Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Firefox stürzt ab nach ungewolltem Software download (https://www.trojaner-board.de/132335-firefox-stuerzt-ab-ungewolltem-software-download.html)

Dramatist 17.03.2013 10:05

Firefox stürzt ab nach ungewolltem Software download
 
Hallo Zusammen,

auf der Suche nach Kalendersoftware habe ich mir die Deltasuchmaschine und Iminent in meinen Firefox geladen. Die Software habe ich wieder deinstalliert. Danach ist Firefox regelmäßig abgestürzt. Dann habe ich Firefox neu installiert. Problem bleibt. Nach einem Suchlauf mit Malewarebytes habe ich den Ordner von Tournamentindicator im windows.old gelöscht, weil er mir da einen Trojaner anzeigte. Immernoch stürzt firefox ab.

OTL hat mir keine Extra-Datei angezeigt. Die andere Datei war zu groß zum hochladen, darum habe ich sie in zwei Teile zerlegt. (Hoffe das ist okay.)

G-Mer hat beim ersten Scan nach einiger Zeit angegegen kein Laufwerk zu finden. Beim zweiten Versuch angesagt, dass Gmer nicht mehr funktioniert. Daher also erst mal keine Gmer-Datei.

Ich bitte herzlich um Hilfe und bedanke mich schon mal im Voraus.

cosinus 17.03.2013 17:30

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner?
Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten!

Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Dramatist 17.03.2013 19:29

Okay. Hier kommt das Logfile von dem Malewarebytes-scan. Ich könnte noch zwei Avira Reports anbieten. Beide ohne Fund. (der letzte Scan ist von heute mittag.)

Code:


Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.03.14.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
*** :: ***-PC [Administrator]

14.03.2013 17:39:54
mbam-log-2013-03-14 (17-39-54).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 624847
Laufzeit: 3 Stunde(n), 16 Minute(n), 28 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Windows.old\Program Files\Tournament Indicator\PSA.exe (Trojan.FakeAlert) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Vielen Dank.

cosinus 17.03.2013 19:53

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen, die ich im Laufe dieses Strangs hier posten werde, aufmerksam durch. Frag umgehend nach, wenn dir irgendetwas unklar sein sollte, bevor du anfängst meine Anleitungen umzusetzen.

  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.

  • Bitte nur Scans durchführen zu denen du von einem Helfer aufgefordert wurdest! Installiere / Deinstalliere keine Software ohne Aufforderung!

  • Poste die Logfiles direkt in deinen Thread (bitte in CODE-Tags) und nicht als Anhang, ausser du wurdest dazu aufgefordert. Logs in Anhängen erschweren mir das Auswerten!

  • Die Logs der aufgegebenen Tools wie zB Malwarebytes sind immer zu posten - egal ob ein Fund dabei war oder nicht!

  • Beachte bitte auch => Löschen von Logfiles und andere Anfragen

Note:
Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread.
Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards.


Rootkitscan mit GMER

Bitte lade dir GMER Rootkit Scanner GMER herunter: (Dateiname zufällig)
  • Schließe alle anderen Programme, deaktiviere deinen Virenscanner und trenne den Rechner vom Internet bevor du GMER startest.
  • Sollte sich nach dem Start ein Fenster mit folgender Warnung öffnen:
    WARNING !!!
    GMER has found system modification, which might have been caused by ROOTKIT activity.
    Do you want to fully scan your system ?
    Unbedingt auf "No" klicken.
  • Entferne rechts den Haken bei: IAT/EAT und Show All
  • Setze den Haken bei Quickscan und entferne ihn bei allen anderen Laufwerken.
  • Starte den Scan mit "Scan".
  • Mache nichts am Computer während der Scan läuft.
  • Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!


Tauchen Probleme auf?
  • Probiere alternativ den abgesicherten Modus.
  • Erhältst du einen Bluescreen, dann entferne den Haken vor Devices.


Anschließend bitte MBAR ausführen:

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Dramatist 18.03.2013 10:33

Da bin ich wieder.

Nachdem ich bei Gmer wieder dieselbe Fehlermeldung bekommen habe, habe ich es im abgesicherten Modus probiert. Auf einem Bluescreen hat er mir fünf Auswahloptionen angeboten:

USB: Generic Flash HS-CF
USB: Generic Flash HS-MS/SD
USB: Generic Flash HS-SM
IDE:WDC WD6400 AACS-00G8B1
IDE:HL-DT-ST DVDRAM GH22NS40

Ich habe es mit escape probiert (using default). Wenn ich dann Gmer ausführe startet der Rechner nach kurzer Zeit neu.

Und was jetzt?

Vielen Dank für Deine Hilfsbereitschaft.

cosinus 18.03.2013 11:59

Lass GMER weg und mach erstmal nur mit MBAR weiter

Dramatist 19.03.2013 11:11

MBar sagt mir "No Maleware found".

Ein Logfile kann ich nicht finden.

cosinus 19.03.2013 12:37

Anleitungen bitte richtig lesen, es wurde genau beschrieben wo du das LOg findest

Dramatist 19.03.2013 14:28

Hallo,

also ich finde es ganz toll, dass ich hier Hilfe bekomme. Und ich bin Dir dafür sehr dankbar. Und zu meiner Dankbarkeit gehört, dass ich die Anweisungen so gut es mir möglich ist umsetze.

"Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese in Dein Thema."

Der einzige Ordner den ich finden kann, ist der verpackte Ordner mbar-1.01.0.1021
Wenn ich hier den mbar-Ordner öffne finde ich auch keine Logdatei. Ich habe auch bei "imageformats" "Data" und "Languages" gesucht. Ich habe mit dem Windowsexplorer nach mbar-log" gesucht.


Jetzt weiss ich nicht mehr weiter.

Kann ich Dich darum bitten mir sowohl Wertschätzung Deiner Hilfe, als auch größtmögliches Bemühen zur Kooperation zu unterstellen? Wenn ich mich doof anstellen, dann liegt das an Unvermögen und nicht an Unwillen oder Geringschätzung.

cosinus 19.03.2013 14:45

Sry aber wenn du die Anleitungen richtig machst, wird MBAR dir auch das Log erstellen. Sollte ich jetzt ein zweites Mal die Anleitung posten, macht doch auch keinen Sinn
Einfach MBAR nochmal nach der Anleitung machen und das erwähnte Log posten

Dramatist 19.03.2013 15:55

Sorry, meinerseits. Weiss nicht was ich diesmal anders gemacht habe als die beiden male zuvor. Jedenfalls hab ich jetzt ein logfile.

Code:

Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org

Database version: v2013.03.19.06

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
*** :: ***-PC [administrator]

19.03.2013 15:21:02
mbar-log-2013-03-19 (15-21-02).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 29509
Time elapsed: 10 minute(s), 57 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


cosinus 19.03.2013 16:00

aswMBR

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).




TDSS-Killer

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Dramatist 19.03.2013 20:39

so ... weiter gehts...

Code:

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-03-19 17:57:46
-----------------------------
17:57:46.662    OS Version: Windows 6.0.6002 Service Pack 2
17:57:46.662    Number of processors: 2 586 0x203
17:57:46.662    ComputerName: CARSTEN-PC  UserName: Carsten
17:57:48.597    Initialize success
17:59:50.004    AVAST engine defs: 13031900
18:00:00.409    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005d
18:00:00.409    Disk 0 Vendor: WDC_WD64 05.0 Size: 610480MB BusType: 8
18:00:00.659    Disk 0 MBR read successfully
18:00:00.659    Disk 0 MBR scan
18:00:00.674    Disk 0 Windows VISTA default MBR code
18:00:00.674    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      589993 MB offset 2048
18:00:00.690    Disk 0 Partition - 00    0F Extended LBA            20483 MB offset 1208307712
18:00:00.705    Disk 0 Partition 2 00    0B        FAT32 MSDOS5.0    20483 MB offset 1208307775
18:00:00.737    Disk 0 scanning sectors +1250258625
18:00:00.815    Disk 0 scanning C:\Windows\system32\drivers
18:00:12.125    Service scanning
18:00:18.708    Service ieUnattd C:\Windows\system32\rpchttpd.exe **INFECTED** Win32:Agent-AQRH [Trj]
18:00:31.125    Modules scanning
18:00:34.963    Disk 0 trace - called modules:
18:00:34.994    ntkrnlpa.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix86s.sys
18:00:34.994    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8728aac8]
18:00:35.010    3 CLASSPNP.SYS[8b5a28b3] -> nt!IofCallDriver -> \Device\0000005d[0x865b8890]
18:00:37.163    AVAST engine scan C:\Windows
18:00:41.000    AVAST engine scan C:\Windows\system32
18:02:03.542    File: C:\Windows\system32\rpchttpd.exe  **INFECTED** Win32:Agent-AQRH [Trj]
18:03:54.629    AVAST engine scan C:\Windows\system32\drivers
18:04:08.701    AVAST engine scan C:\Users\Carsten
18:23:32.291    AVAST engine scan C:\ProgramData
18:26:43.297    Scan finished successfully
18:36:09.687    Disk 0 MBR has been saved successfully to "C:\Users\Carsten\Desktop\Desktop\MBR.dat"
18:36:09.687    The log file has been saved successfully to "C:\Users\Carsten\Desktop\Desktop\aswMBR.txt"

Code:

20:28:04.0660 3480  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:28:04.0816 3480  ============================================================
20:28:04.0816 3480  Current date / time: 2013/03/19 20:28:04.0816
20:28:04.0816 3480  SystemInfo:
20:28:04.0816 3480 
20:28:04.0816 3480  OS Version: 6.0.6002 ServicePack: 2.0
20:28:04.0816 3480  Product type: Workstation
20:28:04.0816 3480  ComputerName: ***-PC
20:28:04.0816 3480  UserName: ***
20:28:04.0816 3480  Windows directory: C:\Windows
20:28:04.0816 3480  System windows directory: C:\Windows
20:28:04.0816 3480  Processor architecture: Intel x86
20:28:04.0816 3480  Number of processors: 2
20:28:04.0816 3480  Page size: 0x1000
20:28:04.0816 3480  Boot type: Normal boot
20:28:04.0816 3480  ============================================================
20:28:05.0861 3480  Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
20:28:05.0877 3480  ============================================================
20:28:05.0877 3480  \Device\Harddisk0\DR0:
20:28:05.0877 3480  MBR partitions:
20:28:05.0877 3480  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x48054800
20:28:05.0892 3480  \Device\Harddisk0\DR0\Partition2: MBR, Type 0xB, StartLBA 0x4805503F, BlocksNum 0x2801E82
20:28:05.0892 3480  ============================================================
20:28:05.0923 3480  C: <-> \Device\Harddisk0\DR0\Partition1
20:28:05.0955 3480  D: <-> \Device\Harddisk0\DR0\Partition2
20:28:05.0955 3480  ============================================================
20:28:05.0955 3480  Initialize success
20:28:05.0955 3480  ============================================================
20:28:22.0163 5428  ============================================================
20:28:22.0163 5428  Scan started
20:28:22.0163 5428  Mode: Manual; SigCheck; TDLFS;
20:28:22.0163 5428  ============================================================
20:28:23.0037 5428  ================ Scan system memory ========================
20:28:23.0037 5428  System memory - ok
20:28:23.0052 5428  ================ Scan services =============================
20:28:23.0224 5428  [ 585E64BB6DFBC0A2F1F0B554DED012DF ] 61883          C:\Windows\system32\DRIVERS\61883.sys
20:28:23.0411 5428  61883 - ok
20:28:23.0458 5428  [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI            C:\Windows\system32\drivers\acpi.sys
20:28:23.0473 5428  ACPI - ok
20:28:23.0551 5428  [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:28:23.0567 5428  AdobeFlashPlayerUpdateSvc - ok
20:28:23.0629 5428  [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
20:28:23.0645 5428  adp94xx - ok
20:28:23.0692 5428  [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci        C:\Windows\system32\drivers\adpahci.sys
20:28:23.0707 5428  adpahci - ok
20:28:23.0723 5428  [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
20:28:23.0739 5428  adpu160m - ok
20:28:23.0754 5428  [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
20:28:23.0770 5428  adpu320 - ok
20:28:23.0817 5428  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
20:28:23.0895 5428  AeLookupSvc - ok
20:28:23.0957 5428  [ 3911B972B55FEA0478476B2E777B29FA ] AFD            C:\Windows\system32\drivers\afd.sys
20:28:23.0988 5428  AFD - ok
20:28:24.0004 5428  [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440          C:\Windows\system32\drivers\agp440.sys
20:28:24.0019 5428  agp440 - ok
20:28:24.0066 5428  [ 03081E98C515CB838434D252F407F6E8 ] ahcix86s        C:\Windows\system32\DRIVERS\ahcix86s.sys
20:28:24.0082 5428  ahcix86s - ok
20:28:24.0129 5428  [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
20:28:24.0144 5428  aic78xx - ok
20:28:24.0160 5428  [ A1545B731579895D8CC44FC0481C1192 ] ALG            C:\Windows\System32\alg.exe
20:28:24.0238 5428  ALG - ok
20:28:24.0253 5428  [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide          C:\Windows\system32\drivers\aliide.sys
20:28:24.0269 5428  aliide - ok
20:28:24.0316 5428  [ E4E01F3F9724C82378EB360C95A14540 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
20:28:24.0363 5428  AMD External Events Utility - ok
20:28:24.0378 5428  [ C47344BC706E5F0B9DCE369516661578 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
20:28:24.0394 5428  amdagp - ok
20:28:24.0441 5428  [ F12456AD77B1C32D8C5CA51927872850 ] amdide          C:\Windows\system32\DRIVERS\amdide.sys
20:28:24.0472 5428  amdide - ok
20:28:24.0487 5428  [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7          C:\Windows\system32\drivers\amdk7.sys
20:28:24.0534 5428  AmdK7 - ok
20:28:24.0550 5428  [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
20:28:24.0597 5428  AmdK8 - ok
20:28:24.0768 5428  [ 459465DA28E49B358ECFE0D788F328F4 ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe
20:28:24.0784 5428  AntiVirSchedulerService - ok
20:28:24.0815 5428  [ BCDD17E8469D647A71B347C4B6F86685 ] AntiVirService  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
20:28:24.0831 5428  AntiVirService - ok
20:28:24.0846 5428  [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo        C:\Windows\System32\appinfo.dll
20:28:24.0877 5428  Appinfo - ok
20:28:24.0955 5428  [ 018857EAD9A077A56AEDFC0E5EF7A24A ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:28:24.0955 5428  Apple Mobile Device - ok
20:28:25.0002 5428  [ 5D2888182FB46632511ACEE92FDAD522 ] arc            C:\Windows\system32\drivers\arc.sys
20:28:25.0018 5428  arc - ok
20:28:25.0049 5428  [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
20:28:25.0065 5428  arcsas - ok
20:28:25.0174 5428  [ 40C145F12FF461A0220303BDA134F598 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:28:25.0174 5428  aspnet_state - ok
20:28:25.0205 5428  [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
20:28:25.0267 5428  AsyncMac - ok
20:28:25.0283 5428  [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi          C:\Windows\system32\drivers\atapi.sys
20:28:25.0299 5428  atapi - ok
20:28:25.0455 5428  [ EC6B30E644E11D7B18382601F3F95807 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
20:28:25.0704 5428  atikmdag - ok
20:28:25.0751 5428  [ 5A1465AD2E7C1BC39CDA12A355329096 ] AtiPcie        C:\Windows\system32\DRIVERS\AtiPcie.sys
20:28:25.0767 5428  AtiPcie - ok
20:28:25.0829 5428  [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:28:25.0876 5428  AudioEndpointBuilder - ok
20:28:25.0907 5428  [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv        C:\Windows\System32\Audiosrv.dll
20:28:25.0923 5428  Audiosrv - ok
20:28:25.0985 5428  [ F4B56425A00BEB32F5FA6603FF7B0EA2 ] Avc            C:\Windows\system32\DRIVERS\avc.sys
20:28:26.0016 5428  Avc - ok
20:28:26.0063 5428  [ A5C175039B1D6D85D0E79F5855828E4D ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
20:28:26.0079 5428  avgntflt - ok
20:28:26.0141 5428  [ CAE7B6E4D7EB17829C526153D19B9C95 ] avgtp          C:\Windows\system32\drivers\avgtpx86.sys
20:28:26.0141 5428  avgtp - ok
20:28:26.0157 5428  [ 37B854C7D1F477E66C5B49C7700C47CC ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
20:28:26.0172 5428  avipbb - ok
20:28:26.0203 5428  [ CC4EBA25D80DE42BBC2BF3E553219388 ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
20:28:26.0203 5428  avkmgr - ok
20:28:26.0250 5428  [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep            C:\Windows\system32\drivers\Beep.sys
20:28:26.0313 5428  Beep - ok
20:28:26.0359 5428  [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE            C:\Windows\System32\bfe.dll
20:28:26.0406 5428  BFE - ok
20:28:26.0484 5428  [ 93952506C6D67330367F7E7934B6A02F ] BITS            C:\Windows\system32\qmgr.dll
20:28:26.0578 5428  BITS - ok
20:28:26.0593 5428  [ D4DF28447741FD3D953526E33A617397 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
20:28:26.0625 5428  blbdrive - ok
20:28:26.0671 5428  [ D002033C1A37F6AF51B5F0BA6D0211BC ] BMLoad          C:\Windows\system32\drivers\BMLoad.sys
20:28:26.0687 5428  BMLoad ( UnsignedFile.Multi.Generic ) - warning
20:28:26.0687 5428  BMLoad - detected UnsignedFile.Multi.Generic (1)
20:28:26.0781 5428  [ 673CF4F6BB1FBE09331B526802FBB892 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
20:28:26.0796 5428  Bonjour Service - ok
20:28:26.0859 5428  [ 35F376253F687BDE63976CCB3F2108CA ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
20:28:26.0874 5428  bowser - ok
20:28:26.0905 5428  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
20:28:26.0937 5428  BrFiltLo - ok
20:28:26.0983 5428  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
20:28:27.0030 5428  BrFiltUp - ok
20:28:27.0093 5428  [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser        C:\Windows\System32\browser.dll
20:28:27.0139 5428  Browser - ok
20:28:27.0186 5428  [ B304E75CFF293029EDDF094246747113 ] Brserid        C:\Windows\system32\drivers\brserid.sys
20:28:27.0342 5428  Brserid - ok
20:28:27.0342 5428  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
20:28:27.0436 5428  BrSerWdm - ok
20:28:27.0451 5428  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
20:28:27.0514 5428  BrUsbMdm - ok
20:28:27.0529 5428  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
20:28:27.0592 5428  BrUsbSer - ok
20:28:27.0607 5428  [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
20:28:27.0685 5428  BTHMODEM - ok
20:28:27.0904 5428  catchme - ok
20:28:27.0904 5428  [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
20:28:27.0966 5428  cdfs - ok
20:28:27.0982 5428  [ 6B4BFFB9BECD728097024276430DB314 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
20:28:28.0029 5428  cdrom - ok
20:28:28.0060 5428  [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc    C:\Windows\System32\certprop.dll
20:28:28.0091 5428  CertPropSvc - ok
20:28:28.0122 5428  [ E5D4133F37219DBCFE102BC61072589D ] circlass        C:\Windows\system32\drivers\circlass.sys
20:28:28.0169 5428  circlass - ok
20:28:28.0200 5428  [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS            C:\Windows\system32\CLFS.sys
20:28:28.0216 5428  CLFS - ok
20:28:28.0247 5428  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:28:28.0263 5428  clr_optimization_v2.0.50727_32 - ok
20:28:28.0325 5428  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:28:28.0356 5428  clr_optimization_v4.0.30319_32 - ok
20:28:28.0387 5428  [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
20:28:28.0403 5428  cmdide - ok
20:28:28.0419 5428  [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
20:28:28.0434 5428  Compbatt - ok
20:28:28.0434 5428  COMSysApp - ok
20:28:28.0450 5428  [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
20:28:28.0465 5428  crcdisk - ok
20:28:28.0481 5428  [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
20:28:28.0528 5428  Crusoe - ok
20:28:28.0590 5428  [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
20:28:28.0637 5428  CryptSvc - ok
20:28:28.0699 5428  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch      C:\Windows\system32\rpcss.dll
20:28:28.0777 5428  DcomLaunch - ok
20:28:28.0824 5428  [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
20:28:28.0871 5428  DfsC - ok
20:28:28.0965 5428  [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR            C:\Windows\system32\DFSR.exe
20:28:29.0136 5428  DFSR - ok
20:28:29.0183 5428  [ 9028559C132146FB75EB7ACF384B086A ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
20:28:29.0230 5428  Dhcp - ok
20:28:29.0261 5428  [ 5D4AEFC3386920236A548271F8F1AF6A ] disk            C:\Windows\system32\drivers\disk.sys
20:28:29.0277 5428  disk - ok
20:28:29.0323 5428  [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache        C:\Windows\System32\dnsrslvr.dll
20:28:29.0370 5428  Dnscache - ok
20:28:29.0401 5428  [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc        C:\Windows\System32\dot3svc.dll
20:28:29.0448 5428  dot3svc - ok
20:28:29.0479 5428  [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS            C:\Windows\system32\dps.dll
20:28:29.0511 5428  DPS - ok
20:28:29.0573 5428  [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
20:28:29.0604 5428  drmkaud - ok
20:28:29.0651 5428  [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
20:28:29.0682 5428  DXGKrnl - ok
20:28:29.0729 5428  [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60          C:\Windows\system32\DRIVERS\E1G60I32.sys
20:28:29.0760 5428  E1G60 - ok
20:28:29.0823 5428  [ C0B95E40D85CD807D614E264248A45B9 ] EapHost        C:\Windows\System32\eapsvc.dll
20:28:29.0854 5428  EapHost - ok
20:28:29.0932 5428  [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache          C:\Windows\system32\drivers\ecache.sys
20:28:29.0947 5428  Ecache - ok
20:28:30.0025 5428  [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
20:28:30.0057 5428  ehRecvr - ok
20:28:30.0072 5428  [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched        C:\Windows\ehome\ehsched.exe
20:28:30.0119 5428  ehSched - ok
20:28:30.0135 5428  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart        C:\Windows\ehome\ehstart.dll
20:28:30.0150 5428  ehstart - ok
20:28:30.0181 5428  [ 23B62471681A124889978F6295B3F4C6 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
20:28:30.0197 5428  elxstor - ok
20:28:30.0244 5428  [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
20:28:30.0322 5428  EMDMgmt - ok
20:28:30.0337 5428  [ 3DB974F3935483555D7148663F726C61 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
20:28:30.0384 5428  ErrDev - ok
20:28:30.0447 5428  [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem    C:\Windows\system32\es.dll
20:28:30.0478 5428  EventSystem - ok
20:28:30.0540 5428  [ 0F40E249E4DD0CE47C7CA19C5C8FB48A ] ewusbnet        C:\Windows\system32\DRIVERS\ewusbnet.sys
20:28:30.0649 5428  ewusbnet - ok
20:28:30.0696 5428  [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat          C:\Windows\system32\drivers\exfat.sys
20:28:30.0743 5428  exfat - ok
20:28:30.0883 5428  [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
20:28:30.0930 5428  fastfat - ok
20:28:30.0946 5428  [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
20:28:30.0977 5428  fdc - ok
20:28:31.0024 5428  [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost        C:\Windows\system32\fdPHost.dll
20:28:31.0039 5428  fdPHost - ok
20:28:31.0086 5428  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub        C:\Windows\system32\fdrespub.dll
20:28:31.0164 5428  FDResPub - ok
20:28:31.0211 5428  [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
20:28:31.0227 5428  FileInfo - ok
20:28:31.0227 5428  [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
20:28:31.0273 5428  Filetrace - ok
20:28:31.0289 5428  [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
20:28:31.0336 5428  flpydisk - ok
20:28:31.0367 5428  [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
20:28:31.0383 5428  FltMgr - ok
20:28:31.0492 5428  [ 8CE364388C8ECA59B14B539179276D44 ] FontCache      C:\Windows\system32\FntCache.dll
20:28:31.0585 5428  FontCache - ok
20:28:31.0648 5428  [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
20:28:31.0663 5428  FontCache3.0.0.0 - ok
20:28:31.0726 5428  [ 790A4CA68F44BE35967B3DF61F3E4675 ] FsUsbExDisk    C:\Windows\system32\FsUsbExDisk.SYS
20:28:31.0726 5428  FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
20:28:31.0726 5428  FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
20:28:31.0773 5428  [ D3F9205CC4CB07553F2F9472C767EA87 ] FsUsbExService  C:\Windows\system32\FsUsbExService.Exe
20:28:31.0788 5428  FsUsbExService ( UnsignedFile.Multi.Generic ) - warning
20:28:31.0788 5428  FsUsbExService - detected UnsignedFile.Multi.Generic (1)
20:28:31.0819 5428  [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
20:28:31.0866 5428  Fs_Rec - ok
20:28:31.0882 5428  [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
20:28:31.0897 5428  gagp30kx - ok
20:28:32.0007 5428  [ 927998FA07039F4B2CA11BC3B078575D ] GFilterSvc      C:\Windows\System32\GFilterSvc.exe
20:28:32.0022 5428  GFilterSvc ( UnsignedFile.Multi.Generic ) - warning
20:28:32.0022 5428  GFilterSvc - detected UnsignedFile.Multi.Generic (1)
20:28:32.0053 5428  [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio          C:\Windows\system32\giveio.sys
20:28:32.0085 5428  giveio ( UnsignedFile.Multi.Generic ) - warning
20:28:32.0085 5428  giveio - detected UnsignedFile.Multi.Generic (1)
20:28:32.0131 5428  [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc          C:\Windows\System32\gpsvc.dll
20:28:32.0178 5428  gpsvc - ok
20:28:32.0287 5428  [ 626A24ED1228580B9518C01930936DF9 ] gupdate1c9de4d978f7944 C:\Program Files\Google\Update\GoogleUpdate.exe
20:28:32.0287 5428  gupdate1c9de4d978f7944 - ok
20:28:32.0303 5428  [ 626A24ED1228580B9518C01930936DF9 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
20:28:32.0319 5428  gupdatem - ok
20:28:32.0381 5428  [ C1B577B2169900F4CF7190C39F085794 ] gusvc          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
20:28:32.0397 5428  gusvc - ok
20:28:32.0428 5428  [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:28:32.0475 5428  HdAudAddService - ok
20:28:32.0506 5428  [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
20:28:32.0568 5428  HDAudBus - ok
20:28:32.0584 5428  [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth          C:\Windows\system32\drivers\hidbth.sys
20:28:32.0646 5428  HidBth - ok
20:28:32.0662 5428  [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr          C:\Windows\system32\drivers\hidir.sys
20:28:32.0724 5428  HidIr - ok
20:28:32.0740 5428  [ 84067081F3318162797385E11A8F0582 ] hidserv        C:\Windows\System32\hidserv.dll
20:28:32.0755 5428  hidserv - ok
20:28:32.0787 5428  [ CCA4B519B17E23A00B826C55716809CC ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
20:28:32.0818 5428  HidUsb - ok
20:28:32.0849 5428  [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc          C:\Windows\system32\kmsvc.dll
20:28:32.0896 5428  hkmsvc - ok
20:28:32.0911 5428  [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
20:28:32.0927 5428  HpCISSs - ok
20:28:32.0958 5428  [ F870AA3E254628EBEAFE754108D664DE ] HTTP            C:\Windows\system32\drivers\HTTP.sys
20:28:33.0005 5428  HTTP - ok
20:28:33.0052 5428  [ 92CA47DA32009CCC00A5ADED04ABBD78 ] hwdatacard      C:\Windows\system32\DRIVERS\ewusbmdm.sys
20:28:33.0099 5428  hwdatacard - ok
20:28:33.0145 5428  [ 089085538885367E281686762A973EB5 ] hwusbfake      C:\Windows\system32\DRIVERS\ewusbfake.sys
20:28:33.0192 5428  hwusbfake - ok
20:28:33.0223 5428  [ C6B032D69650985468160FC9937CF5B4 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
20:28:33.0239 5428  i2omp - ok
20:28:33.0317 5428  [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
20:28:33.0348 5428  i8042prt - ok
20:28:33.0379 5428  [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
20:28:33.0395 5428  iaStorV - ok
20:28:33.0473 5428  [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:28:33.0504 5428  idsvc - ok
20:28:33.0551 5428  [ 6727B2CF2423C8C9FD9435CA5A8CDAD5 ] ieUnattd        C:\Windows\system32\rpchttpd.exe
20:28:33.0582 5428  ieUnattd ( UnsignedFile.Multi.Generic ) - warning
20:28:33.0582 5428  ieUnattd - detected UnsignedFile.Multi.Generic (1)
20:28:33.0598 5428  [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
20:28:33.0613 5428  iirsp - ok
20:28:33.0645 5428  [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT          C:\Windows\System32\ikeext.dll
20:28:33.0707 5428  IKEEXT - ok
20:28:33.0738 5428  [ 83AA759F3189E6370C30DE5DC5590718 ] intelide        C:\Windows\system32\drivers\intelide.sys
20:28:33.0754 5428  intelide - ok
20:28:33.0769 5428  [ 224191001E78C89DFA78924C3EA595FF ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
20:28:33.0801 5428  intelppm - ok
20:28:33.0847 5428  [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
20:28:33.0879 5428  IPBusEnum - ok
20:28:33.0894 5428  [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:28:33.0925 5428  IpFilterDriver - ok
20:28:33.0972 5428  [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
20:28:34.0019 5428  iphlpsvc - ok
20:28:34.0019 5428  IpInIp - ok
20:28:34.0050 5428  [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
20:28:34.0066 5428  IPMIDRV - ok
20:28:34.0081 5428  [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
20:28:34.0113 5428  IPNAT - ok
20:28:34.0113 5428  [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
20:28:34.0159 5428  IRENUM - ok
20:28:34.0175 5428  [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
20:28:34.0191 5428  isapnp - ok
20:28:34.0237 5428  [ 232FA340531D940AAC623B121A595034 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
20:28:34.0253 5428  iScsiPrt - ok
20:28:34.0269 5428  [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
20:28:34.0284 5428  iteatapi - ok
20:28:34.0300 5428  [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid        C:\Windows\system32\drivers\iteraid.sys
20:28:34.0300 5428  iteraid - ok
20:28:34.0331 5428  [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
20:28:34.0331 5428  kbdclass - ok
20:28:34.0347 5428  [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
20:28:34.0393 5428  kbdhid - ok
20:28:34.0425 5428  [ A3E186B4B935905B829219502557314E ] KeyIso          C:\Windows\system32\lsass.exe
20:28:34.0471 5428  KeyIso - ok
20:28:34.0518 5428  [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
20:28:34.0534 5428  KSecDD - ok
20:28:34.0612 5428  [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm          C:\Windows\system32\msdtckrm.dll
20:28:34.0659 5428  KtmRm - ok
20:28:34.0705 5428  [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer    C:\Windows\System32\srvsvc.dll
20:28:34.0721 5428  LanmanServer - ok
20:28:34.0752 5428  [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:28:34.0815 5428  LanmanWorkstation - ok
20:28:34.0861 5428  [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
20:28:34.0893 5428  lltdio - ok
20:28:34.0939 5428  [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
20:28:34.0971 5428  lltdsvc - ok
20:28:35.0002 5428  [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts        C:\Windows\System32\lmhsvc.dll
20:28:35.0049 5428  lmhosts - ok
20:28:35.0064 5428  [ C7E15E82879BF3235B559563D4185365 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
20:28:35.0080 5428  LSI_FC - ok
20:28:35.0111 5428  [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
20:28:35.0127 5428  LSI_SAS - ok
20:28:35.0142 5428  [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
20:28:35.0158 5428  LSI_SCSI - ok
20:28:35.0173 5428  [ 8F5C7426567798E62A3B3614965D62CC ] luafv          C:\Windows\system32\drivers\luafv.sys
20:28:35.0220 5428  luafv - ok
20:28:35.0236 5428  [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
20:28:35.0267 5428  Mcx2Svc - ok
20:28:35.0329 5428  [ 0001CE609D66632FA17B84705F658879 ] megasas        C:\Windows\system32\drivers\megasas.sys
20:28:35.0329 5428  megasas - ok
20:28:35.0361 5428  [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
20:28:35.0376 5428  MegaSR - ok
20:28:35.0423 5428  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS          C:\Windows\system32\mmcss.dll
20:28:35.0470 5428  MMCSS - ok
20:28:35.0485 5428  [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem          C:\Windows\system32\drivers\modem.sys
20:28:35.0532 5428  Modem - ok
20:28:35.0563 5428  [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
20:28:35.0595 5428  monitor - ok
20:28:35.0626 5428  [ 5BF6A1326A335C5298477754A506D263 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
20:28:35.0641 5428  mouclass - ok
20:28:35.0641 5428  [ 93B8D4869E12CFBE663915502900876F ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
20:28:35.0688 5428  mouhid - ok
20:28:35.0688 5428  [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
20:28:35.0704 5428  MountMgr - ok
20:28:35.0766 5428  [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
20:28:35.0782 5428  MozillaMaintenance - ok
20:28:35.0797 5428  [ 511D011289755DD9F9A7579FB0B064E6 ] mpio            C:\Windows\system32\drivers\mpio.sys
20:28:35.0813 5428  mpio - ok
20:28:35.0829 5428  [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
20:28:35.0860 5428  mpsdrv - ok
20:28:35.0907 5428  [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc          C:\Windows\system32\mpssvc.dll
20:28:35.0969 5428  MpsSvc - ok
20:28:36.0016 5428  [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
20:28:36.0016 5428  Mraid35x - ok
20:28:36.0063 5428  [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
20:28:36.0094 5428  MRxDAV - ok
20:28:36.0125 5428  [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
20:28:36.0172 5428  mrxsmb - ok
20:28:36.0203 5428  [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:28:36.0234 5428  mrxsmb10 - ok
20:28:36.0265 5428  [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:28:36.0281 5428  mrxsmb20 - ok
20:28:36.0328 5428  [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci          C:\Windows\system32\drivers\msahci.sys
20:28:36.0343 5428  msahci - ok
20:28:36.0359 5428  [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
20:28:36.0375 5428  msdsm - ok
20:28:36.0406 5428  [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC          C:\Windows\System32\msdtc.exe
20:28:36.0437 5428  MSDTC - ok
20:28:36.0484 5428  [ 343291A4DFD7C923C3F71F550830EC1C ] MSDV            C:\Windows\system32\DRIVERS\msdv.sys
20:28:36.0515 5428  MSDV - ok
20:28:36.0531 5428  [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
20:28:36.0562 5428  Msfs - ok
20:28:36.0593 5428  [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
20:28:36.0609 5428  msisadrv - ok
20:28:36.0640 5428  [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
20:28:36.0671 5428  MSiSCSI - ok
20:28:36.0671 5428  msiserver - ok
20:28:36.0702 5428  [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
20:28:36.0749 5428  MSKSSRV - ok
20:28:36.0780 5428  [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
20:28:36.0796 5428  MSPCLOCK - ok
20:28:36.0811 5428  [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
20:28:36.0843 5428  MSPQM - ok
20:28:36.0874 5428  [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
20:28:36.0889 5428  MsRPC - ok
20:28:36.0905 5428  [ E384487CB84BE41D09711C30CA79646C ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
20:28:36.0921 5428  mssmbios - ok
20:28:36.0952 5428  [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
20:28:36.0967 5428  MSTEE - ok
20:28:36.0983 5428  [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup            C:\Windows\system32\Drivers\mup.sys
20:28:36.0999 5428  Mup - ok
20:28:37.0014 5428  [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent        C:\Windows\system32\qagentRT.dll
20:28:37.0045 5428  napagent - ok
20:28:37.0077 5428  [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
20:28:37.0092 5428  NativeWifiP - ok
20:28:37.0123 5428  [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS            C:\Windows\system32\drivers\ndis.sys
20:28:37.0139 5428  NDIS - ok
20:28:37.0170 5428  [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
20:28:37.0217 5428  NdisTapi - ok
20:28:37.0233 5428  [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
20:28:37.0248 5428  Ndisuio - ok
20:28:37.0311 5428  [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
20:28:37.0326 5428  NdisWan - ok
20:28:37.0342 5428  [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
20:28:37.0357 5428  NDProxy - ok
20:28:37.0498 5428  [ 40D7D0A208EE863BCA8D89E299216F15 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
20:28:37.0545 5428  Nero BackItUp Scheduler 3 - ok
20:28:37.0591 5428  [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
20:28:37.0623 5428  NetBIOS - ok
20:28:37.0669 5428  [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
20:28:37.0716 5428  netbt - ok
20:28:37.0732 5428  [ A3E186B4B935905B829219502557314E ] Netlogon        C:\Windows\system32\lsass.exe
20:28:37.0747 5428  Netlogon - ok
20:28:37.0779 5428  [ C8052711DAECC48B982434C5116CA401 ] Netman          C:\Windows\System32\netman.dll
20:28:37.0825 5428  Netman - ok
20:28:37.0857 5428  [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm        C:\Windows\System32\netprofm.dll
20:28:37.0903 5428  netprofm - ok
20:28:37.0935 5428  [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:28:37.0935 5428  NetTcpPortSharing - ok
20:28:37.0981 5428  [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
20:28:37.0981 5428  nfrd960 - ok
20:28:38.0013 5428  [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc          C:\Windows\System32\nlasvc.dll
20:28:38.0044 5428  NlaSvc - ok
20:28:38.0153 5428  [ EBA1B4BF2E2375ABDADEDB649F283541 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
20:28:38.0200 5428  NMIndexingService - ok
20:28:38.0231 5428  [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
20:28:38.0262 5428  Npfs - ok
20:28:38.0309 5428  [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi            C:\Windows\system32\nsisvc.dll
20:28:38.0356 5428  nsi - ok
20:28:38.0371 5428  [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
20:28:38.0403 5428  nsiproxy - ok
20:28:38.0465 5428  [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
20:28:38.0512 5428  Ntfs - ok
20:28:38.0543 5428  [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi      C:\Windows\system32\drivers\ntrigdigi.sys
20:28:38.0574 5428  ntrigdigi - ok
20:28:38.0590 5428  [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null            C:\Windows\system32\drivers\Null.sys
20:28:38.0621 5428  Null - ok
20:28:38.0637 5428  [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
20:28:38.0652 5428  nvraid - ok
20:28:38.0668 5428  [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
20:28:38.0683 5428  nvstor - ok
20:28:38.0699 5428  [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
20:28:38.0715 5428  nv_agp - ok
20:28:38.0715 5428  NwlnkFlt - ok
20:28:38.0715 5428  NwlnkFwd - ok
20:28:38.0777 5428  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
20:28:38.0808 5428  odserv - ok
20:28:38.0855 5428  [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
20:28:38.0886 5428  ohci1394 - ok
20:28:38.0917 5428  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:28:38.0933 5428  ose - ok
20:28:38.0980 5428  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
20:28:39.0042 5428  p2pimsvc - ok
20:28:39.0073 5428  [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc          C:\Windows\system32\p2psvc.dll
20:28:39.0120 5428  p2psvc - ok
20:28:39.0136 5428  [ 0FA9B5055484649D63C303FE404E5F4D ] Parport        C:\Windows\system32\drivers\parport.sys
20:28:39.0183 5428  Parport - ok
20:28:39.0214 5428  [ B9C2B89F08670E159F7181891E449CD9 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
20:28:39.0229 5428  partmgr - ok
20:28:39.0245 5428  [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
20:28:39.0307 5428  Parvdm - ok
20:28:39.0339 5428  [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc          C:\Windows\System32\pcasvc.dll
20:28:39.0385 5428  PcaSvc - ok
20:28:39.0417 5428  [ 175CC28DCF819F78CAA3FBD44AD9E52A ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfd.sys
20:28:39.0463 5428  pccsmcfd - ok
20:28:39.0495 5428  [ 941DC1D19E7E8620F40BBC206981EFDB ] pci            C:\Windows\system32\drivers\pci.sys
20:28:39.0510 5428  pci - ok
20:28:39.0526 5428  [ FC175F5DDAB666D7F4D17449A547626F ] pciide          C:\Windows\system32\drivers\pciide.sys
20:28:39.0541 5428  pciide - ok
20:28:39.0557 5428  [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
20:28:39.0573 5428  pcmcia - ok
20:28:39.0619 5428  [ 5B6C11DE7E839C05248CED8825470FEF ] pcouffin        C:\Windows\system32\Drivers\pcouffin.sys
20:28:39.0635 5428  pcouffin - ok
20:28:39.0682 5428  [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
20:28:39.0791 5428  PEAUTH - ok
20:28:39.0853 5428  [ 4E87EF38A053F02E454935C8440EC91A ] pgsql-8.3      C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
20:28:39.0869 5428  pgsql-8.3 ( UnsignedFile.Multi.Generic ) - warning
20:28:39.0869 5428  pgsql-8.3 - detected UnsignedFile.Multi.Generic (1)
20:28:39.0916 5428  [ B1689DF169143F57053F795390C99DB3 ] pla            C:\Windows\system32\pla.dll
20:28:40.0009 5428  pla - ok
20:28:40.0041 5428  [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\Windows\system32\IoctlSvc.exe
20:28:40.0072 5428  PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - warning
20:28:40.0072 5428  PLFlash DeviceIoControl Service - detected UnsignedFile.Multi.Generic (1)
20:28:40.0119 5428  [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
20:28:40.0150 5428  PlugPlay - ok
20:28:40.0181 5428  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
20:28:40.0212 5428  PNRPAutoReg - ok
20:28:40.0243 5428  [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc        C:\Windows\system32\p2psvc.dll
20:28:40.0275 5428  PNRPsvc - ok
20:28:40.0321 5428  [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
20:28:40.0368 5428  PolicyAgent - ok
20:28:40.0399 5428  [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
20:28:40.0446 5428  PptpMiniport - ok
20:28:40.0477 5428  [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor      C:\Windows\system32\DRIVERS\processr.sys
20:28:40.0524 5428  Processor - ok
20:28:40.0555 5428  [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc        C:\Windows\system32\profsvc.dll
20:28:40.0602 5428  ProfSvc - ok
20:28:40.0618 5428  [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
20:28:40.0633 5428  ProtectedStorage - ok
20:28:40.0649 5428  [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
20:28:40.0680 5428  PSched - ok
20:28:40.0789 5428  [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
20:28:40.0836 5428  ql2300 - ok
20:28:40.0852 5428  [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
20:28:40.0867 5428  ql40xx - ok
20:28:40.0930 5428  [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE          C:\Windows\system32\qwave.dll
20:28:40.0961 5428  QWAVE - ok
20:28:40.0977 5428  [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
20:28:40.0992 5428  QWAVEdrv - ok
20:28:40.0992 5428  [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
20:28:41.0023 5428  RasAcd - ok
20:28:41.0023 5428  [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto        C:\Windows\System32\rasauto.dll
20:28:41.0070 5428  RasAuto - ok
20:28:41.0101 5428  [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
20:28:41.0133 5428  Rasl2tp - ok
20:28:41.0179 5428  [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan          C:\Windows\System32\rasmans.dll
20:28:41.0195 5428  RasMan - ok
20:28:41.0226 5428  [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
20:28:41.0257 5428  RasPppoe - ok
20:28:41.0273 5428  [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
20:28:41.0289 5428  RasSstp - ok
20:28:41.0320 5428  [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
20:28:41.0335 5428  rdbss - ok
20:28:41.0335 5428  [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
20:28:41.0367 5428  RDPCDD - ok
20:28:41.0398 5428  [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
20:28:41.0413 5428  rdpdr - ok
20:28:41.0429 5428  [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
20:28:41.0460 5428  RDPENCDD - ok
20:28:41.0491 5428  [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
20:28:41.0523 5428  RDPWD - ok
20:28:41.0569 5428  [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess    C:\Windows\System32\mprdim.dll
20:28:41.0632 5428  RemoteAccess - ok
20:28:41.0679 5428  [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry  C:\Windows\system32\regsvc.dll
20:28:41.0694 5428  RemoteRegistry - ok
20:28:41.0725 5428  [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator      C:\Windows\system32\locator.exe
20:28:41.0772 5428  RpcLocator - ok
20:28:41.0803 5428  [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs          C:\Windows\system32\rpcss.dll
20:28:41.0819 5428  RpcSs - ok
20:28:41.0850 5428  [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
20:28:41.0897 5428  rspndr - ok
20:28:41.0913 5428  [ ABBE0F54BA3A378262C9CB86CF7D91F8 ] RTL8169        C:\Windows\system32\DRIVERS\Rtlh86.sys
20:28:41.0959 5428  RTL8169 - ok
20:28:41.0959 5428  [ A3E186B4B935905B829219502557314E ] SamSs          C:\Windows\system32\lsass.exe
20:28:41.0975 5428  SamSs - ok
20:28:41.0991 5428  [ 3CE8F073A557E172B330109436984E30 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
20:28:42.0006 5428  sbp2port - ok
20:28:42.0037 5428  [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
20:28:42.0053 5428  SCardSvr - ok
20:28:42.0084 5428  [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule        C:\Windows\system32\schedsvc.dll
20:28:42.0162 5428  Schedule - ok
20:28:42.0209 5428  [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc    C:\Windows\System32\certprop.dll
20:28:42.0225 5428  SCPolicySvc - ok
20:28:42.0271 5428  [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
20:28:42.0318 5428  SDRSVC - ok
20:28:42.0474 5428  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\***\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
20:28:42.0505 5428  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
20:28:42.0505 5428  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
20:28:42.0537 5428  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
20:28:42.0583 5428  secdrv - ok
20:28:42.0615 5428  [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon        C:\Windows\system32\seclogon.dll
20:28:42.0630 5428  seclogon - ok
20:28:42.0646 5428  [ A9BBAB5759771E523F55563D6CBE140F ] SENS            C:\Windows\system32\sens.dll
20:28:42.0693 5428  SENS - ok
20:28:42.0724 5428  [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
20:28:42.0739 5428  Serenum - ok
20:28:42.0755 5428  [ 6D663022DB3E7058907784AE14B69898 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
20:28:42.0802 5428  Serial - ok
20:28:42.0817 5428  [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
20:28:42.0849 5428  sermouse - ok
20:28:42.0927 5428  [ 9D38320BB32230349379DF5DDBBF7FCE ] ServiceLayer    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
20:28:42.0942 5428  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
20:28:42.0942 5428  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
20:28:42.0989 5428  [ D2193326F729B163125610DBF3E17D57 ] SessionEnv      C:\Windows\system32\sessenv.dll
20:28:43.0005 5428  SessionEnv - ok
20:28:43.0020 5428  [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
20:28:43.0036 5428  sffdisk - ok
20:28:43.0083 5428  [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
20:28:43.0098 5428  sffp_mmc - ok
20:28:43.0114 5428  [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
20:28:43.0145 5428  sffp_sd - ok
20:28:43.0161 5428  [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
20:28:43.0223 5428  sfloppy - ok
20:28:43.0254 5428  [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
20:28:43.0270 5428  SharedAccess - ok
20:28:43.0317 5428  [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:28:43.0363 5428  ShellHWDetection - ok
20:28:43.0379 5428  [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
20:28:43.0395 5428  sisagp - ok
20:28:43.0395 5428  [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
20:28:43.0410 5428  SiSRaid2 - ok
20:28:43.0426 5428  [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
20:28:43.0441 5428  SiSRaid4 - ok
20:28:43.0535 5428  [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc          C:\Windows\system32\SLsvc.exe
20:28:43.0675 5428  slsvc - ok
20:28:43.0722 5428  [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify      C:\Windows\system32\SLUINotify.dll
20:28:43.0738 5428  SLUINotify - ok
20:28:43.0769 5428  [ 7B75299A4D201D6A6533603D6914AB04 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
20:28:43.0785 5428  Smb - ok
20:28:43.0831 5428  [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
20:28:43.0863 5428  SNMPTRAP - ok
20:28:43.0894 5428  [ 5D6401DB90EC81B71F8E2C5C8F0FEF23 ] speedfan        C:\Windows\system32\speedfan.sys
20:28:43.0894 5428  speedfan ( UnsignedFile.Multi.Generic ) - warning
20:28:43.0894 5428  speedfan - detected UnsignedFile.Multi.Generic (1)
20:28:43.0909 5428  [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr          C:\Windows\system32\drivers\spldr.sys
20:28:43.0925 5428  spldr - ok
20:28:43.0941 5428  [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler        C:\Windows\System32\spoolsv.exe
20:28:43.0987 5428  Spooler - ok
20:28:44.0019 5428  [ 41987F9FC0E61ADF54F581E15029AD91 ] srv            C:\Windows\system32\DRIVERS\srv.sys
20:28:44.0050 5428  srv - ok
20:28:44.0097 5428  [ FF33AFF99564B1AA534F58868CBE41EF ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
20:28:44.0143 5428  srv2 - ok
20:28:44.0190 5428  [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
20:28:44.0206 5428  srvnet - ok
20:28:44.0237 5428  [ D6870895FE46A464A19141440EB6CC1E ] sscdbus        C:\Windows\system32\DRIVERS\sscdbus.sys
20:28:44.0268 5428  sscdbus - ok
20:28:44.0299 5428  [ 0FE167362E4689B716CDC8D93ADEDDA8 ] sscdmdfl        C:\Windows\system32\DRIVERS\sscdmdfl.sys
20:28:44.0346 5428  sscdmdfl - ok
20:28:44.0377 5428  [ 55A15707E32B6709242AD127E62CA55A ] sscdmdm        C:\Windows\system32\DRIVERS\sscdmdm.sys
20:28:44.0393 5428  sscdmdm - ok
20:28:44.0440 5428  [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
20:28:44.0487 5428  SSDPSRV - ok
20:28:44.0518 5428  [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv          C:\Windows\system32\DRIVERS\ssmdrv.sys
20:28:44.0533 5428  ssmdrv - ok
20:28:44.0580 5428  [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
20:28:44.0580 5428  SstpSvc - ok
20:28:44.0627 5428  [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc          C:\Windows\System32\wiaservc.dll
20:28:44.0658 5428  stisvc - ok
20:28:44.0705 5428  [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
20:28:44.0721 5428  swenum - ok
20:28:44.0736 5428  [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv          C:\Windows\System32\swprv.dll
20:28:44.0783 5428  swprv - ok
20:28:44.0799 5428  [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
20:28:44.0814 5428  Symc8xx - ok
20:28:44.0830 5428  [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
20:28:44.0845 5428  Sym_hi - ok
20:28:44.0861 5428  [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
20:28:44.0861 5428  Sym_u3 - ok
20:28:44.0908 5428  [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain        C:\Windows\system32\sysmain.dll
20:28:44.0986 5428  SysMain - ok
20:28:45.0017 5428  [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:28:45.0033 5428  TabletInputService - ok
20:28:45.0064 5428  [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv        C:\Windows\System32\tapisrv.dll
20:28:45.0111 5428  TapiSrv - ok
20:28:45.0126 5428  [ CB05822CD9CC6C688168E113C603DBE7 ] TBS            C:\Windows\System32\tbssvc.dll
20:28:45.0157 5428  TBS - ok
20:28:45.0220 5428  [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
20:28:45.0251 5428  Tcpip - ok
20:28:45.0298 5428  [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
20:28:45.0329 5428  Tcpip6 - ok
20:28:45.0360 5428  [ DCFEB82CA988598CEB8F83148616038E ] tcpipBM        C:\Windows\system32\drivers\tcpipBM.sys
20:28:45.0360 5428  tcpipBM ( UnsignedFile.Multi.Generic ) - warning
20:28:45.0360 5428  tcpipBM - detected UnsignedFile.Multi.Generic (1)
20:28:45.0391 5428  [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
20:28:45.0423 5428  tcpipreg - ok
20:28:45.0438 5428  [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
20:28:45.0469 5428  TDPIPE - ok
20:28:45.0469 5428  [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
20:28:45.0501 5428  TDTCP - ok
20:28:45.0532 5428  [ 76B06EB8A01FC8624D699E7045303E54 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
20:28:45.0547 5428  tdx - ok
20:28:45.0547 5428  [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
20:28:45.0563 5428  TermDD - ok
20:28:45.0579 5428  [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService    C:\Windows\System32\termsrv.dll
20:28:45.0657 5428  TermService - ok
20:28:45.0672 5428  [ C7230FBEE14437716701C15BE02C27B8 ] Themes          C:\Windows\system32\shsvcs.dll
20:28:45.0688 5428  Themes - ok
20:28:45.0719 5428  [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER    C:\Windows\system32\mmcss.dll
20:28:45.0735 5428  THREADORDER - ok
20:28:45.0781 5428  [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks          C:\Windows\System32\trkwks.dll
20:28:45.0813 5428  TrkWks - ok
20:28:45.0859 5428  [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:28:45.0891 5428  TrustedInstaller - ok
20:28:45.0906 5428  [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
20:28:45.0937 5428  tssecsrv - ok
20:28:45.0953 5428  [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
20:28:46.0000 5428  tunmp - ok
20:28:46.0031 5428  [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
20:28:46.0047 5428  tunnel - ok
20:28:46.0047 5428  [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35          C:\Windows\system32\drivers\uagp35.sys
20:28:46.0062 5428  uagp35 - ok
20:28:46.0093 5428  [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
20:28:46.0125 5428  udfs - ok
20:28:46.0140 5428  [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
20:28:46.0187 5428  UI0Detect - ok
20:28:46.0203 5428  [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
20:28:46.0218 5428  uliagpkx - ok
20:28:46.0265 5428  [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci        C:\Windows\system32\drivers\uliahci.sys
20:28:46.0281 5428  uliahci - ok
20:28:46.0296 5428  [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata          C:\Windows\system32\drivers\ulsata.sys
20:28:46.0296 5428  UlSata - ok
20:28:46.0327 5428  [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
20:28:46.0327 5428  ulsata2 - ok
20:28:46.0343 5428  [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
20:28:46.0374 5428  umbus - ok
20:28:46.0405 5428  [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost        C:\Windows\System32\upnphost.dll
20:28:46.0452 5428  upnphost - ok
20:28:46.0483 5428  [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
20:28:46.0515 5428  usbccgp - ok
20:28:46.0546 5428  [ E9476E6C486E76BC4898074768FB7131 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
20:28:46.0593 5428  usbcir - ok
20:28:46.0639 5428  [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
20:28:46.0686 5428  usbehci - ok
20:28:46.0717 5428  [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
20:28:46.0733 5428  usbhub - ok
20:28:46.0749 5428  [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
20:28:46.0795 5428  usbohci - ok
20:28:46.0811 5428  [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
20:28:46.0858 5428  usbprint - ok
20:28:46.0873 5428  [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:28:46.0905 5428  USBSTOR - ok
20:28:46.0905 5428  [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
20:28:46.0951 5428  usbuhci - ok
20:28:46.0967 5428  [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms          C:\Windows\System32\uxsms.dll
20:28:46.0998 5428  UxSms - ok
20:28:47.0029 5428  [ CD88D1B7776DC17A119049742EC07EB4 ] vds            C:\Windows\System32\vds.exe
20:28:47.0061 5428  vds - ok
20:28:47.0107 5428  [ 87B06E1F30B749A114F74622D013F8D4 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
20:28:47.0123 5428  vga - ok
20:28:47.0139 5428  [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave        C:\Windows\System32\drivers\vga.sys
20:28:47.0185 5428  VgaSave - ok
20:28:47.0217 5428  [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp          C:\Windows\system32\drivers\viaagp.sys
20:28:47.0232 5428  viaagp - ok
20:28:47.0248 5428  [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7          C:\Windows\system32\drivers\viac7.sys
20:28:47.0263 5428  ViaC7 - ok
20:28:47.0295 5428  [ AADF5587A4063F52C2C3FED7887426FC ] viaide          C:\Windows\system32\drivers\viaide.sys
20:28:47.0295 5428  viaide - ok
20:28:47.0373 5428  [ 1B0D441D8AB264D39C2B09130CC28045 ] VMCService      C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
20:28:47.0388 5428  VMCService ( UnsignedFile.Multi.Generic ) - warning
20:28:47.0388 5428  VMCService - detected UnsignedFile.Multi.Generic (1)
20:28:47.0404 5428  [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
20:28:47.0404 5428  volmgr - ok
20:28:47.0435 5428  [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
20:28:47.0451 5428  volmgrx - ok
20:28:47.0482 5428  [ 786DB5771F05EF300390399F626BF30A ] volsnap        C:\Windows\system32\drivers\volsnap.sys
20:28:47.0497 5428  volsnap - ok
20:28:47.0544 5428  [ 587253E09325E6BF226B299774B728A9 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
20:28:47.0560 5428  vsmraid - ok
20:28:47.0607 5428  [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS            C:\Windows\system32\vssvc.exe
20:28:47.0700 5428  VSS - ok
20:28:47.0841 5428  [ 3AD1E72748978D8B0B3B674741E4C3E2 ] vToolbarUpdater14.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
20:28:47.0872 5428  vToolbarUpdater14.2.0 - ok
20:28:47.0903 5428  [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time        C:\Windows\system32\w32time.dll
20:28:47.0934 5428  W32Time - ok
20:28:47.0950 5428  [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
20:28:47.0997 5428  WacomPen - ok
20:28:48.0012 5428  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
20:28:48.0043 5428  Wanarp - ok
20:28:48.0059 5428  [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
20:28:48.0075 5428  Wanarpv6 - ok
20:28:48.0090 5428  [ A3CD60FD826381B49F03832590E069AF ] wcncsvc        C:\Windows\System32\wcncsvc.dll
20:28:48.0121 5428  wcncsvc - ok
20:28:48.0153 5428  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:28:48.0168 5428  WcsPlugInService - ok
20:28:48.0215 5428  [ 78FE9542363F297B18C027B2D7E7C07F ] Wd              C:\Windows\system32\drivers\wd.sys
20:28:48.0215 5428  Wd - ok
20:28:48.0277 5428  [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
20:28:48.0293 5428  Wdf01000 - ok
20:28:48.0324 5428  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
20:28:48.0371 5428  WdiServiceHost - ok
20:28:48.0371 5428  [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost  C:\Windows\system32\wdi.dll
20:28:48.0402 5428  WdiSystemHost - ok
20:28:48.0433 5428  [ 04C37D8107320312FBAE09926103D5E2 ] WebClient      C:\Windows\System32\webclnt.dll
20:28:48.0465 5428  WebClient - ok
20:28:48.0511 5428  [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc          C:\Windows\system32\wecsvc.dll
20:28:48.0574 5428  Wecsvc - ok
20:28:48.0589 5428  [ 670FF720071ED741206D69BD995EA453 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
20:28:48.0621 5428  wercplsupport - ok
20:28:48.0667 5428  [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc          C:\Windows\System32\WerSvc.dll
20:28:48.0683 5428  WerSvc - ok
20:28:48.0730 5428  [ 4575AA12561C5648483403541D0D7F2B ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
20:28:48.0745 5428  WinDefend - ok
20:28:48.0761 5428  WinHttpAutoProxySvc - ok
20:28:48.0792 5428  [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
20:28:48.0808 5428  Winmgmt - ok
20:28:48.0855 5428  [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM          C:\Windows\system32\WsmSvc.dll
20:28:48.0948 5428  WinRM - ok
20:28:48.0979 5428  [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc        C:\Windows\System32\wlansvc.dll
20:28:49.0057 5428  Wlansvc - ok
20:28:49.0089 5428  [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
20:28:49.0120 5428  WmiAcpi - ok
20:28:49.0167 5428  [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
20:28:49.0198 5428  wmiApSrv - ok
20:28:49.0245 5428  [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
20:28:49.0354 5428  WMPNetworkSvc - ok
20:28:49.0369 5428  [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
20:28:49.0385 5428  WPCSvc - ok
20:28:49.0432 5428  [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
20:28:49.0463 5428  WPDBusEnum - ok
20:28:49.0479 5428  [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
20:28:49.0494 5428  WpdUsb - ok
20:28:49.0603 5428  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
20:28:49.0635 5428  WPFFontCache_v0400 - ok
20:28:49.0650 5428  [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
20:28:49.0697 5428  ws2ifsl - ok
20:28:49.0744 5428  [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc          C:\Windows\system32\wscsvc.dll
20:28:49.0775 5428  wscsvc - ok
20:28:49.0775 5428  WSearch - ok
20:28:49.0853 5428  [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv        C:\Windows\system32\wuaueng.dll
20:28:49.0915 5428  wuauserv - ok
20:28:50.0009 5428  [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
20:28:50.0040 5428  WudfPf - ok
20:28:50.0071 5428  [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
20:28:50.0087 5428  WUDFRd - ok
20:28:50.0149 5428  [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
20:28:50.0181 5428  wudfsvc - ok
20:28:50.0196 5428  ================ Scan global ===============================
20:28:50.0227 5428  [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
20:28:50.0259 5428  [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
20:28:50.0274 5428  [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
20:28:50.0321 5428  [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
20:28:50.0337 5428  [Global] - ok
20:28:50.0337 5428  ================ Scan MBR ==================================
20:28:50.0337 5428  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
20:28:50.0617 5428  \Device\Harddisk0\DR0 - ok
20:28:50.0617 5428  ================ Scan VBR ==================================
20:28:50.0617 5428  [ 10A932C9A19CD84BCA32FBB98A93DEC1 ] \Device\Harddisk0\DR0\Partition1
20:28:50.0617 5428  \Device\Harddisk0\DR0\Partition1 - ok
20:28:50.0633 5428  [ ECD76066D316B167E28C6B7D2110FDC7 ] \Device\Harddisk0\DR0\Partition2
20:28:50.0633 5428  \Device\Harddisk0\DR0\Partition2 - ok
20:28:50.0633 5428  ============================================================
20:28:50.0633 5428  Scan finished
20:28:50.0633 5428  ============================================================
20:28:50.0649 3268  Detected object count: 13
20:28:50.0649 3268  Actual detected object count: 13
20:29:31.0958 3268  BMLoad ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0958 3268  BMLoad ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0958 3268  FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0958 3268  FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0958 3268  FsUsbExService ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0958 3268  FsUsbExService ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0958 3268  GFilterSvc ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0958 3268  GFilterSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0958 3268  giveio ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0958 3268  giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0958 3268  ieUnattd ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0958 3268  ieUnattd ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0974 3268  pgsql-8.3 ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0974 3268  pgsql-8.3 ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0974 3268  PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0974 3268  PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0974 3268  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0974 3268  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0974 3268  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0974 3268  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0974 3268  speedfan ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0974 3268  speedfan ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0974 3268  tcpipBM ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0974 3268  tcpipBM ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:29:31.0974 3268  VMCService ( UnsignedFile.Multi.Generic ) - skipped by user
20:29:31.0974 3268  VMCService ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 20.03.2013 13:01

Zitat:

C:\Windows\system32\rpchttpd.exe
Bitte diese Datei bei Virustotal auswerten lassen und den Ergebnislink posten. Falls Du die Datei nicht siehst, musst Du sie evtl. vorher sichtbar machen.
Wenn die Datei schon ausgewertet sein sollte, bitte eine weitere Auswertung starten.

Dramatist 20.03.2013 17:47

Okay. Auswertung habe ich hingekriegt. Ich hoffe, das Folgende meinst Du mit Ergebnislink:

https://www.virustotal.com/de/file/e95e6baa8ebf3519f4b45bef5cabf9b2482386f958c47ba553e099cf09c2dd19/analysis/1363797780/

cosinus 20.03.2013 22:53

Dann bitte jetzt Combofix ausführen:

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Dramatist 21.03.2013 11:26

Code:

ComboFix 13-03-20.02 - *** 21.03.2013  11:06:55.4.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3325.2255 [GMT 1:00]
ausgeführt von:: c:\users\***\Desktop\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\***\AppData\Roaming\Microsoft\Windows\Recent\Kritik am Schulsystem Hüther will Gymnasium und Lehrpläne abschaffen - SPIEGEL ONLINE.URL
c:\windows\system32\GFilterSvc.exe~RF23909.TMP
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-02-21 bis 2013-03-21  ))))))))))))))))))))))))))))))
.
.
2013-03-21 10:14 . 2013-03-21 10:14        --------        d-----w-        c:\users\***\AppData\Local\temp
2013-03-20 20:55 . 2013-02-12 01:57        15872        ----a-w-        c:\windows\system32\drivers\usb8023.sys
2013-03-19 08:31 . 2013-02-08 00:45        6954968        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{74C8F4F5-4615-41AE-BC14-C587C46FB140}\mpengine.dll
2013-03-14 14:33 . 2013-03-14 14:33        --------        d-----w-        c:\users\***\AppData\Roaming\ERGOM
2013-03-14 14:31 . 2013-03-14 14:31        --------        d-----w-        c:\program files\Business Objects
2013-03-14 14:30 . 2013-03-14 14:30        --------        d-----w-        c:\program files\Ergom
2013-03-13 19:39 . 2013-03-13 19:39        --------        d-----w-        c:\users\***\AppData\Roaming\Kalenderchen
2013-03-13 19:36 . 2013-03-18 21:24        95232        ----a-w-        c:\windows\system32\GFilterSvc.exe
2013-03-13 19:36 . 2013-03-13 19:36        67584        ----a-w-        c:\windows\system32\rpchttpd.exe
2013-03-13 19:36 . 2011-05-13 12:16        493056        ----a-w-        c:\windows\system32\dhRichClient3.dll
2013-03-13 19:36 . 2011-03-25 20:42        338432        ----a-w-        c:\windows\system32\sqlite36_engine.dll
2013-03-13 19:36 . 2013-03-13 19:36        --------        d-----w-        c:\users\***\AppData\Roaming\DesktopIconForAmazon
2013-03-13 19:36 . 2013-03-13 19:36        --------        d-----w-        c:\users\***\AppData\Roaming\OCS
2013-03-13 17:33 . 2013-03-13 17:33        --------        d-----w-        c:\users\***\AppData\Roaming\ASCOMP Software
2013-03-13 17:33 . 2013-03-13 17:33        --------        d-----w-        c:\program files\ASCOMP Software
2013-03-12 21:42 . 2013-03-13 14:15        --------        d-----w-        c:\program files\Mozilla Thunderbird
2013-03-08 08:31 . 2013-03-08 08:32        --------        d-----w-        c:\users\***\AppData\Roaming\Ahnenblatt
2013-02-24 11:30 . 2013-02-24 11:30        --------        d-----w-        c:\users\***\AppData\Roaming\Avira
2013-02-24 11:24 . 2013-02-24 09:19        36552        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-02-24 11:24 . 2013-02-24 09:19        83944        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-02-24 11:24 . 2013-02-24 09:19        134336        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-02-24 11:23 . 2013-02-24 11:23        --------        d-----w-        c:\programdata\Avira
2013-02-24 11:23 . 2013-02-24 11:23        --------        d-----w-        c:\program files\Avira
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-12 18:30 . 2012-04-09 15:28        693976        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2013-03-12 18:30 . 2011-06-15 07:21        73432        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-18 20:43 . 2012-08-29 15:29        33112        ----a-w-        c:\windows\system32\drivers\avgtpx86.sys
2013-01-17 00:28 . 2009-10-03 13:46        232336        ------w-        c:\windows\system32\MpSigStub.exe
2013-01-15 15:56 . 2012-09-10 21:01        477616        ----a-w-        c:\windows\system32\npdeployJava1.dll
2013-01-15 15:56 . 2011-04-04 20:42        473520        ----a-w-        c:\windows\system32\deployJava1.dll
2013-01-05 05:26 . 2013-02-13 07:32        3602808        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2013-01-05 05:26 . 2013-02-13 07:32        3550072        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-01-04 11:28 . 2013-02-13 07:32        905576        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-01-04 01:38 . 2013-02-13 07:32        2048512        ----a-w-        c:\windows\system32\win32k.sys
2013-03-07 14:30 . 2013-03-08 09:09        263064        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-02-18 20:43        1929392        ----a-w-        c:\program files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll" [2013-02-18 1929392]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"WizMouse"="c:\program files\WizMouse\WizMouse.exe" [2010-05-23 723248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2013-02-18 1151152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-02-24 385248]
"Ocs_SM"="c:\users\***\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2013-03-13 106496]
.
c:\users\autor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2013-03-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:30]
.
2013-03-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-26 22:01]
.
2013-03-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-26 22:01]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.delta-search.com/?affID=119828&babsrc=HP_ss&mntrId=CE8A0024211949FC
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{07BA1DA9-F501-4796-8728-74D1B91A6CD5} - c:\program files\PokerStars.EU\PokerStarsUpdate.exe
LSP: bmnet.dll
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\
FF - prefs.js: browser.search.selectedEngine - Amazon.de
FF - ExtSQL: 2013-02-18 15:51; {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
FF - ExtSQL: 2013-03-13 20:36; firejump@firejump.net; c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\extensions\firejump@firejump.net
FF - ExtSQL: !HIDDEN! 2009-06-25 03:00; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2013-03-13 20:36; firejump@firejump.net; c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\extensions\firejump@firejump.net
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=ce8aa8950000000000000024211949fc&q=
FF - user.js: extensions.BabylonToolbar.id - ce8aa8950000000000000024211949fc
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15581
FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.9.12
FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.9.12
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.9.1217:25
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109958&tt=3512_1
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - ce8aa8950000000000000024211949fc
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15777
FF - user.js: extensions.delta.vrsn - 1.8.10.0
FF - user.js: extensions.delta.vrsni - 1.8.10.0
FF - user.js: extensions.delta.vrsnTs - 1.8.10.020:41
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.6.9.12\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-03-21 11:14
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'lsass.exe'(652)
c:\windows\system32\bmnet.dll
.
Zeit der Fertigstellung: 2013-03-21  11:16:54
ComboFix-quarantined-files.txt  2013-03-21 10:16
.
Vor Suchlauf: 21 Verzeichnis(se), 287.029.846.016 Bytes frei
Nach Suchlauf: 23 Verzeichnis(se), 287.417.131.008 Bytes frei
.
- - End Of File - - EA1DB66E1126D8881427656C00A752AE


cosinus 21.03.2013 11:31

Combofix-Skript
WARNUNG für die MITLESER:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

  • Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von folgenden Download-Spiegel neu herunter: Link
  • Speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!
  • Drücke die Windows + R Taste --> notepad (hinein schreiben) --> OK
  • Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
    Code:

    File::
    c:\windows\system32\rpchttpd.exe

  • Speichere dies als CFScript.txt auf deinem Desktop.
  • Wichtig: Stelle deine Anti Viren Software temporär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Schließe alle laufenden Programme damit ComboFix ungehindert arbeiten kann.
  • Ziehe CFScript.txt in die ComboFix.exe wie in diesem Bild:
  • Mache nichts am Computer, bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein. Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Wenn ComboFix fertig ist wird es ein Log erstellen: C:\ComboFix.txt
    Bitte füge es hier als Antwort (in CODE-Tags mit dem #-Button des Editors) ein.

Hinweis:
Suspect:: und Collect::
Falls im Skript diese Anweisungen enthalten sind, sollen Dateien zur Analyse eingeschickt werden. Es erscheint eine Message-Box, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen. Teile mir unbedingt mit, ob der Upload geklappt hat!


Dramatist 21.03.2013 14:24

Hallo,

Anweisungen für eine Analyse habe ich nicht bekommen. Das Logfile folgt hier:

Code:

ComboFix 13-03-20.02 - *** 21.03.2013  12:06:12.5.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3325.2283 [GMT 1:00]
ausgeführt von:: c:\users\***\Desktop\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\***\Desktop\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\rpchttpd.exe"
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\rpchttpd.exe
.
.
(((((((((((((((((((((((((((((((((((((((  Treiber/Dienste  )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ieUnattd
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-02-21 bis 2013-03-21  ))))))))))))))))))))))))))))))
.
.
2013-03-21 11:14 . 2013-03-21 11:21        --------        d-----w-        c:\users\***\AppData\Local\temp
2013-03-21 11:14 . 2013-03-21 11:14        --------        d-----w-        c:\users\Public\AppData\Local\temp
2013-03-21 11:14 . 2013-03-21 11:14        --------        d-----w-        c:\users\postgres\AppData\Local\temp
2013-03-21 11:14 . 2013-03-21 11:14        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-03-21 11:14 . 2013-03-21 11:14        --------        d-----w-        c:\users\autor\AppData\Local\temp
2013-03-20 20:55 . 2013-02-12 01:57        15872        ----a-w-        c:\windows\system32\drivers\usb8023.sys
2013-03-19 08:31 . 2013-02-08 00:45        6954968        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{74C8F4F5-4615-41AE-BC14-C587C46FB140}\mpengine.dll
2013-03-14 14:33 . 2013-03-14 14:33        --------        d-----w-        c:\users\***\AppData\Roaming\ERGOM
2013-03-14 14:31 . 2013-03-14 14:31        --------        d-----w-        c:\program files\Business Objects
2013-03-14 14:30 . 2013-03-14 14:30        --------        d-----w-        c:\program files\Ergom
2013-03-13 19:39 . 2013-03-13 19:39        --------        d-----w-        c:\users\***\AppData\Roaming\Kalenderchen
2013-03-13 19:36 . 2013-03-18 21:24        95232        ----a-w-        c:\windows\system32\GFilterSvc.exe
2013-03-13 19:36 . 2011-05-13 12:16        493056        ----a-w-        c:\windows\system32\dhRichClient3.dll
2013-03-13 19:36 . 2011-03-25 20:42        338432        ----a-w-        c:\windows\system32\sqlite36_engine.dll
2013-03-13 19:36 . 2013-03-13 19:36        --------        d-----w-        c:\users\***\AppData\Roaming\DesktopIconForAmazon
2013-03-13 19:36 . 2013-03-13 19:36        --------        d-----w-        c:\users\***\AppData\Roaming\OCS
2013-03-13 17:33 . 2013-03-13 17:33        --------        d-----w-        c:\users\***\AppData\Roaming\ASCOMP Software
2013-03-13 17:33 . 2013-03-13 17:33        --------        d-----w-        c:\program files\ASCOMP Software
2013-03-12 21:42 . 2013-03-13 14:15        --------        d-----w-        c:\program files\Mozilla Thunderbird
2013-03-08 08:31 . 2013-03-08 08:32        --------        d-----w-        c:\users\***\AppData\Roaming\Ahnenblatt
2013-02-24 11:30 . 2013-02-24 11:30        --------        d-----w-        c:\users\***\AppData\Roaming\Avira
2013-02-24 11:24 . 2013-02-24 09:19        36552        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-02-24 11:24 . 2013-02-24 09:19        83944        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-02-24 11:24 . 2013-02-24 09:19        134336        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-02-24 11:23 . 2013-02-24 11:23        --------        d-----w-        c:\programdata\Avira
2013-02-24 11:23 . 2013-02-24 11:23        --------        d-----w-        c:\program files\Avira
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-12 18:30 . 2012-04-09 15:28        693976        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2013-03-12 18:30 . 2011-06-15 07:21        73432        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-18 20:43 . 2012-08-29 15:29        33112        ----a-w-        c:\windows\system32\drivers\avgtpx86.sys
2013-01-17 00:28 . 2009-10-03 13:46        232336        ------w-        c:\windows\system32\MpSigStub.exe
2013-01-15 15:56 . 2012-09-10 21:01        477616        ----a-w-        c:\windows\system32\npdeployJava1.dll
2013-01-15 15:56 . 2011-04-04 20:42        473520        ----a-w-        c:\windows\system32\deployJava1.dll
2013-01-05 05:26 . 2013-02-13 07:32        3602808        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2013-01-05 05:26 . 2013-02-13 07:32        3550072        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-01-04 11:28 . 2013-02-13 07:32        905576        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-01-04 01:38 . 2013-02-13 07:32        2048512        ----a-w-        c:\windows\system32\win32k.sys
2013-03-07 14:30 . 2013-03-08 09:09        263064        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-02-18 20:43        1929392        ----a-w-        c:\program files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll" [2013-02-18 1929392]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"WizMouse"="c:\program files\WizMouse\WizMouse.exe" [2010-05-23 723248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2013-02-18 1151152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-02-24 385248]
"Ocs_SM"="c:\users\***\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2013-03-13 106496]
.
c:\users\autor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - BMLoad
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2013-03-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:30]
.
2013-03-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-26 22:01]
.
2013-03-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-26 22:01]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.delta-search.com/?affID=119828&babsrc=HP_ss&mntrId=CE8A0024211949FC
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{07BA1DA9-F501-4796-8728-74D1B91A6CD5} - c:\program files\PokerStars.EU\PokerStarsUpdate.exe
LSP: bmnet.dll
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll
FF - ProfilePath - c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\
FF - prefs.js: browser.search.selectedEngine - Amazon.de
FF - ExtSQL: 2013-02-18 15:51; {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
FF - ExtSQL: 2013-03-13 20:36; firejump@firejump.net; c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\extensions\firejump@firejump.net
FF - ExtSQL: !HIDDEN! 2009-06-25 03:00; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2013-03-13 20:36; firejump@firejump.net; c:\users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\extensions\firejump@firejump.net
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=ce8aa8950000000000000024211949fc&q=
FF - user.js: extensions.BabylonToolbar.id - ce8aa8950000000000000024211949fc
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15581
FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.9.12
FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.9.12
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.9.1217:25
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109958&tt=3512_1
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - ce8aa8950000000000000024211949fc
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15777
FF - user.js: extensions.delta.vrsn - 1.8.10.0
FF - user.js: extensions.delta.vrsni - 1.8.10.0
FF - user.js: extensions.delta.vrsnTs - 1.8.10.020:41
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-03-21 12:21
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'lsass.exe'(652)
c:\windows\system32\bmnet.dll
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\atiesrxx.exe
c:\windows\system32\atieclxx.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\FsUsbExService.Exe
c:\windows\System32\GFilterSvc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe
c:\windows\system32\IoctlSvc.exe
c:\users\***\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conime.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-03-21  12:24:13 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-03-21 11:24
ComboFix2.txt  2013-03-21 10:16
.
Vor Suchlauf: 22 Verzeichnis(se), 289.032.962.048 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 288.736.059.392 Bytes frei
.
- - End Of File - - 43CDD0393B264C5E2104F1895BBCF81F


cosinus 21.03.2013 16:48

Ok, bitte einen neuen Durchgang mit aswMBR machen

Dramatist 21.03.2013 22:28

Hi,
hab bei diesem Durchgang vergessen, den Virenscanner auszuschalten. Jetzt lässt er mich das nicht noch mal scannen. GEht es auch so ...?

Code:

aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-03-19 17:57:46
-----------------------------
17:57:46.662    OS Version: Windows 6.0.6002 Service Pack 2
17:57:46.662    Number of processors: 2 586 0x203
17:57:46.662    ComputerName: ***-PC  UserName: ***
17:57:48.597    Initialize success
17:59:50.004    AVAST engine defs: 13031900
18:00:00.409    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005d
18:00:00.409    Disk 0 Vendor: WDC_WD64 05.0 Size: 610480MB BusType: 8
18:00:00.659    Disk 0 MBR read successfully
18:00:00.659    Disk 0 MBR scan
18:00:00.674    Disk 0 Windows VISTA default MBR code
18:00:00.674    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      589993 MB offset 2048
18:00:00.690    Disk 0 Partition - 00    0F Extended LBA            20483 MB offset 1208307712
18:00:00.705    Disk 0 Partition 2 00    0B        FAT32 MSDOS5.0    20483 MB offset 1208307775
18:00:00.737    Disk 0 scanning sectors +1250258625
18:00:00.815    Disk 0 scanning C:\Windows\system32\drivers
18:00:12.125    Service scanning
18:00:18.708    Service ieUnattd C:\Windows\system32\rpchttpd.exe **INFECTED** Win32:Agent-AQRH [Trj]
18:00:31.125    Modules scanning
18:00:34.963    Disk 0 trace - called modules:
18:00:34.994    ntkrnlpa.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix86s.sys
18:00:34.994    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8728aac8]
18:00:35.010    3 CLASSPNP.SYS[8b5a28b3] -> nt!IofCallDriver -> \Device\0000005d[0x865b8890]
18:00:37.163    AVAST engine scan C:\Windows
18:00:41.000    AVAST engine scan C:\Windows\system32
18:02:03.542    File: C:\Windows\system32\rpchttpd.exe  **INFECTED** Win32:Agent-AQRH [Trj]
18:03:54.629    AVAST engine scan C:\Windows\system32\drivers
18:04:08.701    AVAST engine scan C:\Users\***
18:23:32.291    AVAST engine scan C:\ProgramData
18:26:43.297    Scan finished successfully
18:36:09.687    Disk 0 MBR has been saved successfully to "C:\Users\***\Desktop\Desktop\MBR.dat"
18:36:09.687    The log file has been saved successfully to "C:\Users\***\Desktop\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-03-21 20:27:39
-----------------------------
20:27:39.462    OS Version: Windows 6.0.6002 Service Pack 2
20:27:39.462    Number of processors: 2 586 0x203
20:27:39.462    ComputerName: ***-PC  UserName: ***
20:27:40.991    Initialize success
20:29:56.543    AVAST engine defs: 13032101
20:52:06.647    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005d
20:52:06.662    Disk 0 Vendor: WDC_WD64 05.0 Size: 610480MB BusType: 8
20:52:06.818    Disk 0 MBR read successfully
20:52:06.818    Disk 0 MBR scan
20:52:06.834    Disk 0 Windows VISTA default MBR code
20:52:06.849    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      589993 MB offset 2048
20:52:06.849    Disk 0 Partition - 00    0F Extended LBA            20483 MB offset 1208307712
20:52:06.865    Disk 0 Partition 2 00    0B        FAT32 MSDOS5.0    20483 MB offset 1208307775
20:52:06.943    Disk 0 scanning sectors +1250258625
20:52:07.005    Disk 0 scanning C:\Windows\system32\drivers
20:52:23.931    Service scanning
20:52:47.565    Modules scanning
20:52:52.043    Disk 0 trace - called modules:
20:52:52.573    ntkrnlpa.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix86s.sys
20:52:52.573    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86e0fac8]
20:52:52.573    3 CLASSPNP.SYS[8b1a08b3] -> nt!IofCallDriver -> \Device\0000005d[0x861b8ac8]
20:52:54.273    AVAST engine scan C:\Windows
20:52:59.000    AVAST engine scan C:\Windows\system32
20:58:01.314    AVAST engine scan C:\Windows\system32\drivers
20:58:19.113    AVAST engine scan C:\Users\***
21:19:56.224    AVAST engine scan C:\ProgramData
21:22:56.732    Scan finished successfully
21:42:00.165    Disk 0 MBR has been saved successfully to "C:\Users\***\Desktop\Desktop\MBR.dat"
21:42:00.258    The log file has been saved successfully to "C:\Users\***\Desktop\Desktop\aswMBR.txt"


cosinus 22.03.2013 12:40

JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




Im Anschluss:

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).


Danach eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles in CODE-Tags hier in den Thread.

Dramatist 23.03.2013 09:39

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.7.2 (03.15.2013:1)
OS: Windows Vista (TM) Home Premium x86
Ran by *** on 22.03.2013 at 18:06:01,82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{98889811-442d-49dd-99d7-dc866be87dbc}
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1492898777-1315905052-4281177461-1000\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1492898777-1315905052-4281177461-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_classes_root\esrv.babylonesrvc
Successfully deleted: [Registry Key] hkey_classes_root\esrv.babylonesrvc.1
Successfully deleted: [Registry Key] hkey_local_machine\software\babylon
Successfully deleted: [Registry Key] hkey_current_user\software\babylontoolbar
Successfully deleted: [Registry Key] hkey_local_machine\software\babylontoolbar
Successfully deleted: [Registry Key] hkey_current_user\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Failed to delete: [Registry Key] hkey_current_user\software\datamngr_toolbar
Successfully deleted: [Registry Key] hkey_current_user\software\iminent
Successfully deleted: [Registry Key] hkey_local_machine\software\iminent
Successfully deleted: [Registry Key] hkey_current_user\software\softonic
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\searchqutoolbar
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\babylon
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\lowregistry\search settings
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\browserconnection.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\dnsbho.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\scripthelper.exe
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\viprotocol.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\b
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\babylon.dskbnd
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\babylon.dskbnd.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\bbylnapp.appcore
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\bbylnapp.appcore.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\bbylntlbr.bbylntlbrhlpr
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\bbylntlbr.bbylntlbrhlpr.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\installer\products\79caa1b036589d14ea74856e2a220f1e
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\protocols\handler\viprotocol
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\searchquiehelper.dnsguard
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\searchquiehelper.dnsguard.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole.1
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{291bccc1-6890-484a-89d3-318c928dac1b}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{2eecd738-5844-4a99-b4b6-146bf802613b}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{2eecd738-5844-4a99-b4b6-146bf802613b}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{97f2ff5b-260c-4ccf-834a-2dda4e29e39e}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{98889811-442d-49dd-99d7-dc866be87dbc}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{b8276a94-891d-453c-9ff3-715c042a2575}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{cc1ac828-bb47-4361-afb5-96eee259dd87}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{ffb9adcb-8c79-4c29-81d3-74d46a93d370}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\Users\***\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\***\AppData\Roaming\babylontoolbar"
Successfully deleted: [Folder] "C:\Users\***\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Users\***\appdata\locallow\search settings"
Successfully deleted: [Folder] "C:\Users\***\appdata\locallow\searchquband"
Successfully deleted: [Folder] "C:\Users\***\appdata\locallow\searchqutoolbar"



~~~ FireFox

Successfully deleted: [File] C:\user.js
Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml"
Successfully deleted: [File] C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\user.js
Successfully deleted: [File] C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\invalidprefs.js
Successfully deleted: [File] "C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\extensions\jid0-3GUEt1r69sQNSrca5p8kx9Ezc3U@jetpack.xpi"
Successfully deleted: [File] C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\delta.xml
Successfully deleted: [File] C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\searchresults.xml
Successfully deleted: [Folder] C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchqutoolbar
Successfully deleted the following from C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\prefs.js

user_pref("extensions.BabylonToolbar.admin", false);
user_pref("extensions.BabylonToolbar.aflt", "babsst");
user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
user_pref("extensions.BabylonToolbar.autoRvrt", "false");
user_pref("extensions.BabylonToolbar.dfltLng", "en");
user_pref("extensions.BabylonToolbar.excTlbr", false);
user_pref("extensions.BabylonToolbar.id", "ce8aa8950000000000000024211949fc");
user_pref("extensions.BabylonToolbar.instlDay", "15581");
user_pref("extensions.BabylonToolbar.instlRef", "sst");
user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar.tlbrId", "base");
user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=ce8aa8950000000000000024211949fc&q=");
user_pref("extensions.BabylonToolbar.vrsn", "1.6.9.12");
user_pref("extensions.BabylonToolbar.vrsni", "1.6.9.12");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109958&tt=3512_1");
user_pref("extensions.BabylonToolbar_i.newTab", false);
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.9.1217:25:36");
user_pref("extensions.delta.admin", false);
user_pref("extensions.delta.aflt", "babsst");
user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
user_pref("extensions.delta.autoRvrt", "false");
user_pref("extensions.delta.dfltLng", "en");
user_pref("extensions.delta.excTlbr", false);
user_pref("extensions.delta.id", "ce8aa8950000000000000024211949fc");
user_pref("extensions.delta.instlDay", "15777");
user_pref("extensions.delta.instlRef", "sst");
user_pref("extensions.delta.newTab", false);
user_pref("extensions.delta.prdct", "delta");
user_pref("extensions.delta.prtnrId", "delta");
user_pref("extensions.delta.rvrt", "false");
user_pref("extensions.delta.smplGrp", "none");
user_pref("extensions.delta.tlbrId", "base");
user_pref("extensions.delta.tlbrSrchUrl", "");
user_pref("extensions.delta.vrsn", "1.8.10.0");
user_pref("extensions.delta.vrsnTs", "1.8.10.020:41:33");
user_pref("extensions.delta.vrsni", "1.8.10.0");
Emptied folder: C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\minidumps [168 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.03.2013 at 18:08:25,87
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Code:

# AdwCleaner v2.115 - Datei am 23/03/2013 um 08:37:55 erstellt
# Aktualisiert am 17/03/2013 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Benutzer : *** - ***-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\***\Desktop\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : GFilterSvc
Gestoppt & Gelöscht : SearchAnonymizer

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\eBay.lnk
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Windows\system32\GFilterSvc.exe
Gelöscht mit Neustart : C:\Program Files\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Program Files\AVG Secure Search
Ordner Gelöscht : C:\ProgramData\AVG Secure Search
Ordner Gelöscht : C:\Users\***\AppData\Local\AVG Secure Search
Ordner Gelöscht : C:\Users\***\AppData\LocalLow\AVG Secure Search
Ordner Gelöscht : C:\Users\***\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\extensions\firejump@firejump.net
Ordner Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\jetpack
Ordner Gelöscht : C:\Users\***\AppData\Roaming\OCS

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\853d688e534e544
Schlüssel Gelöscht : HKCU\Software\AppDataLow\AskBarDis
Schlüssel Gelöscht : HKCU\Software\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{206a7328-437f-4bd9-b53e-12bfee24d588}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DesktopIconAmazon
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchAnonymizer
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchqu 0 MediaBar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{206a7328-437f-4bd9-b53e-12bfee24d588}
Schlüssel Gelöscht : HKLM\SOFTWARE\853d688e534e544
Schlüssel Gelöscht : HKLM\Software\AVG Secure Search
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\6207E55EA2FE71A4AA7ABD89AEF31D1B
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\79CAA1B036589D14EA74856E2A220F1E
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\6207E55EA2FE71A4AA7ABD89AEF31D1B
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DA5BD2D3CA2D6943A1A233CD3F88CE7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC9EFC5C3366B4DB850DAB49330C52
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E98451C7CA808F47AFE467BDABD02FA
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFD11FD45FC7B9E46A8F4B69F3A66E35
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5979AD63CA2D6943A1A233CD3F88CE7
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF9BD2952384A9C49B4A5D3D95329890
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FABA2A33488410A4AA40489BD2224282
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6207E55EA2FE71A4AA7ABD89AEF31D1B
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\79CAA1B036589D14EA74856E2A220F1E
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\Software\Search Settings
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\extensions [firejump@firejump.net]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Ocs_SM]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16470

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v19.0.2 (de)

Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\zxapfs10.default\prefs.js

[OK] Die Datei ist sauber.

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Preferences

Gelöscht [l.8] : urls_to_restore_on_startup =,},"homepage":"hxxp://isearch.avg.com/?cid={9536F7B5-3CC2-431B-81F2-1F4AEC0ADECB}&mid=964f157627f547[...]

*************************

AdwCleaner[S1].txt - [356 octets] - [23/03/2013 08:36:55]
AdwCleaner[S2].txt - [17427 octets] - [23/03/2013 08:37:55]

########## EOF - C:\AdwCleaner[S2].txt - [17488 octets] ##########

Code:

OTL logfile created on: 23.03.2013 08:46:07 - Run 6
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\***\Desktop\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,10 Gb Available Physical Memory | 64,53% Memory free
6,69 Gb Paging File | 4,82 Gb Available in Paging File | 72,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 576,17 Gb Total Space | 268,84 Gb Free Space | 46,66% Space Free | Partition Type: NTFS
Drive D: | 19,99 Gb Total Space | 9,86 Gb Free Space | 49,31% Space Free | Partition Type: FAT32
 
Computer Name: ***-PC | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\***\Desktop\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\ipmgui.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe ()
PRC - C:\Program Files\WizMouse\WizMouse.exe (Antibody Software)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\PostgreSQL\8.3\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\421cb77e6a4c21f94e3c5ddf766de23b\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e64304962098e90f0d3f4c33c1b080a6\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9b2eef59d0cfc5aff182d0951de5f040\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b5df40c22ab563a816103629e2ca99d4\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\004bc6615f9c06df5c98859d35149fe6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\System32\CmdLineExt03.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3257.27012__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3257.26996__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3257.27013__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3257.27071__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3257.27008__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3257.27037__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3257.27003__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Dashboard\2.0.3257.27107__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3257.27092__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3257.27056__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3257.27093__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3257.27056__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Runtime\2.0.3257.27106__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3257.27003__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3257.27050__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3257.27055__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3257.27091__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3257.27039__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3257.27004__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3257.27014__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3257.27033__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3257.27065__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3257.27013__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3257.27048__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3257.27038__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3257.27017__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3257.27047__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3257.27049__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3257.27038__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3257.27037__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3257.27038__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3218.28677__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3218.28672__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3218.28683__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3218.28705__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3218.28685__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3218.28705__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3218.28666__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3218.28678__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3218.28664__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3218.28665__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3218.28727__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3218.28687__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0703\2.0.2651.18802__90ba9c70f846762e\DEM.Graphics.I0703.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3218.28681__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3218.28678__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3218.28672__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3218.28686__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.3218.28687__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3218.28688__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3218.28676__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3218.28690__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3218.28688__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3218.28694__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Shared\2.0.3218.28705__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3218.28693__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3218.28692__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3218.28694__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3218.28692__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3257.27101__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3218.28702__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3218.28694__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3218.28685__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3218.28701__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3218.28690__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3218.28688__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3218.28686__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3218.28693__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3218.28689__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.3218.28685__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3218.28670__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3218.28678__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll ()
MOD - C:\Windows\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3257.27109__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3257.26994__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3257.27000__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3257.27080__90ba9c70f846762e\CLI.Component.Systemtray.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3257.27008__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3257.27085__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3257.26994__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3257.27084__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3257.26995__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3218.28682__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3218.28670__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3218.28675__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3218.28672__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3257.27085__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3218.28681__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3218.28686__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3218.28682__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3218.28695__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.3257.26994__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.3257.26992__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.3257.26993__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
 
 
========== Services (SafeList) ==========
 
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (vToolbarUpdater14.2.0) -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe ()
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (pgsql-8.3) -- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avgtp) -- C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (ewusbnet) -- C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbfake) -- C:\Windows\System32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (BMLoad) -- C:\Windows\System32\drivers\BMLoad.sys (Bytemobile, Inc.)
DRV - (tcpipBM) -- C:\Windows\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (ahcix86s) -- C:\Windows\System32\drivers\ahcix86s.sys (Advanced Micro Devices, Inc)
DRV - (AtiPcie) -- C:\Windows\System32\drivers\AtiPcie.sys (ATI Technologies Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation                                            )
DRV - (amdide) -- C:\Windows\System32\drivers\amdide.sys (Advanced Micro Devices)
DRV - (pccsmcfd) -- C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (sscdmdm) -- C:\Windows\System32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) -- C:\Windows\System32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) -- C:\Windows\System32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (speedfan) -- C:\Windows\System32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (giveio) -- C:\Windows\System32\giveio.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\.DEFAULT\..\SearchScopes,defaultscope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-18\..\SearchScopes,defaultscope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-19\..\SearchScopes,defaultscope =
 
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-20\..\SearchScopes,defaultscope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E 32 AF FD 30 60 CD 01  [binary data]
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes,DefaultScope = {0181C607-A64D-4BBC-A2FA-55E2BB7554FB}
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{0181C607-A64D-4BBC-A2FA-55E2BB7554FB}: "URL" = hxxp://de.search.yahoo.com.anonymize-me.de/?anonymto=687474703A2F2F64652E7365617263682E7961686F6F2E636F6D2F7365617263683F66723D6368722D677265656E747265655F69652665693D7574662D3826747970653D38363730333426703D7B7365617263685465726D737D&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494538535243&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{2B5032A6-E854-4E0E-9C2A-C5DCF008CB01}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{359F0056-0341-420C-8B2A-49ED130C72CB}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{870CD05D-0A80-48CC-8D17-D2F4A591BF72}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{DE87B9B7-B9A2-4611-A089-A0EBC29158D5}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{EA9ED40B-01DC-4B88-AA21-3DAA4553C4E7}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\..\SearchScopes\{FF56FBFE-2BB1-46A0-942A-6BD0B16DE457}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=5207cd4e-d476-4bdd-9ee1-9f47ac8e232e&pid=freewarede&mode=bounce&k=0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\S-1-5-21-1492898777-1315905052-4281177461-1004\..\SearchScopes,DefaultScope =
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130129
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.5.8
FF - prefs.js..extensions.enabledAddons: toolbar%40web.de:2.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2009.12.17 20:20:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.13 22:47:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.08 10:09:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.03.12 22:42:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.03.12 22:42:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.03.12 22:42:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2013.03.12 22:42:34 | 000,000,000 | ---D | M]
 
[2011.09.14 22:03:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions
[2010.08.28 17:20:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.03.23 08:38:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\zxapfs10.default\extensions
[2010.06.25 19:17:41 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\zxapfs10.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013.01.31 08:30:06 | 000,000,000 | ---D | M] (WOT) -- C:\Users\***\AppData\Roaming\mozilla\Firefox\Profiles\zxapfs10.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013.03.22 10:31:35 | 000,549,639 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\extensions\toolbar@web.de.xpi
[2013.03.04 00:22:26 | 000,531,283 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013.02.14 17:14:50 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.03.22 10:31:39 | 000,002,418 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\englische-ergebnisse.xml
[2013.03.22 10:31:39 | 000,010,701 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\gmx-suche.xml
[2013.03.22 10:31:39 | 000,002,432 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\lastminute.xml
[2013.03.22 10:31:38 | 000,005,682 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\webde-suche.xml
[2013.03.13 20:36:19 | 000,002,305 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\wot-safe-search.xml
[2013.03.13 20:36:19 | 000,002,077 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\{2EA57602-F694-4ECB-9E4E-006AB5F53A62}.xml
[2013.03.13 20:36:19 | 000,001,870 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\{D88E1900-B5E3-469F-8183-9232B17F07CC}.xml
[2013.03.13 20:36:19 | 000,002,188 | ---- | M] () -- C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\zxapfs10.default\searchplugins\{E4CED27D-38C5-439A-92DB-24F610B847FA}.xml
[2013.03.13 22:47:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.03.08 10:09:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013.03.08 10:09:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013.03.08 10:09:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
[2013.03.07 15:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.11.12 11:41:04 | 000,171,136 | ---- | M] (Tracker Software Products (Canada) Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2013.03.07 16:45:15 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.07 16:45:15 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.03.07 16:45:15 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 16:45:15 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.07 16:45:15 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 16:45:15 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider:  ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
 
O1 HOSTS File: ([2013.03.21 12:14:44 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" File not found
O4 - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000..\Run: [WizMouse] C:\Program Files\WizMouse\WizMouse.exe (Antibody Software)
O4 - HKU\S-1-5-21-1492898777-1315905052-4281177461-1004..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\autor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk =  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1492898777-1315905052-4281177461-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1492898777-1315905052-4281177461-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: PokerStars.eu - {07BA1DA9-F501-4796-8728-74D1B91A6CD5} - C:\Program Files\PokerStars.EU\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{29B00F74-80F5-4076-AFBC-25AB171BA972}: DhcpNameServer = 139.7.30.125 139.7.30.126
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AE6BF88A-4AAD-4EF8-8A12-B89768B61052}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D1C22D29-0853-44E9-BBED-7C83E2706FB5}: DhcpNameServer = 139.7.30.125 139.7.30.126
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.03.22 18:05:56 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.03.22 18:05:45 | 000,000,000 | ---D | C] -- C:\JRT
[2013.03.22 18:04:51 | 000,549,920 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\***\Desktop\Desktop\JRT.exe
[2013.03.21 12:24:15 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.03.21 12:24:15 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Local\temp
[2013.03.21 12:21:27 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013.03.21 11:53:09 | 005,042,364 | R--- | C] (Swearware) -- C:\Users\***\Desktop\Desktop\ComboFix.exe
[2013.03.21 11:03:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.03.21 11:03:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.03.21 11:03:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.03.20 21:55:17 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usb8023.sys
[2013.03.20 10:11:27 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Desktop\V-Mann Recherche
[2013.03.19 20:26:10 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\***\Desktop\Desktop\tdsskiller.exe
[2013.03.19 17:55:11 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\***\Desktop\Desktop\aswMBR.exe
[2013.03.19 11:12:43 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Desktop\Willi Wiesel
[2013.03.17 07:29:55 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\***\Desktop\Desktop\OTL.exe
[2013.03.15 09:30:57 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013.03.14 15:33:02 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\ERGOM
[2013.03.14 15:31:48 | 000,000,000 | ---D | C] -- C:\Program Files\Business Objects
[2013.03.14 15:30:54 | 000,000,000 | ---D | C] -- C:\Program Files\Ergom
[2013.03.14 13:24:22 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Desktop\Recherche
[2013.03.14 13:23:33 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Desktop\browserspiele
[2013.03.13 22:49:42 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013.03.13 22:49:40 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013.03.13 22:49:40 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013.03.13 22:49:40 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013.03.13 22:49:39 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013.03.13 22:49:39 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013.03.13 22:49:38 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013.03.13 22:49:38 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013.03.13 20:39:09 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Kalenderchen
[2013.03.13 20:36:23 | 000,493,056 | ---- | C] ( datenhaus GmbH) -- C:\Windows\System32\dhRichClient3.dll
[2013.03.13 20:36:19 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Opera
[2013.03.13 18:33:11 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\ASCOMP Software
[2013.03.13 18:33:08 | 000,000,000 | ---D | C] -- C:\Program Files\ASCOMP Software
[2013.03.12 22:42:31 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2013.03.08 10:09:08 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013.03.08 09:31:11 | 000,000,000 | ---D | C] -- C:\Users\***\Documents\Ahnenblatt
[2013.03.08 09:31:11 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Ahnenblatt
[2013.02.24 12:30:09 | 000,000,000 | ---D | C] -- C:\Users\***\AppData\Roaming\Avira
[2013.02.24 12:24:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013.02.24 12:24:18 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2013.02.24 12:24:17 | 000,134,336 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2013.02.24 12:24:17 | 000,083,944 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[2013.02.24 12:24:17 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2013.02.24 12:23:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013.02.24 12:23:31 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2013.02.24 11:31:28 | 000,000,000 | ---D | C] -- C:\Users\***\Desktop\Desktop\Werkstatt
[2009.08.27 13:06:09 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\***\AppData\Roaming\pcouffin.sys
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\***\Desktop\Desktop\*.tmp files -> C:\Users\***\Desktop\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.03.23 08:44:31 | 000,000,870 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Firefox stürzt ab nach ungewolltem Software download - Seite 3 - Trojaner-Board.website
[2013.03.23 08:42:07 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.03.23 08:41:40 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.03.23 08:41:12 | 000,003,840 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.03.23 08:41:12 | 000,003,840 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.03.23 08:41:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.03.23 08:40:55 | 3487,883,264 | -HS- | M] () -- C:\hiberfil.sys
[2013.03.23 08:38:21 | 000,000,115 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013.03.23 08:35:25 | 000,609,993 | ---- | M] () -- C:\Users\***\Desktop\Desktop\adwcleaner.exe
[2013.03.23 08:30:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.03.22 18:04:52 | 000,549,920 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\***\Desktop\Desktop\JRT.exe
[2013.03.22 18:03:20 | 000,244,541 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Exposé Bad Beat - Tatort download.pdf
[2013.03.22 17:38:35 | 000,100,640 | ---- | M] () -- C:\Users\***\Desktop\Desktop\mappe 3.jpg
[2013.03.21 21:42:00 | 000,000,512 | ---- | M] () -- C:\Users\***\Desktop\Desktop\MBR.dat
[2013.03.21 12:14:44 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013.03.21 11:53:28 | 005,042,364 | R--- | M] (Swearware) -- C:\Users\***\Desktop\Desktop\ComboFix.exe
[2013.03.20 12:04:56 | 000,002,499 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Day Organizer.lnk
[2013.03.20 11:25:53 | 000,244,541 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Exposé Bad Beat - Tatort.pdf
[2013.03.19 20:26:39 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\***\Desktop\Desktop\tdsskiller.exe
[2013.03.19 17:56:32 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\***\Desktop\Desktop\aswMBR.exe
[2013.03.19 15:51:23 | 013,151,467 | ---- | M] () -- C:\Users\***\Desktop\Desktop\mbar-1.01.0.1021.zip
[2013.03.18 10:26:03 | 238,964,359 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013.03.18 09:52:02 | 000,377,856 | ---- | M] () -- C:\Users\***\Desktop\Desktop\c0d2qsdl.exe
[2013.03.17 07:30:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\***\Desktop\Desktop\OTL.exe
[2013.03.17 07:29:03 | 000,000,000 | ---- | M] () -- C:\Users\***\defogger_reenable
[2013.03.16 22:50:28 | 000,004,398 | ---- | M] () -- C:\Users\***\Desktop\Desktop\ampel.pt3hudgroup
[2013.03.16 19:09:05 | 000,001,356 | ---- | M] () -- C:\Users\***\AppData\Local\d3d9caps.dat
[2013.03.16 09:02:52 | 000,000,226 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Turn Based games on Kongregate.URL
[2013.03.15 15:45:13 | 000,000,240 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Play Falling Sands 2, a free online game on Kongregate.URL
[2013.03.15 14:03:17 | 000,000,244 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Auberginenauflauf orientalische Art (Rezept mit Bild) Chefkoch.de.URL
[2013.03.14 13:21:48 | 000,000,830 | ---- | M] () -- C:\Windows\System32\InstallUtil.InstallLog
[2013.03.12 19:30:40 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.03.12 19:30:40 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013.03.08 13:14:51 | 000,678,092 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.03.08 13:14:51 | 000,637,344 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.03.08 13:14:51 | 000,147,276 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.03.08 13:14:51 | 000,120,848 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.03.08 13:12:34 | 000,123,392 | ---- | M] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.02.27 23:29:14 | 000,000,255 | ---- | M] () -- C:\Users\***\Desktop\Desktop\Antrag auf Leistungen für Bildung und Teilhabe - sammelantrag_but.pdf.URL
[2013.02.24 10:19:02 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avkmgr.sys
[2013.02.24 10:19:02 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2013.02.24 10:19:01 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avipbb.sys
[2013.02.24 10:19:01 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\System32\drivers\avgntflt.sys
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\***\Desktop\Desktop\*.tmp files -> C:\Users\***\Desktop\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.03.23 08:38:06 | 000,000,115 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013.03.23 08:35:25 | 000,609,993 | ---- | C] () -- C:\Users\***\Desktop\Desktop\adwcleaner.exe
[2013.03.22 18:03:19 | 000,244,541 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Exposé Bad Beat - Tatort download.pdf
[2013.03.22 16:08:31 | 000,100,640 | ---- | C] () -- C:\Users\***\Desktop\Desktop\mappe 3.jpg
[2013.03.22 10:15:04 | 000,000,870 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Firefox stürzt ab nach ungewolltem Software download - Seite 3 - Trojaner-Board.website
[2013.03.21 11:03:29 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.03.21 11:03:29 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.03.21 11:03:29 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.03.21 11:03:29 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.03.21 11:03:29 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.03.20 11:11:00 | 000,244,541 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Exposé Bad Beat - Tatort.pdf
[2013.03.19 18:36:09 | 000,000,512 | ---- | C] () -- C:\Users\***\Desktop\Desktop\MBR.dat
[2013.03.19 10:35:28 | 013,151,467 | ---- | C] () -- C:\Users\***\Desktop\Desktop\mbar-1.01.0.1021.zip
[2013.03.18 09:52:02 | 000,377,856 | ---- | C] () -- C:\Users\***\Desktop\Desktop\c0d2qsdl.exe
[2013.03.17 07:29:03 | 000,000,000 | ---- | C] () -- C:\Users\***\defogger_reenable
[2013.03.16 22:50:28 | 000,004,398 | ---- | C] () -- C:\Users\***\Desktop\Desktop\ampel.pt3hudgroup
[2013.03.16 09:02:52 | 000,000,226 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Turn Based games on Kongregate.URL
[2013.03.15 15:45:13 | 000,000,240 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Play Falling Sands 2, a free online game on Kongregate.URL
[2013.03.15 14:03:17 | 000,000,244 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Auberginenauflauf orientalische Art (Rezept mit Bild) Chefkoch.de.URL
[2013.03.14 15:30:59 | 000,002,499 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Day Organizer.lnk
[2013.03.13 20:37:10 | 000,000,830 | ---- | C] () -- C:\Windows\System32\InstallUtil.InstallLog
[2013.03.13 20:36:23 | 000,338,432 | ---- | C] () -- C:\Windows\System32\sqlite36_engine.dll
[2013.02.27 23:29:14 | 000,000,255 | ---- | C] () -- C:\Users\***\Desktop\Desktop\Antrag auf Leistungen für Bildung und Teilhabe - sammelantrag_but.pdf.URL
[2012.04.28 22:41:07 | 000,004,969 | ---- | C] () -- C:\ProgramData\oinwddee.jeg
[2011.08.29 13:00:57 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2011.03.29 07:02:46 | 000,005,078 | ---- | C] () -- C:\ProgramData\bltofzsb.qlf
[2009.08.27 13:06:09 | 000,007,887 | ---- | C] () -- C:\Users\***\AppData\Roaming\pcouffin.cat
[2009.08.27 13:06:09 | 000,001,144 | ---- | C] () -- C:\Users\***\AppData\Roaming\pcouffin.inf
[2009.06.16 13:25:02 | 000,121,512 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009.05.21 11:06:53 | 000,000,218 | ---- | C] () -- C:\Users\***\.recently-used.xbel
[2009.05.10 12:54:50 | 000,000,095 | ---- | C] () -- C:\Users\***\AppData\Local\fusioncache.dat
[2009.04.20 01:04:57 | 000,123,392 | ---- | C] () -- C:\Users\***\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.04.19 14:53:29 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.04.19 12:11:22 | 000,000,108 | ---- | C] () -- C:\Users\***\AppData\Roaming\wklnhst.dat
[2009.04.18 17:37:07 | 000,001,024 | ---- | C] () -- C:\Users\***\.rnd
[2009.04.18 17:29:45 | 000,001,356 | ---- | C] () -- C:\Users\***\AppData\Local\d3d9caps.dat
[2004.01.26 16:15:29 | 000,233,472 | R--- | C] () -- C:\Users\***\AppData\Roaming\MafiaSetup.exe
 
========== ZeroAccess Check ==========
 
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

Code:

OTL Extras logfile created on: 23.03.2013 08:46:07 - Run 6
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\***\Desktop\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 2,10 Gb Available Physical Memory | 64,53% Memory free
6,69 Gb Paging File | 4,82 Gb Available in Paging File | 72,02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 576,17 Gb Total Space | 268,84 Gb Free Space | 46,66% Space Free | Partition Type: NTFS
Drive D: | 19,99 Gb Total Space | 9,86 Gb Free Space | 49,31% Space Free | Partition Type: FAT32
 
Computer Name: ***-PC | User Name: *** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-1492898777-1315905052-4281177461-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1F116016-180A-4EF4-9C05-B8D521A7AE50}" = lport=445 | protocol=6 | dir=in | app=system |
"{4D1BDF44-C657-4DAE-91C1-486CF0A6F96D}" = rport=445 | protocol=6 | dir=out | app=system |
"{518DF5ED-36B2-4621-ACBC-F9AA073BB89B}" = rport=139 | protocol=6 | dir=out | app=system |
"{536C6FB5-BFCB-449C-9E44-96931F688DB7}" = lport=139 | protocol=6 | dir=in | app=system |
"{631A3CA8-0F66-4413-83CE-09D64922F710}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6B022FEA-7D7C-46A2-8A47-EE802265B0DA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{847798EC-D635-4D5D-9024-CAB83B07BD69}" = lport=138 | protocol=17 | dir=in | app=system |
"{90DA1EE9-E340-4CDF-91F5-E45D28236330}" = lport=137 | protocol=17 | dir=in | app=system |
"{B42108F0-A602-44CE-9C2E-065A2AF5FBE3}" = rport=137 | protocol=17 | dir=out | app=system |
"{C46E2E52-54A3-4F33-89BE-7443CCAF72F3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FFB86BB4-F341-43BB-B8F2-C28020DC41F3}" = rport=138 | protocol=17 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0C01BEF1-1C03-461E-A665-F454397A525B}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{12657DB2-64DB-472A-83B7-FA7887DB6B4D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{1336E1A9-541C-4352-9FA9-746F6D0096B1}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{3A9F98D6-6DFA-4FDB-B1D4-9341325F0CCA}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{3F96A377-497A-450E-BB71-A4CE9FA444D6}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
"{492BB7DB-E493-4C16-9693-D4F325749766}" = protocol=6 | dir=in | app=c:\program files\tournament indicator\indicator.exe |
"{496D040B-63FE-4C37-9476-7D04D426FF84}" = protocol=17 | dir=in | app=c:\program files\windows searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{64423B1B-4728-4635-8E5A-A3D3E59B242D}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{6C952451-8B95-494F-B59C-84A39CBE3357}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
"{6D47D2FB-EDC0-4FA6-948F-DCC3ECB8DB88}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{80BE424E-6472-4409-A894-1CBE4E4FB37E}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{828C144B-0F30-455E-9FC5-0FAC6CD0DADA}" = protocol=6 | dir=in | app=c:\program files\windows searchqu toolbar\datamngr\toolbar\dtuser.exe |
"{BAE0AF8C-A5F5-4AD4-A54A-D78E0F3CAF4A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{BC239294-891F-480A-916E-64CD098130C4}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{C99C4E09-F76F-4205-BA40-9F14965B9DCF}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{CFF43058-DD25-423E-A1BC-9A6E4FAA5E3B}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{DC1EF0EC-CF9D-42B7-9E74-4B48B45F3367}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DE8404FB-3A80-4024-B4D6-FCD5C6F0343B}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E209EDC4-9A15-441E-9C1D-16148A179F4E}" = protocol=17 | dir=in | app=c:\program files\tournament indicator\indicator.exe |
"{E26389A5-DD02-472C-98FA-5FD1F0D8F01D}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{E838F6BF-97DD-409B-A49C-E6CEA1C890F6}" = protocol=6 | dir=in | app=c:\program files\tournament indicator\indicator.exe |
"{E98A359B-3538-45CF-BDFB-07D02D7C67BA}" = protocol=17 | dir=in | app=c:\program files\tournament indicator\indicator.exe |
"{EC9C518D-891C-4680-8015-976A25D5175C}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"TCP Query User{1CFF0173-8372-4599-AF4A-A79065B95AC6}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"TCP Query User{32930CD0-B066-4E7C-9BE0-56E1B58AA6AC}C:\program files\zattoo\zattood.exe" = protocol=6 | dir=in | app=c:\program files\zattoo\zattood.exe |
"TCP Query User{40E2BFAE-7CF2-4A5D-A3BB-0D69786B088E}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{6AD78A4E-2831-49B7-AC0D-80BE6CFB20F3}C:\program files\zattoo\zattoo.exe" = protocol=6 | dir=in | app=c:\program files\zattoo\zattoo.exe |
"TCP Query User{93016D79-B339-4486-9023-B8B13BD47EAB}C:\program files\zattoo\zattood.exe" = protocol=6 | dir=in | app=c:\program files\zattoo\zattood.exe |
"TCP Query User{A381992D-CE31-4918-AEDE-620506AFF19B}C:\program files\klebezettel ng\klebez.exe" = protocol=6 | dir=in | app=c:\program files\klebezettel ng\klebez.exe |
"TCP Query User{E39524B4-A99B-4A1F-968B-FD08A14B1B9A}C:\program files\weq\gvdownloader\gvdownloader.ui.exe" = protocol=6 | dir=in | app=c:\program files\weq\gvdownloader\gvdownloader.ui.exe |
"TCP Query User{FE1D2449-3D4B-456E-B998-569822BBD735}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{0B9A8D8C-1353-4DB2-8327-6DBAB5F11295}C:\program files\zattoo\zattoo.exe" = protocol=17 | dir=in | app=c:\program files\zattoo\zattoo.exe |
"UDP Query User{2A47DF2A-7BA1-47FE-A5B0-D1F7BF515CB4}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{46B26B5D-86E8-49B2-A01B-42E8971F6652}C:\program files\weq\gvdownloader\gvdownloader.ui.exe" = protocol=17 | dir=in | app=c:\program files\weq\gvdownloader\gvdownloader.ui.exe |
"UDP Query User{4F168BE8-5CA3-4359-A8FE-8BCF43D25912}C:\program files\klebezettel ng\klebez.exe" = protocol=17 | dir=in | app=c:\program files\klebezettel ng\klebez.exe |
"UDP Query User{59255F16-94E9-4FA5-8571-E98299D16EDA}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{9CF4633D-45D4-4F69-AE2D-58E5D3CD7578}C:\program files\zattoo\zattood.exe" = protocol=17 | dir=in | app=c:\program files\zattoo\zattood.exe |
"UDP Query User{ED71901E-8449-4399-AAEC-278B9F9AC9AA}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{EE0E78C1-09A7-4FF1-A2D3-1CBAA8299C03}C:\program files\zattoo\zattood.exe" = protocol=17 | dir=in | app=c:\program files\zattoo\zattood.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java(TM) 6 Update 39
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40A55E23-B9B4-E627-2112-384E95C47F84}" = ccc-utility
"{47948554-90C6-4AAC-8CFA-D23CE11C1031}" = Nero 8 Essentials
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A5A427F-BA39-4BF0-9A47-9999FBE60C9F}" = Visual C++ Runtime for Dragon NaturallySpeaking
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{59FF69C1-8711-4961-F7B9-E5B92550F881}" = CCC Help English
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5D277F84-ED91-614E-9119-A64CE088972D}" = Catalyst Control Center Graphics Full New
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60B8D26D-5D6D-21D5-0366-3664E5DE3471}" = ATI Catalyst Install Manager
"{699C91CC-B484-3913-C4C4-BF5957910EDC}" = ccc-core-static
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D0C6BE4-F674-43D2-96BC-3509345108C9}_is1" = PokerStove version 1.24
"{6EBAE1B9-2B56-4006-A641-5F249D318750}" = Winamax Poker
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7113847B-EC8E-C244-66B0-C8C98A855525}" = Catalyst Control Center InstallProxy
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}" = Vodafone Mobile Connect Lite
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROPLUS_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROPLUS_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROPLUS_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROPLUS_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROPLUS_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROPLUS_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROPLUS_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_PROPLUS_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROPLUS_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{948CCDD3-3C8D-A6A7-B406-A56D8C005FA9}" = Skins
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{99537FD9-8DC9-40E9-5381-7E27511AE004}" = Catalyst Control Center Graphics Full Existing
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time  Lib Setup
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B1370260-CCF7-483A-ACA0-58C353619467}" = Day Organizer, ver. 2.2.1.2
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B823632F-3B72-4514-8861-B961CE263224}" = PostgreSQL 8.3
"{B8428EB4-F84C-9BA0-6E4D-DF9858D8802D}" = Catalyst Control Center Graphics Light
"{C6CA467B-13F3-CC4A-3489-463D2EE28172}" = Catalyst Control Center Core Implementation
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBEA666D-7D3D-BE18-3045-FF690F36AB7F}" = ccc-core-preinstall
"{CE26F10F-C80F-4377-908B-1B7882AE2CE3}" = Crystal Reports Basic Runtime for Visual Studio 2008
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}" = SAMSUNG SYMBIAN USB Download Driver
"{E7712E53-7A7F-46EB-AA13-70D5987D30F2}" = Dragon NaturallySpeaking 10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F7F58620-9837-DAE7-1B96-61EC7EA0495B}" = Catalyst Control Center Localization German
"{F8E38EFB-8897-0996-F7C7-97FF0F25609B}" = CCC Help German
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone-Konfigurationsprogramm
"{FB3F2F5E-349B-4425-ACB4-B59D7BF81822}" = TableNinja
"{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}" = Pinnacle VideoSpin
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Audacity_is1" = Audacity 1.2.6
"Audiograbber" = Audiograbber 1.83 SE
"Avira AntiVir Desktop" = Avira Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CCleaner" = CCleaner
"Dia" = Dia (nur entfernen)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"EAX Unified" = EAX Unified
"Free DVD Decrypter_is1" = Free DVD Decrypter version 1.5.4
"Free DVD Video Converter_is1" = Free DVD Video Converter version 1.5.12
"Free FLV Converter_is1" = Free FLV Converter V 7.4.0
"Free Video Converter_is1" = Free Video Converter V 2.92
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MozBackup" = MozBackup 1.4.9
"Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de)
"Mozilla Thunderbird 17.0.4 (x86 de)" = Mozilla Thunderbird 17.0.4 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Neuro-Programmer 3_is1" = Neuro-Programmer 3.0.9
"Picasa 3" = Picasa 3
"PKR" = PKR
"PokerStars" = PokerStars
"PokerStars.eu" = PokerStars.eu
"PokerTracker3" = PokerTracker 3 (remove only)
"PokerTracker4" = PokerTracker 4 (remove only)
"PROPLUS" = Microsoft Office Professional Plus 2007
"Recuva" = Recuva
"Revo Uninstaller" = Revo Uninstaller 1.91
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"Security Task Manager" = Security Task Manager 1.8c
"SMPlayer" = SMPlayer 0.6.9
"Speccy" = Speccy
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.6
"SumatraPDF" = SumatraPDF
"Tomb Raider: Anniversary" = Tomb Raider: Anniversary 1.0
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 2.0.0
"wam.04351C371E530C3762CBA45FA283ED972DCDEFB6.1" = Winamax Poker
"WinRAR archiver" = WinRAR 4.00 (32-Bit)
"WizMouse_is1" = WizMouse v1.0.0.9
"WritePro Fiction" = WritePro Fiction
"WritePro FictionMaster" = WritePro FictionMaster
"Writer's Café_is1" = Writer's Café 2.33
"YDKJG" = YOU DON'T KNOW JACK®
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-1492898777-1315905052-4281177461-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Filmmakers Video Uploader" = Filmmakers Video Uploader
"UB" = UB
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 23.03.2013 03:26:51 | Computer Name = ***-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
 
Error - 23.03.2013 03:27:55 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 23.03.2013 03:41:22 | Computer Name = ***-PC | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
 
Error - 23.03.2013 03:42:27 | Computer Name = ***-PC | Source = WinMgmt | ID = 10
Description =
 
[ OSession Events ]
Error - 07.09.2009 13:57:30 | Computer Name = ***-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.6215.1000. This session lasted 108
 seconds with 60 seconds of active time.  This session ended with a crash.
 
Error - 17.11.2010 11:39:05 | Computer Name = ***-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 53
 seconds with 0 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 23.03.2013 03:29:00 | Computer Name = ***-PC | Source = bowser | ID = 8003
Description =
 
Error - 23.03.2013 03:44:02 | Computer Name = ***-PC | Source = bowser | ID = 8003
Description =
 
 
< End of report >


cosinus 23.03.2013 09:43

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes - denk bitte vorher daran, Malwarebytes über den Updatebutton zu aktualisieren

Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Dramatist 31.03.2013 18:54

Hello again,

schon komisch. Kaum hattest Du mir gesagt, dass ich vermutlich keinen Virus hab, schon lag ich mit ner fetten Erkältung im Bett.... :rofl:

Okay. Darum bin ich jetzt erst zum Eset-Scannen gekommen. Und das Ergebnis ... das ist nicht das Beste aller möglichen, oder?

Code:

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.03.24.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
*** :: ***-PC [Administrator]

24.03.2013 17:08:50
mbam-log-2013-03-24 (17-08-50).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 257204
Laufzeit: 4 Minute(n), 31 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=3d8683a1c87d0943a11d31f2a7d5b425
# engine=13521
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-03-31 05:27:00
# local_time=2013-03-31 07:27:00 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1799 16775165 100 97 20801 135422125 13578 0
# compatibility_mode=5892 16776574 100 100 189107 202283548 0 0
# scanned=546899
# found=1
# cleaned=0
# scan_time=9918
sh=D5141079C7AF89F8588CC00A99FD71F949271B43 ft=1 fh=7c22ed9f5c7dd815 vn="a variant of Win32/BHO.OGC trojan" ac=I fn="C:\Qoobox\Quarantine\C\Windows\System32\rpchttpd.exe.vir"


Ach ja. Wünsche natürlich ein frohes Osterfest!!!

cosinus 01.04.2013 18:11

Sieht soweit ok aus, nur ein Fund in der Q von CF

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Dramatist 02.04.2013 18:17

Hallo,

ne. Im Moment hab ich keine Probleme mehr. :bussi:

Tausend Dank!!!

cosinus 02.04.2013 19:19

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter.

Combofix entfernen (nur relevant wenn es hier benutzt wurde!) : Start/Ausführen (Tastenkombination WIN+R), dort den Befehl combofix /uninstall eintippen und ausführen

Mit Hilfe von OTL kannst du auch viele andere Tools entfernen: Starte dazu einfach OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.

Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 19:11 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132