DavemanT | 13.04.2013 19:19 | Hi Leo,
bitte entschuldige, bin eben erst wieder von einer Dienstreise wieder gekommen.
Ich habe alles so gemacht wie angegeben und nachfolgend findest Du nun die Logs in der von Dir vorgegebenen Reihenfolge:
Log Kaspersky: Code:
Untersuchung von Objekten: wurde beendet vor 9 Stunden (Ereignis: 2, Objekte: 87, Zeit: 00:00:47)
08.04.13 22:37 Aufgabe wurde beendet
08.04.13 22:36 Aufgabe wurde gestartet
Untersuchung von Objekten: wurde abgeschlossen vor weniger als einer Minute (Ereignis: 82, Objekte: 1712874, Zeit: 09:30:45)
09.04.13 08:14 Aufgabe wurde abgeschlossen
09.04.13 08:14 Gelöscht: HEUR:Trojan.Win32.Generic C:/Windows/System32/tnnsfklj6.dll
09.04.13 08:13 Gefunden: HEUR:Trojan.Win32.Generic C:/Windows/System32/tnnsfklj6.dll
09.04.13 08:13 Gelöscht: Trojan.Win32.Mediyes.cns C:/Windows/System32/incv0ybrj.tsp
09.04.13 08:13 Gefunden: Trojan.Win32.Mediyes.cns C:/Windows/System32/incv0ybrj.tsp
09.04.13 08:13 Gelöscht: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat
09.04.13 08:13 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat
09.04.13 08:13 Gelöscht: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
09.04.13 08:13 Gefunden: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
09.04.13 08:13 Gelöscht: HEUR:Exploit.Java.CVE-2012-1723.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363
09.04.13 08:13 Gefunden: HEUR:Exploit.Java.CVE-2012-1723.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363
09.04.13 08:13 Gelöscht: HEUR:Exploit.Java.CVE-2013-0431.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62
09.04.13 08:13 Gefunden: HEUR:Exploit.Java.CVE-2013-0431.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62
09.04.13 08:13 Gelöscht: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
09.04.13 03:18 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
09.04.13 03:18 Nicht desinfizierte Objekte: HEUR:Trojan.Win32.Generic C:/Windows/System32/tnnsfklj6.dll Zurückgestellt
09.04.13 03:18 Gefunden: HEUR:Trojan.Win32.Generic C:/Windows/System32/tnnsfklj6.dll
09.04.13 03:17 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj C:/Users/Hellsmobile/AppData/Roaming/skype.dat Zurückgestellt
09.04.13 03:17 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj C:/Users/Hellsmobile/AppData/Roaming/skype.dat
09.04.13 03:17 Nicht desinfizierte Objekte: Trojan.Win32.Agent.xgqe C:/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe Zurückgestellt
09.04.13 03:17 Gefunden: Trojan.Win32.Agent.xgqe C:/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
09.04.13 02:51 Verarbeitungsfehler D:/System Volume Information/_restore{EC8454A9-4D14-4260-9200-8AFCCE9DB3EE}/RP123/A0029210.dll Lesefehler
09.04.13 00:46 Nicht desinfizierte Objekte: HEUR:Trojan.Win32.Generic C:/Windows/System32/tnnsfklj6.dll Zurückgestellt
09.04.13 00:46 Gefunden: HEUR:Trojan.Win32.Generic C:/Windows/System32/tnnsfklj6.dll
09.04.13 00:45 Nicht desinfizierte Objekte: Trojan.Win32.Mediyes.cns C:/Windows/System32/incv0ybrj.tsp Zurückgestellt
09.04.13 00:45 Gefunden: Trojan.Win32.Mediyes.cns C:/Windows/System32/incv0ybrj.tsp
09.04.13 00:33 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj Zurückgestellt
09.04.13 00:33 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
09.04.13 00:18 Nicht desinfizierte Objekte: Trojan.Win32.Agent.xgqe C:/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe Zurückgestellt
09.04.13 00:18 Gefunden: Trojan.Win32.Agent.xgqe C:/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
09.04.13 00:18 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj C:/Users/Hellsmobile/AppData/Roaming/skype.dat Zurückgestellt
09.04.13 00:18 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj C:/Users/Hellsmobile/AppData/Roaming/skype.dat
09.04.13 00:18 Nicht desinfizierte Objekte: HEUR:Exploit.Java.CVE-2012-1723.gen C:/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363 Zurückgestellt
09.04.13 00:18 Gefunden: HEUR:Exploit.Java.CVE-2012-1723.gen C:/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363
09.04.13 00:18 Nicht desinfizierte Objekte: HEUR:Exploit.Java.CVE-2013-0431.gen C:/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62 Zurückgestellt
09.04.13 00:18 Gefunden: HEUR:Exploit.Java.CVE-2013-0431.gen C:/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62
09.04.13 00:14 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj C:/Users/Hellsmobile/AppData/Local/Temp/vdoqaj Zurückgestellt
09.04.13 00:14 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj C:/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
09.04.13 00:06 Nicht desinfizierte Objekte: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe Zurückgestellt
09.04.13 00:06 Gefunden: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
09.04.13 00:05 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat Zurückgestellt
09.04.13 00:05 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat
08.04.13 23:55 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj Zurückgestellt
08.04.13 23:55 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
08.04.13 23:41 Nicht desinfizierte Objekte: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe Zurückgestellt
08.04.13 23:41 Gefunden: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
08.04.13 23:41 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat Zurückgestellt
08.04.13 23:41 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat
08.04.13 23:41 Nicht desinfizierte Objekte: HEUR:Exploit.Java.CVE-2012-1723.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363 Zurückgestellt
08.04.13 23:41 Gefunden: HEUR:Exploit.Java.CVE-2012-1723.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363
08.04.13 23:41 Nicht desinfizierte Objekte: HEUR:Exploit.Java.CVE-2013-0431.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62 Zurückgestellt
08.04.13 23:41 Gefunden: HEUR:Exploit.Java.CVE-2013-0431.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62
08.04.13 23:37 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj Zurückgestellt
08.04.13 23:37 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
08.04.13 23:28 Nicht desinfizierte Objekte: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe Zurückgestellt
08.04.13 23:28 Gefunden: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
08.04.13 23:28 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat Zurückgestellt
08.04.13 23:28 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat
08.04.13 23:18 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj Zurückgestellt
08.04.13 23:18 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
08.04.13 23:04 Nicht desinfizierte Objekte: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe Zurückgestellt
08.04.13 23:04 Gefunden: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
08.04.13 23:03 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat Zurückgestellt
08.04.13 23:03 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat
08.04.13 23:03 Nicht desinfizierte Objekte: HEUR:Exploit.Java.CVE-2012-1723.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363 Zurückgestellt
08.04.13 23:03 Gefunden: HEUR:Exploit.Java.CVE-2012-1723.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/62/2a9a377e-30f91363
08.04.13 23:03 Nicht desinfizierte Objekte: HEUR:Exploit.Java.CVE-2013-0431.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62 Zurückgestellt
08.04.13 23:03 Gefunden: HEUR:Exploit.Java.CVE-2013-0431.gen /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/LocalLow/Sun/Java/Deployment/cache/6.0/46/1edc6b6e-5f3e3b62
08.04.13 22:59 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj Zurückgestellt
08.04.13 22:59 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Local/Temp/vdoqaj
08.04.13 22:50 Nicht desinfizierte Objekte: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe Zurückgestellt
08.04.13 22:50 Gefunden: Trojan.Win32.Agent.xgqe /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/Feur/dyatd.exe
08.04.13 22:50 Nicht desinfizierte Objekte: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat Zurückgestellt
08.04.13 22:50 Gefunden: Trojan-Ransom.Win32.Foreign.bfbj /mnt/MountedDevices/PD-97646C29-0000000006500000/Users/Hellsmobile/AppData/Roaming/skype.dat
08.04.13 22:43 Aufgabe wurde gestartet Fixlog OTL: Code:
All processes killed
========== OTL ==========
Service Update-Service stopped successfully!
Service Update-Service deleted successfully!
C:\Windows\System32\UpdSvc.dll moved successfully.
C:\Users\Hellsmobile\AppData\Roaming\Xayb folder moved successfully.
C:\Users\Hellsmobile\AppData\Roaming\Feur folder moved successfully.
C:\Users\Hellsmobile\AppData\Roaming\Dumoen folder moved successfully.
HKU\S-1-5-21-101454118-1010754368-1925311853-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Prefs.js: "127.0.0.1" removed from network.proxy.backup.ftp
Prefs.js: 3128 removed from network.proxy.backup.ftp_port
Prefs.js: "127.0.0.1" removed from network.proxy.backup.socks
Prefs.js: 3128 removed from network.proxy.backup.socks_port
Prefs.js: "127.0.0.1" removed from network.proxy.backup.ssl
Prefs.js: 3128 removed from network.proxy.backup.ssl_port
Prefs.js: "127.0.0.1" removed from network.proxy.ftp
Prefs.js: 3128 removed from network.proxy.ftp_port
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 3128 removed from network.proxy.http_port
Prefs.js: true removed from network.proxy.share_proxy_settings
Prefs.js: "127.0.0.1" removed from network.proxy.socks
Prefs.js: 3128 removed from network.proxy.socks_port
Prefs.js: "127.0.0.1" removed from network.proxy.ssl
Prefs.js: 3128 removed from network.proxy.ssl_port
Prefs.js: 0 removed from network.proxy.type
ADS C:\ProgramData\TEMP:85C4A4DF deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters\\"ServiceDll"|hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6e,00,73,00,72,00,73,00,6c,00,76,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\\Update-Service-Installer-Service deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\\Update-Service deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Joosoft.com\ deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Telephony\Providers\\"NextProviderID"|dword:00000005 /E : value set successfully!
HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Telephony\Providers\\"NumProviders"|dword:00000004 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Telephony\Providers\\ProviderID4 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Telephony\Providers\\ProviderFilename4 deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Hellsmobile
->Temp folder emptied: 29592467 bytes
->Temporary Internet Files folder emptied: 519825917 bytes
->Java cache emptied: 5717954 bytes
->FireFox cache emptied: 297310133 bytes
->Flash cache emptied: 2661 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 552989 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1213553 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 815,00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 04132013_194359
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot... Log Adwcleaner: Code:
# AdwCleaner v2.200 - Datei am 13/04/2013 um 19:56:32 erstellt
# Aktualisiert am 02/04/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzer : Hellsmobile - HELLSMOBILE-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Hellsmobile\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Ordner Gelöscht : C:\Users\Hellsmobile\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Hellsmobile\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Hellsmobile\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Hellsmobile\AppData\Roaming\pdfforge
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKLM\Software\PIP
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16476
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v19.0.2 (de)
Datei : C:\Users\Hellsmobile\AppData\Roaming\Mozilla\Firefox\Profiles\54blce7v.default\prefs.js
C:\Users\Hellsmobile\AppData\Roaming\Mozilla\Firefox\Profiles\54blce7v.default\user.js ... Gelöscht !
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [1733 octets] - [13/04/2013 19:56:32]
########## EOF - C:\AdwCleaner[S1].txt - [1793 octets] ########## Log von OTL: Code:
OTL logfile created on: 13.04.2013 20:00:37 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Hellsmobile\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,50 Gb Total Physical Memory | 2,57 Gb Available Physical Memory | 73,37% Memory free
7,00 Gb Paging File | 5,91 Gb Available in Paging File | 84,43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 160,66 Gb Total Space | 26,37 Gb Free Space | 16,41% Space Free | Partition Type: NTFS
Drive D: | 137,33 Gb Total Space | 33,63 Gb Free Space | 24,49% Space Free | Partition Type: NTFS
Drive M: | 160,66 Gb Total Space | 26,37 Gb Free Space | 16,41% Space Free | Partition Type: FAT
Computer Name: HELLSMOBILE-PC | User Name: Hellsmobile | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Hellsmobile\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Programme\Telekom\Mediencenter\MediencenterSoftware.exe (Deutsche Telekom AG)
PRC - C:\Programme\Telekom\Mediencenter\DTAG.Mediencenter.BackgroundService.exe (Deutsche Telekom AG)
PRC - C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Programme\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Programme\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\P4G\BatteryLife.exe (ATK)
PRC - C:\Programme\ASUS\Wireless Console 3\wcourier.exe ()
PRC - C:\Windows\System32\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.)
PRC - C:\Programme\ASUS\Splendid\ACMON.exe (ATK)
PRC - C:\Programme\ASUS\ControlDeck\ControlDeckStartUp.exe ()
PRC - C:\Programme\ASUS\ATK Hotkey\HControl.exe (ASUS)
PRC - C:\Programme\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
PRC - C:\Programme\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)
PRC - C:\Programme\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Programme\ASUS\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Programme\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\Programme\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
PRC - C:\Programme\ASUS\ATK Media\DMedia.exe (ASUS)
PRC - C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
PRC - C:\Programme\ASUS\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Programme\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)
PRC - C:\Programme\ASUS\ASUS Live Update\ALU.exe ()
PRC - C:\Programme\ATKGFNEX\GFNEXSrv.exe ()
PRC - C:\Windows\System32\ACEngSvr.exe (ASUSTeK)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\1e04a5319c58010e945220af2751d34e\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\77dfcfed5fd5f67d0d3edc545935bb21\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\3e79256ce40faa9682f9e3511ca115ea\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ad51da1b752b19c992fcefd56eb7c01\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\219c68f83fa608b496b163fd6782e696\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\eb33bf977e97e97b12e82c18e36fbaee\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Programme\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll ()
MOD - C:\Programme\P4G\OvrClk.dll ()
MOD - C:\Programme\ASUS\Wireless Console 3\wcourier.exe ()
MOD - C:\Programme\ASUS\ControlDeck\ControlDeckStartUp.exe ()
MOD - C:\Programme\P4G\DevMng.dll ()
MOD - C:\Programme\ASUS\Splendid\GLCDdll.dll ()
MOD - C:\Programme\ASUS\ASUS Live Update\ALU.exe ()
MOD - C:\Programme\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll ()
MOD - C:\Programme\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll ()
MOD - C:\Programme\ATKGFNEX\AGFNEX.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer8) -- C:\Programme\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (MCSWASVR) -- C:\Programme\Telekom\Mediencenter\DTAG.Mediencenter.BackgroundService.exe (Deutsche Telekom AG)
SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (TuneUp.UtilitiesSvc) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (nvUpdatusService) -- C:\Programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Programme\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (osppsvc) -- C:\Programme\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (FastBootAgent) -- C:\Windows\System32\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASLDRService) -- C:\Programme\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (ADSMService) -- C:\Programme\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)
SRV - (ATKGFNEXSrv) -- C:\Programme\ATKGFNEX\GFNEXSrv.exe ()
========== Driver Services (SafeList) ==========
DRV - (VGPU) -- System32\drivers\rdvgkmd.sys File not found
DRV - (tsusbhub) -- system32\drivers\tsusbhub.sys File not found
DRV - (Synth3dVsc) -- System32\drivers\synth3dvsc.sys File not found
DRV - (pccsmcfd) -- system32\DRIVERS\pccsmcfd.sys File not found
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (AsDsm) -- C:\Windows\System32\drivers\AsDsm.sys (ASUSTek Computer Inc)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ATKACPI.sys (ASUS)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (TuneUpUtilitiesDrv) -- C:\Programme\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (ANDModem) -- C:\Windows\System32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (AndDiag) -- C:\Windows\System32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) -- C:\Windows\System32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (Andbus) -- C:\Windows\System32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (YMIDUSBW) -- C:\Windows\System32\drivers\ymidusbw.sys (Yamaha Corporation)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvstor32) -- C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (nvsmu) -- C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (AmUStor) -- C:\Windows\System32\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV - (hwdatacard) -- C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ASMMAP) -- C:\Programme\ATKGFNEX\ASMMAP.sys ()
DRV - (dsiarhwprog) -- C:\Windows\System32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 65 40 AE 8C 9C CC 01 [binary data]
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-101454118-1010754368-1925311853-1003\..\SearchScopes,DefaultScope =
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.7.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: ""
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: ""
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: ""
FF - prefs.js..network.proxy.ftp: ""
FF - prefs.js..network.proxy.ftp_port: ""
FF - prefs.js..network.proxy.http: ""
FF - prefs.js..network.proxy.http_port: ""
FF - prefs.js..network.proxy.no_proxies_on: "localhost"
FF - prefs.js..network.proxy.share_proxy_settings: ""
FF - prefs.js..network.proxy.socks: ""
FF - prefs.js..network.proxy.socks_port: ""
FF - prefs.js..network.proxy.ssl: ""
FF - prefs.js..network.proxy.ssl_port: ""
FF - prefs.js..network.proxy.type: ""
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@innoplus.de/ino3DViewer: C:\Program Files\innoplus\3D-Viewer-innoPlus\npIno3DViewer.dll (INNOVA-engineering GmbH Dresden)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\Hellsmobile\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.11.13 23:12:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2013.04.10 12:30:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.25 09:23:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.11.13 23:12:21 | 000,000,000 | ---D | M]
[2012.02.04 10:24:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hellsmobile\AppData\Roaming\mozilla\Extensions
[2013.03.20 18:37:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hellsmobile\AppData\Roaming\mozilla\Firefox\Profiles\54blce7v.default\extensions
[2013.03.20 18:37:12 | 000,269,007 | ---- | M] () (No name found) -- C:\Users\Hellsmobile\AppData\Roaming\mozilla\firefox\profiles\54blce7v.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2013.03.25 09:23:15 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2013.03.07 16:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.03.07 17:45:15 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.07 17:45:15 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013.03.07 17:45:15 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 17:45:15 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.07 17:45:15 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 17:45:15 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2012.08.24 19:45:45 | 000,000,852 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AmIcoSinglun] C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (AlcorMicro Co., Ltd.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Programme\ASUS\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Programme\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ETDWare] C:\Programme\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4 - HKLM..\Run: [HControlUser] C:\Programme\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-101454118-1010754368-1925311853-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Hellsmobile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mediencenter Assistent.lnk = C:\Programme\Telekom\Mediencenter\MediencenterSoftware.exe (Deutsche Telekom AG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: An OneNote s&enden - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Hellsmobile\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - C:\Programme\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\..Trusted Domains: clonewarsadventures.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\..Trusted Domains: freerealms.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\..Trusted Domains: soe.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1001\..Trusted Domains: sony.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1003\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1003\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1003\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-21-101454118-1010754368-1925311853-1003\..Trusted Domains: sony.com ([]* in )
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab (DLM Control)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20614.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.80.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.9.2)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://www.randstadlogin.de/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{079EBF9E-E72F-438E-8C9C-E9E94F29CA09}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D245AAB1-3763-49AC-958E-46FA553D34A6}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-101454118-1010754368-1925311853-1001 Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{a096083a-f519-11e1-9bfa-0026189eb056}\Shell - "" = AutoRun
O33 - MountPoints2\{a096083a-f519-11e1-9bfa-0026189eb056}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe
O33 - MountPoints2\{a096083c-f519-11e1-9bfa-0026189eb056}\Shell - "" = AutoRun
O33 - MountPoints2\{a096083c-f519-11e1-9bfa-0026189eb056}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe
O33 - MountPoints2\{ab080144-ad76-11e1-9fc1-0026189eb056}\Shell - "" = AutoRun
O33 - MountPoints2\{ab080144-ad76-11e1-9fc1-0026189eb056}\Shell\AutoRun\command - "" = H:\StartVMCLite.exe
O33 - MountPoints2\{ab080146-ad76-11e1-9fc1-0026189eb056}\Shell - "" = AutoRun
O33 - MountPoints2\{ab080146-ad76-11e1-9fc1-0026189eb056}\Shell\AutoRun\command - "" = H:\StartVMCLite.exe
O33 - MountPoints2\{b20c53fb-509f-11e1-8ace-0026189eb056}\Shell - "" = AutoRun
O33 - MountPoints2\{b20c53fb-509f-11e1-8ace-0026189eb056}\Shell\AutoRun\command - "" = F:\StartVMCLite.exe
O33 - MountPoints2\{b20c540b-509f-11e1-8ace-0026189eb056}\Shell - "" = AutoRun
O33 - MountPoints2\{b20c540b-509f-11e1-8ace-0026189eb056}\Shell\AutoRun\command - "" = H:\StartVMCLite.exe
O33 - MountPoints2\{c101a755-0dd9-11e1-b445-0026189eb056}\Shell - "" = AutoRun
O33 - MountPoints2\{c101a755-0dd9-11e1-b445-0026189eb056}\Shell\AutoRun\command - "" = G:\start.exe /auto
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.04.13 19:43:59 | 000,000,000 | ---D | C] -- C:\_OTL
[2013.04.10 12:31:23 | 000,000,000 | ---D | C] -- C:\Users\Hellsmobile\Documents\Freemake
[2013.04.10 12:31:00 | 000,000,000 | ---D | C] -- C:\Users\Hellsmobile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
[2013.04.10 12:30:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
[2013.04.10 12:30:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Freemake
[2013.04.10 12:30:43 | 000,000,000 | ---D | C] -- C:\Program Files\Freemake
[2013.04.10 12:27:45 | 000,000,000 | ---D | C] -- C:\Users\Hellsmobile\Documents\Tipard Studio
[2013.04.10 12:27:45 | 000,000,000 | ---D | C] -- C:\Users\Hellsmobile\AppData\Local\Tipard Studio
[2013.04.09 00:35:38 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2013.04.02 18:24:56 | 000,000,000 | ---D | C] -- C:\Users\Hellsmobile\Documents\Steuer-Sparbuch
[2013.04.02 15:59:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO Steuer-Sparbuch 2012
[2013.04.02 15:58:41 | 000,000,000 | ---D | C] -- C:\Program Files\WISO
[2013.04.01 11:12:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free M4a to MP3 Converter
[2013.04.01 11:12:15 | 000,000,000 | ---D | C] -- C:\Program Files\Free M4a to MP3 Converter
[2013.04.01 11:03:08 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft
[2013.04.01 11:03:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft
[2013.03.17 16:45:10 | 000,000,000 | ---D | C] -- C:\Users\Hellsmobile\AppData\Local\Adobe_Systems_Incorporate
[2013.03.17 16:45:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2013.03.17 16:45:03 | 000,000,000 | ---D | C] -- C:\Users\Hellsmobile\Documents\My Digital Editions
========== Files - Modified Within 30 Days ==========
[2013.04.13 20:04:57 | 000,657,676 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.04.13 20:04:57 | 000,618,912 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.04.13 20:04:57 | 000,131,016 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.04.13 20:04:57 | 000,107,232 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.04.13 20:03:14 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.13 20:03:14 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.13 19:57:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.13 19:57:50 | 2817,994,752 | -HS- | M] () -- C:\hiberfil.sys
[2013.04.13 19:54:48 | 000,613,083 | ---- | M] () -- C:\Users\Hellsmobile\Desktop\adwcleaner.exe
[2013.04.11 03:22:27 | 000,408,728 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013.04.10 12:30:59 | 000,001,320 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2013.04.09 15:30:03 | 000,377,856 | ---- | M] () -- C:\Users\Hellsmobile\Desktop\194lfszo.exe
[2013.04.09 15:28:45 | 000,000,156 | ---- | M] () -- C:\Users\Hellsmobile\defogger_reenable
[2013.04.09 15:26:03 | 000,050,477 | ---- | M] () -- C:\Users\Hellsmobile\Desktop\Defogger.exe
[2013.04.08 20:33:57 | 000,000,004 | ---- | M] () -- C:\Users\Hellsmobile\AppData\Roaming\skype.ini
[2013.04.02 22:35:47 | 000,000,080 | ---- | M] () -- C:\Windows\wiso.ini
[2013.04.02 15:59:41 | 000,002,113 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
[2013.04.02 15:59:40 | 000,002,081 | ---- | M] () -- C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2012.lnk
[2013.04.02 15:13:41 | 000,000,021 | ---- | M] () -- C:\Users\Hellsmobile\AppData\Local\mc.pixel.data
[2013.03.31 18:42:28 | 000,001,845 | ---- | M] () -- C:\Users\Hellsmobile\Desktop\UseNeXT by Tangysoft.lnk
[2013.03.19 21:21:31 | 000,004,096 | -H-- | M] () -- C:\Users\Hellsmobile\AppData\Local\keyfile3.drm
========== Files Created - No Company Name ==========
[2013.04.13 19:54:34 | 000,613,083 | ---- | C] () -- C:\Users\Hellsmobile\Desktop\adwcleaner.exe
[2013.04.10 12:30:59 | 000,001,320 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2013.04.09 15:30:03 | 000,377,856 | ---- | C] () -- C:\Users\Hellsmobile\Desktop\194lfszo.exe
[2013.04.09 15:28:44 | 000,000,156 | ---- | C] () -- C:\Users\Hellsmobile\defogger_reenable
[2013.04.09 15:26:03 | 000,050,477 | ---- | C] () -- C:\Users\Hellsmobile\Desktop\Defogger.exe
[2013.04.08 10:11:54 | 000,000,004 | ---- | C] () -- C:\Users\Hellsmobile\AppData\Roaming\skype.ini
[2013.04.02 15:59:41 | 000,002,113 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
[2013.04.02 15:59:40 | 000,002,081 | ---- | C] () -- C:\Users\Public\Desktop\WISO Steuer-Sparbuch 2012.lnk
[2013.03.31 18:42:28 | 000,001,845 | ---- | C] () -- C:\Users\Hellsmobile\Desktop\UseNeXT by Tangysoft.lnk
[2013.03.19 21:21:31 | 000,004,096 | -H-- | C] () -- C:\Users\Hellsmobile\AppData\Local\keyfile3.drm
[2012.12.25 17:22:43 | 000,000,021 | ---- | C] () -- C:\Users\Hellsmobile\AppData\Local\mc.pixel.data
[2012.12.22 13:06:11 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.12.22 13:06:11 | 000,138,056 | ---- | C] () -- C:\Users\Hellsmobile\AppData\Roaming\PnkBstrK.sys
[2012.12.22 13:05:38 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2012.12.22 13:05:34 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012.08.06 21:00:34 | 000,003,392 | ---- | C] () -- C:\Users\Hellsmobile\AppData\Local\recently-used.xbel
[2012.06.24 20:29:19 | 000,000,080 | ---- | C] () -- C:\Windows\wiso.ini
[2012.02.06 22:49:36 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2012.01.23 20:08:24 | 000,007,605 | ---- | C] () -- C:\Users\Hellsmobile\AppData\Local\Resmon.ResmonCfg
[2012.01.06 00:46:33 | 000,000,532 | ---- | C] () -- C:\Windows\hpomdl46.dat.temp
[2011.11.13 23:07:35 | 000,217,988 | ---- | C] () -- C:\Windows\hpoins46.dat
[2011.11.13 23:07:35 | 000,000,532 | ---- | C] () -- C:\Windows\hpomdl46.dat
[2011.11.07 22:45:49 | 000,008,704 | ---- | C] () -- C:\Users\Hellsmobile\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.07 20:15:47 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.11.07 20:14:24 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.11.06 22:49:20 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2011.11.06 22:43:45 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\SamSfPa.dat
[2011.10.15 01:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
========== ZeroAccess Check ==========
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.02.17 10:20:19 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\DAEMON Tools Lite
[2013.04.01 11:03:26 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\DVDVideoSoft
[2012.03.04 00:16:05 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\FileZilla
[2013.03.12 23:45:52 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\innoplus
[2012.06.24 18:03:10 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\Juniper Networks
[2012.06.24 19:41:41 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\Nokia
[2012.06.24 19:41:39 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\PC Suite
[2013.01.16 23:39:13 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\TeamViewer
[2012.01.23 20:22:48 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\The Creative Assembly
[2012.01.29 15:13:57 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\TuneUp Software
[2012.07.13 19:59:33 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\Ubisoft
[2013.04.10 11:53:45 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\UseNeXT
[2013.03.06 08:04:22 | 000,000,000 | ---D | M] -- C:\Users\Hellsmobile\AppData\Roaming\Wargaming.net
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Telephony\Providers >
"ProviderID0" = 1
"ProviderID1" = 2
"ProviderID2" = 3
"ProviderID3" = 4
"NextProviderID" = 5
"ProviderFileName0" = unimdm.tsp -- [2010.11.20 14:16:53 | 000,281,088 | ---- | M] (Microsoft Corporation)
"ProviderFileName1" = kmddsp.tsp -- [2009.07.14 03:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation)
"ProviderFileName2" = ndptsp.tsp -- [2009.07.14 03:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation)
"ProviderFileName3" = hidphone.tsp -- [2009.07.14 03:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation)
"NumProviders" = 4
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation /S >
"DisplayName" = @%systemroot%\system32\wkssvc.dll,-100
"Group" = NetworkProvider
"ImagePath" = %SystemRoot%\System32\svchost.exe -k NetworkService -- [2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation)
"Description" = @%systemroot%\system32\wkssvc.dll,-101
"ObjectName" = NT AUTHORITY\NetworkService
"ErrorControl" = 1
"Start" = 2
"Type" = 32
"DependOnService" = BowserMRxSmb10MRxSmb20NSI [binary data]
"ServiceSidType" = 1
"RequiredPrivileges" = SeChangeNotifyPrivilegeSeImperson [Binary data over 200 bytes]
"FailureActions" = 80 51 01 00 00 00 00 00 00 00 00 00 03 00 00 00 14 00 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 C0 D4 01 00 00 00 00 00 00 00 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Linkage]
"Bind" = \Device\Smb_Tcpip_{B89A8BCE-AFD4-4 [Binary data over 200 bytes]
"Route" = "Smb" "Tcpip" "{B89A8BCE-AFD4-490A [Binary data over 200 bytes]
"Export" = \Device\LanmanWorkstation_Smb_Tcpi [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider]
"DeviceName" = \Device\LanmanRedirector
"Name" = Microsoft Windows Network
"DisplayName" = @%systemroot%\system32\wkssvc.dll,-102
"ProviderPath" = %SystemRoot%\System32\ntlanman.dll -- [2010.11.20 14:20:46 | 000,069,120 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]
"ServiceDll" = %SystemRoot%\System32\wkssvc.dll -- [2010.11.20 14:21:36 | 000,084,480 | ---- | M] (Microsoft Corporation)
"ServiceDllUnloadOnStop" = 1
"EnablePlainTextPassword" = 0
"EnableSecuritySignature" = 1
"RequireSecuritySignature" = 0
"OtherDomains" = [binary data]
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache /S >
"DisplayName" = @%SystemRoot%\System32\dnsapi.dll,-101
"Group" = TDI
"ImagePath" = %SystemRoot%\system32\svchost.exe -k NetworkService -- [2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation)
"Description" = @%SystemRoot%\System32\dnsapi.dll,-102
"ObjectName" = NT AUTHORITY\NetworkService
"ErrorControl" = 1
"Start" = 2
"Type" = 32
"DependOnService" = Tdxnsi [binary data]
"ServiceSidType" = 1
"RequiredPrivileges" = SeChangeNotifyPrivilegeSeCreateGlobalPrivilege [binary data]
"FailureActions" = 80 51 01 00 00 00 00 00 00 00 00 00 03 00 00 00 14 00 00 00 01 00 00 00 C0 D4 01 00 01 00 00 00 E0 93 04 00 00 00 00 00 00 00 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters]
"ServiceDll" = %SystemRoot%\System32\dnsrslvr.dll -- [2011.03.03 07:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation)
"ServiceDllUnloadOnStop" = 1
"extension" = %SystemRoot%\System32\dnsext.dll -- [2009.07.14 03:15:12 | 000,006,656 | ---- | M] (Microsoft Corporation)
"ServiceMain" = SetAccessPolicy
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters\DnsCache]
"ShutdownOnIdle" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Security]
"Security" = 01 00 14 80 F8 00 00 00 04 01 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 C8 00 08 00 00 00 00 02 18 00 9D 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 02 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 02 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 04 00 00 00 00 02 14 00 8D 00 02 00 01 01 00 00 00 00 00 05 14 00 00 00 00 02 14 00 8D 00 02 00 01 01 00 00 00 00 00 05 13 00 00 00 00 02 18 00 CD 00 02 00 01 02 00 00 00 00 00 05 20 00 00 00 2C 02 00 00 00 02 28 00 CD 01 02 00 01 06 00 00 00 00 00 05 50 00 00 00 04 C9 44 AF 94 D9 D3 E5 2B E1 B7 1C 17 84 87 13 6E 1A FA 65 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\TriggerInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\TriggerInfo\0]
"Type" = 4
"Action" = 1
"GUID" = 07 9E 56 B7 21 84 E0 4E AD 10 86 91 5A FD AD 09 [binary data]
"Data0" = 5355UDP [binary data]
"DataType0" = 2
< HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost >
"RPCSS" = RpcEptMapperRpcSs [binary data]
"defragsvc" = defragsvc [binary data] -- [2009.07.14 03:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation)
"LocalSystemNetworkRestricted" = UxSmsWdiSystemHostNetmantrkwks [Binary data over 200 bytes]
"LocalService" = nsiWdiServiceHostw32timeEventSy [Binary data over 200 bytes]
"netsvcs" = AeLookupSvcCertPropSvcSCPolicySv [Binary data over 200 bytes]
"WerSvcGroup" = wersvc [binary data] -- [2009.07.14 03:16:18 | 000,065,024 | ---- | M] (Microsoft Corporation)
"LocalServiceNoNetwork" = DPSPLABFEmpssvcWwanSvc [binary data]
"termsvcs" = TermService [binary data]
"swprv" = swprv [binary data] -- [2009.07.14 03:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation)
"LocalServiceNetworkRestricted" = DHCPeventlogAudioSrvBthHFSrvLm [Binary data over 200 bytes]
"LocalServicePeerNet" = PNRPSvcp2pimsvcp2psvcPnrpAutoReg [binary data]
"NetworkServiceAndNoImpersonation" = KtmRm [binary data]
"regsvc" = RemoteRegistry [binary data]
"LocalServiceAndNoImpersonation" = SSDPSRVupnphostSCardSvrTBSFont [Binary data over 200 bytes]
"DcomLaunch" = PowerPlugPlayDcomLaunch [binary data]
"NetworkServiceNetworkRestricted" = PolicyAgent [binary data]
"NetworkService" = CryptSvcDHCPTermServiceDNSCache [Binary data over 200 bytes]
"sdrsvc" = sdrsvc [binary data] -- [2010.11.20 14:21:06 | 000,125,952 | ---- | M] (Microsoft Corporation)
"WbioSvcGroup" = WbioSrvc [binary data] -- [2009.07.14 03:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation)
"imgsvc" = StiSvc [binary data]
"wcssvc" = WcsPlugInService [binary data] -- [2009.07.14 03:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation)
"AxInstSVGroup" = AxInstSV [binary data] -- [2010.11.20 14:18:06 | 000,088,064 | ---- | M] (Microsoft Corporation)
"secsvcs" = WinDefend [binary data]
"bthsvcs" = bthserv [binary data] -- [2009.07.14 03:15:00 | 000,064,512 | ---- | M] (Microsoft Corporation)
"PeerDist" = PeerDistSvc [binary data] -- [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation)
"HPZ12" = Pml Driver HPZ12Net Driver HPZ12 [binary data]
"HPService" = HPSLPSVC [binary data]
"hpdevmgmt" = hpqcxs08hpqddsvc [binary data]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\AxInstSVGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\defragsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalService]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceAndNoImpersonation]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceNetworkRestricted]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalServiceNoNetwork]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalSystemNetworkRestricted]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\netsvcs]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkService]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkServiceRemoteDesktopHyperVAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\NetworkServiceRemoteDesktopPublishing]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\SDRSVC]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\swprv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\termsvcs]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wcssvc]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\wercplsupport]
< HKEY_LOCAL_MACHINE\SOFTWARE\Joosoft.com >
< %SystemRoot%\system32\*.tsp >
[2009.07.14 03:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 03:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 03:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 03:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.20 14:16:53 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
< C:\Windows\system32\*.dll /540 >
[2013.02.15 06:34:10 | 000,131,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\aaclient.dll
[2011.11.07 17:03:35 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\admparse.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
[2012.10.04 18:40:36 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
[2012.10.04 18:40:37 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012.10.04 18:40:37 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
[2012.10.04 18:40:37 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
[2012.10.04 18:40:38 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012.10.04 16:41:50 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
[2012.10.04 16:41:50 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
[2012.10.04 16:41:50 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
[2012.10.04 16:41:50 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
[2012.12.16 16:13:28 | 000,295,424 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\system32\atmfd.dll
[2012.12.16 16:13:20 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\system32\atmlib.dll
[2011.12.13 10:29:24 | 000,021,312 | ---- | M] (TuneUp Software) -- C:\Windows\system32\authuitu.dll
[2012.07.04 23:14:34 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\browcli.dll
[2012.07.04 23:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\browser.dll
[2012.06.06 07:03:06 | 000,805,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cdosys.dll
[2012.10.17 06:33:05 | 000,107,888 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\system32\CmdLineExt.dll
[2012.06.02 06:36:29 | 001,159,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\crypt32.dll
[2012.06.02 06:36:29 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cryptnet.dll
[2012.06.02 06:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cryptsvc.dll
[2013.03.19 06:48:45 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\csrsrv.dll
[2012.10.29 11:22:46 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\deployJava1.dll
[2012.11.02 07:11:31 | 000,376,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dpnet.dll
[2012.08.13 17:25:04 | 000,124,928 | ---- | M] (Deutsche Telekom AG) -- C:\Windows\system32\DTAG.Mediencenter.ShellExtension.dll
[2012.03.03 07:31:19 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\DWrite.dll
[2011.11.07 17:03:36 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dxtmsft.dll
[2011.11.07 17:03:36 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\dxtrans.dll
[2011.11.07 17:03:35 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\icardie.dll
[2011.11.07 17:03:36 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\IEAdvpack.dll
[2011.11.07 17:03:36 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieakeng.dll
[2011.11.07 17:03:35 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieaksie.dll
[2011.11.07 17:03:35 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieakui.dll
[2011.11.07 17:03:35 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieapfltr.dll
[2011.11.07 17:03:35 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iedkcs32.dll
[2013.02.22 05:47:17 | 009,738,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieframe.dll
[2011.11.07 17:03:35 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iepeers.dll
[2011.11.07 17:03:35 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iernonce.dll
[2013.02.22 05:32:05 | 001,796,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iertutil.dll
[2011.11.07 17:03:35 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iesetup.dll
[2011.11.07 17:03:36 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iesysprep.dll
[2013.02.22 05:28:48 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieui.dll
[2012.03.01 07:33:23 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\imagehlp.dll
[2011.11.07 17:03:35 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\imgutil.dll
[2011.11.07 17:03:35 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\inseng.dll
[2013.02.22 05:34:18 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript.dll
[2013.02.22 05:46:00 | 001,800,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript9.dll
[2013.02.22 05:35:31 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jsproxy.dll
[2012.08.11 01:56:14 | 000,542,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kerberos.dll
[2012.10.04 18:43:05 | 000,868,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kernel32.dll
[2012.10.04 18:43:05 | 000,293,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\KernelBase.dll
[2011.11.07 17:03:35 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\licmgr10.dll
[2012.05.14 06:33:42 | 000,769,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\localspl.dll
[2011.11.17 07:32:51 | 001,038,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\lsasrv.dll
[2011.11.09 04:21:56 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msclmd.dll
[2013.02.22 05:33:11 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msfeeds.dll
[2011.11.07 17:03:36 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msfeedsbs.dll
[2013.02.22 06:05:50 | 012,324,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtml.dll
[2013.02.22 05:31:55 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtmled.dll
[2011.11.07 17:03:36 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtmler.dll
[2011.11.07 17:03:36 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msls31.dll
[2011.11.07 17:03:36 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msrating.dll
[2013.02.15 06:37:10 | 003,217,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mstscax.dll
[2011.12.16 09:52:58 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msvcrt.dll
[2012.06.06 07:05:52 | 001,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msxml3.dll
[2012.11.01 06:47:54 | 001,389,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msxml6.dll
[2012.11.20 06:51:09 | 000,220,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ncrypt.dll
[2012.07.04 23:16:56 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\netapi32.dll
[2011.11.01 10:07:24 | 000,075,264 | ---- | M] (Nokia) -- C:\Windows\system32\nmwcdcls.dll
[2012.10.29 11:22:46 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\npDeployJava1.dll
[2011.11.17 07:38:39 | 001,288,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ntdll.dll
[2011.11.07 17:03:35 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\occache.dll
[2011.11.19 16:01:00 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\packager.dll
[2011.11.07 17:03:35 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\pngfilt.dll
[2011.10.26 06:32:11 | 000,514,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\qdvd.dll
[2011.10.26 06:32:11 | 001,328,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\quartz.dll
[2012.02.17 07:34:22 | 000,826,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpcore.dll
[2012.04.26 06:45:54 | 000,129,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpcorekmts.dll
[2012.04.28 06:41:44 | 000,919,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpcorets.dll
[2012.04.26 06:45:55 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\rdpwsx.dll
[2012.06.02 06:40:39 | 000,225,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\schannel.dll
[2011.11.17 07:34:52 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\secur32.dll
[2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\shell32.dll
[2011.11.17 07:34:55 | 000,100,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\sspicli.dll
[2011.11.17 07:34:55 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\sspisrv.dll
[2012.09.26 00:47:43 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\synceng.dll
[2013.02.15 05:25:51 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\tsgqec.dll
[2012.11.09 06:42:49 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\tzres.dll
[2013.02.22 05:36:35 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\url.dll
[2013.02.22 05:38:39 | 001,104,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\urlmon.dll
[2011.12.13 10:29:16 | 000,029,504 | ---- | M] (TuneUp Software) -- C:\Windows\system32\uxtuneup.dll
[2013.02.22 05:34:03 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\vbscript.dll
[2011.11.07 17:03:35 | 000,203,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\webcheck.dll
[2011.11.17 07:35:02 | 000,314,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\webio.dll
[2012.11.09 06:43:04 | 000,492,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\win32spl.dll
[2012.10.29 11:22:46 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\WindowsAccessBridge.dll
[2013.02.22 05:38:00 | 001,129,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wininet.dll
[2013.01.04 06:50:52 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\winsrv.dll
[2012.08.24 18:57:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wintrust.dll
[2012.03.01 07:29:16 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wmi.dll
[2012.06.03 00:19:23 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuapi.dll
[2012.06.03 00:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuaueng.dll
[2012.06.03 00:12:32 | 002,422,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wucltux.dll
[2012.06.03 00:12:13 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wudriver.dll
[2012.06.03 00:19:32 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wups.dll
[2012.06.03 00:19:33 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wups2.dll
[2012.06.02 15:19:42 | 000,171,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuwebv.dll
[2009.07.14 06:53:46 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 06:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
< C:\Windows\system32\*.sys >
[2009.07.13 23:40:41 | 000,009,029 | ---- | M] () -- C:\Windows\system32\ANSI.SYS
[2009.06.05 15:07:40 | 001,168,384 | ---- | M] (Atheros Communications, Inc.) -- C:\Windows\system32\athr.sys
[2009.07.14 03:26:21 | 000,249,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\clfs.sys
[2009.07.13 23:40:44 | 000,027,097 | ---- | M] () -- C:\Windows\system32\country.sys
[2009.07.13 23:40:40 | 000,004,768 | ---- | M] () -- C:\Windows\system32\HIMEM.SYS
[2009.07.13 23:40:43 | 000,042,809 | ---- | M] () -- C:\Windows\system32\KEY01.SYS
[2009.07.13 23:40:43 | 000,042,537 | ---- | M] () -- C:\Windows\system32\KEYBOARD.SYS
[2009.07.13 23:40:23 | 000,027,866 | ---- | M] () -- C:\Windows\system32\NTDOS.SYS
[2009.07.13 23:40:31 | 000,029,146 | ---- | M] () -- C:\Windows\system32\NTDOS404.SYS
[2009.07.13 23:40:35 | 000,029,370 | ---- | M] () -- C:\Windows\system32\NTDOS411.SYS
[2009.07.13 23:40:39 | 000,029,274 | ---- | M] () -- C:\Windows\system32\NTDOS412.SYS
[2009.07.13 23:40:27 | 000,029,146 | ---- | M] () -- C:\Windows\system32\NTDOS804.SYS
[2009.07.13 23:40:11 | 000,033,952 | ---- | M] () -- C:\Windows\system32\NTIO.SYS
[2009.07.13 23:40:15 | 000,034,672 | ---- | M] () -- C:\Windows\system32\NTIO404.SYS
[2009.07.13 23:40:17 | 000,035,776 | ---- | M] () -- C:\Windows\system32\NTIO411.SYS
[2009.07.13 23:40:19 | 000,035,536 | ---- | M] () -- C:\Windows\system32\NTIO412.SYS
[2009.07.13 23:40:13 | 000,034,672 | ---- | M] () -- C:\Windows\system32\NTIO804.SYS
[2013.03.01 05:09:59 | 002,347,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\win32k.sys
< >
========== Files - Unicode (All) ==========
[2012.04.22 08:54:44 | 000,013,081 | ---- | M] ()(C:\Users\Hellsmobile\Documents\Ð?V?M?NT.docx) -- C:\Users\Hellsmobile\Documents\ÐΔVΞMΔNT.docx
[2012.04.22 08:54:38 | 000,013,081 | ---- | C] ()(C:\Users\Hellsmobile\Documents\Ð?V?M?NT.docx) -- C:\Users\Hellsmobile\Documents\ÐΔVΞMΔNT.docx
< End of report > So, ich hoffe, ich habe alles soweit richtig gemacht. Ich bleibe jetzt erstmal online, um jetzt mal etwas schneller reagieren zu können. Sorry nochmal!
VG
David |