Hallo lieber cosinus ich danke dir erstmal das du dir zeit nimmst mit mir mein problem zu lösen.
ich hab in einem theard von hier schonmal ein so problem gefunden gehabt da musste er mit OTL das selbe machen ich hab mir in der zeit wo ich gewartet habe auf die antwort, schonmal das gemacht. ich werde es hier einfach posten falls es auf's selbe hinaus geht wenn nicht mach ich dann mit dem farbar's recovery scan tool
OTL
OTL Logfile: Code:
OTL logfile created on: 10.09.2013 16:39:07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = d:\Users\U\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
8,00 Gb Total Physical Memory | 5,94 Gb Available Physical Memory | 74,31% Memory free
15,99 Gb Paging File | 13,82 Gb Available in Paging File | 86,39% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 58,50 Gb Total Space | 9,47 Gb Free Space | 16,19% Space Free | Partition Type: NTFS
Drive D: | 174,29 Gb Total Space | 56,05 Gb Free Space | 32,16% Space Free | Partition Type: NTFS
Computer Name: U-PC | User Name: U | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.09.10 16:37:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- d:\Users\U\Desktop\OTL.exe
PRC - [2013.09.10 14:28:58 | 002,285,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2013.09.10 14:28:58 | 001,616,048 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe
PRC - [2013.09.10 14:28:58 | 000,161,968 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\loggingserver.exe
PRC - [2013.09.02 14:36:53 | 000,084,024 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2013.09.02 14:36:39 | 000,347,192 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.09.02 14:36:39 | 000,108,088 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.08.27 07:56:14 | 003,534,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2013.08.26 17:31:10 | 004,851,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2013.08.20 23:42:04 | 000,300,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2013.08.17 19:55:05 | 000,311,704 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013.07.03 18:33:38 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013.06.13 11:17:51 | 004,150,112 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2013.03.15 07:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
========== Modules (No Company Name) ==========
MOD - [2013.09.10 14:28:58 | 002,285,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2013.09.10 14:28:58 | 000,521,904 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\log4cplusU.dll
MOD - [2013.09.10 14:28:58 | 000,145,072 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\SiteSafety.dll
MOD - [2013.08.17 19:55:05 | 003,551,640 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013.08.17 19:55:05 | 000,311,704 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
MOD - [2009.08.12 00:18:28 | 000,497,664 | ---- | M] () -- C:\Windows\SysWOW64\ac3filter.acm
========== Services (SafeList) ==========
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.09.10 14:28:58 | 001,616,048 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe -- (vToolbarUpdater15.4.0)
SRV - [2013.09.02 14:36:53 | 000,084,024 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.09.02 14:36:39 | 000,108,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2013.08.28 23:47:18 | 000,563,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.08.27 07:56:14 | 003,534,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013.08.20 23:42:04 | 000,300,640 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013.08.20 21:19:20 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.08.17 19:55:05 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.07.03 18:33:38 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013.06.13 11:17:51 | 004,150,112 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013.06.03 16:21:54 | 000,197,736 | R--- | M] () [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.03.15 07:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.12.18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.09.10 14:28:58 | 000,045,856 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013.09.02 14:36:56 | 000,132,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2013.09.02 14:36:56 | 000,105,344 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2013.08.22 23:25:44 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2013.08.22 23:08:14 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2013.08.22 22:55:04 | 000,241,464 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2013.08.22 22:54:54 | 000,192,824 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2013.08.20 22:53:58 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2013.08.01 16:07:06 | 000,251,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2013.08.01 16:06:28 | 000,147,768 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2013.08.01 16:04:56 | 000,031,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2013.06.21 03:09:46 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss6.sys -- (taphss6)
DRV:64bit: - [2013.04.25 17:49:48 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2013.02.18 09:22:16 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012.08.23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 16:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.02.16 13:42:00 | 000,676,968 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 05:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.06.17 10:15:36 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
DRV:64bit: - [2010.06.14 10:41:10 | 000,038,528 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010.05.14 23:04:16 | 000,073,856 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2010.05.14 23:04:16 | 000,028,800 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008.07.26 19:59:18 | 000,023,464 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\elrawdsk64bit.sys -- (ElRawDisk)
DRV:64bit: - [2007.05.14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV - [2013.03.14 14:36:18 | 000,017,160 | ---- | M] (XFire) [File_System | On_Demand | Stopped] -- D:\Xfire2\XFDriver64.sys -- (XFDriver64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.homesearch-hub.info/?pid=658&r=2013/06/16&hid=2758861023&lg=EN&cc=DE&unqvl=20
IE - HKLM\..\SearchScopes,DefaultScope = {11F4FE08-5C4F-4F73-970F-888E55D190CF}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = hxxp://websearch.homesearch-hub.info/?l=1&q={searchTerms}&pid=658&r=2013/06/16&hid=2758861023&lg=EN&cc=DE&unqvl=20
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = d:\Users\U\Desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 84 55 C6 84 59 AA CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = hxxp://websearch.homesearch-hub.info/?l=1&q={searchTerms}&pid=658&r=2013/06/16&hid=2758861023&lg=EN&cc=DE&unqvl=20
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..CT1561552.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch"
FF - prefs.js..browser.search.defaultthis.engineName: "Hotspot Shield Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&CUI=UN13117919511767327&UM=1&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "WebSearch"
FF - prefs.js..browser.search.order.1,S: S", "WebSearch"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch"
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.21
FF - prefs.js..extensions.enabledAddons: avg%40toolbar:15.4.0.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=2&CUI=UN13117919511767327&UM=1&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: ""
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.7: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.7: C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\U\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\U\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\U\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\15.4.0.5 [2013.09.10 14:29:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.08.17 19:55:02 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.08.17 19:55:02 | 000,000,000 | ---D | M]
[2013.04.26 02:15:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\U\AppData\Roaming\mozilla\Extensions
[2013.08.27 17:27:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\U\AppData\Roaming\mozilla\Firefox\Profiles\hw6pl1gi.default\extensions
[2013.08.27 17:27:09 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\U\AppData\Roaming\mozilla\Firefox\Profiles\hw6pl1gi.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013.07.31 14:53:35 | 000,824,302 | ---- | M] () (No name found) -- C:\Users\U\AppData\Roaming\mozilla\firefox\profiles\hw6pl1gi.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.08.11 13:30:59 | 000,001,005 | ---- | M] () -- C:\Users\U\AppData\Roaming\mozilla\firefox\profiles\hw6pl1gi.default\searchplugins\conduit.xml
[2013.06.16 10:32:57 | 000,007,851 | ---- | M] () -- C:\Users\U\AppData\Roaming\mozilla\firefox\profiles\hw6pl1gi.default\searchplugins\WebSearch.xml
[2013.08.17 19:55:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.08.17 19:55:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2013.08.17 19:55:05 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013.09.10 14:29:24 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\FIREFOXEXT\15.4.0.5
========== Chrome ==========
CHR - Extension: No name found = C:\Users\U\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\U\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\U\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\U\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\U\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: No name found = C:\Users\U\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [EADM] D:\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C2249E8E-86F6-4D3B-B54B-B16425D06487}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0\ViProtocol.dll (AVG Secure Search)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SCTBootTasks)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
ActiveX:64bit: {1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1} - .NET Framework
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1} - .NET Framework
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe ()
MsConfig:64bit - StartUpReg: BCSSync - hkey= - key= - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013.09.10 16:37:54 | 000,602,112 | ---- | C] (OldTimer Tools) -- d:\Users\U\Desktop\OTL.exe
[2013.09.10 14:50:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2013.09.10 14:50:23 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sophos
[2013.09.10 14:50:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos
[2013.09.10 14:30:21 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Roaming\AVG2014
[2013.09.10 14:29:37 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Local\AVG Secure Search
[2013.09.10 14:29:25 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Roaming\TuneUp Software
[2013.09.10 14:29:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013.09.10 14:29:16 | 000,045,856 | ---- | C] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013.09.10 14:29:13 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2013.09.10 14:29:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
[2013.09.10 14:29:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
[2013.09.10 14:28:12 | 000,000,000 | -H-D | C] -- C:\$AVG
[2013.09.10 14:28:12 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2014
[2013.09.10 14:27:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2013.09.10 14:25:38 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Local\MFAData
[2013.09.10 14:25:38 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2013.09.10 14:25:38 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Local\Avg2014
[2013.09.05 20:56:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastChaosGER
[2013.09.05 20:46:50 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Roaming\Unity
[2013.09.05 20:24:36 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Local\Unity
[2013.09.05 19:02:21 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013.08.22 23:25:44 | 000,212,280 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2013.08.22 23:08:14 | 000,294,712 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2013.08.22 22:55:04 | 000,241,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2013.08.22 22:54:54 | 000,192,824 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2013.08.20 22:53:58 | 000,123,704 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2013.08.17 19:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.08.15 18:05:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iSRO
[2013.08.15 14:52:11 | 000,000,000 | ---D | C] -- C:\Users\U\AppData\Local\Diagnostics
========== Files - Modified Within 30 Days ==========
[2013.09.10 16:40:22 | 000,377,856 | ---- | M] () -- d:\Users\U\Desktop\gmer_2.1.19163.exe
[2013.09.10 16:37:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- d:\Users\U\Desktop\OTL.exe
[2013.09.10 16:32:37 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.09.10 16:32:37 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.09.10 16:27:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.09.10 16:27:29 | 2146,148,351 | -HS- | M] () -- C:\hiberfil.sys
[2013.09.10 16:18:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.09.10 16:12:02 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-904730392-2491290814-2578163216-1000UA.job
[2013.09.10 14:50:23 | 000,002,929 | ---- | M] () -- d:\Users\U\Desktop\Sophos Virus Removal Tool.lnk
[2013.09.10 14:29:25 | 000,000,987 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2013.09.10 14:29:24 | 000,003,715 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.09.10 14:28:58 | 000,045,856 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013.09.09 22:34:01 | 000,000,059 | ---- | M] () -- d:\Users\U\Documents\aionmemo_8255658c.dat
[2013.09.09 19:12:00 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-904730392-2491290814-2578163216-1000Core.job
[2013.09.08 15:49:11 | 000,000,080 | ---- | M] () -- C:\Users\U\AppData\Roaming\mBot.ini
[2013.09.02 14:36:56 | 000,132,088 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.09.02 14:36:56 | 000,105,344 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.09.02 14:36:56 | 000,081,112 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013.08.22 23:25:44 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2013.08.22 23:08:14 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2013.08.22 22:55:04 | 000,241,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2013.08.22 22:54:54 | 000,192,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2013.08.20 22:53:58 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
========== Files Created - No Company Name ==========
[2013.09.10 16:40:21 | 000,377,856 | ---- | C] () -- d:\Users\U\Desktop\gmer_2.1.19163.exe
[2013.09.10 14:50:23 | 000,002,929 | ---- | C] () -- d:\Users\U\Desktop\Sophos Virus Removal Tool.lnk
[2013.09.10 14:29:25 | 000,000,987 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2013.09.10 14:29:10 | 000,003,715 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.09.05 19:02:03 | 000,001,104 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-904730392-2491290814-2578163216-1000UA.job
[2013.09.05 19:02:02 | 000,001,052 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-904730392-2491290814-2578163216-1000Core.job
[2013.07.12 23:12:25 | 001,584,728 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.07.02 22:54:17 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.07.02 22:54:16 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.06.15 22:05:19 | 000,003,584 | ---- | C] () -- C:\Users\U\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.05.20 22:40:35 | 000,000,080 | ---- | C] () -- C:\Users\U\AppData\Roaming\mBot.ini
[2013.02.27 08:57:04 | 004,283,392 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2012.12.28 23:04:22 | 000,036,352 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2012.07.17 15:22:04 | 000,179,200 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012.07.03 03:28:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012.05.22 01:28:58 | 000,155,648 | ---- | C] () -- C:\Windows\SysWow64\mlc.dll
[2011.12.08 06:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 04:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.09.10 14:30:21 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\AVG2014
[2013.07.12 23:47:38 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\Just Aion Launcher
[2013.05.26 18:41:07 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\LolClient
[2013.07.02 19:07:49 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\Origin
[2013.09.06 17:14:10 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\Teeworlds
[2013.09.10 16:30:52 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\TS3Client
[2013.09.10 14:29:25 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\TuneUp Software
[2013.09.05 20:46:50 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\Unity
[2013.04.26 02:05:25 | 000,000,000 | ---D | M] -- C:\Users\U\AppData\Roaming\Win7codecs
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2013.09.10 14:28:12 | 000,000,000 | -H-D | M] -- C:\$AVG
[2013.04.25 15:58:01 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2009.07.14 07:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2013.04.25 15:51:40 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2013.04.26 02:21:20 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2013.04.25 17:39:25 | 000,000,000 | ---D | M] -- C:\NVIDIA
[2009.07.14 05:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2013.06.21 18:53:12 | 000,000,000 | R--D | M] -- C:\Program Files
[2013.09.10 14:50:12 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2013.09.10 14:50:29 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2013.04.25 15:51:40 | 000,000,000 | -HSD | M] -- C:\Programme
[2013.04.25 15:51:41 | 000,000,000 | -HSD | M] -- C:\Recovery
[2013.05.24 17:23:07 | 000,000,000 | ---D | M] -- C:\Riot Games
[2013.09.10 16:40:45 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2013.04.25 17:41:43 | 000,000,000 | R--D | M] -- C:\Users
[2013.09.10 16:22:17 | 000,000,000 | ---D | M] -- C:\Windows
< %PROGRAMFILES%\*.exe >
< %LOCALAPPDATA%\*.exe >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.manifest /3 >
< MD5 for: EXPLORER.EXE >
[2011.02.26 08:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 07:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2011.02.26 07:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 04:17:10 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.20 05:24:46 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009.07.14 03:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2011.02.26 08:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
< MD5 for: REGEDIT.EXE >
[2009.07.14 03:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=2E2C937846A0B8789E5E91739284D17A -- C:\Windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe
[2009.07.14 03:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 03:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\SysWOW64\regedit.exe
[2009.07.14 03:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5a78515e29ea6f39\regedit.exe
< MD5 for: USERINIT.EXE >
[2010.11.20 04:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 04:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 05:25:26 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 05:25:26 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WININIT.EXE >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.20 05:25:32 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 05:25:32 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report > --- --- ---
Extras
OTL Logfile: Code:
OTL Extras logfile created on: 10.09.2013 16:39:07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = d:\Users\U\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
8,00 Gb Total Physical Memory | 5,94 Gb Available Physical Memory | 74,31% Memory free
15,99 Gb Paging File | 13,82 Gb Available in Paging File | 86,39% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 58,50 Gb Total Space | 9,47 Gb Free Space | 16,19% Space Free | Partition Type: NTFS
Drive D: | 174,29 Gb Total Space | 56,05 Gb Free Space | 32,16% Space Free | Partition Type: NTFS
Computer Name: U-PC | User Name: U | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe ()
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00580224-E551-4C24-B1F3-666D857BBB1C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{24AD4785-EDE0-40AF-998E-70A45D0F7419}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2EBB3309-0DBD-4306-A0B5-3FE35F7E9807}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3276B5BC-93FB-4A3B-8593-7C63592ED587}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4F4B80B1-581C-4921-836A-7FE0BD7BFBE0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{51B96B0C-8E7C-4BDB-9906-2EDCD7115F0A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{5DF194E6-6816-45E1-AF48-E0487D7A01C2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7852838F-CC74-4D32-B696-2EFAD5DDA720}" = lport=57566 | protocol=6 | dir=in | name=pando media booster |
"{804660C7-49F4-47A2-86E0-6A652C430D80}" = lport=139 | protocol=6 | dir=in | app=system |
"{819FE6C4-8FF2-4767-8341-EA5E1AA99891}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{898A8806-CC1F-4720-80AE-1B4F8AB3B4B9}" = rport=139 | protocol=6 | dir=out | app=system |
"{8C2FC35C-81ED-4C01-B61C-343B0F527908}" = lport=445 | protocol=6 | dir=in | app=system |
"{936181A3-6FA3-4149-8B19-1245A0661EE4}" = lport=57566 | protocol=6 | dir=in | name=pando media booster |
"{95A69E4E-7921-4E40-9448-E8FA9B899604}" = rport=137 | protocol=17 | dir=out | app=system |
"{9774E885-D798-486F-84B3-7BCAA0866703}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{AF752418-24C6-4FC1-9AFD-D19C67C850B5}" = lport=57566 | protocol=17 | dir=in | name=pando media booster |
"{BBA0C30F-2149-488C-86CC-4DF8574EAF88}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C68C667E-085A-4172-B61B-183DC9D4541D}" = lport=138 | protocol=17 | dir=in | app=system |
"{C6EF03FC-2131-45F8-B018-1030A41BDBA8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CCDFAD3C-AA4C-417F-AF86-543D064FD02F}" = rport=445 | protocol=6 | dir=out | app=system |
"{D699F968-B27E-498A-BEF9-24F594C1001D}" = rport=138 | protocol=17 | dir=out | app=system |
"{EC30315C-85A2-4BBB-8EDB-A534CF979ECB}" = lport=137 | protocol=17 | dir=in | app=system |
"{ED7ACBCF-4C59-4DDB-B878-EDE534D15959}" = lport=57566 | protocol=17 | dir=in | name=pando media booster |
"{F5A43B9C-E1DB-45BE-B111-137D68C8707E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FEEB6E3F-C9E3-4E65-AC21-29E6859321A1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00D56EE9-459B-463B-90BD-02B4698DDE1F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{012B38F3-66E7-4930-ACD9-98E8B355CC1A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{03E26567-AB21-4DBE-86F0-77D398C8957A}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{0B338F41-0DA6-484E-88AE-80A6B295E46B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0C17B17D-B3BD-4DC1-A0A4-4854C5DF04D9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{1438CDA0-823E-4037-BA4D-040792CB3A80}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{16B16CC8-58BE-4295-9BFA-B34A273E09D4}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{17013A58-B078-48CE-8C75-4CF784EFA527}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{251A4456-BA9F-4337-8917-9A272CAB9516}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2EA91DBF-A883-4DBC-8E16-FF734CD98C88}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{32898028-6B7F-40C6-896C-C2B270701587}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{329DD643-3909-465E-8579-D84FE0E74B47}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{343D9C97-F0C2-4361-8F63-C2A4EFEC5F4D}" = protocol=6 | dir=in | app=d:\origin\battlefield 3\bf3.exe |
"{35698D68-830F-479B-8451-108F27F5505B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{3BB8C52E-2707-4A56-8741-274726061591}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{41493464-7E1A-41C8-B471-62F83795CD9A}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{4298C049-0C9F-48D2-B8BF-19AB5EC6CFBF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{45A5E063-219E-41B4-BF3A-1058C7C3F645}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{4856F4DD-86C0-44B0-84E4-9A91B681390E}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{49F17401-8E8E-4D28-A4E7-E2AEFD69B14E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4E56D2D2-8867-4A76-877B-6931C70CE6E4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5016E1B4-102A-4231-8E98-32C6F9A37115}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{502D06E0-B6A7-4968-9848-C1732510C60E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{50D32ACA-A735-4BEA-BC72-583D8ED1AC88}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{553BF938-0FA0-47F4-AF00-4F69B42DBD3F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{59A6D243-655D-41E6-85D2-5EDD70082FF4}" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.patch.exe |
"{5A1B75E5-5996-4F81-920F-2CD2FEAB1718}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5B327A0C-1ED9-449A-87A4-1AB85B4B8B8F}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{5DF8F95D-489B-4104-B224-E836B3B1B4A1}" = protocol=58 | dir=in | app=system |
"{5EA3C4CB-DA61-4701-A8E6-E9F462D79D1A}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{60A39773-488E-4E9C-B86B-A3895C172B02}" = protocol=6 | dir=in | app=d:\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{6ED848A5-6F77-4FDC-B6A7-B57430BDF9E0}" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.exe |
"{751BA03E-5FAB-4CA3-9FEF-692C697FA5C1}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{772A73E1-D507-40A2-9F6D-385662DE3632}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{7B9D898C-85EE-4A25-AD3E-3AC3058B678A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D51459E-F540-4274-B05D-F09CEE7AB93F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{7E633D28-5F9C-4B21-BA23-F6AD75465B11}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{83337B99-678B-4E98-B360-F0B14884A072}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{896FA055-BE67-4AAA-AD19-BA9616B94481}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{8D6110D7-BAE3-4215-8083-A5E3C397B011}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{8EADA12D-758B-4FED-AEC8-205D711525C4}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{933CCDC8-3704-480D-9461-A509D78F7906}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{99D9F892-214D-4919-86C1-F60044F88C16}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9C733785-753F-447C-ADD1-D8263BA7A779}" = protocol=6 | dir=in | app=d:\world of warcraft\wow-x.x.x.x-4.0.0.12911-downloader.exe |
"{9E15640C-993F-451F-91FF-8E9674BF05FA}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{A9DF810D-439B-4152-8031-936D729BF5D8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{ABEDE9EC-47C8-4EC8-BCAB-B11D9574E5A4}" = protocol=17 | dir=in | app=d:\world of warcraft\wow-x.x.x.x-4.0.0.12911-downloader.exe |
"{BC9468B9-276D-47B2-8C66-E1309D53EE49}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{BDDDE5EE-E813-42C6-AFF0-7C7BC110B510}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{BEBA6A70-AE9B-47FB-9E01-E3A77ED36776}" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.patch.exe |
"{C8598C67-1D92-451B-BDA3-BA3F3E5CE71C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C9312ED9-4D5B-4575-913A-AF739F5B6F12}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{CD95DB8D-ED49-4A78-BF16-6C05949167E9}" = protocol=6 | dir=out | app=system |
"{D1578289-A012-4619-9129-EB459531E966}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DAA3D5FF-FDE2-46A4-A282-0856FC4ADB03}" = protocol=17 | dir=in | app=d:\origin\battlefield 3\bf3.exe |
"{EB151DFE-D79E-4D09-9CFE-4F03AC84B33C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{EBBB0467-D14F-4755-B675-8FF6C83ECFE4}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EC7BA678-FC3D-48ED-913B-AB5902BD32C5}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{F1C5CA69-871E-403A-913A-6A7D22431F5A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{F7331671-E486-484A-A2D4-CF9A2C7BEE42}" = protocol=17 | dir=in | app=d:\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{FCD5DE4E-2540-4F4A-8598-0E29BE2FB9DE}" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.exe |
"TCP Query User{01C2A085-CAB8-4403-B821-0EC5543CAD96}D:\users\u\desktop\bard\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\bard\mbot_vsro110.exe |
"TCP Query User{05D28D3E-22CF-4CB3-B81F-6D135D41CD5B}D:\users\u\desktop\nuker\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\nuker\mbot_vsro110.exe |
"TCP Query User{1F5166F8-042C-4443-8050-8B792FA0D197}D:\xfire2\xfire.exe" = protocol=6 | dir=in | app=d:\xfire2\xfire.exe |
"TCP Query User{5524EB14-EA9A-4000-8D21-6AC752827238}D:\arma 2\steamapps\common\arma 2\arma2.exe" = protocol=6 | dir=in | app=d:\arma 2\steamapps\common\arma 2\arma2.exe |
"TCP Query User{69BEED31-7E8C-4F91-AF4B-1BDDFA6A736E}D:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"TCP Query User{7F4B8752-F64A-42F2-A609-BFFD81E43CDD}D:\users\u\desktop\neuer ordner\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\neuer ordner\mbot_vsro110.exe |
"TCP Query User{937B75E7-195F-4A02-91B3-D752BF7A5420}D:\users\u\desktop\wizz bot\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\wizz bot\mbot_vsro110.exe |
"TCP Query User{A56895BB-E63E-4C19-B73D-2904FA861691}D:\users\u\desktop\bot 1\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\bot 1\mbot_vsro110.exe |
"TCP Query User{AC8AD8AB-1070-4D95-B42D-FD7D3172BEF5}C:\users\u\appdata\local\temp\skype.exe" = protocol=6 | dir=in | app=c:\users\u\appdata\local\temp\skype.exe |
"TCP Query User{BB1E901D-C131-4325-80F1-A6CB2D592DF7}D:\users\u\desktop\trader\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\trader\mbot_vsro110.exe |
"TCP Query User{C0718375-A207-40DA-8A55-765B5F6628D2}D:\users\u\desktop\bot 0 (wizzard)\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\bot 0 (wizzard)\mbot_vsro110.exe |
"TCP Query User{D873E7B6-5640-44FF-BD40-5F46F86D90E8}D:\users\u\desktop\neuer ordner (2)\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\neuer ordner (2)\mbot_vsro110.exe |
"TCP Query User{DB887205-A5BA-46BD-9B65-799EF4CF94FC}D:\users\u\desktop\rogue bot\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\rogue bot\mbot_vsro110.exe |
"TCP Query User{F4E53452-C0DD-4A20-9C0B-3B38C4DEBC8E}D:\users\u\desktop\spear\mbot_vsro110.exe" = protocol=6 | dir=in | app=d:\users\u\desktop\spear\mbot_vsro110.exe |
"TCP Query User{FCD83A2A-FC53-4F12-AA3E-22AB96FFE5F6}D:\arma 2\steamapps\common\arma 2 operation arrowhead\arma2oa.exe" = protocol=6 | dir=in | app=d:\arma 2\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"UDP Query User{06639E68-98E3-4246-A077-D9E0FCAAF860}D:\users\u\desktop\neuer ordner (2)\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\neuer ordner (2)\mbot_vsro110.exe |
"UDP Query User{147E2022-DE3B-423C-8F1A-DB0BCA9D295B}D:\users\u\desktop\bot 1\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\bot 1\mbot_vsro110.exe |
"UDP Query User{2273B1A7-006B-42E7-8149-2288DCC4DAE1}D:\users\u\desktop\spear\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\spear\mbot_vsro110.exe |
"UDP Query User{293ED498-94BE-4F09-AC1E-62207F861863}D:\users\u\desktop\trader\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\trader\mbot_vsro110.exe |
"UDP Query User{6A0E6516-F3BA-4113-B850-E7985D459CB0}D:\users\u\desktop\wizz bot\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\wizz bot\mbot_vsro110.exe |
"UDP Query User{73E4BB72-44F3-474D-A851-B48B5B534725}D:\arma 2\steamapps\common\arma 2\arma2.exe" = protocol=17 | dir=in | app=d:\arma 2\steamapps\common\arma 2\arma2.exe |
"UDP Query User{82227A65-4EB8-46E5-B2D5-ACFE20B3202B}D:\users\u\desktop\neuer ordner\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\neuer ordner\mbot_vsro110.exe |
"UDP Query User{8E1B50F3-1562-4B87-9977-10BE64BF840B}D:\users\u\desktop\bot 0 (wizzard)\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\bot 0 (wizzard)\mbot_vsro110.exe |
"UDP Query User{93E2661A-2DA1-4FC4-83A8-E09AD71CD791}D:\arma 2\steamapps\common\arma 2 operation arrowhead\arma2oa.exe" = protocol=17 | dir=in | app=d:\arma 2\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"UDP Query User{9F2270F6-76CF-4C24-AA7E-9826D86FD793}D:\users\u\desktop\bard\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\bard\mbot_vsro110.exe |
"UDP Query User{AA856F2F-4BF5-4536-9F7E-866AAFCF900F}C:\users\u\appdata\local\temp\skype.exe" = protocol=17 | dir=in | app=c:\users\u\appdata\local\temp\skype.exe |
"UDP Query User{AD6DD0C5-20D8-4BAF-8A64-F269C2030CD8}D:\users\u\desktop\rogue bot\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\rogue bot\mbot_vsro110.exe |
"UDP Query User{D3BBCC8F-57B4-4D9A-A317-009BA8172C51}D:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"UDP Query User{EFA1B74B-1789-4014-8341-D4B132B9FBAD}D:\xfire2\xfire.exe" = protocol=17 | dir=in | app=d:\xfire2\xfire.exe |
"UDP Query User{F5996B24-B5C1-4798-AEBF-37755087C147}D:\users\u\desktop\nuker\mbot_vsro110.exe" = protocol=17 | dir=in | app=d:\users\u\desktop\nuker\mbot_vsro110.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5
"{2EA43D50-131A-44DE-A678-47F6D572AB30}" = AVG 2014
"{4EC90F78-14A6-460E-A6F7-53C85A431FBD}" = AVG 2014
"{70DFF8B2-44A3-2C2C-FB21-783E8291265F}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"AVG" = AVG 2014
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VLC media player" = VLC media player 2.0.7
"WinRAR archiver" = WinRAR 4.01 (64-Bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable
"{43ADAE00-A4ED-4379-A76D-A1FF5D9D334A}_is1" = Xfire 2.0
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.5
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{82E73E8D-E1E7-45A4-A311-6D31492AA913}_is1" = AION Free-to-Play Version 1.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8C0CAA7A-3272-4991-A808-2C7559DE3409}" = Win7codecs
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2010
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1" = Gameforge Live 1.7.0 "Legend"
"{A86A50FC-7C22-478B-BAEF-82393328825F}" = LastChaosGER
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) - Deutsch
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B829E117-D072-41EA-9606-9826A38D34C1}" = Sophos Virus Removal Tool
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG Secure Search" = AVG Security Toolbar
"ESN Sonar-0.70.4" = ESN Sonar
"Mozilla Firefox 23.0.1 (x86 de)" = Mozilla Firefox 23.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"SP_f5d3e0aa" = SafeSaver 1.74
"Steam App 219540" = Arma 2: Operation Arrowhead Beta
"Steam App 33910" = Arma 2
"Steam App 33930" = Arma 2: Operation Arrowhead
"XfireCodec" = Xfire Codec (remove only)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 10.09.2013 10:35:43 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\guardgui.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:40:43 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\guardgui.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:40:52 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\avscan.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:41:16 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\guardgui.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:41:41 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\avscan.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:41:43 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\guardgui.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:42:17 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\guardgui.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:43:08 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\avscan.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:43:10 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\guardgui.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
Error - 10.09.2013 10:47:03 | Computer Name = U-PC | Source = Avira Antivirus | ID = 4115
Description = Eine Programmdatei von AntiVir (c:\program files (x86)\avira\antivir
desktop\guardgui.exe) ist nicht vorhanden oder wurde verändert bzw. zerstört! Fehlercode:
0x0
[ System Events ]
Error - 10.09.2013 10:22:39 | Computer Name = U-PC | Source = DCOM | ID = 10005
Description =
Error - 10.09.2013 10:22:38 | Computer Name = U-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location
Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 10.09.2013 10:22:39 | Computer Name = U-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location
Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 10.09.2013 10:22:39 | Computer Name = U-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location
Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 10.09.2013 10:22:39 | Computer Name = U-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location
Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 10.09.2013 10:22:39 | Computer Name = U-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location
Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 10.09.2013 10:22:39 | Computer Name = U-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location
Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 10.09.2013 10:22:39 | Computer Name = U-PC | Source = Service Control Manager | ID = 7001
Description = Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location
Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068
Error - 10.09.2013 10:23:22 | Computer Name = U-PC | Source = DCOM | ID = 10005
Description =
Error - 10.09.2013 10:26:14 | Computer Name = U-PC | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
< End of report > --- --- ---
Dann war da der Zweite Schritt das hier
AW: Win32/Jeefo.A loswerden
Lade Dir Gmer von dieser Seite herunter
(auf den Button Download EXE drücken) und das Programm auf dem Desktop speichern.
alle anderen Scanner gegen Viren, Spyware, usw. deaktivieren
Alle anderen Programme sollen geschlossen sein.
Starte gmer.exe (Programm hat einen willkürlichen Programm-Namen).
Vista und Win7 User mit Rechtsklick und als Administrator starten.
Sollte sich ein Fenster mit folgender Warnung öffnen:
WARNING !!!
GMER has found system modification, which might have been caused by ROOTKIT activity.
Do you want to fully scan your system ?
Unbedingt auf "No" klicken.
Entferne rechts den Haken bei:
IAT/EAT
Alle Festplatten ausser die Systemplatte (normalerweise ist nur C:\ angehackt)
Show all (sollte abgehackt sein)
Starte den Scan mit "Scan". Mache nichts am Computer während der Scan läuft.
Wenn der Scan fertig ist klicke auf Save und speichere die Logfile unter Gmer.txt auf deinem Desktop. Mit "Ok" wird GMER beendet.
Antiviren-Programm und sonstige Scanner wieder einschalten, bevor Du ins Netz gehst!
Bitte poste in deiner nächsten Antwort
gmer.txt Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-09-10 16:55:02
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000055 ST325082 rev.3.AE 232,89GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\U\AppData\Local\Temp\pgddapog.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\SysWOW64\PnkBstrA.exe[2148] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000072641a22 2 bytes [64, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2148] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000072641ad0 2 bytes [64, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2148] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000072641b08 2 bytes [64, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2148] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000072641bba 2 bytes [64, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2148] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000072641bda 2 bytes [64, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076091465 2 bytes [09, 76]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760914bb 2 bytes [09, 76]
.text ... * 2
.text C:\Program Files (x86)\AVG Secure Search\vprot.exe[3996] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000076091465 2 bytes [09, 76]
.text C:\Program Files (x86)\AVG Secure Search\vprot.exe[3996] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000760914bb 2 bytes [09, 76]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076091465 2 bytes [09, 76]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760914bb 2 bytes [09, 76]
.text ... * 2
.text d:\Users\U\Desktop\OTL.exe[5000] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 69 0000000076091465 2 bytes [09, 76]
.text d:\Users\U\Desktop\OTL.exe[5000] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 155 00000000760914bb 2 bytes [09, 76]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4396:4824] 000007fefafb2a7c
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4396:4836] 000007feebf9d618
---- Registry - GMER 2.1 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@jacbabbaklamadkjdlld 0x62 0x61 0x6D 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@jacbabbaklamadkjdlhd 0x62 0x61 0x62 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@iaccmejlkdkacmcfoc 0x6B 0x61 0x6A 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@haecofgldpchphem 0x6B 0x61 0x6A 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@iaecofdfbilpngjbbf 0x61 0x62 0x6C 0x61 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@jafcdahdenadmhonnpip 0x62 0x61 0x69 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@baad 0x64 0x61 0x6D 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@babd 0x64 0x61 0x6F 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@cahcmc 0x64 0x61 0x62 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@cahcnc 0x64 0x61 0x63 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@iahflmpafefbgecdea 0x65 0x61 0x6A 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E07D4006-45D1-19E7-101C-87C24E26C6D5}@iahflmpafefbgecdba 0x65 0x61 0x6A 0x62 ...
---- EOF - GMER 2.1 ---- Das ist meine antwort drauf :) |