- C:\WINDOWS\img32\csrss.exe
- C:\WINDOWS\img32\services.exe
- C:\WINDOWS\vzones\services.exe
- C:\WINDOWS\vzones\smss.exe
- C:\WINDOWS\msn64.exe
- O2 - BHO: (no name) - {0F915410-4720-4490-9223-4BDB9DB04DF1} - C:\WINDOWS\system32\pmkjj.dll (file missing)
- O2 - BHO: (no name) - {117F2D2A-7F9D-4082-870E-1998FBD47771} - C:\WINDOWS\system32\xmlprovj.dll (file missing)
- O2 - BHO: {51bda1ad-e08c-de58-1d64-6ad605bc4d71} - {17d4cb50-6da6-46d1-85ed-c80eda1adb15} - C:\WINDOWS\system32\ucskqabw.dll (file missing)
- O2 - BHO: (no name) - {59BE096C-14B3-4E13-817C-EEB2BAF16F22} - C:\WINDOWS\system32\jkhfg.dll (file missing)
- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
- O4 - HKLM\..\Run: [qhgefrlt] C:\WINDOWS\system32\cvghmiii.exe
- O4 - HKLM\..\Run: [Sellgino_PLUtil] C:\Programme\Sellgino\USB Flash Disk Utility\PLBkMon.exe
- O4 - HKLM\..\Run: [5c146d84] rundll32.exe "C:\WINDOWS\system32\dvkkcjlo.dll",sitypnow
- O4 - HKLM\..\Run: [ccAppRemXP] C:\WINDOWS\msn64.exe
- O4 - HKLM\..\Run: [ZoneGames] C:\WINDOWS\img32\csrss.exe
- O4 - HKLM\..\Run: [ZoneGames32] C:\WINDOWS\img32\services.exe
- O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe (file missing)
- O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe (file missing)
- O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
https://upload.facebook.com/controls/...oUploader5.cab
- O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} (Talisma NetAgent Customer ActiveX Control version 3) -
https://etalk.epson.de/netagent/objects/custappx3.cab
- O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) -
https://static.pe.studivz.net/photoup...che=1221055802
- O20 - Winlogon Notify: ddaya - C:\WINDOWS\system32\ddaya.dll (file missing)
- O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
- O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll (file missing)
- O20 - Winlogon Notify: pmnno - C:\WINDOWS\system32\pmnno.dll (file missing)
- O20 - Winlogon Notify: sstqp - C:\WINDOWS\system32\sstqp.dll (file missing)
- O23 - Service: LVCOMSer - Logitech Inc. - C:\Programme\Gemeinsame Dateien\LogiShrd\LVCOMSER\LVComSer.exe