.2013 13:29

Hallo,

Zitat:

Combofix lässt sich nicht löschen, wird nicht gefunden
Dann lade eine neue Combofix.exe herunter, speichere sie auf den Desktop und versuche folgende Eingabe:
Code:

"%userprofile%\Desktop\Combofix.exe" /Uninstall
Zitat:

Windows-Defender meldet nach wie vor: "Fehler bei Anwendungsinitialisierung 0x800106ba.
Schau mal, ob dir das hier hilft: Link

Zitat:

"searchplugins": Soll ich den ignorieren
Ja

Zitat:

Wenn du Tunern gegenüber kritisch bist, was hältst du von dem?
Kenne ich nicht. Wir raten nur davon ab, ohne Not die Registry säubern zu wollen..

SMC36 01.04.2013 20:21

Hi Leo!

Windows-Defender ist immer noch nicht funktionsfähig. Die Anweisungen des Microsoft-Links habe ich ausprobiert, funktionieren aber offensichtlich bei Vista nicht. Habe an Microsoft ein Feedback gegeben. Ich nehme an, du hast keinen weiteren Tipp für mich? Wie wichtig ist der Windows Defender?

Servus
SMC36

aharonov 01.04.2013 20:26

Hi,

Zitat:

Wie wichtig ist der Windows Defender?
Wenn du ein AVP verwendest, solltest du diesen Windows Defender sowieso deaktivieren.. Also von daher nicht schlimm.
Passt sonst noch etwas nicht oder alles in Ordnung?

SMC36 03.04.2013 10:21

Hallo!

Zitat:

Passt sonst noch etwas nicht oder alles in Ordnung?
Ansonsten ist wohl alles o.k., nochmal danke für deine Hilfe! Ich denke, wir können das Thema damit abschließen.

Grüße
SMC36

aharonov 03.04.2013 13:09

Danke für die Rückmeldung.


Freut mich, dass wir helfen konnten. :abklatsch:

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten.
Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter.

Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.

SMC36 03.04.2013 21:25

Hallo!

War doch etwas mehr ...

SystemLook-Scan:

Code:

SystemLook 30.07.11 by jpshortstuff
Log created at 20:49 on 03/04/2013 by Stefan
Administrator - Elevation successful

========== filefind ==========

Searching for "*bProtector*"
C:\Windows\System32\Tasks\bProtector        --a---- 3338 bytes        [09:39 21/03/2013]        [11:03 21/03/2013] 84BF1040ED7D58612A1691AD66F5131F

========== folderfind ==========

Searching for "*bProtector*"
C:\bProtectorForWindows        d------        [08:56 18/09/2012]
C:\028400ff82ebe131fa4ddb\bProtectorForWindows        d------        [15:51 23/11/2012]
C:\04f306920f957153640e166e24\bProtectorForWindows        d------        [11:45 25/09/2012]
C:\1070ab2172b984fda4\bProtectorForWindows        d------        [15:06 20/11/2012]
C:\144a34f9014e5a04ed565c636d\bProtectorForWindows        d------        [12:26 11/09/2012]
C:\29bd94c6368a461105db\bProtectorForWindows        d------        [07:54 28/07/2012]
C:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows        d------        [12:52 05/01/2013]
C:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows        d------        [15:29 21/09/2012]
C:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows        d------        [12:29 05/10/2012]
C:\41322c52a401c9771995\bProtectorForWindows        d------        [12:03 04/09/2012]
C:\497c50009f4d943ea04e\bProtectorForWindows        d------        [15:47 19/10/2012]
C:\4c95bf441978a49f4e959b9286\bProtectorForWindows        d------        [13:57 17/07/2012]
C:\505d135c245ac49998\bProtectorForWindows        d------        [15:48 19/10/2012]
C:\5079e70917c8c1ae1f\bProtectorForWindows        d------        [09:52 18/01/2013]
C:\530ba9c8fad932f9358a1324\bProtectorForWindows        d------        [16:57 15/07/2012]
C:\5d3cd820d23d38204b1f50803608\bProtectorForWindows        d------        [17:13 07/12/2012]
C:\630dc4c59e58d39240234ae8\bProtectorForWindows        d------        [16:57 16/11/2012]
C:\637779ce29fabb2b072e868c\bProtectorForWindows        d------        [15:41 23/01/2013]
C:\6434b20709812de8465309a0de\bProtectorForWindows        d------        [12:52 09/10/2012]
C:\72ee744f4ea283cefa9ea2\bProtectorForWindows        d------        [18:33 18/10/2012]
C:\788a1c8d5697a210a7\bProtectorForWindows        d------        [10:13 18/09/2012]
C:\7909414813e615744eac\bProtectorForWindows        d------        [08:15 07/09/2012]
C:\79a538ecf621240df134\bProtectorForWindows        d------        [11:13 26/07/2012]
C:\82d0d7a58f91d6f543d33d\bProtectorForWindows        d------        [14:59 02/11/2012]
C:\86cc027f15c92c73789210e35360ba\bProtectorForWindows        d------        [09:34 03/08/2012]
C:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows        d------        [08:19 01/12/2012]
C:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows        d------        [16:00 13/11/2012]
C:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows        d------        [13:06 20/07/2012]
C:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows        d------        [16:04 09/11/2012]
C:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows        d------        [12:10 10/07/2012]
C:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows        d------        [11:05 02/10/2012]
C:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows        d------        [13:44 01/08/2012]
C:\a9e57554d4565affc23c\bProtectorForWindows        d------        [13:57 23/10/2012]
C:\ad7961677f5c4817098ff628804a\bProtectorForWindows        d------        [19:58 03/01/2013]
C:\b3932403f1f740cef70ba005\bProtectorForWindows        d------        [17:14 17/08/2012]
C:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows        d------        [10:06 06/11/2012]
C:\c00f737d3b6ba838f4\bProtectorForWindows        d------        [10:53 24/08/2012]
C:\c8615056f13303404f\bProtectorForWindows        d------        [13:53 19/12/2012]
C:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows        d------        [19:11 30/12/2012]
C:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows        d------        [07:07 30/08/2012]
C:\e486b76e32143330e605fbabdb\bProtectorForWindows        d------        [11:57 28/09/2012]
C:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows        d------        [09:13 06/09/2012]
C:\efb932a808458c293935c879f422d675\bProtectorForWindows        d------        [16:38 08/01/2013]
C:\f24f6388f31fd1971adbb8\bProtectorForWindows        d------        [17:03 16/11/2012]
C:\f2f891b9c806289f198083\bProtectorForWindows        d------        [12:28 12/10/2012]
C:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows        d------        [08:20 21/08/2012]
C:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows        d------        [10:16 31/08/2012]
C:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows        d------        [13:55 30/10/2012]
C:\Fraps\bProtectorForWindows        d------        [17:46 08/07/2012]
C:\GAMIGO\LastChaosGER\bProtectorForWindows        d------        [14:32 09/07/2012]
C:\Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows        d------        [11:02 09/07/2012]
C:\Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows        d------        [11:00 09/07/2012]
C:\Program Files\EA Games\bProtectorForWindows        d------        [17:29 17/08/2012]
C:\Program Files\EA Games\Need for Speed Underground 2\bProtectorForWindows        d------        [10:13 22/08/2012]
C:\Program Files\EA Games\NFS Underground\bProtectorForWindows        d------        [17:20 25/09/2012]
C:\Program Files\Electronic Arts\Need For Speed III\3dSetup\bProtectorForWindows        d------        [18:06 09/11/2012]
C:\Program Files\Google\bProtectorForWindows        d------        [16:21 26/11/2012]
C:\Program Files\Google\Picasa3\bProtectorForWindows        d------        [18:49 22/09/2012]
C:\Program Files\Malwarebytes' Anti-Malware\bProtectorForWindows        d------        [12:46 04/09/2012]
C:\Program Files\Maxis\Die Sims\bProtectorForWindows        d------        [11:00 22/07/2012]
C:\Program Files\McAfee\MPF\bProtectorForWindows        d------        [11:18 29/07/2012]
C:\Program Files\McAfee\MPS\bProtectorForWindows        d------        [13:02 22/09/2012]
C:\Program Files\McAfee\MQS\bProtectorForWindows        d------        [13:02 22/09/2012]
C:\Program Files\McAfee\MSC\bProtectorForWindows        d------        [11:02 09/07/2012]
C:\Program Files\McAfee\SiteAdvisor\bProtectorForWindows        d------        [10:09 22/07/2012]
C:\Program Files\McAfee\VirusScan\bProtectorForWindows        d------        [11:02 09/07/2012]
C:\Program Files\McAfee.com\Agent\bProtectorForWindows        d------        [11:02 09/07/2012]
C:\Program Files\PC Performer\bProtectorForWindows        d------        [13:30 09/07/2012]
C:\Program Files\Samsung\Samsung New PC Studio\bProtectorForWindows        d------        [14:33 22/09/2012]
C:\Program Files\T-Online\T-Online_Software_6\Banking\bProtectorForWindows        d------        [19:25 21/09/2012]
C:\Program Files\T-Online\T-Online_Software_6\Browser\bProtectorForWindows        d------        [18:47 22/09/2012]
C:\Program Files\TuneUp Utilities 2011\bProtectorForWindows        d------        [15:07 30/07/2012]
C:\Program Files\Ubisoft\Detection\bProtectorForWindows        d------        [09:35 11/09/2012]
C:\Program Files\Ubisoft\Register\bProtectorForWindows        d------        [09:26 11/09/2012]
C:\ProgramData\bProtectorForWindows        d------        [17:33 08/07/2012]
C:\ProgramData\Electronic Arts\Need For Speed World\bProtectorForWindows        d------        [09:59 31/08/2012]
C:\ProgramData\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows        d------        [19:25 21/09/2012]
C:\Team17\Worms 3D\bProtectorForWindows        d------        [12:22 12/10/2012]
C:\Users\All Users\bProtectorForWindows        d------        [17:33 08/07/2012]
C:\Users\All Users\Electronic Arts\Need For Speed World\bProtectorForWindows        d------        [09:59 31/08/2012]
C:\Users\All Users\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows        d------        [19:25 21/09/2012]
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\Aldi Süd Foto Service\bProtectorForWindows        d------        [12:44 22/09/2012]
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\McAfee Online Backup\bProtectorForWindows        d------        [09:13 02/10/2012]
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows        d------        [14:24 30/07/2012]
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Windows\bProtectorForWindows        d------        [14:54 21/10/2012]
C:\Users\EMail und InterNet\Documents\Pfarrei Hl. Engel\bProtectorForWindows        d------        [16:55 26/01/2013]
C:\Users\EMail und InterNet\Documents\Privat\bProtectorForWindows        d------        [17:56 11/12/2012]
C:\Users\EMail und InterNet\Downloads\bProtectorForWindows        d------        [12:42 05/01/2013]
C:\Users\EMail und InterNet\Pictures\bProtectorForWindows        d------        [14:47 09/10/2012]
C:\Users\EMail und InterNet\Pictures\Diashow Stefan\bProtectorForWindows        d------        [15:12 22/09/2012]
C:\Users\EMail und InterNet\Videos\bProtectorForWindows        d------        [14:49 10/10/2012]
C:\Users\Public\Pictures\Sample Pictures\bProtectorForWindows        d------        [20:12 20/12/2012]
C:\Users\Stefan\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows        d------        [18:03 19/07/2012]
C:\Users\Stefan\Downloads\bProtectorForWindows        d------        [13:11 04/09/2012]
C:\Windows\Microsoft.NET\Framework\v4.0.30319\bProtectorForWindows        d------        [16:59 16/11/2012]

========== regfind ==========

Searching for "bProtector"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
"bProtectorDefaultScope"="{404962F6-6290-47B0-9B38-12EDABF8D24E}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{231D934E-8C9B-481E-AA46-9342C6B0E23E}]
"Path"="\bProtector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bProtector]
[HKEY_USERS\.DEFAULT\Software\bProtector]
[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Microsoft\Internet Explorer\SearchScopes]
"bProtectorDefaultScope"="{404962F6-6290-47B0-9B38-12EDABF8D24E}"
[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\Software\530dbdeb56eea42]
"SERVICE_NAME"="bProtector"
[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\Software\530dbdeb56eea42]
"INSTALL_FOLDER_NAME"="bProtectorForWindows"
[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\Software\Microsoft\Internet Explorer\Main]
"bProtector Start Page"="n*b~µ¸QÆ€'h·8+þ°N±hvªddKyÛ0LˆIK껀*Üîw¯ÓüÍoÂOðJnøÛ¸Iï*NÞtÅs‘¿E|l?ÛmõZîìèˆ×—:Ïm–z8x5ÕÈs¨ài"Å0ížÃ,î*„}:<Ê—¨ôT}»€Z‘exˆÒ*Ä6ƒW÷XŸ»kÕ9ΞÂõ¨&ç0*÷l›xäP™xzêÝzÍÝy*•’ØØ7ÝÒÎ*!:]/S¶Ç·$œN/‚Y.ÂKâש6ác¢:ðð_°Oëgø"EÚÐõØ%˜×)â³Xê¯ò¤Ò¼˜ŽžOÇѶÍ>¥ûdAäŒNÈ!Ü_TúàAŽ·>qJLr+j¬¯‡îrDÚß$q®g‚v9Ê&QŸË¦JpQ°-»N< û|/½…aÏBÈбöüƒ¤,¨ç2 ¹YûC¨Q’¦¢ù
—¿R\xƒ,f«ºÜ!§ØËÀ¶v1N2ˆ°ð¼FŽ~Øm–ØAóÏXÊèj&ÌE)^A)(;<ˆž¼È¿'/‹ÝAt        B
“/"9ÙkÒÌA‰¸ÿã&dUÅ‚î*(v?
£¨š²ÈÍ)κç$‹,£
©²næÒŽ>"
[HKEY_USERS\S-1-5-18\Software\bProtector]

Searching for "        "
[HKEY_LOCAL_MACHINE\SOFTWARE\Canon\ScanGear\12.1\Devices\MP600]
"ProductId"="MP600          "
[HKEY_LOCAL_MACHINE\SOFTWARE\Canon\WIA\1.2\Devices\MP600]
"ProductId"="MP600          "
[HKEY_LOCAL_MACHINE\SOFTWARE\Canon\WIA\Devices\MG6100 series]
"ProductId"="MG6100          "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{813DD25A-94A1-4879-945F-55E5800FAD78}]
"RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1">
            <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{18CD34B7-7AA3-42b9-A303-5A729B2FF228}">
                <Descriptor descriptorID="{9BE7B916-F237-4328-8157-24282DA66151}"/>
            </Rating>
        </Ratings>"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{D5CA9378-7AEB-4B38-8FDD-11825DA6AFD2}]
"RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1">
            <Rating ratingSystemID="{EC290BBB-D618-4cb9-9963-1CAAE515443E}" ratingID="{5098B1DF-486F-4e79-A6D6-6E0879A63811}">
            </Rating>
            <Rating ratingSystemID="{C705DCF4-6AFE-4f4f-BC51-21807E4E5CFB}" ratingID="{6948F4DF-FD98-41ea-979A-8364043D7FD6}">
            </Rating>
            <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{9DD9B30C-E89F-4d1c-AEC4-174D7432C39B}">
            </Rating>
            <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{97D9239C-2BA3-4e1d-A710-B626DC4602A6}">
            </Rating>
        </Ratings>"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell]
"ConfigXML"="            <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" >                <InitializationParameters>                    <Param Name="PSVersion" Value="2.0"/>                </InitializationParameters>                <Resources>                    <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true">                        <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/>                        <Capability Type="Shell"/>                    </Resource>                </Res
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#081212509AF1A9&0#]
"DeviceDesc"="                "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_CCR-60&REV_9412#09022831000A&0#]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"Maxtor 4D060H3                          DAK05GK0"="MaxMode = UDMA-5"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"HDS724040KLSA80                        KFAOA32A"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"HDS722525VLSA80                        V36OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"HDS722516VLSA80                        V34OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"Maxtor 7B250S0                          BANC1B70"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"HTS541060G9SA00                        MB3OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"HTS541080G9SA00                        MB4OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Si3531\ProblemDevices]
"HTS541010G9SA00                        MBZOC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#081212509AF1A9&0#]
"DeviceDesc"="                "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#6&CFB0E7E&0&081212509AF1A9&0#]
"DeviceDesc"="                "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_CCR-60&REV_9412#09022831000A&0#]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"Maxtor 4D060H3                          DAK05GK0"="MaxMode = UDMA-5"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"HDS724040KLSA80                        KFAOA32A"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"HDS722525VLSA80                        V36OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"HDS722516VLSA80                        V34OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"Maxtor 7B250S0                          BANC1B70"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"HTS541060G9SA00                        MB3OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"HTS541080G9SA00                        MB4OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Si3531\ProblemDevices]
"HTS541010G9SA00                        MBZOC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#081212509AF1A9&0#]
"DeviceDesc"="                "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#6&CFB0E7E&0&081212509AF1A9&0#]
"DeviceDesc"="                "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_CCR-60&REV_9412#09022831000A&0#]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"Maxtor 4D060H3                          DAK05GK0"="MaxMode = UDMA-5"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"HDS724040KLSA80                        KFAOA32A"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"HDS722525VLSA80                        V36OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"HDS722516VLSA80                        V34OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"Maxtor 7B250S0                          BANC1B70"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"HTS541060G9SA00                        MB3OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"HTS541080G9SA00                        MB4OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Si3531\ProblemDevices]
"HTS541010G9SA00                        MBZOC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}\0003]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#081212509AF1A9&0#]
"DeviceDesc"="                "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_&REV_0.00#6&CFB0E7E&0&081212509AF1A9&0#]
"DeviceDesc"="                "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#1&19F7E59C&0&_??_USBSTOR#DISK&VEN_&PROD_CCR-60&REV_9412#09022831000A&0#]
"FriendlyName"="CCR-60          "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"Maxtor 4D060H3                          DAK05GK0"="MaxMode = UDMA-5"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"HDS724040KLSA80                        KFAOA32A"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"HDS722525VLSA80                        V36OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"HDS722516VLSA80                        V34OA6MA"="DisableAtaQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"Maxtor 7B250S0                          BANC1B70"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"HTS541060G9SA00                        MB3OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"HTS541080G9SA00                        MB4OC60D"="DisableSataQueueing"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Si3531\ProblemDevices]
"HTS541010G9SA00                        MBZOC60D"="DisableSataQueueing"

-= EOF =-


OTL-Scan:

Code:

OTL logfile created on: 03.04.2013 21:13:02 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Stefan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,62 Gb Available Physical Memory | 31,10% Memory free
4,21 Gb Paging File | 2,16 Gb Available in Paging File | 51,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 122,59 Gb Total Space | 67,94 Gb Free Space | 55,42% Space Free | Partition Type: NTFS
Drive D: | 26,45 Gb Total Space | 17,17 Gb Free Space | 64,93% Space Free | Partition Type: FAT32
 
Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.04.03 21:11:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
PRC - [2013.02.19 15:12:14 | 000,172,416 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2013.02.19 15:08:52 | 000,169,320 | ---- | M] (McAfee, Inc.) -- C:\Programme\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2013.02.19 15:06:50 | 000,203,840 | ---- | M] (McAfee, Inc.) -- C:\Programme\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2013.02.07 14:31:22 | 001,223,704 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\psia.exe
PRC - [2013.02.07 14:31:20 | 000,660,504 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\sua.exe
PRC - [2013.02.07 14:31:18 | 000,575,000 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\psi_tray.exe
PRC - [2013.01.14 19:00:22 | 001,278,064 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee.com\Agent\mcagent.exe
PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.12.16 13:25:20 | 000,545,552 | ---- | M] (SANDBOXIE L.T.D) -- C:\Programme\Sandboxie\SbieCtrl.exe
PRC - [2012.12.16 13:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) -- C:\Programme\Sandboxie\SbieSvc.exe
PRC - [2012.12.14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.12.14 17:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.12.14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.10 22:08:30 | 000,513,888 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee\MAT\McPvTray.exe
PRC - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) -- C:\Programme\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2012.04.12 17:12:56 | 004,212,344 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\T-Online\T-Online_Software_6\Browser\browser.exe
PRC - [2011.11.08 21:51:22 | 000,796,080 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\profilemgr.exe
PRC - [2011.11.08 21:51:22 | 000,111,960 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\sc_watch.exe
PRC - [2011.11.08 21:51:20 | 001,226,152 | ---- | M] (Deutsche Telekom AG) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis2\kernel.exe
PRC - [2010.04.13 20:11:16 | 003,045,176 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Online Backup\MOBKstat.exe
PRC - [2010.04.13 20:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Online Backup\MOBKbackup.exe
PRC - [2010.04.08 17:59:26 | 000,286,720 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe
PRC - [2010.04.01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Lite\DTLite.exe
PRC - [2009.07.20 13:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe
PRC - [2009.06.24 21:10:00 | 002,559,888 | ---- | M] (Salfeld Computer) -- C:\Windows\System32\ccsync.exe
PRC - [2009.06.24 21:10:00 | 002,243,472 | ---- | M] (Salfeld Computer) -- C:\Windows\System32\cchservice.exe
PRC - [2009.04.11 08:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.02.26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008.06.23 18:34:02 | 000,361,072 | ---- | M] (Auslogics) -- C:\Programme\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe
PRC - [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2007.10.22 13:34:20 | 000,421,888 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) -- C:\Programme\Common Files\Marmiko Shared\MInfraIS\MInfraIS.exe
PRC - [2007.01.09 14:39:58 | 000,368,640 | ---- | M] (fun communications GmbH, hxxp://www.fun.de) -- C:\Programme\T-Online\T-Online_Software_6\Notifier\Notifier.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.10.12 14:51:21 | 000,043,520 | ---- | M] () -- C:\Windows\System32\CmdLineExt03.dll
MOD - [2007.05.29 00:13:42 | 000,145,920 | ---- | M] () -- C:\Programme\Auslogics\AusLogics BoostSpeed\madBasic_.bpl
MOD - [2007.05.29 00:13:42 | 000,041,984 | ---- | M] () -- C:\Programme\Auslogics\AusLogics BoostSpeed\madDisAsm_.bpl
MOD - [2007.05.29 00:13:40 | 000,316,928 | ---- | M] () -- C:\Programme\Auslogics\AusLogics BoostSpeed\madExcept_.bpl
MOD - [2005.07.20 13:34:08 | 000,700,497 | ---- | M] () -- C:\Programme\T-Online\T-Online_Software_6\Notifier\libcurl.dll
MOD - [2004.04.16 16:45:52 | 000,143,360 | ---- | M] () -- C:\Programme\T-Online\T-Online_Software_6\Notifier\libexpat.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2013.03.07 16:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.02.19 15:12:14 | 000,172,416 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2013.02.19 15:08:52 | 000,169,320 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2013.02.19 15:06:50 | 000,203,840 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2013.02.07 14:31:22 | 001,223,704 | ---- | M] (Secunia) [Auto | Running] -- C:\Programme\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2013.02.07 14:31:20 | 000,660,504 | ---- | M] (Secunia) [Auto | Running] -- C:\Programme\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.12.16 13:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2012.12.14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.12.14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.11.16 22:07:20 | 000,279,048 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2010.08.25 09:56:38 | 000,765,592 | ---- | M] (Salfeld Computer) [Auto | Stopped] -- C:\Windows\System32\ksupmgr.exe -- (ksupmgr)
SRV - [2010.04.13 20:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Programme\McAfee Online Backup\MOBKbackup.exe -- (MOBKbackup)
SRV - [2009.07.20 13:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) [Auto | Running] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2009.02.06 18:08:58 | 000,533,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2008.04.07 10:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 09:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva400.sys -- (XDva400)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva399.sys -- (XDva399)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva398.sys -- (XDva398)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva397.sys -- (XDva397)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva383.sys -- (XDva383)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva380.sys -- (XDva380)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva375.sys -- (XDva375)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Stefan\AppData\Local\Temp\cdiskdun.sys -- (cdiskdun)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Stefan\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (altnd8vv)
DRV - [2013.02.19 15:15:04 | 000,060,920 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2013.02.19 15:12:24 | 000,210,608 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2013.02.19 15:10:52 | 000,092,632 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2013.02.19 15:09:52 | 000,565,888 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2013.02.19 15:09:02 | 000,363,080 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2013.02.19 15:08:40 | 000,065,928 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2013.02.19 15:08:20 | 000,235,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2013.02.19 15:07:50 | 000,133,416 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2013.02.07 14:15:22 | 000,016,024 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\psi_mf_x86.sys -- (PSI)
DRV - [2012.12.16 13:25:16 | 000,157,776 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2012.12.14 17:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.14 17:26:32 | 000,064,832 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\McPvDrv.sys -- (McPvDrv)
DRV - [2012.04.20 16:40:44 | 000,146,872 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK)
DRV - [2012.04.20 14:37:41 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012.04.12 17:28:22 | 000,278,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2012.04.12 17:28:21 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.08.27 14:23:08 | 000,019,200 | ---- | M] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Stopped] -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys -- (MTOnlPktAlyX)
DRV - [2010.06.23 10:21:32 | 000,259,176 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2010.05.30 19:09:32 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2010.05.30 19:08:31 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2010.05.30 19:08:31 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2010.04.13 20:10:22 | 000,054,776 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\System32\drivers\MOBK.sys -- (MOBKFilter)
DRV - [2009.03.31 10:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009.03.20 11:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009.03.20 11:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus)
DRV - [2009.03.20 11:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl)
DRV - [2009.03.04 19:49:21 | 004,232,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32)
DRV - [2009.02.05 18:39:08 | 000,017,064 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SiWinAcc.sys -- (SiFilter)
DRV - [2009.02.05 18:39:00 | 000,012,200 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SiRemFil.sys -- (SiRemFil)
DRV - [2009.02.05 18:38:24 | 000,212,520 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Si3531.sys -- (Si3531)
DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2007.09.17 16:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006.11.30 15:18:18 | 000,027,416 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\x10ufx2.sys -- (XUIF)
DRV - [2006.11.02 09:41:50 | 000,983,552 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.02 09:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.02 09:30:54 | 001,781,760 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32)
DRV - [2004.05.17 12:21:54 | 000,017,280 | ---- | M] (Intellon, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\plcndis5.sys -- (PLCNDIS5)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 53 8D A2 7B 42 CD 01  [binary data]
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes,bProtectorDefaultScope = {404962F6-6290-47B0-9B38-12EDABF8D24E}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{1E3CF04C-0EFA-4506-BE81-6DC4D939B9E4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{404962F6-6290-47B0-9B38-12EDABF8D24E}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searcmcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = n*b~µ¸QÆ€'h·8+þ°N±hvªddKyÛ0LˆIK껀*Üîw¯ÓüÍoÂOðJnøÛ¸Iï*NÞtÅs‘¿E|l?ÛmõZîìèˆ×—:Ïm–z8x5ÕÈs¨ài"Å0ížÃ,î*„}:<Ê—¨ôT}»€Z‘exˆÒ*Ä6ƒW÷XŸ»kÕ9ΞÂõ¨&ç0*÷l›xäP™xzêÝzÍÝy*•’ØØ7ÝÒÎ*!:]/S¶Ç·$œN/‚Y.ÂKâש6ác¢:ðð_°Oëgø"EÚÐõØ%˜×)â³Xê¯ò¤Ò¼˜ŽžOÇѶÍ>¥ûdAäŒNÈ!Ü_TúàAŽ·>qJLr+j¬¯‡îrDÚß$q®g‚v9Ê&QŸË¦JpQ°-»N< û|/½…aÏBÈбöüƒ¤,¨ç2 ¹YûC¨Q’¦¢ù
—¿R\xƒ,f«ºÜ!§ØËÀ¶v1N2ˆ°ð¼FŽ~Øm–ØAóÏXÊèj&ÌE)^A)(;<ˆž¼È¿'/‹ÝAt        B
“/"9ÙkÒÌA‰¸ÿã&dUÅ‚î*(v?
£¨š²ÈÍ)κç$‹,£
©²næÒŽ>
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.chatzum.com/
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3B 72 7B C5 50 4E CD 01  [binary data]
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes\{5924EA94-E19B-4EFF-811F-3C21B3E7B5EE}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_deDE438
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2013.01.15 17:49:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2013.04.03 19:09:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.31 16:43:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013.03.24 21:28:38 | 000,000,000 | ---D | M]
 
[2013.03.31 16:43:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan\AppData\Roaming\mozilla\Extensions
[2013.03.31 16:43:15 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.03.07 16:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.03.07 17:45:15 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.07 17:45:15 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.03.07 17:45:15 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 17:45:15 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.07 17:45:15 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 17:45:15 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL
CHR - default_search_provider: McAfee (Enabled)
CHR - default_search_provider: search_url = hxxp://de.search.yahoo.com/search?fr=mcafee&p={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL
CHR - homepage: hxxp://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Daten von Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.123.1_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Protect Disc License Acquisition Plugin (Enabled) = C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - Extension: SiteAdvisor = C:\Users\Stefan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\
 
O1 HOSTS File: ([2013.03.25 20:07:45 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Programme\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common Files\Mcafee\SystemCore\ScriptSn.20120627135043.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\Toolbar\WebBrowser: (no name) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No CLSID value found.
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [ChicoSys] C:\Windows\System32\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ToADiMon.exe] C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\.DEFAULT..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [Auslogics BoostSpeed 4] C:\Programme\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe (Auslogics)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\EMail und InterNet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 1
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 1
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{140C4E26-878B-4F2B-AB13-B1A5B4A59635}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8B1D7E6-209D-4841-8E3D-32BCC0D76347}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Programme\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\PROGRA~2\BPROTE~1\261125~1.80\{EAB34~1\protector.dll) - c:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\protector.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\...com [@ = comfile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.04.03 21:11:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
[2013.04.03 18:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
[2013.04.03 18:38:00 | 000,000,000 | ---D | C] -- C:\Program Files\Sandboxie
[2013.04.03 17:48:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\Secunia PSI
[2013.04.03 17:00:53 | 000,000,000 | ---D | C] -- C:\Program Files\Secunia
[2013.03.31 16:43:30 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Roaming\Mozilla
[2013.03.31 16:43:30 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\Mozilla
[2013.03.31 16:43:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013.03.31 16:43:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013.03.31 16:43:14 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.03.30 12:56:41 | 000,000,000 | ---D | C] -- C:\Users\Stefan\Documents\System-Sicherheit
[2013.03.29 14:07:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013.03.29 13:42:49 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.03.25 22:39:46 | 004,546,560 | ---- | C] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2013.03.25 20:11:05 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.03.25 20:11:04 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\temp
[2013.03.24 19:30:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.03.24 19:30:55 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.03.21 20:19:12 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys
[2013.03.21 14:21:02 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\McAfee Anti-Theft
[2013.03.21 14:14:14 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.03.17 17:43:50 | 000,103,680 | ---- | C] (GMER) -- C:\ugdiqpob.sys
[2013.03.16 10:27:09 | 000,064,832 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\McPvDrv.sys
[2013.03.16 10:24:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013.03.15 19:57:48 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.03.15 19:57:43 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.03.15 19:57:43 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.03.15 19:57:43 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.03.15 19:57:42 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.03.15 19:57:40 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.03.15 19:57:40 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.03.15 19:57:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.03.05 19:33:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\devolo
[2013.03.05 19:33:10 | 000,000,000 | ---D | C] -- C:\Program Files\devolo
[2011.12.12 15:13:32 | 009,734,240 | ---- | C] (McAfee, Inc.) -- C:\ProgramData\TempMOBK-update-6f587c3c1a49f2fdf5254a3e5ed05791.exe
[2011.11.03 18:33:23 | 005,006,472 | ---- | C] (Electronic Arts                                            ) -- C:\Users\Stefan\setup_659.exe
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.04.03 21:19:15 | 004,823,142 | ---- | M] () -- C:\Windows\System32\ccsync.err
[2013.04.03 21:19:00 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{7E0FFB30-A1EA-45D9-AE1C-BE220B81E5B8}.job
[2013.04.03 21:19:00 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4ACB5E34-87B0-41B7-A8D4-2B06E96F0430}.job
[2013.04.03 21:11:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
[2013.04.03 21:05:12 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.03 21:05:12 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.03 20:46:16 | 000,139,264 | ---- | M] () -- C:\Users\Stefan\Desktop\SystemLook.exe
[2013.04.03 20:37:05 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.04.03 20:28:33 | 000,003,290 | ---- | M] () -- C:\Windows\MOBK.blk
[2013.04.03 20:28:33 | 000,000,424 | ---- | M] () -- C:\Windows\MOBK.flt
[2013.04.03 20:27:23 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.04.03 19:12:54 | 000,628,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.04.03 19:12:54 | 000,596,246 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.04.03 19:12:54 | 000,126,510 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.04.03 19:12:54 | 000,104,320 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.04.03 19:05:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.03 18:49:02 | 000,001,482 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2013.04.03 17:00:56 | 000,000,903 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2013.03.31 16:43:22 | 000,000,850 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.03.30 18:36:49 | 000,000,903 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2013.03.25 22:39:46 | 004,546,560 | ---- | M] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2013.03.25 20:07:45 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.03.21 13:26:56 | 000,000,192 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.03.21 13:14:45 | 000,035,189 | ---- | M] () -- C:\Windows\System32\cchservice.err
[2013.03.17 17:43:50 | 000,103,680 | ---- | M] (GMER) -- C:\ugdiqpob.sys
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.04.03 20:46:13 | 000,139,264 | ---- | C] () -- C:\Users\Stefan\Desktop\SystemLook.exe
[2013.04.03 18:38:51 | 000,001,482 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2013.04.03 17:00:56 | 000,000,903 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2013.04.03 17:00:56 | 000,000,866 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2013.03.31 16:43:22 | 000,000,862 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.03.31 16:43:22 | 000,000,850 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.03.30 18:36:49 | 000,000,903 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2013.03.21 13:20:34 | 000,000,192 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2012.11.09 19:54:29 | 000,000,025 | ---- | C] () -- C:\Windows\SIERRA.INI
[2012.09.21 21:36:16 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2012.04.12 17:28:22 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2012.04.12 17:28:21 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2012.02.12 16:45:17 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012.02.12 16:44:43 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.02.12 16:44:39 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.12.25 14:06:44 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.12.25 14:06:44 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011.12.15 18:23:51 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.06.17 11:16:37 | 000,000,307 | ---- | C] () -- C:\Windows\game.ini
[2011.05.02 22:43:32 | 000,000,647 | ---- | C] () -- C:\Windows\et.ini
[2011.05.02 22:19:03 | 000,001,233 | ---- | C] () -- C:\Windows\System32\excltmp~.dat
[2011.05.02 22:18:43 | 000,155,536 | ---- | C] () -- C:\Windows\System32\dllcinx.exe
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.02.09 16:25:09 | 000,000,552 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d8caps.dat
[2010.12.08 21:43:23 | 000,091,022 | ---- | C] () -- C:\Users\Stefan\AppData\Roaming\mdbu.bin
[2009.06.29 08:44:04 | 000,000,680 | RHS- | C] () -- C:\Users\Stefan\ntuser.pol
[2009.06.21 17:38:51 | 000,004,608 | ---- | C] () -- C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.20 19:52:04 | 000,001,356 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d9caps.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >


OTL-Extra-Scan:

Code:

OTL Extras logfile created on: 03.04.2013 21:13:02 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Stefan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,62 Gb Available Physical Memory | 31,10% Memory free
4,21 Gb Paging File | 2,16 Gb Available in Paging File | 51,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 122,59 Gb Total Space | 67,94 Gb Free Space | 55,42% Space Free | Partition Type: NTFS
Drive D: | 26,45 Gb Total Space | 17,17 Gb Free Space | 64,93% Space Free | Partition Type: FAT32
 
Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.cmd [@ = cmdfile] -- Reg Error: Key error. File not found
.com [@ = comfile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.pif [@ = piffile] -- Reg Error: Key error. File not found
.vbs [@ = VBSFile] -- Reg Error: Key error. File not found
 
[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0145C7E1-8983-4D68-9D04-C9062CDAAB4F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{01C53FAC-0827-43B6-8D2A-7D2E18716952}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1C704A87-702D-4A5C-915F-517D989842F1}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{483681D5-0A82-4695-A8A7-5C5F3A19F272}" = rport=10243 | protocol=6 | dir=out | app=system |
"{76AFB169-44A5-46A9-9456-644D8747417B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7A5335C5-56D7-41EF-950A-EAA303ED85D2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{899024B7-EFB0-417A-86D5-3EADEA536BE7}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8C6A853A-F33A-460A-B679-92F3A53D006A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{91990706-62C2-46D3-A06B-21E5D7E55DE1}" = lport=49165 | protocol=6 | dir=in | name=akamai netsession interface |
"{9CA08100-EA2E-4011-9CB9-12931D00F8D9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B510CE45-62C4-43D9-ACC1-D15857D07B36}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{080E517A-FDF6-4754-965D-39DDE8B42209}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0B87D39A-4BA8-4678-A6A9-FB1D83B039C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0DAB411E-803B-4A4C-A34B-8768AC200FBC}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{126ED8EF-C4BB-4E6B-8498-5F65ADE44AB2}" = protocol=6 | dir=in | app=c:\program files\electronic arts\need for speed(tm) hot pursuit\launcher.exe |
"{1A786A39-E707-40F3-A01B-96FE9E82C091}" = protocol=17 | dir=in | app=c:\users\daten von johannes\appdata\local\akamai\netsession_win.exe |
"{1D884647-A403-4CC5-97A5-7229CD6DDB16}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{30480CB7-87E1-4A80-A2CA-0F3E81BCC4DF}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{308F4466-62C0-4D13-81DB-2D4207D61EDF}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassinscreed_dx9.exe |
"{35D6331D-214C-4BAD-A28B-E33EAA88E1AD}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{3674F87F-8A41-47E2-BA8D-725E49335D5C}" = protocol=17 | dir=in | app=c:\program files\electronic arts\need for speed(tm) hot pursuit\launcher.exe |
"{40AF031D-908F-4A10-AA7E-C2C99943F094}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassinscreed_dx10.exe |
"{41540FA7-EF4D-4922-886D-CC33F851326C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{43439346-3D78-45E0-90E4-BDAD7DAEDBFB}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{47929918-5760-4DE5-9FA8-877FDBFA0634}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{48229996-3446-4FAE-9A81-FC0E07149DCC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4BD947BD-F98B-4247-84D0-202BB828FEE5}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{51453716-F487-4D49-91CF-59F578019062}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{516D7DE4-60E8-403D-9198-9C16EC7DFC41}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5B2A5C6E-7D24-40E4-8A49-2281268C5D15}" = protocol=6 | dir=in | app=c:\users\daten von johannes\appdata\local\akamai\netsession_win.exe |
"{5B774F1A-EA78-4C38-9A9F-7CAD58C74B5C}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassinscreed_dx9.exe |
"{6288564D-0BFF-4DA6-9E43-587AA834CD11}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{6F23D108-7100-4329-94F8-874A378184F3}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\update service\update service.exe |
"{6F259344-EF0A-47E1-B54C-D05982718841}" = protocol=6 | dir=out | app=system |
"{702C373A-AB5F-4B1E-BFA2-646B0AC067BA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{970EACCC-ADBE-45C1-908C-EF1D89CB1CB7}" = protocol=17 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{A09FB11C-F40D-4ADF-B579-DF68AF20005A}" = dir=in | app=c:\program files\iminent\iminent.exe |
"{A6BCDB2B-C71D-4E3F-9719-570CCFB0B6BF}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{AEC6B6EE-D338-4C12-A8F5-4F8A72F79943}" = protocol=6 | dir=in | app=c:\program files\searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{AFF64449-2AF8-48F0-A3E9-E5D42C199D17}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B6D4CF7E-426D-460F-91E3-D7E210724063}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C4E92764-9CBC-4BD1-BB4A-CA9C759AACE1}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassinscreed_launcher.exe |
"{CC21D245-799E-4AA7-9B33-790764D061C6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D176E26B-6756-4FE9-A41B-2D41584D548C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D4450CBB-AE96-4CEB-8D56-E06BA184F9AB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DEFE8609-CD0D-4B44-A0E1-D30C3ECC55CF}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassinscreed_dx10.exe |
"{E5AD4699-61CA-4BB8-84E9-5A3C34B718E5}" = dir=in | app=c:\program files\iminent\iminent.messengers.exe |
"{F1844879-9522-4601-80C4-98773E9D1C8F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassinscreed_launcher.exe |
"{F8882568-8598-4C12-B368-4E937ABFE551}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FA1B4501-AF75-4702-9BB3-7EFDFD150830}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{FDED7EDB-ED02-41FD-8C82-012399764F05}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"TCP Query User{138386ED-FBE9-4043-8F4A-9D45A5BFF71D}G:\aoe\aoe ii\empires2.exe" = protocol=6 | dir=in | app=g:\aoe\aoe ii\empires2.exe |
"TCP Query User{7477FBC8-6222-41AD-AA89-B929C2187753}G:\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=g:\tmnationsforever\tmforever.exe |
"TCP Query User{7B9D994D-7226-4608-846A-265036CE8A19}C:\program files\t-online\t-online_software_6\notifier\notifier.exe" = protocol=6 | dir=in | app=c:\program files\t-online\t-online_software_6\notifier\notifier.exe |
"UDP Query User{0F6FC8D0-75CE-4742-A2BF-D11ECA40256B}G:\aoe\aoe ii\empires2.exe" = protocol=17 | dir=in | app=g:\aoe\aoe ii\empires2.exe |
"UDP Query User{5F1FDEBE-49C9-43E1-9A79-F60C68DED1F2}C:\program files\t-online\t-online_software_6\notifier\notifier.exe" = protocol=17 | dir=in | app=c:\program files\t-online\t-online_software_6\notifier\notifier.exe |
"UDP Query User{798E6F84-410F-41CA-B63C-D472DD39DF3F}G:\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=g:\tmnationsforever\tmforever.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{09298F26-A95C-31E2-9D95-2C60F586F075}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6100_series" = Canon MG6100 series MP Drivers
"{119B7481-0216-40D2-A5CC-C3E1F461ECC1}" = Windows Live Fotogalerie
"{11AE6807-50D2-4F59-82B3-2C3E695E94C2}" = NVIDIA PhysX v8.05.26
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1945A4B5-73B6-4DE9-99A3-05261B7FDED0}" = Shared C Run-time for x86
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}" = Need for Speed™ Carbon
"{27C467F8-F8EF-4f68-BD72-D63632B2096C}" = McAfee Online Backup
"{295C31E5-3F91-498E-9623-DA24D2FA2B6A}" = T-Online WLAN-Access Finder
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{54B1E5A3-1B29-4582-A226-172A1FC7BA6C}" = Windows Live Family Safety
"{5A166C0B-9557-4364-A057-F946D674E6AC}" = Windows Live Mail
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{636A7142-586A-4DF7-9207-191A2AF5610C}_is1" = AusLogics BoostSpeed
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{81821BF8-DA20-4F8C-AA87-F70A274828D4}" = Windows Live Writer
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83A606F5-BF6F-42ED-9F33-B9F74297CDED}" = Need for Speed(TM) Hot Pursuit
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91E04CA7-0B13-4F8C-AA4D-2A573AC96D19}" = Windows Live Essentials
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch
"{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"{B1275E23-717A-4D52-997A-1AD1E24BC7F3}" = T-Online 6.0
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFF4500E-C5D6-695D-A027-B3D4DDED2CC3}" = McAfee Online Backup
"{D18E9DB2-AC98-4399-8878-C1059403144D}" = Iminent
"{ED636101-1959-4360-8BF7-209436E7DEE4}" = Windows Live Sync
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Aldi Süd Foto Service" = Aldi Süd Foto Service 4.6
"ALDI Sued Fotoservice_is1" = Aldi Sued Fotoservice 2.7
"ALDI Süd Online Druck Service" = ALDI Süd Online Druck Service 4.6
"Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data" = Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data
"Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data" = Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data
"Canon MG6100 series Benutzerregistrierung" = Canon MG6100 series Benutzerregistrierung
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"dlanconf" = devolo dLAN-Konfigurationsassistent
"dslmon" = devolo Informer
"easyclean" = devolo EasyClean
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-PhotoPrint Pro" = Canon Easy-PhotoPrint Pro
"easyshare" = devolo EasyShare
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Google Chrome" = Google Chrome
"HaaliMkx" = Haali Media Splitter
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"Kindersicherung_is1" = Kindersicherung 2011
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"MSC" = McAfee Total Protection
"Picasa 3" = Picasa 3
"Protect Disc License Helper" = Protect Disc License Helper 1.0.118
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"Sandboxie" = Sandboxie 3.76 (32-bit)
"Secunia PSI" = Secunia PSI (3.0.0.6005)
"Update Service" = Update Service
"WinLiveSuite_Wave3" = Windows Live Essentials
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 31.03.2013 06:35:11 | Computer Name = Stefan-PC | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
 took longer than 90000 ms to complete a request.    The process will be terminated.
Thread
 id : 2664 (0xa68)    Thread address : 0x77115CD4    Thread message :      Build VSCORE.15.1.0.520
 / 5500.1093  Object being scanned = \Device\HarddiskVolume1\Program Files\McAfee\MSC\mcsvrcnt.exe

 by C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe  4(0)(0)  4(0)(0) 
7200(0)(0)  7595(0)(0)  7005(0)(0)  7004(0)(0)  5006(0)(0)  5004(0)(0) 
 
Error - 31.03.2013 09:08:32 | Computer Name = Stefan-PC | Source = VSS | ID = 8194
Description =
 
Error - 31.03.2013 09:09:32 | Computer Name = Stefan-PC | Source = VSS | ID = 8194
Description =
 
Error - 31.03.2013 09:35:10 | Computer Name = Stefan-PC | Source = MsiInstaller | ID = 10005
Description =
 
Error - 31.03.2013 10:24:26 | Computer Name = Stefan-PC | Source = MsiInstaller | ID = 10005
Description =
 
Error - 01.04.2013 14:15:35 | Computer Name = Stefan-PC | Source = VSS | ID = 8194
Description =
 
Error - 01.04.2013 14:20:22 | Computer Name = Stefan-PC | Source = VSS | ID = 8194
Description =
 
Error - 03.04.2013 14:28:00 | Computer Name = Stefan-PC | Source = VSS | ID = 8194
Description =
 
Error - 03.04.2013 14:29:57 | Computer Name = Stefan-PC | Source = VSS | ID = 8194
Description =
 
Error - 03.04.2013 15:25:27 | Computer Name = Stefan-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung svchost.exe_WinDefend, Version 6.0.6001.18000,
 Zeitstempel 0x47918b89, fehlerhaftes Modul mpengine.dll, Version 1.1.9302.0, Zeitstempel
 0x5142c9ca, Ausnahmecode 0xc0000006, Fehleroffset 0x001f1638,  Prozess-ID 0x460,
Anwendungsstartzeit 01ce308d66b5e570.
 
Error - 03.04.2013 15:25:27 | Computer Name = Stefan-PC | Source = Application Error | ID = 1005
Description = Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen
 werden:  Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit
der gespeicherten Datei bzw. den auf dem Computer installierten  Speichertreibern;
 oder der Datenträger fehlt.  Das Programm Hostprozess für Windows-Dienste wurde
wegen dieses Fehlers geschlossen.    Programm: Hostprozess für Windows-Dienste  Datei:
    Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet.  Benutzeraktion
1.
 Öffnen Sie die Datei erneut.  Diese Situation ist eventuell ein temporäres Problem,
 das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird.  2.  Wenn
 Sie weiterhin nicht auf die Datei zugreifen können und  - diese sich im Netzwerk
befindet,  dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem
 besteht und dass eine Verbindung mit dem Server hergestellt werden kann.  - diese
 sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet,
 überprüfen Sie, ob der Datenträger richtig in der Computer eingelegt ist.  3. Überprüfen
 und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu
 im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben
 Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE.
4.
 Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin
 besteht.  5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet
 werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt.
  Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware,
um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt.    Zusätzliche
 Daten  Fehlerwert: C0000185  Datenträgertyp: 0
 
[ OSession Events ]
Error - 22.07.2011 08:18:55 | Computer Name = Stefan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 21
 seconds with 0 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 03.04.2013 14:50:38 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 14:50:38 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 14:53:29 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 14:53:29 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 14:53:29 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 15:23:56 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 15:23:56 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 15:23:56 | Computer Name = Stefan-PC | Source = atapi | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden.
 
Error - 03.04.2013 15:25:26 | Computer Name = Stefan-PC | Source = WinDefend | ID = 5008
Description = Das %%827-Modul wurde aufgrund eines unerwarteten Fehlers beendet.

        Fehlertyp:
 %%830    Ausnahmecode: 0xc0000006    Ressource: process:pid:6044
 
Error - 03.04.2013 15:25:39 | Computer Name = Stefan-PC | Source = Service Control Manager | ID = 7031
Description =
 
 
< End of report >

Die Endmeldung gefällt mir gar nicht ...

Grüße

SMC36

aharonov 05.04.2013 16:26

Hallo,

dann schau mal, was nach folgenden Schritten noch zu sehen ist:


Schritt 1
  • Starte bitte die OTL.exe.
  • Kopiere nun den folgenden Inhalt aus der Codebox in die http://larusso.trojaner-board.de/Images/otlfix.jpg Textbox.
    Wichtig: Falls du deinen Benutzernamen im Log unkenntlich gemacht hast (z.B. durch ***), dann mach das hier wieder rückgängig.
Code:

:OTL
O20 - AppInit_DLLs: (c:\PROGRA~2\BPROTE~1\261125~1.80\{EAB34~1\protector.dll) - c:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\protector.dll ()

:files
C:\Windows\System32\Tasks\bProtector
C:\bProtectorForWindows
C:\028400ff82ebe131fa4ddb\bProtectorForWindows
C:\04f306920f957153640e166e24\bProtectorForWindows
C:\1070ab2172b984fda4\bProtectorForWindows
C:\144a34f9014e5a04ed565c636d\bProtectorForWindows
C:\29bd94c6368a461105db\bProtectorForWindows
C:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows
C:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows
C:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows
C:\41322c52a401c9771995\bProtectorForWindows
C:\497c50009f4d943ea04e\bProtectorForWindows
C:\4c95bf441978a49f4e959b9286\bProtectorForWindows
C:\505d135c245ac49998\bProtectorForWindows
C:\5079e70917c8c1ae1f\bProtectorForWindows
C:\530ba9c8fad932f9358a1324\bProtectorForWindows
C:\5d3cd820d23d38204b1f50803608\bProtectorForWindows
C:\630dc4c59e58d39240234ae8\bProtectorForWindows
C:\637779ce29fabb2b072e868c\bProtectorForWindows
C:\6434b20709812de8465309a0de\bProtectorForWindows
C:\72ee744f4ea283cefa9ea2\bProtectorForWindows
C:\788a1c8d5697a210a7\bProtectorForWindows
C:\7909414813e615744eac\bProtectorForWindows
C:\79a538ecf621240df134\bProtectorForWindows
C:\82d0d7a58f91d6f543d33d\bProtectorForWindows
C:\86cc027f15c92c73789210e35360ba\bProtectorForWindows
C:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows
C:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows
C:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows
C:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows
C:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows
C:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows
C:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows
C:\a9e57554d4565affc23c\bProtectorForWindows
C:\ad7961677f5c4817098ff628804a\bProtectorForWindows
C:\b3932403f1f740cef70ba005\bProtectorForWindows
C:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows
C:\c00f737d3b6ba838f4\bProtectorForWindows
C:\c8615056f13303404f\bProtectorForWindows
C:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows
C:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows
C:\e486b76e32143330e605fbabdb\bProtectorForWindows
C:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows
C:\efb932a808458c293935c879f422d675\bProtectorForWindows
C:\f24f6388f31fd1971adbb8\bProtectorForWindows
C:\f2f891b9c806289f198083\bProtectorForWindows
C:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows
C:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows
C:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows
C:\Fraps\bProtectorForWindows
C:\GAMIGO\LastChaosGER\bProtectorForWindows
C:\Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows
C:\Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows
C:\Program Files\EA Games\bProtectorForWindows
C:\Program Files\EA Games\Need for Speed Underground 2\bProtectorForWindows
C:\Program Files\EA Games\NFS Underground\bProtectorForWindows
C:\Program Files\Electronic Arts\Need For Speed III\3dSetup\bProtectorForWindows
C:\Program Files\Google\bProtectorForWindows
C:\Program Files\Google\Picasa3\bProtectorForWindows
C:\Program Files\Malwarebytes' Anti-Malware\bProtectorForWindows
C:\Program Files\Maxis\Die Sims\bProtectorForWindows
C:\Program Files\McAfee\MPF\bProtectorForWindows
C:\Program Files\McAfee\MPS\bProtectorForWindows
C:\Program Files\McAfee\MQS\bProtectorForWindows
C:\Program Files\McAfee\MSC\bProtectorForWindows
C:\Program Files\McAfee\SiteAdvisor\bProtectorForWindows
C:\Program Files\McAfee\VirusScan\bProtectorForWindows
C:\Program Files\McAfee.com\Agent\bProtectorForWindows
C:\Program Files\PC Performer\bProtectorForWindows
C:\Program Files\Samsung\Samsung New PC Studio\bProtectorForWindows
C:\Program Files\T-Online\T-Online_Software_6\Banking\bProtectorForWindows
C:\Program Files\T-Online\T-Online_Software_6\Browser\bProtectorForWindows
C:\Program Files\TuneUp Utilities 2011\bProtectorForWindows
C:\Program Files\Ubisoft\Detection\bProtectorForWindows
C:\Program Files\Ubisoft\Register\bProtectorForWindows
C:\ProgramData\bProtectorForWindows
C:\ProgramData\Electronic Arts\Need For Speed World\bProtectorForWindows
C:\ProgramData\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows
C:\Team17\Worms 3D\bProtectorForWindows
C:\Users\All Users\bProtectorForWindows
C:\Users\All Users\Electronic Arts\Need For Speed World\bProtectorForWindows
C:\Users\All Users\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\Aldi Süd Foto Service\bProtectorForWindows
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\McAfee Online Backup\bProtectorForWindows
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Windows\bProtectorForWindows
C:\Users\EMail und InterNet\Documents\Pfarrei Hl. Engel\bProtectorForWindows
C:\Users\EMail und InterNet\Documents\Privat\bProtectorForWindows
C:\Users\EMail und InterNet\Downloads\bProtectorForWindows
C:\Users\EMail und InterNet\Pictures\bProtectorForWindows
C:\Users\EMail und InterNet\Pictures\Diashow Stefan\bProtectorForWindows
C:\Users\EMail und InterNet\Videos\bProtectorForWindows
C:\Users\Public\Pictures\Sample Pictures\bProtectorForWindows
C:\Users\Stefan\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows
C:\Users\Stefan\Downloads\bProtectorForWindows
C:\Windows\Microsoft.NET\Framework\v4.0.30319\bProtectorForWindows

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
"bProtectorDefaultScope"=-

[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Microsoft\Internet Explorer\SearchScopes]
"bProtectorDefaultScope"=-

[HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\Software\Microsoft\Internet Explorer\Main]
"bProtector Start Page"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{231D934E-8C9B-481E-AA46-9342C6B0E23E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bProtector]
[-HKEY_USERS\.DEFAULT\Software\bProtector]
[-HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\Software\530dbdeb56eea42]
[-HKEY_USERS\S-1-5-18\Software\bProtector]

:commands
[emptytemp]

  • Schliesse nun bitte alle anderen Programme.
  • Klicke jetzt auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Diesen bitte zulassen.
  • Nach dem Neustart findest du ein Textdokument auf deinem Desktop.
    (Auch zu finden unter C:\_OTL\MovedFiles\<date_time>.log)
  • Kopiere nun dessen Inhalt hier in deinen Thread.



Schritt 2

Starte bitte die OTL.exe.
  • Setze den Haken bei Scan all Users.
  • Drücke auf den Quick Scan Button.
  • Poste den Inhalt von OTL.txt hier in den Thread.



Bitte poste in deiner nächsten Antwort:
  • Fixlog von OTL
  • Log von OTL

SMC36 05.04.2013 19:44

Hi Leo!

OTLFix:

Code:

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\PROGRA~2\BPROTE~1\261125~1.80\{EAB34~1\protector.dll deleted successfully.
c:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\protector.dll moved successfully.
========== FILES ==========
C:\Windows\System32\Tasks\bProtector moved successfully.
C:\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\bProtectorForWindows folder moved successfully.
Folder move failed. C:\028400ff82ebe131fa4ddb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\028400ff82ebe131fa4ddb\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\04f306920f957153640e166e24\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\04f306920f957153640e166e24\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\1070ab2172b984fda4\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\1070ab2172b984fda4\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\144a34f9014e5a04ed565c636d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\144a34f9014e5a04ed565c636d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\29bd94c6368a461105db\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\29bd94c6368a461105db\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\41322c52a401c9771995\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\41322c52a401c9771995\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\497c50009f4d943ea04e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\497c50009f4d943ea04e\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\4c95bf441978a49f4e959b9286\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\4c95bf441978a49f4e959b9286\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\505d135c245ac49998\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\505d135c245ac49998\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\5079e70917c8c1ae1f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\5079e70917c8c1ae1f\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\530ba9c8fad932f9358a1324\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\530ba9c8fad932f9358a1324\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\5d3cd820d23d38204b1f50803608\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\5d3cd820d23d38204b1f50803608\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\630dc4c59e58d39240234ae8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\630dc4c59e58d39240234ae8\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\637779ce29fabb2b072e868c\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\637779ce29fabb2b072e868c\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\6434b20709812de8465309a0de\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\6434b20709812de8465309a0de\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\72ee744f4ea283cefa9ea2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\72ee744f4ea283cefa9ea2\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\788a1c8d5697a210a7\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\788a1c8d5697a210a7\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\7909414813e615744eac\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\7909414813e615744eac\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\79a538ecf621240df134\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\79a538ecf621240df134\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\82d0d7a58f91d6f543d33d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\82d0d7a58f91d6f543d33d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\86cc027f15c92c73789210e35360ba\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\86cc027f15c92c73789210e35360ba\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\a9e57554d4565affc23c\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a9e57554d4565affc23c\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\ad7961677f5c4817098ff628804a\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\ad7961677f5c4817098ff628804a\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\b3932403f1f740cef70ba005\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\b3932403f1f740cef70ba005\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\c00f737d3b6ba838f4\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\c00f737d3b6ba838f4\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\c8615056f13303404f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\c8615056f13303404f\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\e486b76e32143330e605fbabdb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\e486b76e32143330e605fbabdb\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\efb932a808458c293935c879f422d675\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\efb932a808458c293935c879f422d675\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\f24f6388f31fd1971adbb8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f24f6388f31fd1971adbb8\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\f2f891b9c806289f198083\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f2f891b9c806289f198083\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows scheduled to be moved on reboot.
C:\Fraps\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Fraps\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\Fraps\bProtectorForWindows folder moved successfully.
C:\GAMIGO\LastChaosGER\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\GAMIGO\LastChaosGER\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\GAMIGO\LastChaosGER\bProtectorForWindows folder moved successfully.
C:\Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows folder moved successfully.
C:\Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows folder moved successfully.
C:\Program Files\EA Games\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\EA Games\bProtectorForWindows folder moved successfully.
C:\Program Files\EA Games\Need for Speed Underground 2\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\EA Games\Need for Speed Underground 2\bProtectorForWindows folder moved successfully.
C:\Program Files\EA Games\NFS Underground\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\EA Games\NFS Underground\bProtectorForWindows folder moved successfully.
C:\Program Files\Electronic Arts\Need For Speed III\3dSetup\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Electronic Arts\Need For Speed III\3dSetup\bProtectorForWindows folder moved successfully.
C:\Program Files\Google\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Google\bProtectorForWindows folder moved successfully.
C:\Program Files\Google\Picasa3\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Google\Picasa3\bProtectorForWindows folder moved successfully.
C:\Program Files\Malwarebytes' Anti-Malware\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Malwarebytes' Anti-Malware\bProtectorForWindows folder moved successfully.
C:\Program Files\Maxis\Die Sims\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Maxis\Die Sims\bProtectorForWindows folder moved successfully.
C:\Program Files\McAfee\MPF\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\McAfee\MPF\bProtectorForWindows folder moved successfully.
C:\Program Files\McAfee\MPS\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\McAfee\MPS\bProtectorForWindows folder moved successfully.
C:\Program Files\McAfee\MQS\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\McAfee\MQS\bProtectorForWindows folder moved successfully.
C:\Program Files\McAfee\MSC\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\McAfee\MSC\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\Program Files\McAfee\MSC\bProtectorForWindows folder moved successfully.
C:\Program Files\McAfee\SiteAdvisor\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\McAfee\SiteAdvisor\bProtectorForWindows folder moved successfully.
C:\Program Files\McAfee\VirusScan\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\McAfee\VirusScan\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\Program Files\McAfee\VirusScan\bProtectorForWindows folder moved successfully.
C:\Program Files\McAfee.com\Agent\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\McAfee.com\Agent\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\Program Files\McAfee.com\Agent\bProtectorForWindows folder moved successfully.
C:\Program Files\PC Performer\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\PC Performer\bProtectorForWindows\2.1.419.7 folder moved successfully.
C:\Program Files\PC Performer\bProtectorForWindows folder moved successfully.
C:\Program Files\Samsung\Samsung New PC Studio\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Samsung\Samsung New PC Studio\bProtectorForWindows folder moved successfully.
C:\Program Files\T-Online\T-Online_Software_6\Banking\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\T-Online\T-Online_Software_6\Banking\bProtectorForWindows folder moved successfully.
C:\Program Files\T-Online\T-Online_Software_6\Browser\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\T-Online\T-Online_Software_6\Browser\bProtectorForWindows folder moved successfully.
C:\Program Files\TuneUp Utilities 2011\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\TuneUp Utilities 2011\bProtectorForWindows folder moved successfully.
C:\Program Files\Ubisoft\Detection\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Ubisoft\Detection\bProtectorForWindows folder moved successfully.
C:\Program Files\Ubisoft\Register\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Program Files\Ubisoft\Register\bProtectorForWindows folder moved successfully.
C:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7}\traking_settings folder moved successfully.
C:\ProgramData\bProtectorForWindows\2.6.1125.80\{eab34bca-99d8-4192-8f3b-58b53f6d08e7} folder moved successfully.
C:\ProgramData\bProtectorForWindows\2.6.1125.80 folder moved successfully.
C:\ProgramData\bProtectorForWindows folder moved successfully.
C:\ProgramData\Electronic Arts\Need For Speed World\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\ProgramData\Electronic Arts\Need For Speed World\bProtectorForWindows folder moved successfully.
C:\ProgramData\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\ProgramData\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows folder moved successfully.
C:\Team17\Worms 3D\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Team17\Worms 3D\bProtectorForWindows folder moved successfully.
File\Folder C:\Users\All Users\bProtectorForWindows not found.
File\Folder C:\Users\All Users\Electronic Arts\Need For Speed World\bProtectorForWindows not found.
File\Folder C:\Users\All Users\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows not found.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\Aldi Süd Foto Service\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\Aldi Süd Foto Service\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\McAfee Online Backup\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\McAfee Online Backup\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Windows\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\AppData\Local\VirtualStore\Windows\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\Documents\Pfarrei Hl. Engel\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\Documents\Pfarrei Hl. Engel\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\Documents\Privat\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\Documents\Privat\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\Downloads\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\Downloads\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\Pictures\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\Pictures\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\Pictures\Diashow Stefan\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\Pictures\Diashow Stefan\bProtectorForWindows folder moved successfully.
C:\Users\EMail und InterNet\Videos\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\EMail und InterNet\Videos\bProtectorForWindows folder moved successfully.
C:\Users\Public\Pictures\Sample Pictures\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\Public\Pictures\Sample Pictures\bProtectorForWindows folder moved successfully.
C:\Users\Stefan\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\Stefan\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows folder moved successfully.
C:\Users\Stefan\Downloads\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Users\Stefan\Downloads\bProtectorForWindows folder moved successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\bProtectorForWindows\2.2.463.83 folder moved successfully.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\bProtectorForWindows folder moved successfully.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope not found.
Registry key HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\Software\Microsoft\Internet Explorer\Main not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{231D934E-8C9B-481E-AA46-9342C6B0E23E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{231D934E-8C9B-481E-AA46-9342C6B0E23E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bProtector\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\bProtector\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3386111443-1739343494-374529350-1002\Software\530dbdeb56eea42\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\bProtector\ not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Daten von Johannes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: EMail und InterNet
->Temp folder emptied: 51414 bytes
->Temporary Internet Files folder emptied: 918466 bytes
->FireFox cache emptied: 3058495 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Gast
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: MusikSpieleJojo
->Temp folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: Stefan
->Temp folder emptied: 33164 bytes
->Temporary Internet Files folder emptied: 17232167 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 943220 bytes
->Flash cache emptied: 944 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4937 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 21,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 04052013_195914

Files\Folders moved on Reboot...
Folder move failed. C:\028400ff82ebe131fa4ddb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\028400ff82ebe131fa4ddb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\028400ff82ebe131fa4ddb\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\04f306920f957153640e166e24\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\04f306920f957153640e166e24\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\04f306920f957153640e166e24\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\1070ab2172b984fda4\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\1070ab2172b984fda4\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\1070ab2172b984fda4\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\144a34f9014e5a04ed565c636d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\144a34f9014e5a04ed565c636d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\144a34f9014e5a04ed565c636d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\29bd94c6368a461105db\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\29bd94c6368a461105db\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\29bd94c6368a461105db\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\41322c52a401c9771995\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\41322c52a401c9771995\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\41322c52a401c9771995\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\497c50009f4d943ea04e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\497c50009f4d943ea04e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\497c50009f4d943ea04e\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\4c95bf441978a49f4e959b9286\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\4c95bf441978a49f4e959b9286\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\4c95bf441978a49f4e959b9286\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\505d135c245ac49998\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\505d135c245ac49998\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\505d135c245ac49998\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\5079e70917c8c1ae1f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\5079e70917c8c1ae1f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\5079e70917c8c1ae1f\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\530ba9c8fad932f9358a1324\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\530ba9c8fad932f9358a1324\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\530ba9c8fad932f9358a1324\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\5d3cd820d23d38204b1f50803608\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\5d3cd820d23d38204b1f50803608\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\5d3cd820d23d38204b1f50803608\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\630dc4c59e58d39240234ae8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\630dc4c59e58d39240234ae8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\630dc4c59e58d39240234ae8\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\637779ce29fabb2b072e868c\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\637779ce29fabb2b072e868c\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\637779ce29fabb2b072e868c\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\6434b20709812de8465309a0de\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\6434b20709812de8465309a0de\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\6434b20709812de8465309a0de\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\72ee744f4ea283cefa9ea2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\72ee744f4ea283cefa9ea2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\72ee744f4ea283cefa9ea2\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\788a1c8d5697a210a7\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\788a1c8d5697a210a7\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\788a1c8d5697a210a7\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\7909414813e615744eac\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\7909414813e615744eac\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\7909414813e615744eac\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\79a538ecf621240df134\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\79a538ecf621240df134\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\79a538ecf621240df134\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\82d0d7a58f91d6f543d33d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\82d0d7a58f91d6f543d33d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\82d0d7a58f91d6f543d33d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\86cc027f15c92c73789210e35360ba\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\86cc027f15c92c73789210e35360ba\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\86cc027f15c92c73789210e35360ba\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\a9e57554d4565affc23c\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a9e57554d4565affc23c\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\a9e57554d4565affc23c\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\ad7961677f5c4817098ff628804a\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\ad7961677f5c4817098ff628804a\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\ad7961677f5c4817098ff628804a\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\b3932403f1f740cef70ba005\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\b3932403f1f740cef70ba005\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\b3932403f1f740cef70ba005\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\c00f737d3b6ba838f4\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\c00f737d3b6ba838f4\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\c00f737d3b6ba838f4\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\c8615056f13303404f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\c8615056f13303404f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\c8615056f13303404f\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\e486b76e32143330e605fbabdb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\e486b76e32143330e605fbabdb\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\e486b76e32143330e605fbabdb\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\efb932a808458c293935c879f422d675\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\efb932a808458c293935c879f422d675\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\efb932a808458c293935c879f422d675\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\f24f6388f31fd1971adbb8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f24f6388f31fd1971adbb8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f24f6388f31fd1971adbb8\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\f2f891b9c806289f198083\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f2f891b9c806289f198083\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f2f891b9c806289f198083\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows scheduled to be moved on reboot.
Folder move failed. C:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows\2.2.463.83 scheduled to be moved on reboot.
Folder move failed. C:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

OTL2-Logfile:

Code:

OTL logfile created on: 05.04.2013 20:05:12 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Stefan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,73 Gb Available Physical Memory | 36,68% Memory free
4,21 Gb Paging File | 2,80 Gb Available in Paging File | 66,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 122,59 Gb Total Space | 67,42 Gb Free Space | 55,00% Space Free | Partition Type: NTFS
Drive D: | 26,45 Gb Total Space | 17,17 Gb Free Space | 64,93% Space Free | Partition Type: FAT32
 
Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2013.04.03 21:11:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
PRC - [2013.02.19 15:12:14 | 000,172,416 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2013.02.19 15:08:52 | 000,169,320 | ---- | M] (McAfee, Inc.) -- C:\Programme\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2013.02.19 15:06:50 | 000,203,840 | ---- | M] (McAfee, Inc.) -- C:\Programme\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2013.02.07 14:31:22 | 001,223,704 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\psia.exe
PRC - [2013.02.07 14:31:20 | 000,660,504 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\sua.exe
PRC - [2013.02.07 14:31:18 | 000,575,000 | ---- | M] (Secunia) -- C:\Programme\Secunia\PSI\psi_tray.exe
PRC - [2013.01.14 19:00:22 | 001,278,064 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee.com\Agent\mcagent.exe
PRC - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.12.16 13:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) -- C:\Programme\Sandboxie\SbieSvc.exe
PRC - [2012.12.14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.12.14 17:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.12.14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) -- C:\Programme\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010.04.13 20:11:16 | 003,045,176 | ---- | M] (McAfee, Inc.) -- C:\Programme\McAfee Online Backup\MOBKstat.exe
PRC - [2010.04.08 17:59:26 | 000,286,720 | ---- | M] (Deutsche Telekom AG, Marmiko IT-Solutions GmbH) -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe
PRC - [2010.04.01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Programme\DAEMON Tools Lite\DTLite.exe
PRC - [2009.07.20 13:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe
PRC - [2009.06.24 21:10:00 | 002,559,888 | ---- | M] (Salfeld Computer) -- C:\Windows\System32\ccsync.exe
PRC - [2009.06.24 21:10:00 | 002,243,472 | ---- | M] (Salfeld Computer) -- C:\Windows\System32\cchservice.exe
PRC - [2009.04.11 08:28:11 | 000,217,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WerFault.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.06.23 18:34:02 | 000,361,072 | ---- | M] (Auslogics) -- C:\Programme\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe
PRC - [2008.01.19 09:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2007.05.29 00:13:42 | 000,145,920 | ---- | M] () -- C:\Programme\Auslogics\AusLogics BoostSpeed\madBasic_.bpl
MOD - [2007.05.29 00:13:42 | 000,041,984 | ---- | M] () -- C:\Programme\Auslogics\AusLogics BoostSpeed\madDisAsm_.bpl
MOD - [2007.05.29 00:13:40 | 000,316,928 | ---- | M] () -- C:\Programme\Auslogics\AusLogics BoostSpeed\madExcept_.bpl
 
 
========== Services (SafeList) ==========
 
SRV - [2013.03.07 16:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.02.19 15:12:14 | 000,172,416 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2013.02.19 15:08:52 | 000,169,320 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2013.02.19 15:06:50 | 000,203,840 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2013.02.07 14:31:22 | 001,223,704 | ---- | M] (Secunia) [Auto | Running] -- C:\Programme\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2013.02.07 14:31:20 | 000,660,504 | ---- | M] (Secunia) [Auto | Running] -- C:\Programme\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012.12.18 16:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.12.16 13:25:18 | 000,085,776 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2012.12.14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.12.14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.11.16 22:07:20 | 000,279,048 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Programme\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2012.08.31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2011.07.20 06:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2010.08.25 09:56:38 | 000,765,592 | ---- | M] (Salfeld Computer) [Auto | Stopped] -- C:\Windows\System32\ksupmgr.exe -- (ksupmgr)
SRV - [2010.04.13 20:11:14 | 000,229,688 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Programme\McAfee Online Backup\MOBKbackup.exe -- (MOBKbackup)
SRV - [2009.07.20 13:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) [Auto | Running] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2009.02.06 18:08:58 | 000,533,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2008.04.07 10:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Programme\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 09:33:39 | 000,896,512 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2006.10.26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva400.sys -- (XDva400)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva399.sys -- (XDva399)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva398.sys -- (XDva398)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva397.sys -- (XDva397)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva383.sys -- (XDva383)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva380.sys -- (XDva380)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva375.sys -- (XDva375)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Stefan\AppData\Local\Temp\cdiskdun.sys -- (cdiskdun)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Stefan\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Unknown] --  -- (a9j2e2nk)
DRV - [2013.02.19 15:15:04 | 000,060,920 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2013.02.19 15:12:24 | 000,210,608 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2013.02.19 15:10:52 | 000,092,632 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2013.02.19 15:09:52 | 000,565,888 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2013.02.19 15:09:02 | 000,363,080 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2013.02.19 15:08:40 | 000,065,928 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2013.02.19 15:08:20 | 000,235,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2013.02.19 15:07:50 | 000,133,416 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2013.02.07 14:15:22 | 000,016,024 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\psi_mf_x86.sys -- (PSI)
DRV - [2012.12.16 13:25:16 | 000,157,776 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2012.12.14 17:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.14 17:26:32 | 000,064,832 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\McPvDrv.sys -- (McPvDrv)
DRV - [2012.04.20 16:40:44 | 000,146,872 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK)
DRV - [2012.04.20 14:37:41 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012.04.12 17:28:22 | 000,278,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2012.04.12 17:28:21 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.08.27 14:23:08 | 000,019,200 | ---- | M] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) [Kernel | On_Demand | Stopped] -- C:\Programme\T-Online\T-Online_Software_6\Basis-Software\Basis1\MTOnlPktAlyx.sys -- (MTOnlPktAlyX)
DRV - [2010.06.23 10:21:32 | 000,259,176 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2010.05.30 19:09:32 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2010.05.30 19:08:31 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2010.05.30 19:08:31 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2010.04.13 20:10:22 | 000,054,776 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\System32\drivers\MOBK.sys -- (MOBKFilter)
DRV - [2009.03.31 10:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009.03.20 11:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009.03.20 11:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus)
DRV - [2009.03.20 11:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl)
DRV - [2009.03.04 19:49:21 | 004,232,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32)
DRV - [2009.02.05 18:39:08 | 000,017,064 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SiWinAcc.sys -- (SiFilter)
DRV - [2009.02.05 18:39:00 | 000,012,200 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SiRemFil.sys -- (SiRemFil)
DRV - [2009.02.05 18:38:24 | 000,212,520 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Si3531.sys -- (Si3531)
DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2007.09.17 16:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006.11.30 15:18:18 | 000,027,416 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\x10ufx2.sys -- (XUIF)
DRV - [2006.11.02 09:41:50 | 000,983,552 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.02 09:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.02 09:30:54 | 001,781,760 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32)
DRV - [2004.05.17 12:21:54 | 000,017,280 | ---- | M] (Intellon, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\plcndis5.sys -- (PLCNDIS5)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 53 8D A2 7B 42 CD 01  [binary data]
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes,DefaultScope = {404962F6-6290-47B0-9B38-12EDABF8D24E}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{02949DD9-5482-47ED-8232-DB3561192FB0}: "URL" = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&rlz=1I7ADRA_deDE438
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{1E3CF04C-0EFA-4506-BE81-6DC4D939B9E4}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{404962F6-6290-47B0-9B38-12EDABF8D24E}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPPDLicenseHelper: C:\Program Files\ProtectDisc\License Helper\NPPDLicenseHelper.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2013.04.05 19:59:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2013.04.05 20:05:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.31 16:43:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013.03.24 21:28:38 | 000,000,000 | ---D | M]
 
[2013.03.31 16:43:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stefan\AppData\Roaming\mozilla\Extensions
[2013.03.31 16:43:15 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.03.07 16:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.03.07 17:45:15 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.07 17:45:15 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.03.07 17:45:15 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 17:45:15 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.07 17:45:15 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 17:45:15 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2013.03.25 20:07:45 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Programme\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\Common Files\Mcafee\SystemCore\ScriptSn.20120627135043.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programme\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [ChicoSys] C:\Windows\System32\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ToADiMon.exe] C:\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\ToADiMon.exe (Deutsche Telekom AG, Marmiko IT-Solutions GmbH)
O4 - HKU\.DEFAULT..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\.DEFAULT..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-18..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-18..\Run: [InfoCockpit] C:\Program Files\T-Online\T-Online_Software_6\Info-Cockpit\IC_START.EXE (Deutsche Telekom AG, T-Com)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [Auslogics BoostSpeed 4] C:\Programme\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe (Auslogics)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\EMail und InterNet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programme\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{140C4E26-878B-4F2B-AB13-B1A5B4A59635}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B8B1D7E6-209D-4841-8E3D-32BCC0D76347}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Programme\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programme\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Programme\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-3386111443-1739343494-374529350-1000\...com [@ = comfile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.04.05 19:59:14 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.04.03 21:11:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
[2013.04.03 18:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
[2013.04.03 18:38:00 | 000,000,000 | ---D | C] -- C:\Program Files\Sandboxie
[2013.04.03 17:48:45 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\Secunia PSI
[2013.04.03 17:00:53 | 000,000,000 | ---D | C] -- C:\Program Files\Secunia
[2013.03.31 16:43:30 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Roaming\Mozilla
[2013.03.31 16:43:30 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\Mozilla
[2013.03.31 16:43:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013.03.31 16:43:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013.03.31 16:43:14 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.03.30 12:56:41 | 000,000,000 | ---D | C] -- C:\Users\Stefan\Documents\System-Sicherheit
[2013.03.29 14:07:29 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013.03.29 13:42:49 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.03.25 20:11:05 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.03.25 20:11:04 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\temp
[2013.03.24 19:30:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.03.24 19:30:55 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.03.21 14:21:02 | 000,000,000 | ---D | C] -- C:\Users\Stefan\AppData\Local\McAfee Anti-Theft
[2013.03.21 14:14:14 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.03.17 17:43:50 | 000,103,680 | ---- | C] (GMER) -- C:\ugdiqpob.sys
[2013.03.16 10:27:09 | 000,064,832 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\McPvDrv.sys
[2013.03.16 10:24:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011.12.12 15:13:32 | 009,734,240 | ---- | C] (McAfee, Inc.) -- C:\ProgramData\TempMOBK-update-6f587c3c1a49f2fdf5254a3e5ed05791.exe
[2011.11.03 18:33:23 | 005,006,472 | ---- | C] (Electronic Arts                                            ) -- C:\Users\Stefan\setup_659.exe
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.04.05 20:17:29 | 005,080,372 | ---- | M] () -- C:\Windows\System32\ccsync.err
[2013.04.05 20:01:36 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.04.05 20:01:08 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.05 20:01:08 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.05 20:01:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.05 19:59:00 | 000,000,426 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{7E0FFB30-A1EA-45D9-AE1C-BE220B81E5B8}.job
[2013.04.05 19:59:00 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4ACB5E34-87B0-41B7-A8D4-2B06E96F0430}.job
[2013.04.05 19:27:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.04.05 17:23:42 | 000,001,482 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2013.04.04 20:29:14 | 000,003,290 | ---- | M] () -- C:\Windows\MOBK.blk
[2013.04.04 20:29:14 | 000,000,424 | ---- | M] () -- C:\Windows\MOBK.flt
[2013.04.03 21:11:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stefan\Desktop\OTL.exe
[2013.04.03 20:46:16 | 000,139,264 | ---- | M] () -- C:\Users\Stefan\Desktop\SystemLook.exe
[2013.04.03 19:12:54 | 000,628,992 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.04.03 19:12:54 | 000,596,246 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.04.03 19:12:54 | 000,126,510 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.04.03 19:12:54 | 000,104,320 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.04.03 17:00:56 | 000,000,903 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2013.03.31 16:43:22 | 000,000,850 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.03.30 18:36:49 | 000,000,903 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2013.03.25 20:07:45 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.03.21 13:26:56 | 000,000,192 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.03.21 13:14:45 | 000,035,189 | ---- | M] () -- C:\Windows\System32\cchservice.err
[2013.03.17 17:43:50 | 000,103,680 | ---- | M] (GMER) -- C:\ugdiqpob.sys
[4 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.04.03 20:46:13 | 000,139,264 | ---- | C] () -- C:\Users\Stefan\Desktop\SystemLook.exe
[2013.04.03 18:38:51 | 000,001,482 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2013.04.03 17:00:56 | 000,000,903 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2013.04.03 17:00:56 | 000,000,866 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2013.03.31 16:43:22 | 000,000,862 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013.03.31 16:43:22 | 000,000,850 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013.03.30 18:36:49 | 000,000,903 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2013.03.21 13:20:34 | 000,000,192 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2012.11.09 19:54:29 | 000,000,025 | ---- | C] () -- C:\Windows\SIERRA.INI
[2012.09.21 21:36:16 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2012.04.12 17:28:22 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2012.04.12 17:28:21 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2012.02.12 16:45:17 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012.02.12 16:44:43 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.02.12 16:44:39 | 000,183,112 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.12.25 14:06:44 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.12.25 14:06:44 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011.12.15 18:23:51 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011.06.17 11:16:37 | 000,000,307 | ---- | C] () -- C:\Windows\game.ini
[2011.05.02 22:43:32 | 000,000,647 | ---- | C] () -- C:\Windows\et.ini
[2011.05.02 22:19:03 | 000,001,233 | ---- | C] () -- C:\Windows\System32\excltmp~.dat
[2011.05.02 22:18:43 | 000,155,536 | ---- | C] () -- C:\Windows\System32\dllcinx.exe
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.02.09 16:25:09 | 000,000,552 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d8caps.dat
[2010.12.08 21:43:23 | 000,091,022 | ---- | C] () -- C:\Users\Stefan\AppData\Roaming\mdbu.bin
[2009.06.29 08:44:04 | 000,000,680 | RHS- | C] () -- C:\Users\Stefan\ntuser.pol
[2009.06.21 17:38:51 | 000,004,608 | ---- | C] () -- C:\Users\Stefan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.06.20 19:52:04 | 000,001,356 | ---- | C] () -- C:\Users\Stefan\AppData\Local\d3d9caps.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 14:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2013.01.05 14:47:36 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\Canneverbe Limited
[2012.09.29 15:32:23 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\Canon
[2011.10.31 14:40:57 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\Petroglyph
[2009.06.24 19:05:07 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\T-Online
[2012.04.30 12:41:07 | 000,000,000 | ---D | M] -- C:\Users\EMail und InterNet\AppData\Roaming\TuneUp Software
[2010.01.02 18:16:02 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Auslogics
[2012.04.20 14:47:51 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\DAEMON Tools Lite
[2011.01.02 22:34:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Leadertech
[2011.11.03 21:18:07 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Need for Speed World
[2011.12.25 16:38:03 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\PC Suite
[2011.06.23 10:53:25 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\ProtectDisc
[2011.12.25 14:06:27 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Samsung
[2009.06.20 23:51:33 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\T-Online
[2012.04.20 14:24:35 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\Teeworlds
[2012.04.20 14:54:13 | 000,000,000 | ---D | M] -- C:\Users\Stefan\AppData\Roaming\TuneUp Software
 
========== Purity Check ==========
 
 

< End of report >

Während des Scans habe ich eine Fehlermeldung von Windows bekommen:
"Hostprozess für Windows-Dienst wurde beendet und geschlosssen."

Grüße

SMC36

aharonov 05.04.2013 19:53

Hi,

wie ist die Lage jetzt?

SMC36 05.04.2013 23:00

Hallo!
Momentan keine Fehlermeldungen mehr. PC war vor den Scans + dem Fix heute ziemlich langsam, sieht jetzt wieder besser aus.
"Folder move failed"-Meldungen kritisch?
Gruß
SMC36

aharonov 05.04.2013 23:05

Hallo,

lass mich mal nachsehen, was dort sonst noch drin ist:


Code:

dir /a/s/b "C:\028400ff82ebe131fa4ddb" /c
dir /a/s/b "C:\efb932a808458c293935c879f422d675" /c
dir /a/s/b "C:\f24f6388f31fd1971adbb8" /c

  • Schliesse bitte alle anderen Programme.
  • Klicke nun auf None (deutsch "Nichts") und danach auf den Scan Button.
  • Kopiere danach den Inhalt der OTL.txt hier in deinen Thread.

SMC36 06.04.2013 14:21

Hallo Leo!

OTL-Scan (None):

Code:

OTL logfile created on: 06.04.2013 15:12:33 - Run 3
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Stefan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,53 Gb Available Physical Memory | 26,54% Memory free
4,21 Gb Paging File | 2,53 Gb Available in Paging File | 60,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 122,59 Gb Total Space | 66,41 Gb Free Space | 54,17% Space Free | Partition Type: NTFS
Drive D: | 26,45 Gb Total Space | 17,17 Gb Free Space | 64,93% Space Free | Partition Type: FAT32
 
Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
 
========== Custom Scans ==========
 
< dir /a/s/b "C:\028400ff82ebe131fa4ddb" /c >
C:\028400FF82EBE131FA4DDB\bProtectorForWindows
C:\028400FF82EBE131FA4DDB\searchplugins
C:\028400FF82EBE131FA4DDB\bProtectorForWindows\2.2.463.83
 
< dir /a/s/b "C:\efb932a808458c293935c879f422d675" /c >
C:\EFB932A808458C293935C879F422D675\bProtectorForWindows
C:\EFB932A808458C293935C879F422D675\searchplugins
C:\EFB932A808458C293935C879F422D675\bProtectorForWindows\2.2.463.83
 
< dir /a/s/b "C:\f24f6388f31fd1971adbb8" /c >
C:\F24F6388F31FD1971ADBB8\bProtectorForWindows
C:\F24F6388F31FD1971ADBB8\searchplugins
C:\F24F6388F31FD1971ADBB8\bProtectorForWindows\2.2.463.83
 
<          >

< End of report >

Irgendwas scheint noch nicht ganz in Ordnung zu sein. Die Desktop-Befehle auf dem Administratoren-Pfad reagieren sehr langsam.

Grüße
SMC36

aharonov 07.04.2013 01:02

Hi,

Zitat:

Irgendwas scheint noch nicht ganz in Ordnung zu sein. Die Desktop-Befehle auf dem Administratoren-Pfad reagieren sehr langsam.
Ich versteh nicht ganz, was du damit meinst. Kannst du es ein bisschen genauer beschreiben?

SMC36 07.04.2013 16:26

Hi Leo!
Gestern hatte ich beim Einwählen ins Internet den Eindruck, der PC hängt sich auf und das Öffnen der OTL-Datei hat erst beim dritten Mal funktioniert. Heute läuft alles wieder normal. Vielleicht war ich nur durch die Fehlermeldung des Windows-Hosts verunsichert.
Wie ist dein Kommentar zu dieser Fehlermeldung und den letzten Logfiles? Ist aus deiner Sicht jetzt alles o.k.?

Grüße
SMC36

aharonov 07.04.2013 16:52

Hi,

kannst du all diese Ordner wie C:\028400FF82EBE131FA4DDB sehen und öffnen?

SMC36 07.04.2013 20:26

Zitat:

Zitat von aharonov (Beitrag 1042352)
Hi,

kannst du all diese Ordner wie C:\028400FF82EBE131FA4DDB sehen und öffnen?

Hallo!

Ich kann die Ordner sehen, habe aber keine Zugangsberechtigung.

SMC36

aharonov 07.04.2013 20:50

Ok, dann:


Lade dir bitte BlitzBlank (von Emsisoft) herunter und speichere es auf den Desktop.
  • Starte die BlitzBlank.exe und bestätige die Warnung mit OK.
  • Wechsle in den Reiter Script.
  • Kopiere nun folgenden Inhalt aus der Codebox und füge ihn ins Textfeld von BlitzBlank ein:
    (Wichtig: Falls du deinen Benutzernamen unkenntlich gemacht hast (z.B. durch ***), dann mach das hier im Skript wieder rückgängig.)
    Code:

    DeleteFolder:
    C:\028400ff82ebe131fa4ddb
    C:\04f306920f957153640e166e24
    C:\1070ab2172b984fda4
    C:\144a34f9014e5a04ed565c636d
    C:\29bd94c6368a461105db
    C:\2c5bc8a548f55b6e74166070e2
    C:\37d7b130e47b51ef6ab1b4a7a893bda5
    C:\3ce31d4563a9032f7a1695dc91
    C:\41322c52a401c9771995
    C:\497c50009f4d943ea04e
    C:\4c95bf441978a49f4e959b9286
    C:\505d135c245ac49998
    C:\5079e70917c8c1ae1f
    C:\530ba9c8fad932f9358a1324
    C:\5d3cd820d23d38204b1f50803608
    C:\630dc4c59e58d39240234ae8
    C:\637779ce29fabb2b072e868c
    C:\6434b20709812de8465309a0de
    C:\72ee744f4ea283cefa9ea2
    C:\788a1c8d5697a210a7
    C:\7909414813e615744eac
    C:\79a538ecf621240df134
    C:\82d0d7a58f91d6f543d33d
    C:\86cc027f15c92c73789210e35360ba
    C:\87bfbef07d97463aaa26979f943585aa
    C:\87cb6e9bf70b6adda316d2a93226853a
    C:\9383f6469f2b42ffcc43bcc2
    C:\9448ee8ea0acdbb7f0d0217900
    C:\977b324f966c710b3a2ca9706a7b254d
    C:\a57ebd56f0ff7aea7d446a396bbb
    C:\a61cb58f46d80aaf6874a7ab8c609e
    C:\a9e57554d4565affc23c
    C:\ad7961677f5c4817098ff628804a
    C:\b3932403f1f740cef70ba005
    C:\b44e8dc639c80aeac0a076cb7e
    C:\c00f737d3b6ba838f4
    C:\c8615056f13303404f
    C:\d6b0378eabefe90263ce1478b92796
    C:\e2f4d2fbe0b96c60f45f0d
    C:\e486b76e32143330e605fbabdb
    C:\eceedb9faf0ada27dfc1d456fa
    C:\efb932a808458c293935c879f422d675
    C:\f24f6388f31fd1971adbb8
    C:\f2f891b9c806289f198083
    C:\f463bd2e88e7bd909ad379f4a1
    C:\fb2ce738514d20f2b6f3c6f8
    C:\fe1c11490544867598f939a27c8a0f

  • Schliesse jetzt alle anderen laufenden Programme und Anwendungen.
  • Drücke dann auf Jetzt ausführen.
  • Bestätige die Warnung und den Neustart jeweils mit OK. Der Rechner wird neu gestartet.
  • Nach dem Neustart findest du ein Logfile unter C:\blitzblank.log. Poste dessen Inhalt bitte hier in deinen Thread.

SMC36 07.04.2013 21:45

Hallo!

Hier der BlitzBlank-Logfile:

Code:

BlitzBlank 1.0.0.32

File/Registry Modification Engine native application
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\028400ff82ebe131fa4ddb", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\028400ff82ebe131fa4ddb\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\028400ff82ebe131fa4ddb\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\028400ff82ebe131fa4ddb\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\04f306920f957153640e166e24", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\04f306920f957153640e166e24\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\04f306920f957153640e166e24\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\04f306920f957153640e166e24\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\1070ab2172b984fda4", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\1070ab2172b984fda4\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\1070ab2172b984fda4\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\1070ab2172b984fda4\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\144a34f9014e5a04ed565c636d", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\144a34f9014e5a04ed565c636d\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\144a34f9014e5a04ed565c636d\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\144a34f9014e5a04ed565c636d\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\29bd94c6368a461105db", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\29bd94c6368a461105db\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\29bd94c6368a461105db\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\29bd94c6368a461105db\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\2c5bc8a548f55b6e74166070e2", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\2c5bc8a548f55b6e74166070e2\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\2c5bc8a548f55b6e74166070e2\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\37d7b130e47b51ef6ab1b4a7a893bda5", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\37d7b130e47b51ef6ab1b4a7a893bda5\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\3ce31d4563a9032f7a1695dc91", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\3ce31d4563a9032f7a1695dc91\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\3ce31d4563a9032f7a1695dc91\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\41322c52a401c9771995", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\41322c52a401c9771995\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\41322c52a401c9771995\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\41322c52a401c9771995\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\497c50009f4d943ea04e", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\497c50009f4d943ea04e\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\497c50009f4d943ea04e\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\497c50009f4d943ea04e\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\4c95bf441978a49f4e959b9286", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\4c95bf441978a49f4e959b9286\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\4c95bf441978a49f4e959b9286\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\4c95bf441978a49f4e959b9286\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\505d135c245ac49998", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\505d135c245ac49998\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\505d135c245ac49998\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\505d135c245ac49998\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5079e70917c8c1ae1f", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5079e70917c8c1ae1f\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5079e70917c8c1ae1f\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5079e70917c8c1ae1f\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\530ba9c8fad932f9358a1324", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\530ba9c8fad932f9358a1324\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\530ba9c8fad932f9358a1324\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\530ba9c8fad932f9358a1324\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5d3cd820d23d38204b1f50803608", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5d3cd820d23d38204b1f50803608\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5d3cd820d23d38204b1f50803608\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\5d3cd820d23d38204b1f50803608\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\630dc4c59e58d39240234ae8", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\630dc4c59e58d39240234ae8\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\630dc4c59e58d39240234ae8\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\630dc4c59e58d39240234ae8\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\637779ce29fabb2b072e868c", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\637779ce29fabb2b072e868c\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\637779ce29fabb2b072e868c\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\637779ce29fabb2b072e868c\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\6434b20709812de8465309a0de", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\6434b20709812de8465309a0de\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\6434b20709812de8465309a0de\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\6434b20709812de8465309a0de\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\72ee744f4ea283cefa9ea2", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\72ee744f4ea283cefa9ea2\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\72ee744f4ea283cefa9ea2\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\72ee744f4ea283cefa9ea2\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\788a1c8d5697a210a7", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\788a1c8d5697a210a7\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\788a1c8d5697a210a7\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\788a1c8d5697a210a7\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\7909414813e615744eac", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\7909414813e615744eac\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\7909414813e615744eac\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\7909414813e615744eac\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\79a538ecf621240df134", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\79a538ecf621240df134\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\79a538ecf621240df134\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\79a538ecf621240df134\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\82d0d7a58f91d6f543d33d", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\82d0d7a58f91d6f543d33d\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\82d0d7a58f91d6f543d33d\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\82d0d7a58f91d6f543d33d\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\86cc027f15c92c73789210e35360ba", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\86cc027f15c92c73789210e35360ba\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\86cc027f15c92c73789210e35360ba\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\86cc027f15c92c73789210e35360ba\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87bfbef07d97463aaa26979f943585aa", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87bfbef07d97463aaa26979f943585aa\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87bfbef07d97463aaa26979f943585aa\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87cb6e9bf70b6adda316d2a93226853a", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\87cb6e9bf70b6adda316d2a93226853a\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9383f6469f2b42ffcc43bcc2", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9383f6469f2b42ffcc43bcc2\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9383f6469f2b42ffcc43bcc2\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9448ee8ea0acdbb7f0d0217900", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9448ee8ea0acdbb7f0d0217900\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\9448ee8ea0acdbb7f0d0217900\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\977b324f966c710b3a2ca9706a7b254d", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\977b324f966c710b3a2ca9706a7b254d\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a57ebd56f0ff7aea7d446a396bbb", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a57ebd56f0ff7aea7d446a396bbb\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a61cb58f46d80aaf6874a7ab8c609e", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a61cb58f46d80aaf6874a7ab8c609e\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a9e57554d4565affc23c", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a9e57554d4565affc23c\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a9e57554d4565affc23c\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\a9e57554d4565affc23c\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\ad7961677f5c4817098ff628804a", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\ad7961677f5c4817098ff628804a\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\ad7961677f5c4817098ff628804a\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\ad7961677f5c4817098ff628804a\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b3932403f1f740cef70ba005", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b3932403f1f740cef70ba005\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b3932403f1f740cef70ba005\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b3932403f1f740cef70ba005\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b44e8dc639c80aeac0a076cb7e", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b44e8dc639c80aeac0a076cb7e\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\b44e8dc639c80aeac0a076cb7e\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c00f737d3b6ba838f4", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c00f737d3b6ba838f4\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c00f737d3b6ba838f4\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c00f737d3b6ba838f4\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c8615056f13303404f", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c8615056f13303404f\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c8615056f13303404f\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\c8615056f13303404f\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\d6b0378eabefe90263ce1478b92796", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\d6b0378eabefe90263ce1478b92796\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\d6b0378eabefe90263ce1478b92796\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e2f4d2fbe0b96c60f45f0d", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e2f4d2fbe0b96c60f45f0d\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e2f4d2fbe0b96c60f45f0d\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e486b76e32143330e605fbabdb", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e486b76e32143330e605fbabdb\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e486b76e32143330e605fbabdb\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\e486b76e32143330e605fbabdb\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\eceedb9faf0ada27dfc1d456fa", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\eceedb9faf0ada27dfc1d456fa\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\eceedb9faf0ada27dfc1d456fa\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\efb932a808458c293935c879f422d675", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\efb932a808458c293935c879f422d675\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\efb932a808458c293935c879f422d675\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\efb932a808458c293935c879f422d675\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f24f6388f31fd1971adbb8", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f24f6388f31fd1971adbb8\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f24f6388f31fd1971adbb8\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f24f6388f31fd1971adbb8\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f2f891b9c806289f198083", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f2f891b9c806289f198083\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f2f891b9c806289f198083\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f2f891b9c806289f198083\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f463bd2e88e7bd909ad379f4a1", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f463bd2e88e7bd909ad379f4a1\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\f463bd2e88e7bd909ad379f4a1\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fb2ce738514d20f2b6f3c6f8", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fb2ce738514d20f2b6f3c6f8\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fb2ce738514d20f2b6f3c6f8\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fe1c11490544867598f939a27c8a0f", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fe1c11490544867598f939a27c8a0f\bProtectorForWindows\2.2.463.83", destinationDirectory = "(null)", replaceWithDummy = 0
MoveDirectoryOnReboot: sourceDirectory = "\??\c:\fe1c11490544867598f939a27c8a0f\searchplugins", destinationDirectory = "(null)", replaceWithDummy = 0

O.K.?

SMC36

aharonov 07.04.2013 21:54

OK, bestehen jetzt im Moment noch Probleme auf dem Rechner?

SMC36 08.04.2013 17:10

Zitat:

Zitat von aharonov (Beitrag 1042619)
OK, bestehen jetzt im Moment noch Probleme auf dem Rechner?

Hallo!

Ich habe noch 6 solcher Ordner (bprotector? "Zugriff verweigert") auf dem C-Boot, die offensichtlich nicht gelöscht wurden. Muss ich das noch nachholen?

Ansonsten ist wohl alles o.k.

Grüße
SMC36

aharonov 08.04.2013 17:11

Code:

dir /a/b "C:\" /c
c:|bprotector;true;true;true /FP

  • Schliesse bitte alle anderen Programme.
  • Klicke nun auf None (deutsch "Nichts") und danach auf den Scan Button.
  • Kopiere danach den Inhalt der OTL.txt hier in deinen Thread.

SMC36 08.04.2013 20:14

Hallo!
PC ist beim OTL-Scan abgestürzt. Soll ich den Scan nochmal probieren?
Grüße
SMC36

aharonov 08.04.2013 20:19

Ja, versuch es bitte noch einmal.

SMC36 09.04.2013 13:12

Hallo!

Der OTL-Scan:

Code:

OTL logfile created on: 09.04.2013 13:53:20 - Run 4
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Stefan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 0,76 Gb Available Physical Memory | 37,95% Memory free
4,21 Gb Paging File | 2,73 Gb Available in Paging File | 64,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 122,59 Gb Total Space | 73,76 Gb Free Space | 60,17% Space Free | Partition Type: NTFS
Drive D: | 26,45 Gb Total Space | 17,17 Gb Free Space | 64,93% Space Free | Partition Type: FAT32
 
Computer Name: STEFAN-PC | User Name: Stefan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
 
========== Custom Scans ==========
 
< dir /a/b "C:\" /c >
$RECYCLE.BIN
2438174a4b512dea4ce3950edb
6f14471a14ed234dbe95db0655c274ce
885e2c574b6663e090
8e22877e5abde1486614352ccfe3fc
autoexec.bat
b173c7f3ba70a278ece0
blitzblank.log
Boot
bootmgr
BOOTSECT.BAK
chatzum_nt.exe
config.sys
DelFix.txt
Documents and Settings
Dokumente und Einstellungen
ea13a4c05e4f60363acc2b
eula.1031.txt
found.000
found.001
Fraps
Games
GAMIGO
globdata.ini
HbUser
install.ini
install.res.1031.dll
Intel
IO.SYS
MSDOS.SYS
MSOCache
NET.INI
pagefile.sys
pcwdbg.log
PDVD.iss
PerfLogs
Program Files
ProgramData
Programme
searchplugins
System Volume Information
T-Online_Software_6
Team17
temp
TO_InstallLog.txt
ugdiqpob.sys
Users
vcredist.bmp
VC_RED.cab
VC_RED.MSI
Windows
_OTL
 
< c:|bprotector;true;true;true /FP >
[2013.04.05 19:59:17 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_bProtectorForWindows
[2012.09.18 10:56:18 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:17 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_\bProtectorForWindows
[2012.11.23 17:51:31 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_028400ff82ebe131fa4ddb\bProtectorForWindows
[2012.09.25 13:45:33 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_04f306920f957153640e166e24\bProtectorForWindows
[2012.11.20 17:06:19 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_1070ab2172b984fda4\bProtectorForWindows
[2012.09.11 14:26:38 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_144a34f9014e5a04ed565c636d\bProtectorForWindows
[2012.07.28 09:54:14 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_29bd94c6368a461105db\bProtectorForWindows
[2013.01.05 14:52:15 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_2c5bc8a548f55b6e74166070e2\bProtectorForWindows
[2012.09.21 17:29:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_37d7b130e47b51ef6ab1b4a7a893bda5\bProtectorForWindows
[2012.10.05 14:29:48 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_3ce31d4563a9032f7a1695dc91\bProtectorForWindows
[2012.09.04 14:03:17 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_41322c52a401c9771995\bProtectorForWindows
[2012.10.19 17:47:53 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_497c50009f4d943ea04e\bProtectorForWindows
[2012.07.17 15:57:42 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_4c95bf441978a49f4e959b9286\bProtectorForWindows
[2012.10.19 17:48:25 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_505d135c245ac49998\bProtectorForWindows
[2013.01.18 11:52:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_5079e70917c8c1ae1f\bProtectorForWindows
[2012.07.15 18:57:11 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_530ba9c8fad932f9358a1324\bProtectorForWindows
[2012.12.07 19:13:17 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_5d3cd820d23d38204b1f50803608\bProtectorForWindows
[2012.11.16 18:57:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_630dc4c59e58d39240234ae8\bProtectorForWindows
[2013.01.23 17:41:25 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_637779ce29fabb2b072e868c\bProtectorForWindows
[2012.10.09 14:52:04 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_6434b20709812de8465309a0de\bProtectorForWindows
[2012.10.18 20:33:57 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_72ee744f4ea283cefa9ea2\bProtectorForWindows
[2012.09.18 12:13:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_788a1c8d5697a210a7\bProtectorForWindows
[2012.09.07 10:15:40 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_7909414813e615744eac\bProtectorForWindows
[2012.07.26 13:13:08 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_79a538ecf621240df134\bProtectorForWindows
[2012.11.02 16:59:10 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_82d0d7a58f91d6f543d33d\bProtectorForWindows
[2012.08.03 11:34:07 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_86cc027f15c92c73789210e35360ba\bProtectorForWindows
[2012.12.01 10:19:26 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_87bfbef07d97463aaa26979f943585aa\bProtectorForWindows
[2012.11.13 18:00:12 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_87cb6e9bf70b6adda316d2a93226853a\bProtectorForWindows
[2012.07.20 15:06:36 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_9383f6469f2b42ffcc43bcc2\bProtectorForWindows
[2012.11.09 18:04:18 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_9448ee8ea0acdbb7f0d0217900\bProtectorForWindows
[2012.07.10 14:10:15 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_977b324f966c710b3a2ca9706a7b254d\bProtectorForWindows
[2012.10.02 13:05:08 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_a57ebd56f0ff7aea7d446a396bbb\bProtectorForWindows
[2012.08.01 15:44:12 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_a61cb58f46d80aaf6874a7ab8c609e\bProtectorForWindows
[2012.10.23 15:57:57 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_a9e57554d4565affc23c\bProtectorForWindows
[2013.01.03 21:58:39 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_ad7961677f5c4817098ff628804a\bProtectorForWindows
[2012.08.17 19:14:37 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_b3932403f1f740cef70ba005\bProtectorForWindows
[2012.11.06 12:06:58 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_b44e8dc639c80aeac0a076cb7e\bProtectorForWindows
[2012.08.24 12:53:26 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_c00f737d3b6ba838f4\bProtectorForWindows
[2012.12.19 15:53:37 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_c8615056f13303404f\bProtectorForWindows
[2012.12.30 21:11:52 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_d6b0378eabefe90263ce1478b92796\bProtectorForWindows
[2012.08.30 09:07:39 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_e2f4d2fbe0b96c60f45f0d\bProtectorForWindows
[2012.09.28 13:57:45 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_e486b76e32143330e605fbabdb\bProtectorForWindows
[2012.09.06 11:13:43 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_eceedb9faf0ada27dfc1d456fa\bProtectorForWindows
[2013.01.08 18:38:37 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_efb932a808458c293935c879f422d675\bProtectorForWindows
[2012.11.16 19:03:03 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_f24f6388f31fd1971adbb8\bProtectorForWindows
[2012.10.12 14:28:00 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_f2f891b9c806289f198083\bProtectorForWindows
[2012.08.21 10:20:34 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_f463bd2e88e7bd909ad379f4a1\bProtectorForWindows
[2012.08.31 12:16:38 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_fb2ce738514d20f2b6f3c6f8\bProtectorForWindows
[2012.10.30 15:55:46 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_fe1c11490544867598f939a27c8a0f\bProtectorForWindows
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Fraps\bProtectorForWindows
[2012.07.08 19:46:44 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Fraps\bProtectorForWindows\2.1.419.7
[2012.09.04 15:12:01 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Fraps\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_GAMIGO\LastChaosGER\bProtectorForWindows
[2012.07.09 16:32:14 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_GAMIGO\LastChaosGER\bProtectorForWindows\2.1.419.7
[2012.07.09 16:32:14 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_GAMIGO\LastChaosGER\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows
[2012.07.09 13:02:34 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows\2.1.419.7
[2012.07.11 13:53:28 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Common Files\Mcafee\HackerWatch\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows
[2012.07.09 13:00:26 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows\2.1.419.7
[2012.07.09 15:34:54 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Common Files\Mcafee\McSvcHost\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\EA Games\bProtectorForWindows
[2012.08.17 19:29:19 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\EA Games\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\EA Games\Need for Speed Underground 2\bProtectorForWindows
[2012.08.22 12:13:20 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\EA Games\Need for Speed Underground 2\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\EA Games\NFS Underground\bProtectorForWindows
[2012.09.25 19:20:49 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\EA Games\NFS Underground\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Electronic Arts\Need For Speed III\3dSetup\bProtectorForWindows
[2012.11.09 20:06:50 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Electronic Arts\Need For Speed III\3dSetup\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Google\bProtectorForWindows
[2012.11.26 18:21:39 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Google\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Google\Picasa3\bProtectorForWindows
[2012.09.22 20:49:45 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Google\Picasa3\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Malwarebytes' Anti-Malware\bProtectorForWindows
[2012.09.04 14:46:29 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Malwarebytes' Anti-Malware\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Maxis\Die Sims\bProtectorForWindows
[2012.07.22 13:00:49 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Maxis\Die Sims\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:21 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MPF\bProtectorForWindows
[2012.07.29 13:18:33 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MPF\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MPS\bProtectorForWindows
[2012.09.22 15:02:09 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MPS\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MQS\bProtectorForWindows
[2012.09.22 15:02:15 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MQS\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MSC\bProtectorForWindows
[2012.07.09 13:02:29 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MSC\bProtectorForWindows\2.1.419.7
[2012.07.11 13:52:32 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\MSC\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\SiteAdvisor\bProtectorForWindows
[2012.07.22 12:09:04 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\SiteAdvisor\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\VirusScan\bProtectorForWindows
[2012.07.09 13:02:32 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\VirusScan\bProtectorForWindows\2.1.419.7
[2012.07.11 13:53:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee\VirusScan\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee.com\Agent\bProtectorForWindows
[2012.07.09 13:02:29 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee.com\Agent\bProtectorForWindows\2.1.419.7
[2012.07.09 16:31:53 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\McAfee.com\Agent\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\PC Performer\bProtectorForWindows
[2012.07.09 15:30:15 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\PC Performer\bProtectorForWindows\2.1.419.7
[2012.07.09 15:30:14 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\PC Performer\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Samsung\Samsung New PC Studio\bProtectorForWindows
[2012.09.22 16:33:34 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Samsung\Samsung New PC Studio\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\T-Online\T-Online_Software_6\Banking\bProtectorForWindows
[2012.09.21 21:25:32 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\T-Online\T-Online_Software_6\Banking\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\T-Online\T-Online_Software_6\Browser\bProtectorForWindows
[2012.09.22 20:47:17 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\T-Online\T-Online_Software_6\Browser\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\TuneUp Utilities 2011\bProtectorForWindows
[2012.07.30 17:07:44 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\TuneUp Utilities 2011\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Ubisoft\Detection\bProtectorForWindows
[2012.09.11 11:35:14 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Ubisoft\Detection\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Ubisoft\Register\bProtectorForWindows
[2012.09.11 11:26:29 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Program Files\Ubisoft\Register\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\c_ProgramData\bProtectorForWindows
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\c_ProgramData\bProtectorForWindows\2.6.1125.80
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\c_ProgramData\Electronic Arts\Need For Speed World\bProtectorForWindows
[2012.08.31 11:59:47 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\c_ProgramData\Electronic Arts\Need For Speed World\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\c_ProgramData\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows
[2012.09.21 21:25:22 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\c_ProgramData\T-Online\T-Online_Software_6\Basis-Software\update\clone\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Team17\Worms 3D\bProtectorForWindows
[2012.10.12 14:22:33 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Team17\Worms 3D\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\Aldi Süd Foto Service\bProtectorForWindows
[2012.09.22 14:44:00 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\Aldi Süd Foto Service\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\McAfee Online Backup\bProtectorForWindows
[2012.10.02 11:13:25 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\McAfee Online Backup\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows
[2012.07.30 16:24:05 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Windows\bProtectorForWindows
[2012.10.21 16:54:00 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\AppData\Local\VirtualStore\Windows\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Documents\Pfarrei Hl. Engel\bProtectorForWindows
[2013.01.26 18:55:18 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Documents\Pfarrei Hl. Engel\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Documents\Privat\bProtectorForWindows
[2012.12.11 19:56:56 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Documents\Privat\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Downloads\bProtectorForWindows
[2013.01.05 14:42:51 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Downloads\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Pictures\bProtectorForWindows
[2012.10.09 16:47:45 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Pictures\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:23 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Pictures\Diashow Stefan\bProtectorForWindows
[2012.09.22 17:12:02 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Pictures\Diashow Stefan\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:24 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Videos\bProtectorForWindows
[2012.10.10 16:49:58 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\EMail und InterNet\Videos\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:24 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\Public\Pictures\Sample Pictures\bProtectorForWindows
[2012.12.20 22:12:03 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\Public\Pictures\Sample Pictures\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:24 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\Stefan\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows
[2012.07.19 20:03:31 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\Stefan\AppData\Local\VirtualStore\Program Files\T-Online\T-Online_Software_6\Basis-Software\Basis1\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:24 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\Stefan\Downloads\bProtectorForWindows
[2012.09.04 15:11:37 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Users\Stefan\Downloads\bProtectorForWindows\2.2.463.83
[2013.04.05 19:59:24 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Windows\Microsoft.NET\Framework\v4.0.30319\bProtectorForWindows
[2012.11.16 18:59:13 | 000,000,000 | ---D | M] -- c:\_OTL\MovedFiles\04052013_195914\C_Windows\Microsoft.NET\Framework\v4.0.30319\bProtectorForWindows\2.2.463.83
[2013.03.21 13:03:13 | 000,003,338 | ---- | M] () -- c:\_OTL\MovedFiles\04052013_195914\C_Windows\System32\Tasks\bProtector
 
<          >

< End of report >

Was sagst du zum Scan?

Grüße
SMC36

aharonov 09.04.2013 13:35

Ok, die gefundenen bprotector sind alle bereits in Quarantäne. Der ist weg.
Falls von deiner Seite nichts mehr offen ist, können wir das Thema beenden.

SMC36 09.04.2013 17:18

Wunderbar, Leo!
Nochmals danke für deine Hilfe, deine Tipps und deine Geduld.
Alles Gute für dich und euer Team!

Viele Grüße
SMC36

aharonov 09.04.2013 17:19

Prima, dann noch einmal delfix und das wär's.

Downloade dir bitte delfix auf deinen Desktop.
  • Schliesse alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.
  • DelFix entfernt u.a. alle von uns verwendeten Programme und löscht sich anschliessend selbst.
    Sollte denoch etwas übrig bleiben, kannst du es manuell löschen.



Freut mich, dass wir helfen konnten. :abklatsch:

Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun.

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten.
Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter.

Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:16 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58