Malwarebytes findet jetzt keine Trojaner mehr, hier meine aktuellen OTL-Logs: Code:
OTL logfile created on: 26.04.2013 15:00:00 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,32 Gb Available Physical Memory | 58,13% Memory free
8,22 Gb Paging File | 6,43 Gb Available in Paging File | 78,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,27 Gb Total Space | 3,26 Gb Free Space | 6,61% Space Free | Partition Type: NTFS
Drive D: | 416,48 Gb Total Space | 38,72 Gb Free Space | 9,30% Space Free | Partition Type: NTFS
Computer Name: JUPP-PC | User Name: Jupp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - D:\Programme\Last.fm\Last.fm Scrobbler.exe (Last.fm)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - D:\Programme\Winamp\winamp.exe (Nullsoft, Inc.)
PRC - D:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Windows\SysWOW64\conime.exe (Microsoft Corporation)
PRC - D:\Programme\Rainlendar2\Rainlendar2.exe ()
PRC - C:\Program Files (x86)\ASUS\AASP\1.00.65\aaCenter.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\winamp.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\vis_milk2.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\vis_avs.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\vis_nsfs.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\tagz.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\winampa.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_pmp.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_wifi.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_ipod.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ombrowser.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_android.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\out_ds.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_wire.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_usb.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_transcode.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\out_wave.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\out_disk.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_rg.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_activesync.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_p4s.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_njb.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\playlist.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_local.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_disc.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_plg.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mp3.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_midi.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mod.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wm.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_online.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_cdda.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_playlists.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_nsv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_vorbis.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_undo.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_downloads.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_history.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_devices.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_tray.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_autotag.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wav.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_dshow.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wave.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_flac.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_impex.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_bookmarks.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mp4.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_avi.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_enqplay.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mkv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_orb.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_nowplaying.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_addons.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_swf.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_linein.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_flv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\burnlib.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_jumpex_original.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_jumpex.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_classicart.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_ff.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_ml.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_play_remove.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\dsp_sps.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_skinmanager.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_hotkeys.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\auth.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_timerestore.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_nopro.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_orgler.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_crasher.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_fhgaac.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_wma.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_lame.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_find_on_disk.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_wav.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_vorbis.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_flac.lng ()
MOD - D:\Programme\Last.fm\listener.dll ()
MOD - D:\Programme\Last.fm\unicorn.dll ()
MOD - D:\Programme\Last.fm\logger.dll ()
MOD - D:\Programme\Last.fm\lastfm.dll ()
MOD - D:\Programme\Last.fm\plugins\phonon_backend\phonon_vlc.dll ()
MOD - D:\Programme\Last.fm\phonon.dll ()
MOD - D:\Programme\Last.fm\libvlccore.dll ()
MOD - D:\Programme\Last.fm\plugins\audio_output\libaout_directx_plugin.dll ()
MOD - D:\Programme\Last.fm\libvlc.dll ()
MOD - D:\Programme\Winamp\System\jnetlib.w5s ()
MOD - D:\Programme\Winamp\System\jpeg.w5s ()
MOD - D:\Programme\Winamp\System\xml.w5s ()
MOD - D:\Programme\Winamp\System\png.w5s ()
MOD - D:\Programme\Winamp\System\playlist.w5s ()
MOD - D:\Programme\Winamp\tataki.dll ()
MOD - D:\Programme\Winamp\zlib.dll ()
MOD - D:\Programme\Winamp\System\timer.w5s ()
MOD - D:\Programme\Winamp\System\tagz.w5s ()
MOD - D:\Programme\Winamp\System\primo.w5s ()
MOD - D:\Programme\Winamp\Plugins\in_wm.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_local.dll ()
MOD - D:\Programme\Winamp\Plugins\in_vorbis.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_devices.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_pmp.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_disc.dll ()
MOD - D:\Programme\Winamp\System\auth.w5s ()
MOD - D:\Programme\Winamp\Plugins\pmp_ipod.dll ()
MOD - D:\Programme\Winamp\Plugins\unrar.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_online.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_p4s.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_wifi.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_playlists.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_plg.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_android.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_impex.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_usb.dll ()
MOD - D:\Programme\Winamp\Plugins\out_ds.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_history.dll ()
MOD - D:\Programme\Winamp\System\devices.w5s ()
MOD - D:\Programme\Winamp\Plugins\ml_rg.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_transcode.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_bookmarks.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_autotag.dll ()
MOD - D:\Programme\Winamp\Plugins\in_swf.dll ()
MOD - D:\Programme\Winamp\System\albumart.w5s ()
MOD - D:\Programme\Winamp\Plugins\out_disk.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_njb.dll ()
MOD - D:\Programme\Winamp\System\gif.w5s ()
MOD - D:\Programme\Winamp\System\bmp.w5s ()
MOD - D:\Programme\Winamp\Plugins\out_wave.dll ()
MOD - D:\Programme\Winamp\Plugins\in_wave.dll ()
MOD - D:\Programme\Winamp\System\dlmgr.w5s ()
MOD - D:\Programme\Winamp\System\gracenote.w5s ()
MOD - D:\Programme\Winamp\System\filereader.w5s ()
MOD - D:\Programme\Winamp\Plugins\gen_ff.dll ()
MOD - D:\Programme\Winamp\nsutil.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_ml.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mp3.dll ()
MOD - D:\Programme\Winamp\libsndfile.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_jumpex.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mod.dll ()
MOD - D:\Programme\Winamp\Plugins\in_midi.dll ()
MOD - D:\Programme\Winamp\Plugins\in_cdda.dll ()
MOD - D:\Programme\Winamp\nde.dll ()
MOD - D:\Programme\Winamp\Plugins\in_nsv.dll ()
MOD - D:\Programme\Winamp\Plugins\in_dshow.dll ()
MOD - D:\Programme\Winamp\Plugins\in_avi.dll ()
MOD - D:\Programme\Winamp\Plugins\in_flac.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_orgler.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mp4.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mkv.dll ()
MOD - D:\Programme\Winamp\Plugins\in_flv.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_hotkeys.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_tray.dll ()
MOD - D:\Programme\Winamp\Plugins\in_linein.dll ()
MOD - D:\Programme\Rainlendar2\plugins\iCalendarPlugin.dll ()
MOD - D:\Programme\Rainlendar2\Rainlendar2.exe ()
MOD - D:\Programme\Rainlendar2\lfs.dll ()
MOD - D:\Programme\Rainlendar2\lua51.dll ()
MOD - C:\Program Files (x86)\ASUS\AASP\1.00.65\aaCenter.exe ()
MOD - C:\Program Files (x86)\ASUS\AASP\1.00.65\cpuutil.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files (x86)\ASUS\AASP\1.00.65\PowerDll.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- D:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- D:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (DAUpdaterSvc) -- D:\Spiele\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- D:\Programme\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (epmntdrv) -- C:\Windows\SysNative\epmntdrv.sys ()
DRV:64bit: - (EuGdiDrv) -- C:\Windows\SysNative\EuGdiDrv.sys ()
DRV:64bit: - (VClone) -- C:\Windows\SysNative\DRIVERS\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\DRIVERS\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (L1E) -- C:\Windows\SysNative\DRIVERS\L1E60x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\DRIVERS\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (netr7364) -- C:\Windows\SysNative\DRIVERS\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (RTL8187) -- C:\Windows\SysNative\DRIVERS\wg111v2.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\DRIVERS\ASACPI.sys ()
DRV - (DrvAgent64) -- C:\Windows\SysWOW64\drivers\DrvAgent64.SYS (Phoenix Technologies)
DRV - (epmntdrv) -- C:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (EuGdiDrv) -- C:\Windows\SysWOW64\EuGdiDrv.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 CE C0 EE F1 41 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..network.proxy.http: "87.98.136.60"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: D:\Programme\VLC\npvlc.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.04.12 08:11:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.04.12 08:10:59 | 000,000,000 | ---D | M]
[2011.07.16 15:05:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\Extensions
[2013.04.25 22:40:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\Firefox\Profiles\8fnqi441.default\extensions
[2012.12.12 05:45:36 | 000,036,098 | ---- | M] () (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\firefox\profiles\8fnqi441.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
[2013.02.14 06:10:46 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\firefox\profiles\8fnqi441.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.04.12 08:10:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.04.12 08:11:01 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.08.12 20:20:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.06.28 17:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.08.31 18:12:36 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.31 18:12:36 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.31 18:12:36 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.31 18:12:36 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.31 18:12:36 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.31 18:12:36 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 23:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] D:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKCU..\Run: [Rainlendar2] D:\Programme\Rainlendar2\Rainlendar2.exe ()
O4 - HKLM..\RunOnce: [Z1] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Jupp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Jupp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2254D07A-F1F5-45A1-9197-CF2292ED39CE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F21EAA53-5830-4C8A-9A84-F18B79B3AB60}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: D:\Eigene Dateien\Desktop\The_Simpsons_1680 x 1050 widescreen.jpg
O24 - Desktop BackupWallPaper: D:\Eigene Dateien\Desktop\The_Simpsons_1680 x 1050 widescreen.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 0
O33 - MountPoints2\{1a66d130-690a-11e1-ae57-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1a66d130-690a-11e1-ae57-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Msetup4.exe
O33 - MountPoints2\{4642c5c5-2663-11e1-8996-00248c2af28a}\Shell - "" = AutoRun
O33 - MountPoints2\{4642c5c5-2663-11e1-8996-00248c2af28a}\Shell\AutoRun\command - "" = I:\Setup.exe
O33 - MountPoints2\{7133bda4-afaa-11e0-b4f4-00248c2af28a}\Shell - "" = AutoRun
O33 - MountPoints2\{7133bda4-afaa-11e0-b4f4-00248c2af28a}\Shell\AutoRun\command - "" = J:\OriginInstaller.exe
O33 - MountPoints2\{b2cf56e9-afa4-11e0-8069-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b2cf56e9-afa4-11e0-8069-806e6f6e6963}\Shell\AutoRun\command - "" = B:\Bin\ASSETUP.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.04.25 22:32:04 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Avira
[2013.04.25 22:26:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013.04.25 22:26:39 | 000,130,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.04.25 22:26:39 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.04.25 22:26:39 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013.04.25 22:26:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013.04.24 17:45:31 | 001,092,512 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2013.04.24 17:45:31 | 000,971,680 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2013.04.24 17:45:31 | 000,311,200 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.04.24 17:45:26 | 000,188,832 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.04.24 17:45:26 | 000,188,320 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.04.24 17:45:26 | 000,108,448 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.04.24 17:45:09 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.04.21 09:32:09 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Siup
[2013.04.21 09:32:09 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Nuyt
[2013.04.21 09:32:09 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Ertu
[2013.04.19 09:58:14 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Local\.elfohilfe
[2013.04.14 22:58:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2013.04.12 08:10:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.04.05 11:50:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2013.04.05 11:46:00 | 026,956,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2013.04.05 11:46:00 | 025,256,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2013.04.05 11:46:00 | 020,542,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2013.04.05 11:46:00 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2013.04.05 11:46:00 | 015,508,512 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2013.04.05 11:46:00 | 015,042,928 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2013.04.05 11:46:00 | 013,088,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2013.04.05 11:46:00 | 009,414,456 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2013.04.05 11:46:00 | 007,959,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2013.04.05 11:46:00 | 007,573,816 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2013.04.05 11:46:00 | 006,271,872 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2013.04.05 11:46:00 | 002,913,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2013.04.05 11:46:00 | 002,728,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2013.04.05 11:46:00 | 002,539,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2013.04.05 11:46:00 | 002,355,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2013.04.05 11:46:00 | 001,995,552 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2013.04.05 11:46:00 | 001,807,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6431422.dll
[2013.04.05 11:46:00 | 001,510,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6431422.dll
[2013.04.04 17:25:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mega Codec Pack
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.04.26 14:49:44 | 000,003,840 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.26 14:49:44 | 000,003,840 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.26 12:56:20 | 001,468,666 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.04.26 12:56:20 | 000,636,228 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.04.26 12:56:20 | 000,602,310 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.04.26 12:56:20 | 000,131,254 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.04.26 12:56:20 | 000,107,728 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.04.26 12:49:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.26 11:40:53 | 000,000,020 | ---- | M] () -- C:\Users\Jupp\defogger_reenable
[2013.04.25 23:03:01 | 000,375,288 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.04.24 17:45:16 | 000,108,448 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.04.24 17:45:13 | 000,311,200 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.04.24 17:45:13 | 000,188,832 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.04.24 17:45:13 | 000,188,320 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.04.24 17:45:12 | 001,092,512 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2013.04.24 17:45:12 | 000,971,680 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2013.04.23 21:27:31 | 000,036,352 | ---- | M] () -- C:\Users\Jupp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.04.18 18:59:20 | 000,691,592 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.04.18 18:59:20 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.04.05 13:34:11 | 000,004,459 | ---- | M] () -- C:\Users\Jupp\.recently-used.xbel
[2013.04.04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.04.26 11:40:53 | 000,000,020 | ---- | C] () -- C:\Users\Jupp\defogger_reenable
[2013.04.05 13:34:11 | 000,004,459 | ---- | C] () -- C:\Users\Jupp\.recently-used.xbel
[2013.02.10 14:19:50 | 000,000,000 | ---- | C] () -- C:\Users\Jupp\.JavaPowUpload.properties
[2012.05.15 08:51:31 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2012.05.15 08:51:31 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2012.05.15 08:51:31 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2012.05.15 08:45:39 | 000,030,903 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2012.05.10 16:33:31 | 000,010,818 | ---- | C] () -- C:\Windows\scunin.dat
[2012.01.23 01:44:58 | 000,024,576 | R--- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2012.01.23 01:44:58 | 000,014,392 | R--- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011.12.14 16:28:27 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2011.12.14 16:28:09 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2011.12.14 16:27:46 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011.10.12 09:56:43 | 001,489,842 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.09.11 19:11:53 | 000,000,216 | ---- | C] () -- C:\Windows\PowerReg.dat
[2011.08.07 09:03:38 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2011.08.03 12:09:10 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011.07.21 10:24:55 | 000,036,352 | ---- | C] () -- C:\Users\Jupp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.17 18:48:45 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011.07.16 15:19:24 | 002,340,992 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2011.07.16 15:19:24 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2011.07.16 15:19:24 | 000,018,048 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2011.07.16 15:19:24 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2011.07.16 15:19:24 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2011.07.16 14:45:57 | 000,031,776 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2011.07.16 14:45:57 | 000,031,776 | ---- | C] () -- C:\ProgramData\nvModes.001
[2011.07.16 14:22:46 | 000,011,916 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2011.07.16 14:22:31 | 000,011,683 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011.07.16 14:19:45 | 000,000,732 | ---- | C] () -- C:\Users\Jupp\AppData\Local\d3d9caps64.dat
========== ZeroAccess Check ==========
[2006.11.02 17:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysWOW64\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.21 04:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report > Code:
OTL logfile created on: 26.04.2013 15:00:00 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,32 Gb Available Physical Memory | 58,13% Memory free
8,22 Gb Paging File | 6,43 Gb Available in Paging File | 78,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 49,27 Gb Total Space | 3,26 Gb Free Space | 6,61% Space Free | Partition Type: NTFS
Drive D: | 416,48 Gb Total Space | 38,72 Gb Free Space | 9,30% Space Free | Partition Type: NTFS
Computer Name: JUPP-PC | User Name: Jupp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - D:\Programme\Last.fm\Last.fm Scrobbler.exe (Last.fm)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - D:\Programme\Winamp\winamp.exe (Nullsoft, Inc.)
PRC - D:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - D:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Windows\SysWOW64\conime.exe (Microsoft Corporation)
PRC - D:\Programme\Rainlendar2\Rainlendar2.exe ()
PRC - C:\Program Files (x86)\ASUS\AASP\1.00.65\aaCenter.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\winamp.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\vis_milk2.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\vis_avs.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\vis_nsfs.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\tagz.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\winampa.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_pmp.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_wifi.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_ipod.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ombrowser.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_android.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\out_ds.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_wire.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_usb.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_transcode.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\out_wave.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\out_disk.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_rg.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_activesync.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_p4s.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\pmp_njb.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\playlist.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_local.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_disc.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_plg.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mp3.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_midi.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mod.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wm.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_online.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_cdda.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_playlists.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_nsv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_vorbis.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_undo.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_downloads.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_history.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_devices.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_tray.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_autotag.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wav.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_dshow.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wave.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_flac.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_impex.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_bookmarks.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mp4.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_avi.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_enqplay.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_wv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_mkv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_orb.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_nowplaying.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\ml_addons.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_swf.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_linein.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\in_flv.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\burnlib.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_jumpex_original.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_jumpex.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_classicart.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_ff.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_ml.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_play_remove.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\dsp_sps.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_skinmanager.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_hotkeys.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\auth.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_timerestore.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_nopro.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_orgler.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_crasher.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_fhgaac.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_wma.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_lame.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\gen_find_on_disk.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_wav.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_vorbis.lng ()
MOD - C:\Users\Jupp\AppData\Local\Temp\WLZ60F5.tmp\enc_flac.lng ()
MOD - D:\Programme\Last.fm\listener.dll ()
MOD - D:\Programme\Last.fm\unicorn.dll ()
MOD - D:\Programme\Last.fm\logger.dll ()
MOD - D:\Programme\Last.fm\lastfm.dll ()
MOD - D:\Programme\Last.fm\plugins\phonon_backend\phonon_vlc.dll ()
MOD - D:\Programme\Last.fm\phonon.dll ()
MOD - D:\Programme\Last.fm\libvlccore.dll ()
MOD - D:\Programme\Last.fm\plugins\audio_output\libaout_directx_plugin.dll ()
MOD - D:\Programme\Last.fm\libvlc.dll ()
MOD - D:\Programme\Winamp\System\jnetlib.w5s ()
MOD - D:\Programme\Winamp\System\jpeg.w5s ()
MOD - D:\Programme\Winamp\System\xml.w5s ()
MOD - D:\Programme\Winamp\System\png.w5s ()
MOD - D:\Programme\Winamp\System\playlist.w5s ()
MOD - D:\Programme\Winamp\tataki.dll ()
MOD - D:\Programme\Winamp\zlib.dll ()
MOD - D:\Programme\Winamp\System\timer.w5s ()
MOD - D:\Programme\Winamp\System\tagz.w5s ()
MOD - D:\Programme\Winamp\System\primo.w5s ()
MOD - D:\Programme\Winamp\Plugins\in_wm.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_local.dll ()
MOD - D:\Programme\Winamp\Plugins\in_vorbis.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_devices.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_pmp.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_disc.dll ()
MOD - D:\Programme\Winamp\System\auth.w5s ()
MOD - D:\Programme\Winamp\Plugins\pmp_ipod.dll ()
MOD - D:\Programme\Winamp\Plugins\unrar.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_online.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_p4s.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_wifi.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_playlists.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_plg.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_android.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_impex.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_usb.dll ()
MOD - D:\Programme\Winamp\Plugins\out_ds.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_history.dll ()
MOD - D:\Programme\Winamp\System\devices.w5s ()
MOD - D:\Programme\Winamp\Plugins\ml_rg.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_transcode.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_bookmarks.dll ()
MOD - D:\Programme\Winamp\Plugins\ml_autotag.dll ()
MOD - D:\Programme\Winamp\Plugins\in_swf.dll ()
MOD - D:\Programme\Winamp\System\albumart.w5s ()
MOD - D:\Programme\Winamp\Plugins\out_disk.dll ()
MOD - D:\Programme\Winamp\Plugins\pmp_njb.dll ()
MOD - D:\Programme\Winamp\System\gif.w5s ()
MOD - D:\Programme\Winamp\System\bmp.w5s ()
MOD - D:\Programme\Winamp\Plugins\out_wave.dll ()
MOD - D:\Programme\Winamp\Plugins\in_wave.dll ()
MOD - D:\Programme\Winamp\System\dlmgr.w5s ()
MOD - D:\Programme\Winamp\System\gracenote.w5s ()
MOD - D:\Programme\Winamp\System\filereader.w5s ()
MOD - D:\Programme\Winamp\Plugins\gen_ff.dll ()
MOD - D:\Programme\Winamp\nsutil.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_ml.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mp3.dll ()
MOD - D:\Programme\Winamp\libsndfile.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_jumpex.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mod.dll ()
MOD - D:\Programme\Winamp\Plugins\in_midi.dll ()
MOD - D:\Programme\Winamp\Plugins\in_cdda.dll ()
MOD - D:\Programme\Winamp\nde.dll ()
MOD - D:\Programme\Winamp\Plugins\in_nsv.dll ()
MOD - D:\Programme\Winamp\Plugins\in_dshow.dll ()
MOD - D:\Programme\Winamp\Plugins\in_avi.dll ()
MOD - D:\Programme\Winamp\Plugins\in_flac.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_orgler.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mp4.dll ()
MOD - D:\Programme\Winamp\Plugins\in_mkv.dll ()
MOD - D:\Programme\Winamp\Plugins\in_flv.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_hotkeys.dll ()
MOD - D:\Programme\Winamp\Plugins\gen_tray.dll ()
MOD - D:\Programme\Winamp\Plugins\in_linein.dll ()
MOD - D:\Programme\Rainlendar2\plugins\iCalendarPlugin.dll ()
MOD - D:\Programme\Rainlendar2\Rainlendar2.exe ()
MOD - D:\Programme\Rainlendar2\lfs.dll ()
MOD - D:\Programme\Rainlendar2\lua51.dll ()
MOD - C:\Program Files (x86)\ASUS\AASP\1.00.65\aaCenter.exe ()
MOD - C:\Program Files (x86)\ASUS\AASP\1.00.65\cpuutil.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files (x86)\ASUS\AASP\1.00.65\PowerDll.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- D:\Programme\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- D:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (DAUpdaterSvc) -- D:\Spiele\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- D:\Programme\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (epmntdrv) -- C:\Windows\SysNative\epmntdrv.sys ()
DRV:64bit: - (EuGdiDrv) -- C:\Windows\SysNative\EuGdiDrv.sys ()
DRV:64bit: - (VClone) -- C:\Windows\SysNative\DRIVERS\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\DRIVERS\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (L1E) -- C:\Windows\SysNative\DRIVERS\L1E60x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\DRIVERS\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (netr7364) -- C:\Windows\SysNative\DRIVERS\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (RTL8187) -- C:\Windows\SysNative\DRIVERS\wg111v2.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\DRIVERS\ASACPI.sys ()
DRV - (DrvAgent64) -- C:\Windows\SysWOW64\drivers\DrvAgent64.SYS (Phoenix Technologies)
DRV - (epmntdrv) -- C:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (EuGdiDrv) -- C:\Windows\SysWOW64\EuGdiDrv.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 CE C0 EE F1 41 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/ig"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..network.proxy.http: "87.98.136.60"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, stealthy.co"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: D:\Programme\VLC\npvlc.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.04.12 08:11:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.04.12 08:10:59 | 000,000,000 | ---D | M]
[2011.07.16 15:05:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\Extensions
[2013.04.25 22:40:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\Firefox\Profiles\8fnqi441.default\extensions
[2012.12.12 05:45:36 | 000,036,098 | ---- | M] () (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\firefox\profiles\8fnqi441.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
[2013.02.14 06:10:46 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Jupp\AppData\Roaming\mozilla\firefox\profiles\8fnqi441.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.04.12 08:10:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.04.12 08:11:01 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.08.12 20:20:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.06.28 17:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2012.08.31 18:12:36 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.31 18:12:36 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.31 18:12:36 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.31 18:12:36 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.31 18:12:36 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.31 18:12:36 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2006.09.18 23:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] D:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKCU..\Run: [Rainlendar2] D:\Programme\Rainlendar2\Rainlendar2.exe ()
O4 - HKLM..\RunOnce: [Z1] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Jupp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Jupp\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - D:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Programme\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2254D07A-F1F5-45A1-9197-CF2292ED39CE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F21EAA53-5830-4C8A-9A84-F18B79B3AB60}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: D:\Eigene Dateien\Desktop\The_Simpsons_1680 x 1050 widescreen.jpg
O24 - Desktop BackupWallPaper: D:\Eigene Dateien\Desktop\The_Simpsons_1680 x 1050 widescreen.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Programme\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 0
O33 - MountPoints2\{1a66d130-690a-11e1-ae57-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1a66d130-690a-11e1-ae57-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Msetup4.exe
O33 - MountPoints2\{4642c5c5-2663-11e1-8996-00248c2af28a}\Shell - "" = AutoRun
O33 - MountPoints2\{4642c5c5-2663-11e1-8996-00248c2af28a}\Shell\AutoRun\command - "" = I:\Setup.exe
O33 - MountPoints2\{7133bda4-afaa-11e0-b4f4-00248c2af28a}\Shell - "" = AutoRun
O33 - MountPoints2\{7133bda4-afaa-11e0-b4f4-00248c2af28a}\Shell\AutoRun\command - "" = J:\OriginInstaller.exe
O33 - MountPoints2\{b2cf56e9-afa4-11e0-8069-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b2cf56e9-afa4-11e0-8069-806e6f6e6963}\Shell\AutoRun\command - "" = B:\Bin\ASSETUP.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013.04.25 22:32:04 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Avira
[2013.04.25 22:26:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013.04.25 22:26:39 | 000,130,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.04.25 22:26:39 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.04.25 22:26:39 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013.04.25 22:26:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013.04.24 17:45:31 | 001,092,512 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2013.04.24 17:45:31 | 000,971,680 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2013.04.24 17:45:31 | 000,311,200 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.04.24 17:45:26 | 000,188,832 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.04.24 17:45:26 | 000,188,320 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.04.24 17:45:26 | 000,108,448 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.04.24 17:45:09 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.04.21 09:32:09 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Siup
[2013.04.21 09:32:09 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Nuyt
[2013.04.21 09:32:09 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Roaming\Ertu
[2013.04.19 09:58:14 | 000,000,000 | ---D | C] -- C:\Users\Jupp\AppData\Local\.elfohilfe
[2013.04.14 22:58:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2013.04.12 08:10:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.04.05 11:50:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2013.04.05 11:46:00 | 026,956,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2013.04.05 11:46:00 | 025,256,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2013.04.05 11:46:00 | 020,542,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2013.04.05 11:46:00 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2013.04.05 11:46:00 | 015,508,512 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2013.04.05 11:46:00 | 015,042,928 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2013.04.05 11:46:00 | 013,088,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2013.04.05 11:46:00 | 009,414,456 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2013.04.05 11:46:00 | 007,959,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2013.04.05 11:46:00 | 007,573,816 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2013.04.05 11:46:00 | 006,271,872 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2013.04.05 11:46:00 | 002,913,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2013.04.05 11:46:00 | 002,728,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2013.04.05 11:46:00 | 002,539,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2013.04.05 11:46:00 | 002,355,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2013.04.05 11:46:00 | 001,995,552 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2013.04.05 11:46:00 | 001,807,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6431422.dll
[2013.04.05 11:46:00 | 001,510,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6431422.dll
[2013.04.04 17:25:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mega Codec Pack
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.04.26 14:49:44 | 000,003,840 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.04.26 14:49:44 | 000,003,840 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.04.26 12:56:20 | 001,468,666 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.04.26 12:56:20 | 000,636,228 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.04.26 12:56:20 | 000,602,310 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.04.26 12:56:20 | 000,131,254 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.04.26 12:56:20 | 000,107,728 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.04.26 12:49:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.04.26 11:40:53 | 000,000,020 | ---- | M] () -- C:\Users\Jupp\defogger_reenable
[2013.04.25 23:03:01 | 000,375,288 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.04.24 17:45:16 | 000,108,448 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013.04.24 17:45:13 | 000,311,200 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2013.04.24 17:45:13 | 000,188,832 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2013.04.24 17:45:13 | 000,188,320 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2013.04.24 17:45:12 | 001,092,512 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2013.04.24 17:45:12 | 000,971,680 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll
[2013.04.23 21:27:31 | 000,036,352 | ---- | M] () -- C:\Users\Jupp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.04.18 18:59:20 | 000,691,592 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.04.18 18:59:20 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.04.05 13:34:11 | 000,004,459 | ---- | M] () -- C:\Users\Jupp\.recently-used.xbel
[2013.04.04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.04.26 11:40:53 | 000,000,020 | ---- | C] () -- C:\Users\Jupp\defogger_reenable
[2013.04.05 13:34:11 | 000,004,459 | ---- | C] () -- C:\Users\Jupp\.recently-used.xbel
[2013.02.10 14:19:50 | 000,000,000 | ---- | C] () -- C:\Users\Jupp\.JavaPowUpload.properties
[2012.05.15 08:51:31 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2012.05.15 08:51:31 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2012.05.15 08:51:31 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2012.05.15 08:45:39 | 000,030,903 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2012.05.10 16:33:31 | 000,010,818 | ---- | C] () -- C:\Windows\scunin.dat
[2012.01.23 01:44:58 | 000,024,576 | R--- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2012.01.23 01:44:58 | 000,014,392 | R--- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011.12.14 16:28:27 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2011.12.14 16:28:09 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2011.12.14 16:27:46 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011.10.12 09:56:43 | 001,489,842 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.09.11 19:11:53 | 000,000,216 | ---- | C] () -- C:\Windows\PowerReg.dat
[2011.08.07 09:03:38 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2011.08.03 12:09:10 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011.07.21 10:24:55 | 000,036,352 | ---- | C] () -- C:\Users\Jupp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.17 18:48:45 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011.07.16 15:19:24 | 002,340,992 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2011.07.16 15:19:24 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2011.07.16 15:19:24 | 000,018,048 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2011.07.16 15:19:24 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2011.07.16 15:19:24 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2011.07.16 14:45:57 | 000,031,776 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2011.07.16 14:45:57 | 000,031,776 | ---- | C] () -- C:\ProgramData\nvModes.001
[2011.07.16 14:22:46 | 000,011,916 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2011.07.16 14:22:31 | 000,011,683 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011.07.16 14:19:45 | 000,000,732 | ---- | C] () -- C:\Users\Jupp\AppData\Local\d3d9caps64.dat
========== ZeroAccess Check ==========
[2006.11.02 17:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysWOW64\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.21 04:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report > Kann ich denn jetzt davon ausgehen, dass das Problem behoben ist? Müssen diese Systemordner auf meiner zweiten Partition bestehen bleiben?
Und könntest du mir vielleicht noch sagen, was jetzt eigentlich genau passiert ist und wie ich so etwas in Zukunft verhindern kann? |