|
Log-Analyse und Auswertung: Musik spielt ab, aber keine Anwendung läuftWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.12.2012, 00:35 | #1 | |
| Musik spielt ab, aber keine Anwendung läuft Hallo, auf meinen beiden Laptops spielt Musik, aber keine Anwendung läuft. Zu diesem Thema habe ich gegoogelt, aber keine brauchbare Antwort gefunden, darum wende ich mich nun an euch. Ich habe Antivir und Malwarebytes als Sicherheitsprogramme auf den Laptops, ein vollständiger Scan mit beiden Programmen ergab keinen Fund. Nun habe ich mit OTL noch eine Analyse durchgeführt, leider kann ich nicht wirklich was mit der Log-Datei anfangen. Hier ist sie: Zitat:
|
19.12.2012, 02:47 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Musik spielt ab, aber keine Anwendung läuft Hallo und
__________________Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
Note: Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread. Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards. 1. aswMBR Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop. Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehlalarm!
Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes: Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button. 2. TDSS-Killer Download TDSS-Killer auf Desktop siehe => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs. Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!
__________________ |
19.12.2012, 04:34 | #3 | ||
| Musik spielt ab, aber keine Anwendung läuft Hallo Cosinus,
__________________danke für deine schnelle Antwort. Ich hoffe, ich habe alles richtig gemacht, hier die Files: Zitat:
Zitat:
|
19.12.2012, 05:57 | #4 | ||
/// Winkelfunktion /// TB-Süch-Tiger™ | Musik spielt ab, aber keine Anwendung läuft
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
19.12.2012, 08:11 | #5 |
| Musik spielt ab, aber keine Anwendung läuft Combifix: Combofix Logfile: Code:
ATTFilter ComboFix 12-12-17.02 - sandra 19.12.2012 8:02.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8089.6447 [GMT 1:00] ausgeführt von:: c:\users\sandra\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2012-11-19 bis 2012-12-19 )))))))))))))))))))))))))))))) . . 2012-12-19 07:07 . 2012-12-19 07:07 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2012-12-19 07:07 . 2012-12-19 07:07 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-12-19 03:21 . 2012-12-19 03:21 -------- d-----w- c:\program files (x86)\Perion 2012-12-19 03:21 . 2012-12-19 03:21 447 ----a-w- C:\user.js 2012-12-19 03:20 . 2012-12-19 03:20 -------- d-----w- c:\program files (x86)\Wajam 2012-12-17 18:33 . 2012-12-17 18:33 -------- d-----w- c:\program files (x86)\DAOC-Charplan 2012-12-16 21:06 . 2012-12-16 21:06 -------- d-----w- c:\program files (x86)\MSXML 4.0 2012-12-16 07:55 . 2012-12-16 07:55 -------- d-----w- c:\programdata\Malwarebytes 2012-12-16 07:55 . 2012-09-29 18:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-12-16 07:55 . 2012-12-16 07:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-12-16 00:57 . 2012-07-26 08:00 2560 ----a-w- c:\windows\system32\drivers\it-IT\wdf01000.sys.mui 2012-12-16 00:57 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui 2012-12-16 00:57 . 2012-07-26 05:05 2560 ----a-w- c:\windows\system32\drivers\es-ES\wdf01000.sys.mui 2012-12-16 00:57 . 2012-07-26 05:04 2560 ----a-w- c:\windows\system32\drivers\fr-FR\wdf01000.sys.mui 2012-12-16 00:57 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui 2012-12-16 00:57 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys 2012-12-16 00:57 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2012-12-16 00:57 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll 2012-12-16 00:52 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe 2012-12-16 00:44 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2012-12-16 00:44 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2012-12-16 00:44 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2012-12-16 00:44 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2012-12-16 00:44 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2012-12-16 00:44 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2012-12-16 00:44 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2012-12-16 00:42 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2012-12-16 00:42 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll 2012-12-16 00:42 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2012-12-16 00:42 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2012-12-16 00:42 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2012-12-15 14:27 . 2012-12-15 14:27 -------- d-----w- C:\NVIDIA 2012-12-15 02:42 . 2012-12-15 02:42 -------- d-----w- c:\users\Gretel 2012-12-15 02:07 . 2012-10-04 17:45 215040 ----a-w- c:\windows\system32\winsrv.dll 2012-12-14 19:07 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll 2012-12-14 19:07 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll 2012-12-14 19:07 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys 2012-12-14 19:04 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll 2012-12-14 19:04 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe 2012-12-14 19:04 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll 2012-12-14 19:04 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll 2012-12-14 19:04 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll 2012-12-14 19:04 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll 2012-12-14 19:04 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll 2012-12-14 19:03 . 2012-06-02 14:19 186752 ----a-w- c:\windows\system32\wuwebv.dll 2012-12-14 19:03 . 2012-06-02 14:15 36864 ----a-w- c:\windows\system32\wuapp.exe 2012-12-14 15:52 . 2012-12-14 15:52 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2012-12-14 15:52 . 2012-12-14 15:52 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2012-12-14 15:50 . 2012-12-14 15:50 -------- d-----w- c:\program files (x86)\Electronic Arts 2012-12-14 15:38 . 2012-12-14 15:38 -------- d-----w- c:\users\ronny 2012-12-14 15:35 . 2012-12-14 15:36 -------- d-----w- c:\program files (x86)\Google 2012-12-14 15:26 . 2012-12-14 15:26 -------- d-----w- c:\programdata\Intel 2012-12-14 14:07 . 2012-12-14 14:07 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2012-12-14 14:04 . 2012-12-14 15:33 -------- d-----w- c:\program files (x86)\MAGIX 2012-12-14 14:04 . 2007-04-27 08:43 120200 ----a-w- c:\windows\SysWow64\DLLDEV32i.dll 2012-12-14 14:04 . 2012-12-14 15:31 -------- d-----w- c:\program files (x86)\Common Files\MAGIX Services 2012-12-14 14:04 . 2007-04-17 10:51 14112 ----a-w- c:\windows\system32\drivers\regi.sys 2012-12-14 14:04 . 2012-12-14 14:04 -------- d-----w- c:\program files (x86)\Common Files\InterVideo 2012-12-14 14:04 . 2012-12-14 14:04 -------- d-----w- c:\program files (x86)\Common Files\Protexis 2012-12-14 14:04 . 2012-12-14 14:04 -------- d-----w- c:\programdata\Corel 2012-12-14 14:04 . 2012-12-14 14:04 -------- d-----w- c:\program files (x86)\Corel 2012-12-14 14:00 . 2012-12-14 14:26 -------- d-----w- c:\users\sandra 2012-12-14 13:58 . 2012-12-14 13:58 -------- d-----w- C:\Recovery . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-15 02:08 . 2011-03-29 01:36 19696 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-10-16 08:38 . 2012-12-15 02:07 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-12-15 02:07 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-12-15 02:07 561664 ----a-w- c:\windows\apppatch\AcLayers.dll 2012-10-04 16:40 . 2012-12-15 02:07 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2012-10-02 22:21 . 2012-03-15 05:32 973672 ----a-w- c:\windows\system32\nvumdshimx.dll 2012-10-02 22:21 . 2012-03-15 05:32 247144 ----a-w- c:\windows\system32\nvinitx.dll 2012-10-02 22:21 . 2012-03-15 05:32 202600 ----a-w- c:\windows\SysWow64\nvinit.dll 2012-10-02 22:21 . 2012-03-15 05:32 1760104 ----a-w- c:\windows\system32\nvdispco64.dll 2012-10-02 22:21 . 2012-03-15 05:32 2731880 ----a-w- c:\windows\system32\nvapi64.dll 2012-10-02 22:21 . 2012-03-15 05:32 2428776 ----a-w- c:\windows\SysWow64\nvapi.dll 2012-10-02 19:51 . 2012-03-15 05:32 3536817 ----a-w- c:\windows\system32\nvcoproc.bin 2012-10-02 19:51 . 2012-03-15 05:32 3293544 ----a-w- c:\windows\system32\nvsvc64.dll 2012-10-02 19:51 . 2012-03-15 05:32 6200680 ----a-w- c:\windows\system32\nvcpl.dll 2012-10-02 19:50 . 2012-03-15 05:32 891240 ----a-w- c:\windows\system32\nvvsvc.exe 2012-10-02 19:50 . 2012-03-15 05:32 866664 ----a-w- c:\windows\system32\nv3dappshext.dll 2012-10-02 19:50 . 2012-03-15 05:32 63336 ----a-w- c:\windows\system32\nvshext.dll 2012-10-02 19:50 . 2012-03-15 05:32 55144 ----a-w- c:\windows\system32\nv3dappshextr.dll 2012-10-02 19:50 . 2012-03-15 05:32 2557800 ----a-w- c:\windows\system32\nvsvcr.dll 2012-10-02 19:50 . 2012-03-15 05:32 118120 ----a-w- c:\windows\system32\nvmctray.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-04 291608] "S-Bar"="c:\program files (x86)\S-Bar\S-Bar.exe" [2011-11-03 5499392] "Super-Charger"="c:\program files (x86)\MSI\Super-Charger\Super-Charger.exe" [2012-01-03 502288] "KLM"="c:\program files (x86)\MSI\KLM\KLM.exe" [2011-12-19 1522376] "VGAOCAP"="c:\program files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe" [2012-01-31 88576] "THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" [2011-08-29 1517056] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "YouCam Mirage"="c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe" [2011-10-13 136488] "YouCam Tray"="c:\program files (x86)\CyberLink\YouCam\YouCam.exe" [2011-10-13 230696] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Qualcomm Atheros Killer Network Manager.lnk - c:\program files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe [2012-3-8 549888] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936] R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-12-13 94720] R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-12-13 747008] R3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-14 60416] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928] R3 MGHwCtrl;MGHwCtrl;c:\program files\MSI\MSI Software Install\MGHwCtrl.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys [2012-01-04 16152] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-10-02 30056] S1 BfLwf;Bigfoot Networks Bandwidth Control;c:\windows\system32\DRIVERS\bflwfx64.sys [2012-03-08 75880] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-12-20 1014096] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-12-20 1104208] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-12-07 2429544] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432] S2 Micro Star SCM;Micro Star SCM;c:\program files (x86)\S-Bar\MSIService.exe [2011-11-03 160768] S2 MSI Foundation Service;MSI Foundation Service;c:\program files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [2010-07-16 12800] S2 MSI_SuperCharger;MSI_SuperCharger;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe [2012-01-03 138768] S2 Qualcomm Atheros Killer Service;Qualcomm Atheros Killer Service;c:\program files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [2012-03-08 492032] S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 14112] S2 WajamUpdater;WajamUpdater;c:\program files (x86)\Wajam\Updater\WajamUpdater.exe [2012-10-05 109064] S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-12-20 1304912] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2011-10-13 31216] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-05 331264] S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys [2012-01-04 355096] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys [2012-01-04 786200] S3 L1C;NDIS Miniport Driver for the Killer e2200 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\e22w7x64.sys [2012-03-08 161616] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [2009-11-17 32344] S3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2010-01-18 14136] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-12-06 339048] . . Inhalt des "geplante Tasks" Ordners . 2012-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-14 15:35] . 2012-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-14 15:35] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-12 170264] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-12 398104] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-12 440600] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-12-20 11406608] "THXCfg64"="c:\windows\system32\THXCfg64.dll" [2010-09-14 25600] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-01-10 12445288] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://mystart.incredibar.com/mbmb212?a=6PQT9c2gZt&i=26 mStart Page = hxxp://msi.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm LSP: %SYSTEMROOT%\system32\BfLLR.dll TCP: DhcpNameServer = 192.168.0.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2012-12-19 08:09:03 ComboFix-quarantined-files.txt 2012-12-19 07:09 . Vor Suchlauf: 10 Verzeichnis(se), 386.101.075.968 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 386.013.777.920 Bytes frei . - - End Of File - - C805673AC5B12DCC9F3EBF6BABCA40C8 |
19.12.2012, 22:09 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Musik spielt ab, aber keine Anwendung läuft adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop. Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
__________________ --> Musik spielt ab, aber keine Anwendung läuft |
20.12.2012, 07:36 | #7 | |
| Musik spielt ab, aber keine Anwendung läuft hier der AdvCleaner: Zitat:
|
20.12.2012, 15:26 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Musik spielt ab, aber keine Anwendung läuft adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
Danach eine Kontrolle mit OTL bitte:
__________________ Logfiles bitte immer in CODE-Tags posten |
21.12.2012, 13:31 | #9 | |
| Musik spielt ab, aber keine Anwendung läuft Datei vom adwCleaner: Zitat:
OTL Logfile: Code:
ATTFilter OTL logfile created on: 21.12.2012 13:22:14 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\sandra\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,90 Gb Total Physical Memory | 5,96 Gb Available Physical Memory | 75,45% Memory free 15,80 Gb Paging File | 13,51 Gb Available in Paging File | 85,51% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 411,91 Gb Total Space | 357,35 Gb Free Space | 86,75% Space Free | Partition Type: NTFS Drive D: | 274,60 Gb Total Space | 266,81 Gb Free Space | 97,16% Space Free | Partition Type: NTFS Drive E: | 4,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: SANDRA-MSI | User Name: sandra | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\sandra\Desktop\OTL (1).exe (OldTimer Tools) PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe () PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) PRC - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (MSI) PRC - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (MSI) PRC - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Intel Corporation) PRC - C:\Program Files (x86)\MSI\KLM\KLM.exe (Micro-Star International Co., Ltd.) PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) PRC - C:\Program Files (x86)\S-Bar\MSIService.exe (Micro-Star International Co., Ltd.) PRC - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) PRC - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Creative Technology Ltd) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) PRC - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) ========== Modules (No Company Name) ========== MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\0284e2e0afcfd7ce09094b30c0486d46\System.ServiceProcess.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System.Management\5d0dc33658e23a6f960c46a5beab7ecf\System.Management.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\5e3ccfdf88ccd6a9ff4e6ddae7e3fec6\System.Xaml.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4a29fb5e489e57ccc97b19ca70db94a8\Microsoft.VisualBasic.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\4a443c775f768ede71bde8e10f50ec0b\IAStorUtil.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e88f87e9200afb5ede994c89c92e22b8\IAStorCommon.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1ec80905a71750be50dfc7981ad5ae28\PresentationFramework.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53d6d827964619285771ed72332d3659\PresentationCore.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b311b783e1efaa9527f4c2c9680c44d1\WindowsBase.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c64ca3678261c8ffcd9e7efd1af6ed54\System.Configuration.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c881e2d2ec912499834feb85c4c2e483\PresentationFramework.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\58f50a891bafb8fd7149e6eebc2b7b52\PresentationCore.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\caffbced23ee85b40b919ad4a122b7aa\System.Windows.Forms.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\05ebffcb5aac31412fea8c38cbac8df8\WindowsBase.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\9422d0c052186760a4645e10995487f5\System.Drawing.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\cb0c00757e89f0b1fe282913ed667212\System.Xml.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\cbb227c0a77a5b15a1255220984239f2\PresentationFramework.Aero.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ed886fb71addf400705481dcf8de12da\System.Configuration.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\System\811a7bc79f8f0a5be8065292a320819e\System.ni.dll () MOD - C:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\16126cae96ea2422253ae06eeb672abc\mscorlib.ni.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\libglesv2.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\libegl.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avutil-51.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avformat-54.dll () MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll () MOD - C:\windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll () MOD - C:\Program Files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe () MOD - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\de-DE\THXAudio.resources.dll () MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll () ========== Services (SafeList) ========== SRV:64bit: - (Qualcomm Atheros Killer Service) -- C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe () SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation) SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation) SRV - (MSI_SuperCharger) -- C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (MSI) SRV - (Bluetooth OBEX Service) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) SRV - (Bluetooth Media Service) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) SRV - (Bluetooth Device Monitor) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation) SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.) SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) SRV - (Micro Star SCM) -- C:\Program Files (x86)\S-Bar\MSIService.exe (Micro-Star International Co., Ltd.) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (MSI Foundation Service) -- C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe (MSI) SRV - (IviRegMgr) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (PSI_SVC_2) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (MGHwCtrl) -- C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys File not found DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation) DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (BfLwf) -- C:\Windows\SysNative\drivers\bflwfx64.sys (Bigfoot Networks, Inc.) DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\e22W7x64.sys (Qualcomm Atheros, Inc.) DRV:64bit: - (Fs_Rec) -- C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation) DRV:64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation) DRV:64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation) DRV:64bit: - (ibtfltcoex) -- C:\Windows\SysNative\drivers\iBtFltCoex.sys (Intel Corporation) DRV:64bit: - (btmhsf) -- C:\Windows\SysNative\drivers\btmhsf.sys (Intel Corporation) DRV:64bit: - (btmaux) -- C:\Windows\SysNative\drivers\btmaux.sys (Intel Corporation) DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation) DRV:64bit: - (NETwNs64) -- C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (clwvd) -- C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (MBfilt) -- C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (regi) -- C:\Windows\SysNative\drivers\regi.sys (InterVideo) DRV - (NTIOLib_1_0_3) -- C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys (MSI) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{7938087C-7958-4B93-979E-5706042D5497}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://msi.msn.com IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{7938087C-7958-4B93-979E-5706042D5497}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=MSITDF&pc=MAM3&src=IE-SearchBox IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-1950173301-3659085451-2770679902-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-1950173301-3659085451-2770679902-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com IE - HKU\S-1-5-21-1950173301-3659085451-2770679902-1001\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-1950173301-3659085451-2770679902-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.12.14 16:52:56 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2012.12.14 17:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sandra\AppData\Roaming\mozilla\Extensions [2012.12.19 04:21:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions ========== Chrome ========== CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [THXCfg64] C:\windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [KLM] C:\Program Files (x86)\MSI\KLM\KLM.exe (Micro-Star International Co., Ltd.) O4 - HKLM..\Run: [S-Bar] C:\Program Files (x86)\S-Bar\S-Bar.exe (Micro-Star International Co.,Ltd.) O4 - HKLM..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (MSI) O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Creative Technology Ltd) O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) O4 - HKLM..\Run: [VGAOCAP] C:\Program Files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe () O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe (CyberLink Corp.) O4 - HKU\S-1-5-21-1950173301-3659085451-2770679902-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1950173301-3659085451-2770679902-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1950173301-3659085451-2770679902-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1950173301-3659085451-2770679902-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1950173301-3659085451-2770679902-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O7 - HKU\S-1-5-21-1950173301-3659085451-2770679902-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\BfLLR.dll (Bigfoot Networks, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\BfLLR.dll (Bigfoot Networks, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\BfLLR.dll (Bigfoot Networks, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\BfLLR.dll (Bigfoot Networks, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000016 - C:\Windows\SysNative\BfLLR.dll (Bigfoot Networks, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\BfLLR.dll (Bigfoot Networks, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\BfLLR.dll (Bigfoot Networks, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\BfLLR.dll (Bigfoot Networks, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\BfLLR.dll (Bigfoot Networks, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\SysWOW64\BfLLR.dll (Bigfoot Networks, Inc.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54D6DB9F-048D-4B0E-A7D4-6F9A21FB7059}: DhcpNameServer = 192.168.0.1 O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation) O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation) O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2007.07.25 16:09:28 | 000,000,049 | R--- | M] () - E:\autorun.inf -- [ UDF ] O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012.12.19 12:45:43 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Avira [2012.12.19 12:40:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2012.12.19 12:40:15 | 000,129,216 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\windows\SysNative\drivers\avipbb.sys [2012.12.19 12:40:15 | 000,099,912 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\windows\SysNative\drivers\avgntflt.sys [2012.12.19 12:40:15 | 000,027,800 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\windows\SysNative\drivers\avkmgr.sys [2012.12.19 12:40:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2012.12.19 12:40:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira [2012.12.19 12:26:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2012.12.19 08:08:50 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\SysNative\atmfd.dll [2012.12.19 08:08:50 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\SysWow64\atmfd.dll [2012.12.19 08:08:49 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\windows\SysNative\atmlib.dll [2012.12.19 08:08:49 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\windows\SysWow64\atmlib.dll [2012.12.19 08:07:10 | 000,000,000 | ---D | C] -- C:\windows\temp [2012.12.19 07:51:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe [2012.12.19 07:51:59 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe [2012.12.19 07:51:59 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe [2012.12.19 07:51:54 | 000,000,000 | ---D | C] -- C:\Qoobox [2012.12.19 07:51:42 | 000,000,000 | ---D | C] -- C:\windows\erdnt [2012.12.19 07:49:15 | 005,012,571 | R--- | C] (Swearware) -- C:\Users\sandra\Desktop\ComboFix.exe [2012.12.19 04:21:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2012.12.19 00:10:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\sandra\Desktop\OTL (1).exe [2012.12.17 19:33:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAOC-Charplan [2012.12.17 19:33:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAOC-Charplan [2012.12.16 22:06:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0 [2012.12.16 08:55:25 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Malwarebytes [2012.12.16 08:55:20 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys [2012.12.16 08:55:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012.12.16 08:55:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012.12.16 08:55:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2012.12.16 01:57:57 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\WdfLdr.sys [2012.12.16 01:57:57 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\Wdfres.dll [2012.12.16 01:52:40 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\browserchoice.exe [2012.12.16 01:46:15 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll [2012.12.16 01:46:15 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inetcpl.cpl [2012.12.16 01:46:15 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl [2012.12.16 01:46:15 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msfeeds.dll [2012.12.16 01:46:15 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll [2012.12.16 01:46:15 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\url.dll [2012.12.16 01:46:15 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll [2012.12.16 01:46:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll [2012.12.16 01:46:15 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieUnatt.exe [2012.12.16 01:46:15 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieUnatt.exe [2012.12.16 01:46:15 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll [2012.12.16 01:46:15 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll [2012.12.16 01:46:14 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll [2012.12.16 01:46:14 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll [2012.12.16 01:46:14 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\vbscript.dll [2012.12.16 01:44:50 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\WUDFPlatform.dll [2012.12.16 01:44:49 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\WUDFx.dll [2012.12.16 01:44:49 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\WUDFHost.exe [2012.12.16 01:44:49 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\WUDFCoinstaller.dll [2012.12.16 01:42:28 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\imagehlp.dll [2012.12.16 01:42:28 | 000,023,408 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\fs_rec.sys [2012.12.15 15:28:09 | 026,331,496 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvoglv64.dll [2012.12.15 15:28:09 | 025,256,296 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvcompiler.dll [2012.12.15 15:28:09 | 019,906,920 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvoglv32.dll [2012.12.15 15:28:09 | 018,252,136 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvd3dumx.dll [2012.12.15 15:28:09 | 017,559,912 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvcompiler.dll [2012.12.15 15:28:09 | 015,309,160 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvd3dum.dll [2012.12.15 15:28:09 | 014,922,600 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvwgf2umx.dll [2012.12.15 15:28:09 | 012,501,352 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvwgf2um.dll [2012.12.15 15:28:09 | 009,146,728 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvcuda.dll [2012.12.15 15:28:09 | 007,697,768 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvcuda.dll [2012.12.15 15:28:09 | 007,414,632 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvopencl.dll [2012.12.15 15:28:09 | 006,127,464 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvopencl.dll [2012.12.15 15:28:09 | 002,747,240 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvcuvid.dll [2012.12.15 15:28:09 | 002,574,696 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvcuvid.dll [2012.12.15 15:28:09 | 002,218,344 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvcuvenc.dll [2012.12.15 15:28:09 | 001,867,112 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvcuvenc.dll [2012.12.15 15:28:09 | 001,482,600 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\nvdispgenco64.dll [2012.12.15 15:28:09 | 000,831,848 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysWow64\nvumdshim.dll [2012.12.15 15:28:09 | 000,030,056 | ---- | C] (NVIDIA Corporation) -- C:\windows\SysNative\drivers\nvpciflt.sys [2012.12.15 15:27:01 | 000,000,000 | ---D | C] -- C:\NVIDIA [2012.12.15 03:08:40 | 001,544,704 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\DWrite.dll [2012.12.15 03:08:38 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\poqexec.exe [2012.12.15 03:08:38 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\poqexec.exe [2012.12.15 03:08:37 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dhcpcore6.dll [2012.12.15 03:08:37 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dhcpcore6.dll [2012.12.15 03:08:37 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dhcpcsvc6.dll [2012.12.15 03:08:27 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntshrui.dll [2012.12.15 03:08:26 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\timedate.cpl [2012.12.15 03:08:26 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\timedate.cpl [2012.12.15 03:08:26 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msxml3r.dll [2012.12.15 03:08:26 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msxml3r.dll [2012.12.15 03:08:24 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntoskrnl.exe [2012.12.15 03:08:23 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntkrnlpa.exe [2012.12.15 03:08:23 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntoskrnl.exe [2012.12.15 03:08:21 | 001,465,344 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\XpsPrint.dll [2012.12.15 03:08:21 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\XpsPrint.dll [2012.12.15 03:08:19 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\d3d10level9.dll [2012.12.15 03:08:19 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\RNDISMP.sys [2012.12.15 03:08:18 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ncrypt.dll [2012.12.15 03:08:18 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdpcorekmts.dll [2012.12.15 03:08:18 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdpwsx.dll [2012.12.15 03:08:18 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdrmemptylst.exe [2012.12.15 03:08:16 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\netio.sys [2012.12.15 03:08:16 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\netcorehc.dll [2012.12.15 03:08:16 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ncsi.dll [2012.12.15 03:08:16 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ncsi.dll [2012.12.15 03:08:15 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\drivers\FWPKCLNT.SYS [2012.12.15 03:08:15 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\netcorehc.dll [2012.12.15 03:08:15 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\netevent.dll [2012.12.15 03:08:15 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\netevent.dll [2012.12.15 03:07:58 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\kernel32.dll [2012.12.15 03:07:58 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\KernelBase.dll [2012.12.15 03:07:58 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\conhost.exe [2012.12.15 03:07:58 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\winsrv.dll [2012.12.15 03:07:56 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wow64win.dll [2012.12.15 03:07:56 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wow64.dll [2012.12.15 03:07:56 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\setup16.exe [2012.12.15 03:07:56 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ntvdm64.dll [2012.12.15 03:07:56 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ntvdm64.dll [2012.12.15 03:07:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wow64cpu.dll [2012.12.15 03:07:56 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\instnm.exe [2012.12.15 03:07:56 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2012.12.15 03:07:56 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-security-base-l1-1-0.dll [2012.12.15 03:07:56 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2012.12.15 03:07:56 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-file-l1-1-0.dll [2012.12.15 03:07:56 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\wow32.dll [2012.12.15 03:07:56 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-synch-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2012.12.15 03:07:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-localization-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-misc-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-memory-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-heap-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-util-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-string-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-profile-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-io-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-handle-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-debug-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2012.12.15 03:07:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\SysNative\api-ms-win-core-console-l1-1-0.dll [2012.12.15 03:07:56 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\user.exe [2012.12.15 03:07:52 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\dpnet.dll [2012.12.15 03:07:52 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\dpnet.dll [2012.12.15 03:07:52 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wintrust.dll [2012.12.15 03:07:51 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\OxpsConverter.exe [2012.12.15 03:07:29 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msi.dll [2012.12.15 03:07:28 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\synceng.dll [2012.12.15 03:07:28 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\synceng.dll [2012.12.15 03:07:22 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\srcore.dll [2012.12.15 03:07:22 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\netapi32.dll [2012.12.15 03:07:22 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\browcli.dll [2012.12.15 03:07:22 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\browcli.dll [2012.12.15 03:07:18 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msvcrt.dll [2012.12.15 03:07:15 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\localspl.dll [2012.12.15 03:07:13 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\cdosys.dll [2012.12.15 03:07:12 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cdosys.dll [2012.12.15 03:07:12 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\win32spl.dll [2012.12.15 03:07:12 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\win32spl.dll [2012.12.15 03:07:12 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\windows\splwow64.exe [2012.12.15 03:07:08 | 001,464,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\crypt32.dll [2012.12.15 03:07:08 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cryptnet.dll [2012.12.14 23:54:16 | 000,000,000 | -HSD | C] -- C:\System Volume Information [2012.12.14 20:07:43 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\rdpcore.dll [2012.12.14 20:07:43 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\rdpcore.dll [2012.12.14 20:04:14 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wucltux.dll [2012.12.14 20:04:14 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuauclt.exe [2012.12.14 20:04:14 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wups2.dll [2012.12.14 20:04:05 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapi.dll [2012.12.14 20:04:05 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wudriver.dll [2012.12.14 20:04:05 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wups.dll [2012.12.14 20:03:57 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuwebv.dll [2012.12.14 20:03:57 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapp.exe [2012.12.14 17:25:01 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Thunderbird [2012.12.14 17:25:01 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\Thunderbird [2012.12.14 17:25:01 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Mozilla [2012.12.14 16:52:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2012.12.14 16:52:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012.12.14 16:52:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird [2012.12.14 16:50:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts [2012.12.14 16:36:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2012.12.14 16:35:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google [2012.12.14 16:35:24 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\Google [2012.12.14 16:35:15 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\Deployment [2012.12.14 16:35:15 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\Apps [2012.12.14 16:34:48 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Macromedia [2012.12.14 16:34:46 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Adobe [2012.12.14 16:27:05 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\Micro-Star_International_ [2012.12.14 16:27:02 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Intel Corporation [2012.12.14 16:26:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel [2012.12.14 15:26:08 | 000,000,000 | R--D | C] -- C:\Users\sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2012.12.14 15:26:08 | 000,000,000 | R--D | C] -- C:\Users\sandra\Searches [2012.12.14 15:26:08 | 000,000,000 | R--D | C] -- C:\Users\sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2012.12.14 15:26:00 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Identities [2012.12.14 15:25:58 | 000,000,000 | R--D | C] -- C:\Users\sandra\Contacts [2012.12.14 15:10:05 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\VirtualStore [2012.12.14 15:09:11 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\InstallShield [2012.12.14 15:07:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2012.12.14 15:07:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2012.12.14 15:07:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2012.12.14 15:06:25 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\MAGIX [2012.12.14 15:05:20 | 001,003,520 | ---- | C] (MAGIX AG) -- C:\windows\SysWow64\MXRestore.exe [2012.12.14 15:05:20 | 000,724,992 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLAV32.dll [2012.12.14 15:05:20 | 000,278,528 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLRES32.dll [2012.12.14 15:05:20 | 000,221,184 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLDRV32.dll [2012.12.14 15:05:20 | 000,212,992 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLDEV32.dll [2012.12.14 15:05:20 | 000,147,456 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLCPY32.dll [2012.12.14 15:05:20 | 000,114,688 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLCDA32.dll [2012.12.14 15:05:20 | 000,094,208 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLIO32.dll [2012.12.14 15:05:20 | 000,090,112 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLPRF32.dll [2012.12.14 15:05:20 | 000,077,824 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLPNT32.dll [2012.12.14 15:05:20 | 000,065,536 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\STRING32.dll [2012.12.14 15:05:20 | 000,065,536 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLPTL32.dll [2012.12.14 15:05:20 | 000,061,440 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLCDF32.dll [2012.12.14 15:05:20 | 000,057,344 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLTPO32.dll [2012.12.14 15:05:20 | 000,053,248 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLPRJ32.dll [2012.12.14 15:05:20 | 000,045,056 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLIMG32.dll [2012.12.14 15:05:20 | 000,040,960 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLRD32.dll [2012.12.14 15:05:20 | 000,038,784 | ---- | C] (MAGIX) -- C:\windows\SysWow64\drivers\virtualdisk_u.sys [2012.12.14 15:05:20 | 000,038,272 | ---- | C] (MAGIX) -- C:\windows\SysWow64\drivers\virtualdisk.sys [2012.12.14 15:05:20 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLMSC32.dll [2012.12.14 15:05:20 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLISO32.dll [2012.12.14 15:05:20 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLDIR32.dll [2012.12.14 15:05:20 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\TTIC32.dll [2012.12.14 15:05:20 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\TTI32.dll [2012.12.14 15:05:20 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH) -- C:\windows\SysWow64\DLLIX.dll [2012.12.14 15:05:20 | 000,014,208 | ---- | C] (MAGIX) -- C:\windows\SysWow64\drivers\disksec.sys [2012.12.14 15:05:15 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msxml4a.dll [2012.12.14 15:05:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX [2012.12.14 15:05:05 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX [2012.12.14 15:04:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX [2012.12.14 15:04:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MAGIX Services [2012.12.14 15:04:42 | 000,014,112 | ---- | C] (InterVideo) -- C:\windows\SysNative\drivers\regi.sys [2012.12.14 15:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel [2012.12.14 15:04:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InterVideo [2012.12.14 15:04:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Protexis [2012.12.14 15:04:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Corel [2012.12.14 15:04:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Corel [2012.12.14 15:03:50 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\d3dx9_29.dll [2012.12.14 15:02:46 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\RTCOM [2012.12.14 15:02:46 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2012.12.14 15:02:39 | 003,747,944 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtkAPO64.dll [2012.12.14 15:02:39 | 002,634,856 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtPgEx64.dll [2012.12.14 15:02:39 | 002,603,864 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\WavesGUILib.dll [2012.12.14 15:02:39 | 001,560,168 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RTSnMg64.cpl [2012.12.14 15:02:39 | 001,247,848 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RTCOM64.dll [2012.12.14 15:02:39 | 000,823,912 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtkApi64.dll [2012.12.14 15:02:39 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSX64.dll [2012.12.14 15:02:39 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEP64A.dll [2012.12.14 15:02:39 | 000,331,880 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtlCPAPI64.dll [2012.12.14 15:02:39 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DHT64.dll [2012.12.14 15:02:39 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DAA64.dll [2012.12.14 15:02:39 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSH64.dll [2012.12.14 15:02:39 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEED64A.dll [2012.12.14 15:02:39 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSHP64.dll [2012.12.14 15:02:39 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSWOW64.dll [2012.12.14 15:02:39 | 000,149,608 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtkCfg64.dll [2012.12.14 15:02:39 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEL64A.dll [2012.12.14 15:02:39 | 000,100,968 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RCoInstII64.dll [2012.12.14 15:02:39 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEG64A.dll [2012.12.14 15:02:39 | 000,014,952 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\SysNative\RtkCoLDR64.dll [2012.12.14 15:02:38 | 002,131,288 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioEQ.dll [2012.12.14 15:02:38 | 000,955,736 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPOShell64.dll [2012.12.14 15:02:38 | 000,626,264 | ---- | C] (Creative Technology Ltd.) -- C:\windows\SysNative\MBTHX64.dll [2012.12.14 15:02:38 | 000,561,752 | ---- | C] (Creative Technology Ltd.) -- C:\windows\SysWow64\MBTHX32.dll [2012.12.14 15:02:38 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPO20.dll [2012.12.14 15:02:38 | 000,080,984 | ---- | C] (Creative Technology Ltd.) -- C:\windows\SysNative\MBWrp64.dll [2012.12.14 15:02:38 | 000,032,344 | ---- | C] (Creative Technology Ltd.) -- C:\windows\SysNative\drivers\MBfilt64.sys [2012.12.14 15:02:37 | 002,528,832 | ---- | C] (Fortemedia Corporation) -- C:\windows\SysNative\FMAPO64.dll [2012.12.14 15:02:36 | 001,698,408 | ---- | C] (Realtek Semiconductor Corp.) -- C:\windows\RtlExUpd.dll [2012.12.14 15:02:36 | 000,200,800 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\SysNative\AERTAC64.dll [2012.12.14 15:02:36 | 000,108,960 | ---- | C] (Andrea Electronics Corporation) -- C:\windows\SysNative\AERTAR64.dll [2012.12.14 15:02:36 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp [2012.12.14 15:00:14 | 000,000,000 | --SD | C] -- C:\Users\sandra\AppData\Roaming\Microsoft [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Videos [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Saved Games [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Pictures [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Music [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Links [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Favorites [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Downloads [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Documents [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\Desktop [2012.12.14 15:00:14 | 000,000,000 | R--D | C] -- C:\Users\sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Vorlagen [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\AppData\Local\Verlauf [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\AppData\Local\Temporary Internet Files [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Startmenü [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\SendTo [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Recent [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Netzwerkumgebung [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Lokale Einstellungen [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Documents\Eigene Videos [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Documents\Eigene Musik [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Eigene Dateien [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Documents\Eigene Bilder [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Druckumgebung [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Cookies [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\AppData\Local\Anwendungsdaten [2012.12.14 15:00:14 | 000,000,000 | -HSD | C] -- C:\Users\sandra\Anwendungsdaten [2012.12.14 15:00:14 | 000,000,000 | -H-D | C] -- C:\Users\sandra\AppData [2012.12.14 15:00:14 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\Temp [2012.12.14 15:00:14 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Local\Microsoft [2012.12.14 15:00:14 | 000,000,000 | ---D | C] -- C:\Users\sandra\AppData\Roaming\Media Center Programs [2012.12.14 14:58:58 | 000,000,000 | ---D | C] -- C:\Recovery [2012.12.14 14:58:55 | 000,000,000 | ---D | C] -- C:\windows\SoftwareDistribution [1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012.12.21 13:19:28 | 000,001,106 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2012.12.21 13:19:01 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2012.12.21 13:18:56 | 2066,284,543 | -HS- | M] () -- C:\hiberfil.sys [2012.12.21 12:40:00 | 000,001,110 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2012.12.21 10:20:32 | 000,024,432 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.12.21 10:20:32 | 000,024,432 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.12.20 07:34:11 | 000,547,175 | ---- | M] () -- C:\Users\sandra\Desktop\adwcleaner.exe [2012.12.19 12:26:20 | 000,295,544 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT [2012.12.19 07:49:42 | 005,012,571 | R--- | M] (Swearware) -- C:\Users\sandra\Desktop\ComboFix.exe [2012.12.19 04:20:34 | 002,195,988 | ---- | M] () -- C:\Users\sandra\Desktop\tdsskiller-2-8-14-0.zip [2012.12.19 04:16:17 | 000,000,512 | ---- | M] () -- C:\Users\sandra\Desktop\MBR.dat [2012.12.19 00:11:00 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\sandra\Desktop\OTL (1).exe [2012.12.18 05:45:16 | 004,043,186 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2012.12.18 05:45:16 | 000,705,842 | ---- | M] () -- C:\windows\SysNative\perfh00C.dat [2012.12.18 05:45:16 | 000,704,866 | ---- | M] () -- C:\windows\SysNative\perfh00A.dat [2012.12.18 05:45:16 | 000,700,520 | ---- | M] () -- C:\windows\SysNative\perfh010.dat [2012.12.18 05:45:16 | 000,665,578 | ---- | M] () -- C:\windows\SysNative\perfh007.dat [2012.12.18 05:45:16 | 000,627,420 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2012.12.18 05:45:16 | 000,140,814 | ---- | M] () -- C:\windows\SysNative\perfc00A.dat [2012.12.18 05:45:16 | 000,133,892 | ---- | M] () -- C:\windows\SysNative\perfc00C.dat [2012.12.18 05:45:16 | 000,133,758 | ---- | M] () -- C:\windows\SysNative\perfc007.dat [2012.12.18 05:45:16 | 000,130,896 | ---- | M] () -- C:\windows\SysNative\perfc010.dat [2012.12.18 05:45:16 | 000,110,140 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2012.12.17 19:33:08 | 000,001,944 | ---- | M] () -- C:\Users\Public\Desktop\DAOC-Charplan.lnk [2012.12.16 08:55:20 | 000,001,123 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.12.15 17:26:46 | 000,000,186 | ---- | M] () -- C:\Users\sandra\Desktop\reservierung.rtf [2012.12.14 23:57:44 | 000,159,772 | ---- | M] () -- C:\windows\SysWow64\license.rtf [2012.12.14 23:57:44 | 000,159,772 | ---- | M] () -- C:\windows\SysNative\license.rtf [2012.12.14 16:46:08 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2012.12.14 16:36:21 | 000,002,295 | ---- | M] () -- C:\Users\sandra\Desktop\Google Chrome.lnk [2012.12.14 15:05:10 | 000,000,040 | -H-- | M] () -- C:\windows\SysNative\ivireg.ivr [2012.12.03 15:36:36 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\SysNative\drivers\avipbb.sys [2012.12.03 15:36:35 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\windows\SysNative\drivers\avgntflt.sys [1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.12.20 07:34:10 | 000,547,175 | ---- | C] () -- C:\Users\sandra\Desktop\adwcleaner.exe [2012.12.19 07:51:59 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe [2012.12.19 07:51:59 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe [2012.12.19 07:51:59 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe [2012.12.19 07:51:59 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe [2012.12.19 07:51:59 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe [2012.12.19 04:20:33 | 002,195,988 | ---- | C] () -- C:\Users\sandra\Desktop\tdsskiller-2-8-14-0.zip [2012.12.19 04:10:24 | 000,000,512 | ---- | C] () -- C:\Users\sandra\Desktop\MBR.dat [2012.12.17 19:33:08 | 000,001,944 | ---- | C] () -- C:\Users\Public\Desktop\DAOC-Charplan.lnk [2012.12.16 08:55:20 | 000,001,123 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2012.12.16 01:57:59 | 000,000,003 | ---- | C] () -- C:\windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012.12.16 01:44:49 | 000,000,003 | ---- | C] () -- C:\windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012.12.15 17:26:46 | 000,000,186 | ---- | C] () -- C:\Users\sandra\Desktop\reservierung.rtf [2012.12.14 23:54:16 | 2066,284,543 | -HS- | C] () -- C:\hiberfil.sys [2012.12.14 16:52:59 | 000,002,112 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk [2012.12.14 16:36:21 | 000,002,295 | ---- | C] () -- C:\Users\sandra\Desktop\Google Chrome.lnk [2012.12.14 16:35:29 | 000,001,110 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2012.12.14 16:35:28 | 000,001,106 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2012.12.14 16:26:54 | 000,001,419 | ---- | C] () -- C:\Users\sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [2012.12.14 16:26:10 | 000,001,453 | ---- | C] () -- C:\Users\sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2012.12.14 15:07:56 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2012.12.14 15:05:20 | 000,038,492 | ---- | C] () -- C:\windows\SysWow64\DLLAV32.lib [2012.12.14 15:04:59 | 000,120,200 | ---- | C] () -- C:\windows\SysWow64\DLLDEV32i.dll [2012.12.14 15:04:43 | 000,000,040 | -H-- | C] () -- C:\windows\SysNative\ivireg.ivr [2012.12.14 15:02:41 | 000,000,176 | ---- | C] () -- C:\windows\SysNative\drivers\RTHDAEQ0.dat [2012.12.14 15:02:39 | 000,216,472 | ---- | C] () -- C:\windows\SysNative\drivers\RTAIODAT.DAT [2012.03.15 07:19:58 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2012.03.15 07:01:16 | 000,001,313 | ---- | C] () -- C:\windows\THXCfg_SP_APOIM.ini [2012.03.15 07:01:16 | 000,001,212 | ---- | C] () -- C:\windows\THXCfg_HP_APOIM.ini [2012.03.15 07:01:16 | 000,001,212 | ---- | C] () -- C:\windows\THXCfg_APOIM.ini [2012.03.15 07:01:14 | 000,182,272 | ---- | C] () -- C:\windows\SysWow64\APOMngr.DLL [2012.03.15 07:01:14 | 000,073,728 | ---- | C] () -- C:\windows\SysWow64\CmdRtr.DLL [2012.03.15 05:53:07 | 000,734,772 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin [2012.03.15 05:53:05 | 000,557,476 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin [2012.03.15 05:53:03 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll [2012.03.15 05:53:02 | 012,978,688 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll ========== ZeroAccess Check ========== [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] < End of report > Extras.text von OTL: OTL Logfile: Code:
ATTFilter OTL Extras logfile created on: 21.12.2012 13:22:14 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\sandra\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,90 Gb Total Physical Memory | 5,96 Gb Available Physical Memory | 75,45% Memory free 15,80 Gb Paging File | 13,51 Gb Available in Paging File | 85,51% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 411,91 Gb Total Space | 357,35 Gb Free Space | 86,75% Space Free | Partition Type: NTFS Drive D: | 274,60 Gb Total Space | 266,81 Gb Free Space | 97,16% Space Free | Partition Type: NTFS Drive E: | 4,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: SANDRA-MSI | User Name: sandra | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) [HKEY_USERS\S-1-5-21-1950173301-3659085451-2770679902-1001\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{B5FD8464-E477-4C81-A68C-E112E67EF7D0}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{FF848A2C-D1FB-4C4D-9EBA-9DD82CACBCAB}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{2634129A-E867-4A74-AEA2-0B0AC20B7185}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{5760818F-EA22-402D-82B2-29459E749C53}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe | "{9CF975B1-5913-4A48-BF54-B1322DC835DB}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe | "{A2171194-FF6D-4FBD-89EA-487DC8D7273A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{B86B9644-A599-41CA-8231-69560B947A42}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{E65FFFCC-8B00-49C8-8213-CDE48394DA00}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe | "{EFE468A5-DF09-4F29-A68A-10559031D1AA}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources "{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources "{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.0604 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF446558-ADF7-4884-9B2D-281979CCE71F}" = Qualcomm Atheros Killer Network Manager "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F0932859-AA60-459E-B843-0BDECA34E2C7}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "SynTPDeinstKey" = Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver "{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}" = BurnRecovery "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger "{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX "{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}" = MSI Software Install "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{39BDC923-826E-4007-8179-50E7C570E545}" = S-Bar "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack "{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live "{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer "{4DEA5B85-6C56-45F3-AE00-FED756B0D3B4}" = KLM "{4FA6CB9A-2972-4AAF-A36E-3C40FCC22395}" = THX TruStudio Pro "{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5C1F18D2-F6B7-4242-B803-B5A78648185D}" = Corel WinDVD "{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker "{619FA785-489B-4D22-911F-82D6EDF5BDB0}" = Battery Calibration "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker "{6E8AFC13-F7B8-41D8-88AB-F1D0CFC56305}" = Windows Live Messenger "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common "{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack "{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh "{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime "{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1" = Super-Charger "{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010 "{95193654-3EF2-4D17-8503-9F80B56D9ED5}" = MSI VGA Overclock Tool "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Deutsch "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections "{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DA5597C9-9216-44FF-9670-D1E48817B998}" = MSI HOUSE "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources "{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live "{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) OpenCL CPU Runtime "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker "Avira AntiVir Desktop" = Avira Free Antivirus "DAOCCharplan" = DAOC-Charplan "Dark Age of Camelot" = Dark Age of Camelot "Google Chrome" = Google Chrome "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{4DEA5B85-6C56-45F3-AE00-FED756B0D3B4}" = KLM "InstallShield_{DF446558-ADF7-4884-9B2D-281979CCE71F}" = Qualcomm Atheros Killer Network Manager "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000 "Mozilla Thunderbird 17.0 (x86 de)" = Mozilla Thunderbird 17.0 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 14.12.2012 22:08:04 | Computer Name = sandra-MSI | Source = .NET Runtime | ID = 1026 Description = Error - 14.12.2012 22:08:07 | Computer Name = sandra-MSI | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: KLM.exe, Version: 1.0.1112.1901, Zeitstempel: 0x4eeed613 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17651, Zeitstempel: 0x4e211319 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000b9bc ID des fehlerhaften Prozesses: 0x18a4 Startzeit der fehlerhaften Anwendung: 0x01cdda69035cbfb0 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\MSI\KLM\KLM.exe Pfad des fehlerhaften Moduls: C:\windows\syswow64\KERNELBASE.dll Berichtskennung: 441f3149-465c-11e2-94b0-8c89a5024cfb Error - 14.12.2012 22:08:17 | Computer Name = sandra-MSI | Source = Microsoft-Windows-CAPI2 | ID = 4107 Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error - 14.12.2012 22:42:36 | Computer Name = sandra-MSI | Source = .NET Runtime | ID = 1026 Description = Error - 14.12.2012 22:42:38 | Computer Name = sandra-MSI | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: KLM.exe, Version: 1.0.1112.1901, Zeitstempel: 0x4eeed613 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17651, Zeitstempel: 0x4e211319 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000b9bc ID des fehlerhaften Prozesses: 0x207c Startzeit der fehlerhaften Anwendung: 0x01cdda6dd6f3deda Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\MSI\KLM\KLM.exe Pfad des fehlerhaften Moduls: C:\windows\syswow64\KERNELBASE.dll Berichtskennung: 1624ae13-4661-11e2-94b0-8c89a5024cfb Error - 15.12.2012 15:27:32 | Computer Name = sandra-MSI | Source = WinMgmt | ID = 10 Description = Error - 15.12.2012 15:34:26 | Computer Name = sandra-MSI | Source = .NET Runtime | ID = 1026 Description = Error - 15.12.2012 15:34:27 | Computer Name = sandra-MSI | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: KLM.exe, Version: 1.0.1112.1901, Zeitstempel: 0x4eeed613 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17651, Zeitstempel: 0x4e211319 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000b9bc ID des fehlerhaften Prozesses: 0x1648 Startzeit der fehlerhaften Anwendung: 0x01cddafb30c06b5a Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\MSI\KLM\KLM.exe Pfad des fehlerhaften Moduls: C:\windows\syswow64\KERNELBASE.dll Berichtskennung: 6fb6c8c7-46ee-11e2-a6d8-8c89a5024cfb Error - 15.12.2012 15:36:28 | Computer Name = sandra-MSI | Source = .NET Runtime | ID = 1026 Description = Error - 15.12.2012 15:36:29 | Computer Name = sandra-MSI | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: KLM.exe, Version: 1.0.1112.1901, Zeitstempel: 0x4eeed613 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17651, Zeitstempel: 0x4e211319 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000b9bc ID des fehlerhaften Prozesses: 0x1798 Startzeit der fehlerhaften Anwendung: 0x01cddafb798c962b Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\MSI\KLM\KLM.exe Pfad des fehlerhaften Moduls: C:\windows\syswow64\KERNELBASE.dll Berichtskennung: b845e9b3-46ee-11e2-a6d8-8c89a5024cfb [ System Events ] Error - 15.12.2012 20:39:32 | Computer Name = sandra-MSI | Source = DCOM | ID = 10010 Description = Error - 15.12.2012 20:40:02 | Computer Name = sandra-MSI | Source = DCOM | ID = 10010 Description = Error - 15.12.2012 20:57:37 | Computer Name = sandra-MSI | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft XML Core Services 4.0 Service Pack 2 für x64-Systeme (KB954430) Error - 15.12.2012 21:01:36 | Computer Name = sandra-MSI | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Update für Microsoft XML Core Services 4.0 Service Pack 2 für x64-basierte Systeme (KB973688) Error - 16.12.2012 00:50:33 | Computer Name = sandra-MSI | Source = Service Control Manager | ID = 7031 Description = Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error - 16.12.2012 00:51:24 | Computer Name = sandra-MSI | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update-Dienst (gupdate) erreicht. Error - 16.12.2012 00:51:24 | Computer Name = sandra-MSI | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 16.12.2012 00:51:25 | Computer Name = sandra-MSI | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Rapid Storage Technology erreicht. Error - 16.12.2012 00:51:25 | Computer Name = sandra-MSI | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Intel(R) Rapid Storage Technology" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 16.12.2012 00:53:32 | Computer Name = sandra-MSI | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet: %%16405 < End of report > |
22.12.2012, 19:56 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Musik spielt ab, aber keine Anwendung läuft Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes - denk bitte vorher daran, Malwarebytes über den Updatebutton zu aktualisieren Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
29.12.2012, 09:40 | #11 | |
| Musik spielt ab, aber keine Anwendung läuft Hallo, sorry Weihnachten ist etwas dazwischen gekommen, darum antworte ich jetzt erst: ESET Logfile: Zitat:
|
29.12.2012, 21:42 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Musik spielt ab, aber keine Anwendung läuft WArum fehlt das Log von Malwarebytes?
__________________ Logfiles bitte immer in CODE-Tags posten |
30.12.2012, 11:48 | #13 | |
| Musik spielt ab, aber keine Anwendung läuft weil ich nicht wußte, dass du das auch haben willst.. stand ja nich dabei.... Zitat:
|
30.12.2012, 17:56 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Musik spielt ab, aber keine Anwendung läuftCode:
ATTFilter 16.12.2012 08:57:36 mbam-log-2012-12-16 (08-57-36).txt
__________________ Logfiles bitte immer in CODE-Tags posten |
31.12.2012, 09:04 | #15 | |
| Musik spielt ab, aber keine Anwendung läuft ja hast du und nachdem du das Log wolltest, hab ich nochmal einen Scan gemacht und musste auf Logdateien klicken, weil kein Fenster aufgegangen ist nach dem Scan. Diese Dateien hab ich dann kopiert.. ich hatte keine anderen... Zitat:
|
Themen zu Musik spielt ab, aber keine Anwendung läuft |
adobe, antivir, avira, cpu, desktop, dll, error, explorer, flash player, format, google, home, install.exe, log-datei, logfile, mozilla, musik, nvidia, nvidia update, realtek, registry, rundll, scan, security, server, software, usb, usb 3.0, windows |