|
Plagegeister aller Art und deren Bekämpfung: Malwarebytes bricht ständig abWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.01.2013, 09:53 | #1 |
| Malwarebytes bricht ständig ab Hallo, da ich seit kurzem immer wieder Probleme mit dem Browser Firefox und GoogleChrome habe, bin ich googeln gegangen und habe das Forum gefunden. Und fräse mich gerade durch die Anleitungen. Ich habe mir das Malewarebytes Programm runter geladen und auch ausgeführt. Gestern fand er 48 schädliche Einträge. :-P Bin dann wie beschrieben vorgegangen. So aber immer wenn ich auf "Ausgewähltes entfernen" gehe, bricht das Programm ab und ich bekomme die Meldung: Keine Rückmeldung. Komischer Weise hat er gestern im ersten Durchgang dann irgendwie trotzdem 45 Einträge verschoben aber die letzten drei wollen einfach nicht. Immer wieder Abbruch von Malewarbytes. Brauche echt mal Hilfe. Anbei mal ein Screenshot. Zum System: Windows Vista Home Premium, Service Pack 2. Was braucht ihr noch, um helfen zu können? Vielen Dank Kirstin |
14.01.2013, 14:48 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malwarebytes bricht ständig ab Schön und wo sind die Logs dazu?
__________________Solche Angaben reichen nicht, bitte poste die vollständigen Angaben/Logs der Virenscanner siehe http://www.trojaner-board.de/125889-...tml#post941520 Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log
__________________ |
14.01.2013, 16:33 | #3 |
| Malwarebytes bricht ständig ab Also die Logdatei von Malewarebytes sieht so aus:
__________________2013/01/13 22:19:45 +0100 KIRSTINS-PC Kirstin MESSAGE Starting protection 2013/01/13 22:19:45 +0100 KIRSTINS-PC Kirstin MESSAGE Protection started successfully 2013/01/13 22:19:45 +0100 KIRSTINS-PC Kirstin MESSAGE Starting IP protection 2013/01/13 22:19:56 +0100 KIRSTINS-PC Kirstin MESSAGE IP Protection started successfully 2013/01/13 22:20:47 +0100 KIRSTINS-PC Kirstin MESSAGE Starting database refresh 2013/01/13 22:20:47 +0100 KIRSTINS-PC Kirstin MESSAGE Stopping IP protection 2013/01/13 22:20:47 +0100 KIRSTINS-PC Kirstin MESSAGE IP Protection stopped successfully 2013/01/13 22:20:51 +0100 KIRSTINS-PC Kirstin MESSAGE Database refreshed successfully 2013/01/13 22:20:51 +0100 KIRSTINS-PC Kirstin MESSAGE Starting IP protection 2013/01/13 22:21:00 +0100 KIRSTINS-PC Kirstin MESSAGE IP Protection started successfully 2013/01/13 22:23:10 +0100 KIRSTINS-PC Kirstin MESSAGE Executing scheduled update: Daily 2013/01/13 22:23:16 +0100 KIRSTINS-PC Kirstin MESSAGE Database already up-to-date zweite Datei: 2013/01/14 07:32:18 +0100 KIRSTINS-PC (null) MESSAGE Executing scheduled update: Daily 2013/01/14 07:32:28 +0100 KIRSTINS-PC (null) MESSAGE Starting protection 2013/01/14 07:32:28 +0100 KIRSTINS-PC (null) MESSAGE Protection started successfully 2013/01/14 07:32:28 +0100 KIRSTINS-PC (null) MESSAGE Starting IP protection 2013/01/14 07:32:39 +0100 KIRSTINS-PC (null) MESSAGE Scheduled update executed successfully: database updated from version v2013.01.13.08 to version v2013.01.14.02 2013/01/14 07:32:42 +0100 KIRSTINS-PC (null) MESSAGE IP Protection started successfully 2013/01/14 07:32:42 +0100 KIRSTINS-PC (null) MESSAGE Starting database refresh 2013/01/14 07:32:42 +0100 KIRSTINS-PC (null) MESSAGE Stopping IP protection 2013/01/14 07:32:42 +0100 KIRSTINS-PC (null) MESSAGE IP Protection stopped successfully 2013/01/14 07:32:52 +0100 KIRSTINS-PC (null) MESSAGE Database refreshed successfully 2013/01/14 07:32:52 +0100 KIRSTINS-PC (null) MESSAGE Starting IP protection 2013/01/14 07:33:00 +0100 KIRSTINS-PC (null) MESSAGE IP Protection started successfully 2013/01/14 08:36:44 +0100 KIRSTINS-PC Kirstin MESSAGE Stopping IP protection 2013/01/14 08:36:54 +0100 KIRSTINS-PC Kirstin MESSAGE IP Protection stopped successfully 2013/01/14 08:37:44 +0100 KIRSTINS-PC Kirstin MESSAGE Protection stopped Hatte einmal das Malewarbytes deinstalliert und nochmal neu installiert. In der Hoffnung, dass es dann läuft. |
14.01.2013, 21:37 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malwarebytes bricht ständig ab
__________________ Logfiles bitte immer in CODE-Tags posten |
14.01.2013, 22:26 | #5 |
| Malwarebytes bricht ständig ab Also er hat sogar zwei Logdateien erstellt allerdings sehen die dann so aus wie oben kopiert. Hier nochmal zwei Screenshots |
14.01.2013, 23:01 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malwarebytes bricht ständig ab Ok, die hast du aber schon gepostet Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
Note: Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread. Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards. Malwarebytes Anti-Rootkit Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ --> Malwarebytes bricht ständig ab |
16.01.2013, 08:09 | #7 |
| HILFE: Malewarebytes Anti-Roolkit Hallo, ich habe Malewarebytes Anti-Roolkit heruntergeladen und wie beschrieben auf dem Desktop entpackt. Dann bin ich auf mbar.exe gegangen und nun bekomme ich folgende Meldung: "Registry value "Applnit_DLL" has been found, wich may be caused by rootkit activity" Note: Press "No" button if you're not sure. If the tool crashes or terminates unexpectedly during a system scan, restart the tool an press "yes" should this message appear again. Do you want to remove this value and restart the tool? Auswahl: Ja oder nein. Bin jetzt unsicher..... und hab erstmal nein gesagt. Kann ich die Meldung einfach übergehen und auf ja gehen?? Will nix falsch machen. Screenshot anbei. Geändert von Gentlegladur (16.01.2013 um 08:28 Uhr) |
16.01.2013, 15:57 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malwarebytes bricht ständig ab "nein" ist auch richtig Mach bitte den Scan
__________________ Logfiles bitte immer in CODE-Tags posten |
17.01.2013, 11:38 | #9 |
| Malwarebytes bricht ständig ab Also, scan gestartet, 17 Maleware gefunden. Dann wie beschrieben cleanup Button gedrückt. Er hat dann restore Point kreiert, hängt jetzt aber seit gut ner 1/2Std. Im "Scheduling clean up" und nix tut sich. Oben steht immer noch der hinweis "Detected maleware objects. Uncheck items you want to keep intact.click Cleanup to start to removal." Neu starten? Warten? Alle Programme sind zu und ich habe den Rechner nicht angerührt. Schreib gerade übers Handy. Durchgehalten. Vielleicht auch das nochmal ins Tutorial schreiben, nix anfassen und einfach durchhalten, denn es verunsichert schon, wenn sich augenscheinlich irgendwie nix tut.... :-) Hier kommt die Logfiles: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.01.0.1016 www.malwarebytes.org Database version: v2013.01.17.03 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Kirstin :: KIRSTINS-PC [administrator] 17.01.2013 10:58:29 mbar-log-2013-01-17 (10-58-29).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 31557 Time elapsed: 32 minute(s), 30 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 14 HKLM\SOFTWARE\CLASSES\INTERFACE\{23C70BCA-6E23-4A65-AD2E-1389062074F1} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\TypeLib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{295CACB4-51F5-46FD-914E-C72BAAE1B672} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{34C1FDF7-02C1-4F23-B393-F48B16E071D1} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{54291324-7A3D-4F11-B707-3FB6A2C97BD9} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{C0585B2F-74D7-4734-88DE-6C150C5D4036} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347} (PUP.Funmoods) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\INTERFACE\{EF0588D6-1621-4A75-B8BE-F4BC34794136} (PUP.Funmoods) -> Delete on reboot. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 3 c:\Users\Kirstin\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Delete on reboot. c:\Users\Kirstin\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Delete on reboot. c:\Users\Kirstin\AppData\LocalLow\bbrs_002.tb\content\cache (PUP.Blabbers) -> Delete on reboot. Files Detected: 0 (No malicious items detected) (end) Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.01.0.1016 www.malwarebytes.org Database version: v2013.01.17.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Kirstin :: KIRSTINS-PC [administrator] 17.01.2013 14:18:07 mbar-log-2013-01-17 (14-18-07).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 31550 Time elapsed: 39 minute(s), 59 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) hxxp://ad.yieldmanager.com/st?ad_type=iframe&ad_size=800x440§ion=2922708&pub_url=${PUB_URL} Feld ist leer, nix drin. Eben wieder. |
17.01.2013, 16:06 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malwarebytes bricht ständig ab Wir sind hier ja auch längst noch nicht fertig! 1. aswMBR Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop. Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehlalarm!
Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes: Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button. 2. TDSS-Killer Download TDSS-Killer auf Desktop siehe => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs. Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!
__________________ Logfiles bitte immer in CODE-Tags posten |
17.01.2013, 23:22 | #11 |
| Malwarebytes bricht ständig ab 2x beim Scannen mit aswMBR voller Systemabsturz. Bildschirm blau. Hab dann ohne Quick Scan, sondern mit "none" gescannt. Code:
ATTFilter aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software Run date: 2013-01-17 23:09:49 ----------------------------- 23:09:49.611 OS Version: Windows 6.0.6002 Service Pack 2 23:09:49.611 Number of processors: 2 586 0x301 23:09:49.612 ComputerName: KIRSTINS-PC UserName: Kirstin 23:09:56.036 Initialize success 23:10:20.477 AVAST engine defs: 13011701 23:11:04.449 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\000000a9 23:11:04.461 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 8 23:11:04.486 Disk 0 MBR read successfully 23:11:04.495 Disk 0 MBR scan 23:11:04.517 Disk 0 unknown MBR code 23:11:04.572 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 10000 MB offset 2048 23:11:04.654 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 466938 MB offset 20482048 23:11:04.704 Disk 0 scanning sectors +976771072 23:11:05.349 Disk 0 scanning C:\Windows\system32\drivers 23:12:04.507 Service scanning 23:13:14.911 Modules scanning 23:13:52.862 Disk 0 trace - called modules: 23:13:52.925 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys ahcix86s.sys 23:13:52.937 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8748aac8] 23:13:52.949 3 CLASSPNP.SYS[89f328b3] -> nt!IofCallDriver -> [0x86a8fa60] 23:13:52.958 5 acpi.sys[8060a6bc] -> nt!IofCallDriver -> \Device\000000a9[0x867b8b88] 23:13:52.972 Scan finished successfully 23:14:25.106 Disk 0 MBR has been saved successfully to "C:\Users\Kirstin\Desktop\MBR.dat" 23:14:25.134 The log file has been saved successfully to "C:\Users\Kirstin\Desktop\aswMBR.txt" Code:
ATTFilter 23:30:48.0576 5216 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 23:30:50.0583 5216 ============================================================ 23:30:50.0583 5216 Current date / time: 2013/01/17 23:30:50.0583 23:30:50.0584 5216 SystemInfo: 23:30:50.0584 5216 23:30:50.0584 5216 OS Version: 6.0.6002 ServicePack: 2.0 23:30:50.0584 5216 Product type: Workstation 23:30:50.0585 5216 ComputerName: KIRSTINS-PC 23:30:50.0586 5216 UserName: Kirstin 23:30:50.0586 5216 Windows directory: C:\Windows 23:30:50.0586 5216 System windows directory: C:\Windows 23:30:50.0586 5216 Processor architecture: Intel x86 23:30:50.0586 5216 Number of processors: 2 23:30:50.0586 5216 Page size: 0x1000 23:30:50.0586 5216 Boot type: Normal boot 23:30:50.0586 5216 ============================================================ 23:30:54.0606 5216 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 23:30:54.0667 5216 Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 23:30:54.0715 5216 ============================================================ 23:30:54.0715 5216 \Device\Harddisk0\DR0: 23:30:54.0729 5216 MBR partitions: 23:30:54.0729 5216 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1388800, BlocksNum 0x38FFD000 23:30:54.0729 5216 \Device\Harddisk2\DR2: 23:30:54.0731 5216 MBR partitions: 23:30:54.0731 5216 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x74705982 23:30:54.0731 5216 ============================================================ 23:30:54.0797 5216 C: <-> \Device\Harddisk0\DR0\Partition1 23:30:54.0824 5216 F: <-> \Device\Harddisk2\DR2\Partition1 23:30:54.0826 5216 ============================================================ 23:30:54.0826 5216 Initialize success 23:30:54.0826 5216 ============================================================ 23:31:42.0892 1908 ============================================================ 23:31:42.0892 1908 Scan started 23:31:42.0892 1908 Mode: Manual; SigCheck; TDLFS; 23:31:42.0892 1908 ============================================================ 23:32:03.0928 1908 ================ Scan system memory ======================== 23:32:03.0928 1908 System memory - ok 23:32:03.0929 1908 ================ Scan services ============================= 23:32:04.0373 1908 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 23:32:04.0685 1908 ACDaemon - ok 23:32:05.0704 1908 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys 23:32:05.0971 1908 ACPI - ok 23:32:06.0227 1908 [ 86E6273AC7BA2977FBCFEFFB2C09481B ] AcrSch2Svc C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe 23:32:06.0312 1908 AcrSch2Svc - ok 23:32:06.0426 1908 [ F84C9DEE4698DF3C1D76801B7B1B55D7 ] Adobe LM Service C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe 23:32:06.0512 1908 Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning 23:32:06.0512 1908 Adobe LM Service - detected UnsignedFile.Multi.Generic (1) 23:32:06.0750 1908 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 23:32:06.0830 1908 AdobeARMservice - ok 23:32:07.0221 1908 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 23:32:07.0343 1908 AdobeFlashPlayerUpdateSvc - ok 23:32:07.0545 1908 [ FC9D93D13127E3252466D4A33039B54B ] AdobeVersionCue C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe 23:32:07.0637 1908 AdobeVersionCue ( UnsignedFile.Multi.Generic ) - warning 23:32:07.0638 1908 AdobeVersionCue - detected UnsignedFile.Multi.Generic (1) 23:32:07.0958 1908 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 23:32:08.0517 1908 adp94xx - ok 23:32:08.0689 1908 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys 23:32:08.0761 1908 adpahci - ok 23:32:08.0837 1908 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 23:32:08.0911 1908 adpu160m - ok 23:32:08.0952 1908 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 23:32:09.0006 1908 adpu320 - ok 23:32:09.0075 1908 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 23:32:09.0196 1908 AeLookupSvc - ok 23:32:09.0245 1908 [ FE3EA6E9AFC1A78E6EDCA121E006AFB7 ] Afc C:\Windows\system32\drivers\Afc.sys 23:32:09.0271 1908 Afc - ok 23:32:09.0419 1908 [ 53696AD8FFC5FAC51949A525FF65A689 ] afcdp C:\Windows\system32\DRIVERS\afcdp.sys 23:32:09.0480 1908 afcdp - ok 23:32:10.0268 1908 [ AF44F7E027037628F1FAC3C13CDE73E6 ] afcdpsrv C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe 23:32:11.0851 1908 afcdpsrv - ok 23:32:12.0008 1908 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys 23:32:12.0089 1908 AFD - ok 23:32:12.0209 1908 [ EFBC44FBD75E4F80BD927AEBF6E7EADE ] AgereModemAudio C:\Windows\system32\agrsmsvc.exe 23:32:12.0368 1908 AgereModemAudio - ok 23:32:12.0608 1908 [ 38325C6AA8EAE011897D61CE48EC6435 ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys 23:32:12.0926 1908 AgereSoftModem - ok 23:32:13.0047 1908 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys 23:32:13.0095 1908 agp440 - ok 23:32:13.0191 1908 [ 03081E98C515CB838434D252F407F6E8 ] ahcix86s C:\Windows\system32\DRIVERS\ahcix86s.sys 23:32:13.0232 1908 ahcix86s - ok 23:32:13.0314 1908 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys 23:32:13.0369 1908 aic78xx - ok 23:32:14.0829 1908 [ B9B98E08EC127900025F42462D3D0A66 ] Akamai c:\program files\common files\akamai/netsession_win_ce5ba24.dll 23:32:14.0830 1908 Suspicious file (Hidden): c:\program files\common files\akamai/netsession_win_ce5ba24.dll. md5: B9B98E08EC127900025F42462D3D0A66 23:32:14.0864 1908 Akamai ( HiddenFile.Multi.Generic ) - warning 23:32:14.0864 1908 Akamai - detected HiddenFile.Multi.Generic (1) 23:32:14.0945 1908 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe 23:32:15.0060 1908 ALG - ok 23:32:15.0117 1908 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys 23:32:15.0141 1908 aliide - ok 23:32:15.0221 1908 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys 23:32:15.0247 1908 amdagp - ok 23:32:15.0280 1908 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys 23:32:15.0324 1908 amdide - ok 23:32:15.0361 1908 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys 23:32:15.0555 1908 AmdK7 - ok 23:32:15.0604 1908 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 23:32:15.0767 1908 AmdK8 - ok 23:32:16.0748 1908 [ 64895A6443D147C1ABA523589B485E02 ] amdkmdag C:\Windows\system32\DRIVERS\atipmdag.sys 23:32:17.0713 1908 amdkmdag - ok 23:32:17.0794 1908 [ 2DB28DBC59F2AD9998B128E32BAD7491 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys 23:32:17.0850 1908 amdkmdap - ok 23:32:18.0102 1908 [ 0FA2D8304ECA29CA0AB7E3EE50FD585A ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe 23:32:18.0167 1908 AntiVirSchedulerService - ok 23:32:18.0369 1908 [ 5C69AAC8A59207DA9710FF2E42D6F80F ] AntiVirService C:\Program Files\Avira\AntiVir Desktop\avguard.exe 23:32:18.0454 1908 AntiVirService - ok 23:32:18.0639 1908 [ 255527AB98293EA390352A8C53B0042A ] AntiVirWebService C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE 23:32:18.0692 1908 AntiVirWebService - ok 23:32:18.0804 1908 [ 8D3A55F7B7BE6B374479E5195F477226 ] AnyDVD C:\Windows\system32\Drivers\AnyDVD.sys 23:32:18.0868 1908 AnyDVD - ok 23:32:18.0930 1908 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll 23:32:19.0040 1908 Appinfo - ok 23:32:19.0298 1908 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 23:32:19.0444 1908 Apple Mobile Device - ok 23:32:19.0530 1908 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys 23:32:19.0593 1908 arc - ok 23:32:19.0654 1908 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys 23:32:19.0712 1908 arcsas - ok 23:32:19.0762 1908 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 23:32:20.0336 1908 AsyncMac - ok 23:32:20.0482 1908 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys 23:32:20.0654 1908 atapi - ok 23:32:21.0051 1908 [ ACDB46B1A467752A2F280C68C8461556 ] athr C:\Windows\system32\DRIVERS\athr.sys 23:32:21.0418 1908 athr - ok 23:32:21.0623 1908 [ 202F86BA4B7BDF9D0A6E81D148FEF560 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe 23:32:21.0961 1908 Ati External Event Utility - ok 23:32:22.0089 1908 [ 5A1465AD2E7C1BC39CDA12A355329096 ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie.sys 23:32:22.0148 1908 AtiPcie - ok 23:32:22.0344 1908 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 23:32:22.0447 1908 AudioEndpointBuilder - ok 23:32:22.0465 1908 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll 23:32:22.0504 1908 Audiosrv - ok 23:32:22.0602 1908 [ A5C175039B1D6D85D0E79F5855828E4D ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 23:32:22.0639 1908 avgntflt - ok 23:32:22.0762 1908 [ 37B854C7D1F477E66C5B49C7700C47CC ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 23:32:22.0817 1908 avipbb - ok 23:32:22.0865 1908 [ FFB78D74E1EA5F811341A6E7AC547A46 ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 23:32:22.0880 1908 avkmgr - ok 23:32:22.0992 1908 [ 502F1C30BD50B32D00CE4DCAECC3D3C7 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 23:32:23.0101 1908 b57nd60x - ok 23:32:23.0162 1908 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys 23:32:23.0264 1908 Beep - ok 23:32:23.0377 1908 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll 23:32:23.0520 1908 BFE - ok 23:32:23.0803 1908 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll 23:32:24.0405 1908 BITS - ok 23:32:24.0468 1908 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 23:32:24.0605 1908 blbdrive - ok 23:32:24.0894 1908 [ 1C87705CCB2F60172B0FC86B5D82F00D ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 23:32:25.0016 1908 Bonjour Service - ok 23:32:25.0112 1908 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys 23:32:25.0153 1908 bowser - ok 23:32:25.0235 1908 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 23:32:25.0297 1908 BrFiltLo - ok 23:32:25.0341 1908 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 23:32:25.0435 1908 BrFiltUp - ok 23:32:25.0520 1908 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll 23:32:25.0801 1908 Browser - ok 23:32:25.0946 1908 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys 23:32:26.0170 1908 Brserid - ok 23:32:26.0235 1908 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 23:32:26.0337 1908 BrSerWdm - ok 23:32:26.0376 1908 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 23:32:26.0483 1908 BrUsbMdm - ok 23:32:26.0507 1908 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 23:32:26.0658 1908 BrUsbSer - ok 23:32:26.0721 1908 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 23:32:26.0910 1908 BTHMODEM - ok 23:32:27.0003 1908 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 23:32:27.0101 1908 cdfs - ok 23:32:27.0185 1908 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 23:32:27.0251 1908 cdrom - ok 23:32:27.0383 1908 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll 23:32:27.0447 1908 CertPropSvc - ok 23:32:27.0498 1908 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys 23:32:27.0542 1908 circlass - ok 23:32:27.0700 1908 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys 23:32:27.0778 1908 CLFS - ok 23:32:27.0993 1908 [ 2B272D0A6E5071829B516FFDC7F841CA ] CLHNService C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe 23:32:28.0049 1908 CLHNService - ok 23:32:28.0173 1908 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 23:32:28.0303 1908 clr_optimization_v2.0.50727_32 - ok 23:32:28.0579 1908 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 23:32:28.0787 1908 clr_optimization_v4.0.30319_32 - ok 23:32:28.0913 1908 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 23:32:29.0032 1908 CmBatt - ok 23:32:29.0067 1908 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys 23:32:29.0118 1908 cmdide - ok 23:32:29.0230 1908 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 23:32:29.0255 1908 Compbatt - ok 23:32:29.0262 1908 COMSysApp - ok 23:32:29.0301 1908 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 23:32:29.0327 1908 crcdisk - ok 23:32:29.0396 1908 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys 23:32:29.0499 1908 Crusoe - ok 23:32:29.0598 1908 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll 23:32:29.0789 1908 CryptSvc - ok 23:32:29.0991 1908 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll 23:32:30.0336 1908 DcomLaunch - ok 23:32:30.0382 1908 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys 23:32:30.0449 1908 DfsC - ok 23:32:30.0867 1908 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe 23:32:32.0096 1908 DFSR - ok 23:32:32.0247 1908 [ 6CC6C4B9D7B906A151AA094CA087B9F0 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys 23:32:32.0302 1908 dg_ssudbus - ok 23:32:32.0505 1908 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll 23:32:32.0632 1908 Dhcp - ok 23:32:32.0734 1908 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys 23:32:32.0784 1908 disk - ok 23:32:32.0890 1908 [ 73BAF270D24FE726B9CD7F80BB17A23D ] DKbFltr C:\Windows\system32\DRIVERS\DKbFltr.sys 23:32:32.0923 1908 DKbFltr - ok 23:32:33.0032 1908 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll 23:32:33.0104 1908 Dnscache - ok 23:32:33.0210 1908 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll 23:32:33.0361 1908 dot3svc - ok 23:32:33.0725 1908 [ 4F59C172C094E1A1D46463A8DC061CBD ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 23:32:33.0913 1908 Dot4 - ok 23:32:33.0953 1908 [ 80BF3BA09F6F2523C8F6B7CC6DBF7BD5 ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 23:32:34.0075 1908 Dot4Print - ok 23:32:34.0139 1908 [ C55004CA6B419B6695970DFE849B122F ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 23:32:34.0249 1908 dot4usb - ok 23:32:34.0380 1908 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll 23:32:34.0446 1908 DPS - ok 23:32:34.0533 1908 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 23:32:34.0624 1908 drmkaud - ok 23:32:35.0015 1908 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 23:32:35.0179 1908 DXGKrnl - ok 23:32:35.0290 1908 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys 23:32:35.0392 1908 E1G60 - ok 23:32:35.0520 1908 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll 23:32:35.0607 1908 EapHost - ok 23:32:35.0737 1908 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys 23:32:35.0816 1908 Ecache - ok 23:32:36.0128 1908 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 23:32:36.0293 1908 ehRecvr - ok 23:32:36.0424 1908 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe 23:32:36.0562 1908 ehSched - ok 23:32:36.0724 1908 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll 23:32:36.0998 1908 ehstart - ok 23:32:37.0140 1908 [ D71233D7CCC2E64F8715A20428D5A33B ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys 23:32:37.0202 1908 ElbyCDIO - ok 23:32:37.0433 1908 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys 23:32:37.0636 1908 elxstor - ok 23:32:37.0953 1908 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll 23:32:38.0037 1908 EMDMgmt - ok 23:32:38.0327 1908 [ BF5A69708FDD68EA1E20E72E2AFE6996 ] ePowerSvc C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe 23:32:38.0502 1908 ePowerSvc - ok 23:32:38.0537 1908 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys 23:32:38.0607 1908 ErrDev - ok 23:32:38.0852 1908 [ 2407B8164E966755BC6A4242FC9DE31E ] esgiguard C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys 23:32:38.0867 1908 esgiguard - ok 23:32:39.0160 1908 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll 23:32:39.0314 1908 EventSystem - ok 23:32:39.0449 1908 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys 23:32:39.0518 1908 exfat - ok 23:32:39.0597 1908 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys 23:32:39.0661 1908 fastfat - ok 23:32:39.0725 1908 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys 23:32:39.0822 1908 fdc - ok 23:32:39.0924 1908 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll 23:32:40.0036 1908 fdPHost - ok 23:32:40.0086 1908 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll 23:32:40.0223 1908 FDResPub - ok 23:32:40.0313 1908 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 23:32:40.0427 1908 FileInfo - ok 23:32:40.0469 1908 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys 23:32:40.0555 1908 Filetrace - ok 23:32:41.0317 1908 [ 167D24A045499EBEF438F231976158DF ] FirebirdServerMAGIXInstance C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe 23:32:42.0081 1908 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - warning 23:32:42.0082 1908 FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic (1) 23:32:42.0187 1908 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 23:32:42.0329 1908 flpydisk - ok 23:32:42.0434 1908 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 23:32:42.0504 1908 FltMgr - ok 23:32:42.0849 1908 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll 23:32:43.0346 1908 FontCache - ok 23:32:43.0546 1908 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 23:32:43.0578 1908 FontCache3.0.0.0 - ok 23:32:43.0651 1908 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 23:32:43.0727 1908 Fs_Rec - ok 23:32:43.0806 1908 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 23:32:43.0855 1908 gagp30kx - ok 23:32:43.0930 1908 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 23:32:43.0980 1908 GEARAspiWDM - ok 23:32:44.0244 1908 [ 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F ] GoogleDesktopManager-051210-111108 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 23:32:44.0415 1908 GoogleDesktopManager-051210-111108 - ok 23:32:44.0748 1908 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll 23:32:44.0867 1908 gpsvc - ok 23:32:45.0049 1908 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 23:32:45.0100 1908 gupdate - ok 23:32:45.0161 1908 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 23:32:45.0213 1908 gupdatem - ok 23:32:45.0346 1908 [ 751C1D2CA2ABF4A9F5A6B8D7D45B907C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 23:32:45.0452 1908 gusvc - ok 23:32:45.0616 1908 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 23:32:45.0854 1908 HdAudAddService - ok 23:32:45.0961 1908 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 23:32:46.0143 1908 HDAudBus - ok 23:32:46.0201 1908 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys 23:32:46.0361 1908 HidBth - ok 23:32:46.0463 1908 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys 23:32:46.0584 1908 HidIr - ok 23:32:46.0692 1908 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll 23:32:46.0815 1908 hidserv - ok 23:32:46.0889 1908 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 23:32:46.0989 1908 HidUsb - ok 23:32:47.0101 1908 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll 23:32:47.0290 1908 hkmsvc - ok 23:32:47.0378 1908 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 23:32:47.0407 1908 HpCISSs - ok 23:32:47.0796 1908 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll 23:32:47.0906 1908 hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning 23:32:47.0906 1908 hpqcxs08 - detected UnsignedFile.Multi.Generic (1) 23:32:48.0027 1908 [ 7DA3211AC63EDD90B8ECA1CA1ABFD43B ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll 23:32:48.0079 1908 hpqddsvc ( UnsignedFile.Multi.Generic ) - warning 23:32:48.0079 1908 hpqddsvc - detected UnsignedFile.Multi.Generic (1) 23:32:48.0313 1908 [ 14229263AA19C704E0D6D2E7404A8455 ] HPSLPSVC C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL 23:32:48.0912 1908 HPSLPSVC ( UnsignedFile.Multi.Generic ) - warning 23:32:48.0912 1908 HPSLPSVC - detected UnsignedFile.Multi.Generic (1) 23:32:49.0060 1908 [ 46D67209550973257601A533E2AC5785 ] HSFHWAZL C:\Windows\system32\DRIVERS\VSTAZL3.SYS 23:32:49.0412 1908 HSFHWAZL - ok 23:32:49.0698 1908 [ 1E7C79CBAF71AA92E0EEE924907DCB55 ] HsfXAudioService C:\Windows\system32\XAudio32.dll 23:32:50.0019 1908 HsfXAudioService - ok 23:32:50.0290 1908 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys 23:32:50.0480 1908 HTTP - ok 23:32:50.0561 1908 [ 19E6885A061011D8DABE8F64498423FA ] hwdatacard C:\Windows\system32\DRIVERS\ewusbmdm.sys 23:32:50.0651 1908 hwdatacard - ok 23:32:50.0741 1908 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys 23:32:50.0769 1908 i2omp - ok 23:32:50.0818 1908 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 23:32:50.0862 1908 i8042prt - ok 23:32:50.0933 1908 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 23:32:51.0010 1908 iaStorV - ok 23:32:51.0370 1908 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 23:32:51.0555 1908 idsvc - ok 23:32:51.0592 1908 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys 23:32:51.0618 1908 iirsp - ok 23:32:51.0760 1908 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll 23:32:52.0258 1908 IKEEXT - ok 23:32:52.0804 1908 [ FFB0B713A54DD05193DBCD0B790B37EE ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys 23:32:53.0699 1908 IntcAzAudAddService - ok 23:32:53.0829 1908 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys 23:32:53.0884 1908 intelide - ok 23:32:53.0952 1908 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 23:32:54.0111 1908 intelppm - ok 23:32:54.0214 1908 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 23:32:54.0394 1908 IPBusEnum - ok 23:32:54.0439 1908 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 23:32:54.0546 1908 IpFilterDriver - ok 23:32:54.0852 1908 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 23:32:54.0966 1908 iphlpsvc - ok 23:32:54.0997 1908 IpInIp - ok 23:32:55.0207 1908 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 23:32:55.0344 1908 IPMIDRV - ok 23:32:55.0423 1908 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 23:32:55.0546 1908 IPNAT - ok 23:32:55.0909 1908 [ F62C69376A95795FE7CDB1C778EDACA4 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 23:32:56.0141 1908 iPod Service - ok 23:32:56.0219 1908 [ E50A95179211B12946F7E035D60AF560 ] irda C:\Windows\system32\DRIVERS\irda.sys 23:32:56.0378 1908 irda - ok 23:32:56.0464 1908 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 23:32:56.0627 1908 IRENUM - ok 23:32:56.0741 1908 [ CBB0D940221A281BCFEAEA695BD1CDA5 ] Irmon C:\Windows\System32\irmon.dll 23:32:56.0892 1908 Irmon - ok 23:32:56.0972 1908 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys 23:32:56.0987 1908 isapnp - ok 23:32:57.0083 1908 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 23:32:57.0184 1908 iScsiPrt - ok 23:32:57.0319 1908 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 23:32:57.0346 1908 iteatapi - ok 23:32:57.0391 1908 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys 23:32:57.0427 1908 iteraid - ok 23:32:57.0506 1908 [ EAC21E8014C7E6EE341AFFFB7E2BBD54 ] k57nd60x C:\Windows\system32\DRIVERS\k57nd60x.sys 23:32:57.0636 1908 k57nd60x - ok 23:32:57.0748 1908 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 23:32:57.0807 1908 kbdclass - ok 23:32:57.0868 1908 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 23:32:57.0925 1908 kbdhid - ok 23:32:57.0969 1908 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe 23:32:58.0190 1908 KeyIso - ok 23:32:58.0430 1908 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 23:32:58.0547 1908 KSecDD - ok 23:32:58.0711 1908 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll 23:32:58.0863 1908 KtmRm - ok 23:32:58.0989 1908 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll 23:32:59.0083 1908 LanmanServer - ok 23:32:59.0222 1908 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 23:32:59.0454 1908 LanmanWorkstation - ok 23:32:59.0567 1908 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 23:32:59.0663 1908 lltdio - ok 23:32:59.0772 1908 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll 23:32:59.0921 1908 lltdsvc - ok 23:32:59.0962 1908 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll 23:33:00.0101 1908 lmhosts - ok 23:33:00.0243 1908 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 23:33:00.0755 1908 LSI_FC - ok 23:33:00.0905 1908 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 23:33:01.0011 1908 LSI_SAS - ok 23:33:01.0174 1908 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 23:33:01.0301 1908 LSI_SCSI - ok 23:33:01.0354 1908 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys 23:33:01.0434 1908 luafv - ok 23:33:01.0448 1908 lxct_device - ok 23:33:01.0608 1908 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 23:33:01.0646 1908 MBAMProtector - ok 23:33:01.0971 1908 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 23:33:02.0102 1908 MBAMScheduler - ok 23:33:02.0199 1908 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 23:33:02.0379 1908 MBAMService - ok 23:33:02.0653 1908 [ 22A7776C5D8EB5930EDF9C8DD0884259 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe 23:33:02.0691 1908 McComponentHostService - ok 23:33:02.0800 1908 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 23:33:02.0926 1908 Mcx2Svc - ok 23:33:03.0075 1908 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys 23:33:03.0185 1908 mdmxsdk - ok 23:33:03.0317 1908 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys 23:33:03.0375 1908 megasas - ok 23:33:03.0523 1908 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys 23:33:03.0595 1908 MegaSR - ok 23:33:03.0696 1908 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll 23:33:03.0824 1908 MMCSS - ok 23:33:03.0864 1908 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys 23:33:04.0025 1908 Modem - ok 23:33:04.0130 1908 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 23:33:04.0278 1908 monitor - ok 23:33:04.0342 1908 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 23:33:04.0389 1908 mouclass - ok 23:33:04.0424 1908 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 23:33:04.0504 1908 mouhid - ok 23:33:04.0600 1908 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 23:33:04.0670 1908 MountMgr - ok 23:33:04.0888 1908 [ 730A519505621DF46BCBF9CDAC9FB6AD ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 23:33:04.0948 1908 MozillaMaintenance - ok 23:33:05.0061 1908 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys 23:33:05.0103 1908 mpio - ok 23:33:05.0159 1908 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 23:33:05.0269 1908 mpsdrv - ok 23:33:05.0842 1908 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll 23:33:06.0027 1908 MpsSvc - ok 23:33:06.0109 1908 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 23:33:06.0138 1908 Mraid35x - ok 23:33:06.0231 1908 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 23:33:06.0267 1908 MRxDAV - ok 23:33:06.0402 1908 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 23:33:06.0620 1908 mrxsmb - ok 23:33:06.0750 1908 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 23:33:06.0920 1908 mrxsmb10 - ok 23:33:06.0975 1908 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 23:33:07.0068 1908 mrxsmb20 - ok 23:33:07.0131 1908 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys 23:33:07.0154 1908 msahci - ok 23:33:07.0191 1908 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys 23:33:07.0208 1908 msdsm - ok 23:33:07.0263 1908 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe 23:33:07.0377 1908 MSDTC - ok 23:33:07.0426 1908 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys 23:33:07.0525 1908 Msfs - ok 23:33:07.0630 1908 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 23:33:07.0646 1908 msisadrv - ok 23:33:07.0754 1908 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 23:33:07.0853 1908 MSiSCSI - ok 23:33:07.0864 1908 msiserver - ok 23:33:07.0915 1908 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 23:33:08.0002 1908 MSKSSRV - ok 23:33:08.0050 1908 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 23:33:08.0158 1908 MSPCLOCK - ok 23:33:08.0192 1908 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 23:33:08.0282 1908 MSPQM - ok 23:33:08.0416 1908 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 23:33:08.0480 1908 MsRPC - ok 23:33:08.0575 1908 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 23:33:08.0629 1908 mssmbios - ok 23:33:08.0683 1908 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 23:33:08.0741 1908 MSTEE - ok 23:33:08.0841 1908 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys 23:33:08.0895 1908 Mup - ok 23:33:08.0993 1908 [ 2DE94E435C3EFDE58C7B1856D4F20724 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys 23:33:09.0021 1908 mwlPSDFilter - ok 23:33:09.0067 1908 [ 61920A7146EED3D903DBBB8EC295AF76 ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys 23:33:09.0092 1908 mwlPSDNServ - ok 23:33:09.0146 1908 [ E0F49721E68EBD2983E84C44FADA6665 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys 23:33:09.0162 1908 mwlPSDVDisk - ok 23:33:09.0462 1908 [ 77F8AD024059A9A8E17E654B887D1EF0 ] MWLService C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe 23:33:09.0576 1908 MWLService - ok 23:33:09.0789 1908 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll 23:33:09.0872 1908 napagent - ok 23:33:09.0959 1908 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 23:33:10.0045 1908 NativeWifiP - ok 23:33:10.0127 1908 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys 23:33:10.0187 1908 NDIS - ok 23:33:10.0236 1908 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 23:33:10.0315 1908 NdisTapi - ok 23:33:10.0354 1908 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 23:33:10.0511 1908 Ndisuio - ok 23:33:10.0633 1908 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 23:33:10.0701 1908 NdisWan - ok 23:33:10.0801 1908 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 23:33:10.0931 1908 NDProxy - ok 23:33:10.0980 1908 [ 2969D26EEE289BE7422AA46FC55F4E38 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 23:33:11.0047 1908 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning 23:33:11.0072 1908 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1) 23:33:11.0166 1908 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 23:33:11.0383 1908 NetBIOS - ok 23:33:11.0459 1908 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys 23:33:11.0624 1908 netbt - ok 23:33:11.0692 1908 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe 23:33:11.0740 1908 Netlogon - ok 23:33:11.0841 1908 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll 23:33:12.0445 1908 Netman - ok 23:33:12.0678 1908 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll 23:33:12.0846 1908 netprofm - ok 23:33:13.0163 1908 [ AF14F279BF4AC27560C6BCC82CB09D24 ] netr28u C:\Windows\system32\DRIVERS\netr28u.sys 23:33:13.0527 1908 netr28u - ok 23:33:13.0642 1908 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 23:33:13.0721 1908 NetTcpPortSharing - ok 23:33:13.0809 1908 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 23:33:13.0858 1908 nfrd960 - ok 23:33:13.0986 1908 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll 23:33:14.0103 1908 NlaSvc - ok 23:33:14.0172 1908 [ CFE3462A9E94A57DCD9676F6B7FE7F67 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys 23:33:14.0443 1908 nmwcd - ok 23:33:14.0509 1908 [ 8F2A94F991F8C73CEC26B4B5620D1EDC ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys 23:33:14.0672 1908 nmwcdc - ok 23:33:14.0811 1908 [ 99145C5D4B6C4D6F5CE83EE6ABFFE294 ] nmwcdnsu C:\Windows\system32\drivers\nmwcdnsu.sys 23:33:14.0896 1908 nmwcdnsu - ok 23:33:14.0943 1908 [ FAEE7B61C6885B091CEC1FF06DA2E1AB ] nmwcdnsuc C:\Windows\system32\drivers\nmwcdnsuc.sys 23:33:15.0002 1908 nmwcdnsuc - ok 23:33:15.0065 1908 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys 23:33:15.0174 1908 Npfs - ok 23:33:15.0267 1908 [ 6D8D2E5652FC2442C810C5D8BE784148 ] NSCIRDA C:\Windows\system32\DRIVERS\nscirda.sys 23:33:15.0381 1908 NSCIRDA - ok 23:33:15.0459 1908 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll 23:33:15.0570 1908 nsi - ok 23:33:15.0643 1908 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 23:33:15.0748 1908 nsiproxy - ok 23:33:15.0880 1908 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 23:33:15.0997 1908 Ntfs - ok 23:33:16.0119 1908 [ 516C097A2890BF5D81BCA83F98790281 ] NTI IScheduleSvc C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe 23:33:16.0243 1908 NTI IScheduleSvc - ok 23:33:16.0318 1908 [ 973DCB15731339FCA176E534055CF115 ] NTIBackupSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe 23:33:16.0427 1908 NTIBackupSvc - ok 23:33:16.0468 1908 [ 13E6D89060A3006F8B3ACBE49110635E ] NTIDrvr C:\Windows\system32\Drivers\NTIDrvr.sys 23:33:16.0529 1908 NTIDrvr - ok 23:33:16.0576 1908 [ 58751F9248D50BCE1053976C9E2F0859 ] NTISchedulerSvc C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 23:33:16.0641 1908 NTISchedulerSvc - ok 23:33:16.0688 1908 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys 23:33:16.0795 1908 ntrigdigi - ok 23:33:16.0841 1908 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys 23:33:16.0955 1908 Null - ok 23:33:17.0007 1908 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys 23:33:17.0057 1908 nvraid - ok 23:33:17.0085 1908 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys 23:33:17.0143 1908 nvstor - ok 23:33:17.0236 1908 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 23:33:17.0324 1908 nv_agp - ok 23:33:17.0339 1908 NwlnkFlt - ok 23:33:17.0360 1908 NwlnkFwd - ok 23:33:17.0583 1908 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 23:33:17.0901 1908 odserv - ok 23:33:17.0975 1908 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys 23:33:18.0101 1908 ohci1394 - ok 23:33:18.0236 1908 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 23:33:18.0282 1908 ose - ok 23:33:18.0365 1908 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll 23:33:18.0572 1908 p2pimsvc - ok 23:33:18.0610 1908 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll 23:33:18.0688 1908 p2psvc - ok 23:33:18.0758 1908 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys 23:33:18.0961 1908 Parport - ok 23:33:19.0021 1908 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys 23:33:19.0047 1908 partmgr - ok 23:33:19.0087 1908 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys 23:33:19.0222 1908 Parvdm - ok 23:33:19.0305 1908 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll 23:33:19.0447 1908 PcaSvc - ok 23:33:19.0500 1908 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys 23:33:19.0610 1908 pccsmcfd - ok 23:33:19.0693 1908 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys 23:33:19.0751 1908 pci - ok 23:33:19.0828 1908 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys 23:33:19.0898 1908 pciide - ok 23:33:19.0944 1908 [ B7C5A8769541900F6DFA6FE0C5E4D513 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 23:33:19.0970 1908 pcmcia - ok 23:33:20.0018 1908 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 23:33:20.0194 1908 PEAUTH - ok 23:33:20.0354 1908 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll 23:33:20.0459 1908 pla - ok 23:33:20.0547 1908 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll 23:33:20.0674 1908 PlugPlay - ok 23:33:20.0726 1908 [ BAFC9706BDF425A02B66468AB2605C59 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 23:33:20.0798 1908 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning 23:33:20.0798 1908 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1) 23:33:20.0882 1908 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 23:33:20.0971 1908 PNRPAutoReg - ok 23:33:21.0014 1908 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll 23:33:21.0042 1908 PNRPsvc - ok 23:33:21.0110 1908 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 23:33:21.0171 1908 PolicyAgent - ok 23:33:21.0252 1908 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 23:33:21.0372 1908 PptpMiniport - ok 23:33:21.0446 1908 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\DRIVERS\processr.sys 23:33:21.0587 1908 Processor - ok 23:33:21.0663 1908 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll 23:33:21.0716 1908 ProfSvc - ok 23:33:21.0770 1908 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe 23:33:21.0800 1908 ProtectedStorage - ok 23:33:21.0857 1908 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys 23:33:21.0955 1908 PSched - ok 23:33:22.0252 1908 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 23:33:22.0581 1908 ql2300 - ok 23:33:22.0666 1908 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 23:33:22.0697 1908 ql40xx - ok 23:33:22.0777 1908 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll 23:33:22.0845 1908 QWAVE - ok 23:33:22.0866 1908 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 23:33:22.0943 1908 QWAVEdrv - ok 23:33:22.0979 1908 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 23:33:23.0079 1908 RasAcd - ok 23:33:23.0202 1908 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll 23:33:23.0326 1908 RasAuto - ok 23:33:23.0374 1908 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 23:33:23.0478 1908 Rasl2tp - ok 23:33:23.0562 1908 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll 23:33:23.0618 1908 RasMan - ok 23:33:23.0657 1908 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 23:33:23.0716 1908 RasPppoe - ok 23:33:23.0756 1908 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 23:33:23.0786 1908 RasSstp - ok 23:33:23.0831 1908 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 23:33:23.0919 1908 rdbss - ok 23:33:23.0965 1908 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 23:33:24.0090 1908 RDPCDD - ok 23:33:24.0208 1908 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 23:33:24.0297 1908 rdpdr - ok 23:33:24.0345 1908 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 23:33:24.0452 1908 RDPENCDD - ok 23:33:24.0551 1908 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 23:33:24.0683 1908 RDPWD - ok 23:33:24.0781 1908 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll 23:33:24.0888 1908 RemoteAccess - ok 23:33:24.0990 1908 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll 23:33:25.0032 1908 RemoteRegistry - ok 23:33:25.0086 1908 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe 23:33:25.0148 1908 RpcLocator - ok 23:33:25.0197 1908 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll 23:33:25.0257 1908 RpcSs - ok 23:33:25.0335 1908 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 23:33:25.0425 1908 rspndr - ok 23:33:25.0501 1908 [ 4A8393F03CB2F40E08126D83916C5633 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIV.sys 23:33:25.0539 1908 RTHDMIAzAudService - ok 23:33:25.0570 1908 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe 23:33:25.0599 1908 SamSs - ok 23:33:25.0635 1908 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 23:33:25.0714 1908 sbp2port - ok 23:33:25.0752 1908 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll 23:33:25.0833 1908 SCardSvr - ok 23:33:25.0873 1908 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll 23:33:25.0947 1908 Schedule - ok 23:33:26.0040 1908 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll 23:33:26.0097 1908 SCPolicySvc - ok 23:33:26.0153 1908 [ 126EA89BCC413EE45E3004FB0764888F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 23:33:26.0258 1908 sdbus - ok 23:33:26.0292 1908 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll 23:33:26.0384 1908 SDRSVC - ok 23:33:26.0435 1908 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 23:33:26.0586 1908 secdrv - ok 23:33:26.0665 1908 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll 23:33:26.0801 1908 seclogon - ok 23:33:26.0842 1908 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll 23:33:26.0930 1908 SENS - ok 23:33:26.0959 1908 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys 23:33:27.0082 1908 Serenum - ok 23:33:27.0146 1908 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys 23:33:27.0311 1908 Serial - ok 23:33:27.0356 1908 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys 23:33:27.0417 1908 sermouse - ok 23:33:27.0605 1908 [ 8C1F87F5FDD92229D1754B98F073913F ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe 23:33:27.0650 1908 ServiceLayer ( UnsignedFile.Multi.Generic ) - warning 23:33:27.0650 1908 ServiceLayer - detected UnsignedFile.Multi.Generic (1) 23:33:27.0735 1908 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll 23:33:27.0799 1908 SessionEnv - ok 23:33:27.0875 1908 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 23:33:27.0929 1908 sffdisk - ok 23:33:27.0957 1908 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 23:33:28.0015 1908 sffp_mmc - ok 23:33:28.0043 1908 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 23:33:28.0112 1908 sffp_sd - ok 23:33:28.0151 1908 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 23:33:28.0250 1908 sfloppy - ok 23:33:28.0420 1908 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll 23:33:28.0552 1908 SharedAccess - ok 23:33:28.0657 1908 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 23:33:28.0731 1908 ShellHWDetection - ok 23:33:28.0755 1908 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys 23:33:28.0771 1908 sisagp - ok 23:33:28.0820 1908 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 23:33:28.0836 1908 SiSRaid2 - ok 23:33:28.0855 1908 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 23:33:28.0878 1908 SiSRaid4 - ok 23:33:29.0007 1908 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 23:33:29.0053 1908 SkypeUpdate - ok 23:33:29.0502 1908 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe 23:33:29.0854 1908 slsvc - ok 23:33:29.0932 1908 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll 23:33:30.0009 1908 SLUINotify - ok 23:33:30.0071 1908 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys 23:33:30.0127 1908 Smb - ok 23:33:30.0199 1908 [ EB49860E776CE860DC3CFB9EDB1BA517 ] snapman C:\Windows\system32\DRIVERS\snapman.sys 23:33:30.0252 1908 snapman - ok 23:33:30.0311 1908 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 23:33:30.0384 1908 SNMPTRAP - ok 23:33:30.0452 1908 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys 23:33:30.0493 1908 spldr - ok 23:33:30.0587 1908 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe 23:33:30.0671 1908 Spooler - ok 23:33:30.0822 1908 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys 23:33:30.0888 1908 srv - ok 23:33:30.0958 1908 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 23:33:31.0009 1908 srv2 - ok 23:33:31.0080 1908 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 23:33:31.0152 1908 srvnet - ok 23:33:31.0246 1908 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 23:33:31.0339 1908 SSDPSRV - ok 23:33:31.0379 1908 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\Windows\system32\DRIVERS\ssmdrv.sys 23:33:31.0427 1908 ssmdrv - ok 23:33:31.0512 1908 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll 23:33:31.0587 1908 SstpSvc - ok 23:33:31.0709 1908 [ 359FEE084F1173FFFFD7F9CCBD43D47F ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys 23:33:31.0761 1908 ssudmdm - ok 23:33:31.0894 1908 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll 23:33:31.0958 1908 stisvc - ok 23:33:31.0998 1908 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 23:33:32.0026 1908 swenum - ok 23:33:32.0268 1908 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 23:33:32.0324 1908 SwitchBoard ( UnsignedFile.Multi.Generic ) - warning 23:33:32.0324 1908 SwitchBoard - detected UnsignedFile.Multi.Generic (1) 23:33:32.0436 1908 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll 23:33:32.0522 1908 swprv - ok 23:33:32.0552 1908 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 23:33:32.0610 1908 Symc8xx - ok 23:33:32.0645 1908 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 23:33:32.0674 1908 Sym_hi - ok 23:33:32.0707 1908 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 23:33:32.0736 1908 Sym_u3 - ok 23:33:32.0819 1908 [ AEE6E411A915F50101895BA8DC5C15D4 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 23:33:32.0861 1908 SynTP - ok 23:33:32.0998 1908 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll 23:33:33.0145 1908 SysMain - ok 23:33:33.0198 1908 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll 23:33:33.0255 1908 TabletInputService - ok 23:33:33.0333 1908 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll 23:33:33.0944 1908 TapiSrv - ok 23:33:34.0427 1908 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll 23:33:34.0562 1908 TBS - ok 23:33:34.0808 1908 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 23:33:37.0372 1908 Tcpip - ok 23:33:37.0700 1908 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 23:33:37.0788 1908 Tcpip6 - ok 23:33:37.0843 1908 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 23:33:37.0901 1908 tcpipreg - ok 23:33:37.0945 1908 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 23:33:38.0039 1908 TDPIPE - ok 23:33:38.0097 1908 [ 431801FCC97034E04A6EFF81136578D7 ] tdrpman273 C:\Windows\system32\DRIVERS\tdrpm273.sys 23:33:38.0130 1908 tdrpman273 - ok 23:33:38.0158 1908 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 23:33:38.0223 1908 TDTCP - ok 23:33:38.0282 1908 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 23:33:38.0398 1908 tdx - ok 23:33:38.0434 1908 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 23:33:38.0475 1908 TermDD - ok 23:33:38.0570 1908 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll 23:33:38.0734 1908 TermService - ok 23:33:38.0813 1908 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll 23:33:38.0872 1908 Themes - ok 23:33:38.0898 1908 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll 23:33:38.0955 1908 THREADORDER - ok 23:33:39.0028 1908 [ A34D7024BB7140EC785C86BC065D4F60 ] timounter C:\Windows\system32\DRIVERS\timntr.sys 23:33:39.0072 1908 timounter - ok 23:33:39.0132 1908 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll 23:33:39.0173 1908 TrkWks - ok 23:33:39.0291 1908 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 23:33:39.0415 1908 TrustedInstaller - ok 23:33:39.0463 1908 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 23:33:39.0564 1908 tssecsrv - ok 23:33:39.0590 1908 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 23:33:39.0638 1908 tunmp - ok 23:33:39.0661 1908 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 23:33:39.0703 1908 tunnel - ok 23:33:39.0732 1908 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys 23:33:39.0773 1908 uagp35 - ok 23:33:39.0805 1908 [ F763E070843EE2803DE1395002B42938 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys 23:33:39.0830 1908 UBHelper - ok 23:33:39.0903 1908 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 23:33:39.0968 1908 udfs - ok 23:33:40.0056 1908 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 23:33:40.0168 1908 UI0Detect - ok 23:33:40.0222 1908 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 23:33:40.0320 1908 uliagpkx - ok 23:33:40.0434 1908 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys 23:33:40.0515 1908 uliahci - ok 23:33:40.0557 1908 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys 23:33:40.0631 1908 UlSata - ok 23:33:40.0684 1908 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 23:33:40.0735 1908 ulsata2 - ok 23:33:40.0760 1908 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 23:33:40.0861 1908 umbus - ok 23:33:40.0909 1908 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll 23:33:41.0043 1908 upnphost - ok 23:33:41.0106 1908 [ EC01DA44B090D2651FC032C8B9257232 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 23:33:41.0231 1908 upperdev - ok 23:33:41.0285 1908 [ 83CAFCB53201BBAC04D822F32438E244 ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys 23:33:41.0371 1908 USBAAPL - ok 23:33:41.0408 1908 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 23:33:41.0480 1908 usbccgp - ok 23:33:41.0544 1908 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys 23:33:41.0642 1908 usbcir - ok 23:33:41.0699 1908 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 23:33:41.0815 1908 usbehci - ok 23:33:41.0878 1908 [ EDCA5124B54BCF04E5C0538AA397A9C1 ] usbfilter C:\Windows\system32\DRIVERS\usbfilter.sys 23:33:41.0916 1908 usbfilter - ok 23:33:41.0950 1908 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 23:33:42.0013 1908 usbhub - ok 23:33:42.0065 1908 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 23:33:42.0194 1908 usbohci - ok 23:33:42.0250 1908 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 23:33:42.0324 1908 usbprint - ok 23:33:42.0397 1908 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 23:33:42.0461 1908 usbscan - ok 23:33:42.0524 1908 [ 4ABD37CFBD710E64F01F9DA8710C73F7 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 23:33:42.0583 1908 UsbserFilt - ok 23:33:42.0605 1908 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 23:33:42.0636 1908 USBSTOR - ok 23:33:42.0676 1908 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 23:33:42.0741 1908 usbuhci - ok 23:33:42.0765 1908 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 23:33:42.0826 1908 usbvideo - ok 23:33:42.0865 1908 [ 35C9095FA7076466AFBFC5B9EC4B779E ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys 23:33:42.0949 1908 usb_rndisx - ok 23:33:42.0990 1908 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll 23:33:43.0053 1908 UxSms - ok 23:33:43.0125 1908 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe 23:33:43.0212 1908 vds - ok 23:33:43.0288 1908 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 23:33:43.0439 1908 vga - ok 23:33:43.0493 1908 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys 23:33:43.0617 1908 VgaSave - ok 23:33:43.0655 1908 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys 23:33:43.0704 1908 viaagp - ok 23:33:43.0765 1908 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys 23:33:43.0837 1908 ViaC7 - ok 23:33:43.0897 1908 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys 23:33:43.0926 1908 viaide - ok 23:33:44.0028 1908 [ 6E021D6DA429AD7288FE8322E2BBA96B ] VMCService C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe 23:33:44.0098 1908 VMCService ( UnsignedFile.Multi.Generic ) - warning 23:33:44.0099 1908 VMCService - detected UnsignedFile.Multi.Generic (1) 23:33:44.0132 1908 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys 23:33:44.0179 1908 volmgr - ok 23:33:44.0232 1908 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 23:33:44.0267 1908 volmgrx - ok 23:33:44.0322 1908 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys 23:33:44.0352 1908 volsnap - ok 23:33:44.0396 1908 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 23:33:44.0422 1908 vsmraid - ok 23:33:44.0614 1908 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe 23:33:44.0889 1908 VSS - ok 23:33:44.0979 1908 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll 23:33:45.0102 1908 W32Time - ok 23:33:45.0146 1908 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 23:33:45.0267 1908 WacomPen - ok 23:33:45.0290 1908 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 23:33:45.0363 1908 Wanarp - ok 23:33:45.0369 1908 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 23:33:45.0409 1908 Wanarpv6 - ok 23:33:45.0510 1908 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll 23:33:45.0589 1908 wcncsvc - ok 23:33:45.0636 1908 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 23:33:45.0692 1908 WcsPlugInService - ok 23:33:45.0748 1908 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys 23:33:45.0777 1908 Wd - ok 23:33:45.0865 1908 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 23:33:45.0931 1908 Wdf01000 - ok 23:33:45.0975 1908 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll 23:33:46.0097 1908 WdiServiceHost - ok 23:33:46.0123 1908 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll 23:33:46.0197 1908 WdiSystemHost - ok 23:33:46.0267 1908 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll 23:33:46.0337 1908 WebClient - ok 23:33:46.0433 1908 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll 23:33:46.0507 1908 Wecsvc - ok 23:33:46.0559 1908 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll 23:33:46.0612 1908 wercplsupport - ok 23:33:46.0660 1908 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll 23:33:46.0714 1908 WerSvc - ok 23:33:46.0816 1908 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 23:33:46.0839 1908 WinDefend - ok 23:33:46.0876 1908 WinHttpAutoProxySvc - ok 23:33:46.0938 1908 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 23:33:46.0968 1908 Winmgmt - ok 23:33:47.0095 1908 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll 23:33:47.0216 1908 WinRM - ok 23:33:47.0360 1908 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll 23:33:47.0493 1908 Wlansvc - ok 23:33:47.0786 1908 [ 5144AE67D60EC653F97DDF3FEED29E77 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 23:33:47.0991 1908 wlidsvc - ok 23:33:48.0056 1908 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 23:33:48.0168 1908 WmiAcpi - ok 23:33:48.0251 1908 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 23:33:48.0335 1908 wmiApSrv - ok 23:33:48.0483 1908 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 23:33:48.0619 1908 WMPNetworkSvc - ok 23:33:48.0694 1908 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll 23:33:48.0832 1908 WPCSvc - ok 23:33:48.0899 1908 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 23:33:48.0986 1908 WPDBusEnum - ok 23:33:49.0060 1908 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 23:33:49.0149 1908 WpdUsb - ok 23:33:49.0497 1908 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 23:33:49.0638 1908 WPFFontCache_v0400 - ok 23:33:49.0678 1908 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 23:33:49.0760 1908 ws2ifsl - ok 23:33:49.0803 1908 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll 23:33:49.0884 1908 wscsvc - ok 23:33:49.0901 1908 WSearch - ok 23:33:50.0126 1908 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll 23:33:50.0543 1908 wuauserv - ok 23:33:50.0633 1908 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 23:33:50.0701 1908 WudfPf - ok 23:33:50.0736 1908 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 23:33:50.0797 1908 WUDFRd - ok 23:33:50.0881 1908 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 23:33:50.0925 1908 wudfsvc - ok 23:33:50.0960 1908 [ 22A08B9FAECD6A306868F59B7F03F188 ] XAudio C:\Windows\system32\DRIVERS\XAudio32.sys 23:33:51.0005 1908 XAudio - ok 23:33:51.0047 1908 ================ Scan global =============================== 23:33:51.0161 1908 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll 23:33:51.0265 1908 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 23:33:51.0285 1908 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 23:33:51.0316 1908 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe 23:33:51.0323 1908 [Global] - ok 23:33:51.0323 1908 ================ Scan MBR ================================== 23:33:51.0337 1908 [ BEEDF9B7F43A72A91456F7131AFC11B2 ] \Device\Harddisk0\DR0 23:33:54.0394 1908 \Device\Harddisk0\DR0 - ok 23:33:54.0414 1908 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk2\DR2 23:33:54.0702 1908 \Device\Harddisk2\DR2 - ok 23:33:54.0713 1908 ================ Scan VBR ================================== 23:33:54.0741 1908 [ 99FE4A73127FA1D0AFF5A97EDBF547C4 ] \Device\Harddisk0\DR0\Partition1 23:33:54.0787 1908 \Device\Harddisk0\DR0\Partition1 - ok 23:33:54.0804 1908 [ 687AD03AEA27D313CB5015F18451437D ] \Device\Harddisk2\DR2\Partition1 23:33:54.0815 1908 \Device\Harddisk2\DR2\Partition1 - ok 23:33:54.0819 1908 ============================================================ 23:33:54.0819 1908 Scan finished 23:33:54.0820 1908 ============================================================ 23:33:54.0882 5752 Detected object count: 12 23:33:54.0883 5752 Actual detected object count: 12 23:35:06.0914 5752 Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0915 5752 Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0916 5752 AdobeVersionCue ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0916 5752 AdobeVersionCue ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0916 5752 Akamai ( HiddenFile.Multi.Generic ) - skipped by user 23:35:06.0916 5752 Akamai ( HiddenFile.Multi.Generic ) - User select action: Skip 23:35:06.0922 5752 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0922 5752 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0922 5752 hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0922 5752 hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0932 5752 hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0932 5752 hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0933 5752 HPSLPSVC ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0934 5752 HPSLPSVC ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0940 5752 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0940 5752 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0948 5752 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0949 5752 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0949 5752 ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0949 5752 ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0952 5752 SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0953 5752 SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:35:06.0955 5752 VMCService ( UnsignedFile.Multi.Generic ) - skipped by user 23:35:06.0955 5752 VMCService ( UnsignedFile.Multi.Generic ) - User select action: Skip Du, Cosinus, ich hab noch mal 'ne Frage: Ich hab ja das Windows Vista Home auf'm Rechner. Ich hab immer schon mit dem Gedanken gespielt da ein Update auf Windows 7 oder auch 8 zu machen. Ich trau mich das bloß nicht, weil ich echt Schiß hab, dass dann alle Programme weg sind, bzw. auch dann nicht mehr mit dem neuen Windows kompatibel sind und ich alles komplett neu installieren muss. Gibt's da irgendwie eine Hintertür, das man das nicht tun muss? Rechner ist ein Laptop Acer Aspire 7535G, Vista war vorinstalliert. |
18.01.2013, 12:39 | #12 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malwarebytes bricht ständig ab Schonmal was von Backup vorher gehört?! Bevor man so einen riesigen Eingriff wie ein Update von Vista auf 7 oder 8 macht, versteht sich das Ganze von selbst! Ich halte aber eher nichts von diesen Updaterei. Ich würde immer eine komplette Neuinstallation bevorzugen wenn ich zB von Vista auf 7 oder 8 umsatteln muss. Ist die sauberste Lösung. Die nächsten nicht mehr für Bereinigung relevanten Fragen bitte später stellen! Ich mag es nicht wenn man hier ins offtopic schlittert und dadurch aus der Analyse gerissen wird. Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten Geändert von cosinus (18.01.2013 um 13:12 Uhr) Grund: typo |
18.01.2013, 12:49 | #13 |
| Malwarebytes bricht ständig ab Cosinus, entschuldige bitte, war nicht böse gemeint. Ja Backup mache ich regelmäßig. Ich mach mich jetzt ans Combofix Werk. Danke nochmal für deine geduldige Hilfe! Kirstin Combofix: Code:
ATTFilter ComboFix 13-01-17.04 - Kirstin 19.01.2013 9:57.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2429.1290 [GMT 1:00] ausgeführt von:: c:\users\Kirstin\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ADS - Windows: deleted 72 bytes in 1 streams. . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\BrowserCompanion c:\programdata\SPLE24A.tmp c:\users\Kirstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\BackupManager.list c:\users\Kirstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\eportoZip c:\users\Kirstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\pplCsv.txt c:\users\Kirstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\smartUpdate.txt c:\users\Kirstin\AppData\Local\Microsoft\Windows\Temporary Internet Files\tempCsv.txt c:\users\Kirstin\AppData\Roaming\.# c:\users\Kirstin\AppData\Roaming\.#\BackupManager.list c:\users\Kirstin\Favorites\BackupManager.list c:\users\Kirstin\GoToAssistDownloadHelper.exe c:\users\Public\Favorites\BackupManager.list c:\windows\system32\AutoRun.inf c:\windows\system32\muzapp.exe c:\windows\system32\System32\MASetupCleaner.exe c:\windows\system32\System32\muzapp.exe . . ((((((((((((((((((((((( Dateien erstellt von 2012-12-19 bis 2013-01-19 )))))))))))))))))))))))))))))) . . 2013-01-19 09:20 . 2013-01-19 09:20 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-01-19 00:55 . 2013-01-19 00:55 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6C87C1D0-E101-4DF3-B00E-9D311DABAD07}\offreg.dll 2013-01-18 06:49 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6C87C1D0-E101-4DF3-B00E-9D311DABAD07}\mpengine.dll 2013-01-17 13:45 . 2013-01-17 13:45 110080 ----a-r- c:\users\Kirstin\AppData\Roaming\Microsoft\Installer\{DDABC667-56B3-4122-82B0-2F5782EA2F9A}\IconF7A21AF7.exe 2013-01-17 13:45 . 2013-01-17 13:45 110080 ----a-r- c:\users\Kirstin\AppData\Roaming\Microsoft\Installer\{DDABC667-56B3-4122-82B0-2F5782EA2F9A}\IconD7F16134.exe 2013-01-17 13:45 . 2013-01-17 13:45 110080 ----a-r- c:\users\Kirstin\AppData\Roaming\Microsoft\Installer\{DDABC667-56B3-4122-82B0-2F5782EA2F9A}\IconCF33A0CE.exe 2013-01-17 13:45 . 2013-01-17 13:46 -------- d-----w- C:\sh4ldr 2013-01-17 13:45 . 2013-01-17 13:45 -------- d-----w- c:\program files\Enigma Software Group 2013-01-17 13:43 . 2013-01-17 13:45 -------- d-----w- c:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP 2013-01-14 08:07 . 2013-01-14 08:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2013-01-14 08:07 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-01-13 21:18 . 2013-01-13 21:18 -------- d-----w- c:\users\Kirstin\AppData\Roaming\Malwarebytes 2013-01-13 21:18 . 2013-01-13 21:18 -------- d-----w- c:\programdata\Malwarebytes 2013-01-09 09:33 . 2012-11-23 01:35 2048000 ----a-w- c:\windows\system32\win32k.sys 2013-01-09 09:32 . 2012-11-20 04:22 204288 ----a-w- c:\windows\system32\ncrypt.dll 2013-01-09 09:22 . 2012-11-02 10:19 1400832 ----a-w- c:\windows\system32\msxml6.dll 2013-01-07 21:44 . 2013-01-07 21:44 -------- d-----w- c:\users\Kirstin\AppData\Roaming\HPAppData 2012-12-22 02:01 . 2012-12-16 13:12 34304 ----a-w- c:\windows\system32\atmlib.dll 2012-12-22 02:01 . 2012-12-16 10:50 293376 ----a-w- c:\windows\system32\atmfd.dll 2012-12-21 12:31 . 2012-11-28 09:35 93640 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-12-20 09:56 . 2012-12-20 09:56 -------- d-----w- C:\Languages 2012-12-20 09:56 . 2012-12-20 09:56 -------- d-----w- C:\Help . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-09 09:06 . 2012-05-18 05:58 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-01-09 09:06 . 2011-05-24 06:11 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-12-12 06:03 . 2012-11-07 07:13 134336 ----a-w- c:\windows\system32\drivers\avipbb.sys 2012-12-12 06:03 . 2012-11-07 07:13 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2012-12-05 20:11 . 2012-12-05 20:11 49280 ----a-w- c:\windows\system32\FKStampPainter20.dll 2012-12-04 09:57 . 2012-12-04 09:57 4939904 ----a-w- c:\windows\system32\LxXtreme110.dll 2012-12-04 09:57 . 2012-12-04 09:57 104064 ----a-w- c:\windows\system32\LxUISettingsN100.dll 2012-12-04 09:57 . 2012-12-04 09:57 25728 ----a-w- c:\windows\system32\LxTPSW100.dll 2012-12-04 09:56 . 2012-12-04 09:56 1360512 ----a-w- c:\windows\system32\LxTool110.dll 2012-12-04 09:56 . 2012-12-04 09:56 63104 ----a-w- c:\windows\system32\LxPXTree100.dll 2012-12-04 09:56 . 2012-12-04 09:56 127104 ----a-w- c:\windows\system32\LxMail100.dll 2012-12-04 09:56 . 2012-12-04 09:56 49280 ----a-w- c:\windows\system32\LXCurr100.dll 2012-12-04 09:56 . 2012-12-04 09:56 67712 ----a-w- c:\windows\system32\LxCI12.dll 2012-12-04 09:56 . 2012-12-04 09:56 206976 ----a-w- c:\windows\system32\LxBasics100.dll 2012-11-14 02:09 . 2012-12-14 02:43 1800704 ----a-w- c:\windows\system32\jscript9.dll 2012-11-14 01:58 . 2012-12-14 02:43 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 01:57 . 2012-12-14 02:43 1129472 ----a-w- c:\windows\system32\wininet.dll 2012-11-14 01:49 . 2012-12-14 02:43 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 01:48 . 2012-12-14 02:43 420864 ----a-w- c:\windows\system32\vbscript.dll 2012-11-14 01:44 . 2012-12-14 02:43 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2012-11-13 14:12 . 2012-11-07 07:13 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2012-11-13 01:29 . 2012-12-13 04:41 2048 ----a-w- c:\windows\system32\tzres.dll 2012-11-02 10:18 . 2012-12-13 04:42 376320 ----a-w- c:\windows\system32\dpnet.dll 2012-11-02 08:26 . 2012-12-13 04:42 23040 ----a-w- c:\windows\system32\dpnsvr.exe 2013-01-18 20:40 . 2013-01-18 20:40 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2010-08-12 12:26 . 2013-01-18 20:40 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-12-20 1521952] "{937f343c-c9c2-4235-b544-7fc4da2f2594}"= "c:\program files\Suche_Deutschland\prxtbSuc0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_CLASSES_ROOT\clsid\{937f343c-c9c2-4235-b544-7fc4da2f2594}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{937f343c-c9c2-4235-b544-7fc4da2f2594}] 2011-05-09 09:49 176936 ----a-w- c:\program files\Suche_Deutschland\prxtbSuc0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{937f343c-c9c2-4235-b544-7fc4da2f2594}"= "c:\program files\Suche_Deutschland\prxtbSuc0.dll" [2011-05-09 176936] "{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}"= "c:\program files\ChatZum Toolbar\tbunsa4DD3.tmp\tbcore3.dll" [2012-08-29 2665984] . [HKEY_CLASSES_ROOT\clsid\{937f343c-c9c2-4235-b544-7fc4da2f2594}] . [HKEY_CLASSES_ROOT\clsid\{37d48d9c-3f7e-412f-b5bf-611be7ccfca1}] [HKEY_CLASSES_ROOT\TBSB09850.TBSB09850.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB09850.TBSB09850] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{937F343C-C9C2-4235-B544-7FC4DA2F2594}"= "c:\program files\Suche_Deutschland\prxtbSuc0.dll" [2011-05-09 176936] "{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}"= "c:\program files\ChatZum Toolbar\tbunsa4DD3.tmp\tbcore3.dll" [2012-08-29 2665984] . [HKEY_CLASSES_ROOT\clsid\{937f343c-c9c2-4235-b544-7fc4da2f2594}] . [HKEY_CLASSES_ROOT\clsid\{37d48d9c-3f7e-412f-b5bf-611be7ccfca1}] [HKEY_CLASSES_ROOT\TBSB09850.TBSB09850.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB09850.TBSB09850] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Kirstin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Kirstin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\Kirstin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-10-27 10:05 40496 ------w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2012-09-20 6377120] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Akamai NetSession Interface"="c:\users\Kirstin\AppData\Local\Akamai\netsession_win.exe" [2012-10-09 4441920] "Optimizer Pro"="c:\program files\Optimizer Pro\OptProLauncher.exe" [2012-06-10 79664] "RegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2012-07-08 68000] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "KiesAirMessage"="c:\program files\Samsung\Kies\KiesAirMessage.exe" [2012-12-18 578560] "KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2012-12-20 1476104] "D490D4BEFDEAEF6310F5FBDFAEDB8D5359769B10._service_run"="c:\program files\Google\Chrome\Application\chrome.exe" [2013-01-08 1248360] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AmIcoSinglun"="c:\program files\AmIcoSingLun\AmIcoSinglun.exe" [2008-10-24 237568] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-11 6957600] "PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-05 1410344] "LManager"="c:\program files\Launch Manager\LManager.exe" [2009-02-24 870920] "BackupManagerTray"="c:\program files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2009-03-20 249600] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-04-03 698912] "mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2008-10-27 346672] "ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2009-01-20 156968] "CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2009-01-20 202024] "PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-12-26 173288] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-12 30192] "MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-07-04 2072576] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-09-22 5587832] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-12-06 391240] "ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424] "SAOB Monitor"="c:\program files\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe" [2011-09-22 2571032] "KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-12-20 1574176] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-12-12 384800] "LexwareInfoService"="c:\program files\Common Files\Lexware\Update Manager\LxUpdateManager.exe" [2011-07-31 189808] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] . c:\users\Kirstin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ BackupManager.list [2009-12-17 556] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . S2 afcdpsrv;Acronis Nonstop Backup-Dienst;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [x] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HsfXAudioService REG_MULTI_SZ HsfXAudioService HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HPService REG_MULTI_SZ HPSLPSVC LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache Akamai REG_MULTI_SZ Akamai . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-01-13 15:32 1606760 ----a-w- c:\program files\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe . Inhalt des "geplante Tasks" Ordners . 2013-01-19 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-18 09:06] . 2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-14 19:54] . 2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-14 19:54] . 2013-01-18 c:\windows\Tasks\RegistryBooster.job - c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2012-04-27 12:39] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = https://www.google.de/ mStart Page = hxxp://search.chatzum.com/ uInternet Settings,ProxyOverride = <local> uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 192.168.1.1 DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://www.lidl-fotos.de/ips-opdata/layout/lidl02/objects/jordan.cab FF - ProfilePath - c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2303923&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&locale=de_DE&apn_uid=c499b9f8-8ea2-43a8-b166-8e5718f8f42b&apn_ptnrs=^AGS&apn_sauid=B51F3D41-F8DA-4BC7-A3B0-29FCBD8F8293&apn_dtid=^YYYYYY^YY^DE&&q= FF - prefs.js: network.proxy.type - 2 FF - ExtSQL: 2012-11-25 21:58; firebug@software.joehewitt.com; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\firebug@software.joehewitt.com.xpi FF - ExtSQL: 2012-11-25 22:07; browserlab@adobe.com; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\browserlab@adobe.com FF - ExtSQL: 2012-11-25 22:07; DrupalForFirebug@drupal.org; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\DrupalForFirebug@drupal.org.xpi FF - ExtSQL: 2012-11-25 22:07; firebug@tools.sitepoint.com; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\firebug@tools.sitepoint.com.xpi FF - ExtSQL: 2012-11-25 22:07; firebugpaintevents@kylescholz.com; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\firebugpaintevents@kylescholz.com.xpi FF - ExtSQL: 2012-11-25 22:07; firefinder@robertnyman.com; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\firefinder@robertnyman.com.xpi FF - ExtSQL: 2012-11-25 22:07; icffirebug@robertnyman.com; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\icffirebug@robertnyman.com.xpi FF - ExtSQL: 2012-11-25 22:07; {9aad3da6-6c46-4ef0-9109-6df5eaaf597c}; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\{9aad3da6-6c46-4ef0-9109-6df5eaaf597c}.xpi FF - ExtSQL: 2012-12-21 13:16; {E6C1199F-E687-42da-8C24-E7770CC3AE66}; c:\users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi FF - ExtSQL: !HIDDEN! 2010-01-13 15:40; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - user.js: browser.search.selectedEngine - foxsearch FF - user.js: browser.search.order.1 - foxsearch FF - user.js: browser.search.defaultenginename - foxsearch FF - user.js: keyword.URL - hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q= FF - user.js: privacy.item.cookies - false FF - user.js: privacy.sanitize.promptOnSanitize - false FF - user.js: extentions.y2layers.installId - 39c5220d-e4f0-4f86-921f-f7916ca5d3c0 FF - user.js: extentions.y2layers.defaultEnableAppsList - BestVideoDownloader,BestVideoDownloader, FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: security.csp.enable - false FF - user.js: extensions.funmoods.hmpg - true FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=sware&chnl=sware&cd=2XzuyEtN2Y1L1QzutDtDtC0FtCyCzyzz0ByBtD0EtC0E0FyBtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1891229338 FF - user.js: extensions.funmoods.dfltSrch - true FF - user.js: extensions.funmoods.srchPrvdr - Search FF - user.js: extensions.funmoods.dnsErr - true FF - user.js: extensions.funmoods_i.newTab - true FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=sware&chnl=sware&cd=2XzuyEtN2Y1L1QzutDtDtC0FtCyCzyzz0ByBtD0EtC0E0FyBtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1891229338 FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://start.funmoods.com/?f=3&a=sware&chnl=sware&cd=2XzuyEtN2Y1L1QzutDtDtC0FtCyCzyzz0ByBtD0EtC0E0FyBtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1891229338&q= FF - user.js: extensions.funmoods.id - 001F1698B70E1EF7 FF - user.js: extensions.funmoods.instlDay - 15580 FF - user.js: extensions.funmoods.vrsn - 1.5.23.22 FF - user.js: extensions.funmoods.vrsni - 1.5.23.22 FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2223:24 FF - user.js: extensions.funmoods.prtnrId - funmoods FF - user.js: extensions.funmoods.prdct - funmoods FF - user.js: extensions.funmoods.aflt - sware FF - user.js: extensions.funmoods_i.smplGrp - none FF - user.js: extensions.funmoods.tlbrId - base FF - user.js: extensions.funmoods.instlRef - sware FF - user.js: extensions.funmoods.dfltLng - FF - user.js: extensions.funmoods.excTlbr - false FF - user.js: extensions.funmoods.autoRvrt - false FF - user.js: extensions.funmoods.envrmnt - production FF - user.js: extensions.funmoods.isdcmntcmplt - true FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . SafeBoot-WudfPf SafeBoot-WudfRd HKLM_ActiveSetup-{5CCF8330-F742-411A-8A04-719806D168B5} - msiexec AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2013-01-19 10:20 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai] "ServiceDll"="c:\program files\common files\akamai/netsession_win_ce5ba24.dll" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2900932004-3961150359-2209842598-1000\Software\AppDataLow\Software\Conduit\Community Alerts\Settings\Locales\e*n**PB8›*4] @Allowed: (Read) (RestrictedCode) @SACL=(02 0001) "LP_LastUpdateTime"="0" "LP_LastCheckTime"=dword:4f50013f . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'Explorer.exe'(1680) c:\program files\SlySoft\AnyDVD\ADvdDiscHlp.dll c:\users\Kirstin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll c:\program files\EgisTec\MyWinLocker 3\x86\mwlUI.dll c:\program files\EgisTec\MyWinLocker 3\x86\GDIExtendCtrl.dll c:\program files\EgisTec\MyWinLocker 3\x86\mwlOP.dll c:\program files\EgisTec\MyWinLocker 3\x86\CryptoAPI.dll c:\program files\EgisTec\MyWinLocker 3\x86\ShowErrMsg.dll c:\program files\Acer\Acer ePower Management\SysHook.dll . Zeit der Fertigstellung: 2013-01-19 10:25:37 ComboFix-quarantined-files.txt 2013-01-19 09:25 . Vor Suchlauf: 19 Verzeichnis(se), 221.460.393.984 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 223.471.558.656 Bytes frei . - - End Of File - - 2C5B5112DE237C6DD51756B1A27F71BF |
20.01.2013, 18:47 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Malwarebytes bricht ständig ab adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren Downloade Dir bitte AdwCleaner auf deinen Desktop. Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
__________________ Logfiles bitte immer in CODE-Tags posten |
20.01.2013, 19:20 | #15 |
| Malwarebytes bricht ständig ab AdwCleaner: Code:
ATTFilter # AdwCleaner v2.106 - Datei am 20/01/2013 um 19:17:46 erstellt # Aktualisiert am 17/01/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : Kirstin - KIRSTINS-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Kirstin\Desktop\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gefunden : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml Datei Gefunden : C:\user.js Datei Gefunden : C:\Users\Kirstin\AppData\Local\funmoods-speeddial.crx Datei Gefunden : C:\Users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\searchplugins\Askcom.xml Datei Gefunden : C:\Windows\system32\conduitEngine.tmp Ordner Gefunden : C:\Program Files\Ask.com Ordner Gefunden : C:\Program Files\BabylonToolbar Ordner Gefunden : C:\Program Files\ChatZum Toolbar Ordner Gefunden : C:\Program Files\Conduit Ordner Gefunden : C:\Program Files\Mozilla Firefox\Extensions\ffxtlbr@babylon.com Ordner Gefunden : C:\Program Files\Suche_Deutschland Ordner Gefunden : C:\Program Files\Yontoo Ordner Gefunden : C:\ProgramData\Babylon Ordner Gefunden : C:\ProgramData\Tarma Installer Ordner Gefunden : C:\Users\Kirstin\AppData\Local\APN Ordner Gefunden : C:\Users\Kirstin\AppData\Local\AskToolbar Ordner Gefunden : C:\Users\Kirstin\AppData\Local\Conduit Ordner Gefunden : C:\Users\Kirstin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Ordner Gefunden : C:\Users\Kirstin\AppData\LocalLow\AskToolbar Ordner Gefunden : C:\Users\Kirstin\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\Kirstin\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\Kirstin\AppData\LocalLow\Suche_Deutschland Ordner Gefunden : C:\Users\Kirstin\AppData\LocalLow\Toolbar4 Ordner Gefunden : C:\Users\Kirstin\AppData\Roaming\Babylon Ordner Gefunden : C:\Users\Kirstin\AppData\Roaming\BabylonToolbar Ordner Gefunden : C:\Users\Kirstin\AppData\Roaming\iWin Ordner Gefunden : C:\Users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\bbrs_002@blabbers.com Ordner Gefunden : C:\Users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\extensions\toolbar@ask.com Ordner Gefunden : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKCU\Software\APN Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Suche_Deutschland Schlüssel Gefunden : HKCU\Software\AppDataLow\Toolbar Schlüssel Gefunden : HKCU\Software\Ask.com Schlüssel Gefunden : HKCU\Software\AskToolbar Schlüssel Gefunden : HKCU\Software\BabylonToolbar Schlüssel Gefunden : HKCU\Software\Blabbers Schlüssel Gefunden : HKCU\Software\BrowserCompanion Schlüssel Gefunden : HKCU\Software\ChatZum Toolbar Schlüssel Gefunden : HKCU\Software\Conduit Schlüssel Gefunden : HKCU\Software\Microsoft\Babylon Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83AA2913-C123-4146-85BD-AD8F93971D39} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrowserCompanion Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ChatZum Toolbar Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Suche_Deutschland Toolbar Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{937F343C-C9C2-4235-B544-7FC4DA2F2594} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4EB4BD89-4701-4106-A78C-3C01E8CD02D1} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{937F343C-C9C2-4235-B544-7FC4DA2F2594} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gefunden : HKCU\Software\Optimizer Pro Schlüssel Gefunden : HKCU\Software\Softonic Schlüssel Gefunden : HKLM\Software\APN Schlüssel Gefunden : HKLM\Software\AskToolbar Schlüssel Gefunden : HKLM\Software\Babylon Schlüssel Gefunden : HKLM\Software\BabylonToolbar Schlüssel Gefunden : HKLM\Software\BrowserCompanion Schlüssel Gefunden : HKLM\Software\ChatZum Toolbar Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Schlüssel Gefunden : HKLM\SOFTWARE\Classes\b Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Babylon.dskBnd Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\bbylnApp.appCore Schlüssel Gefunden : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{4EB4BD89-4701-4106-A78C-3C01E8CD02D1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{937F343C-C9C2-4235-B544-7FC4DA2F2594} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gefunden : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc Schlüssel Gefunden : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1 Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\3192AA38321C641458DBDAF83979D193 Schlüssel Gefunden : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\3192AA38321C641458DBDAF83979D193 Schlüssel Gefunden : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbRequest Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbTask Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2303923 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Schlüssel Gefunden : HKLM\Software\Conduit Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\bodddioamolcibagionmmobehnbhiakf Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8CE2C24C-CBA8-4424-8120-7771EF7DC92A} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C6909F59-197A-4762-B1E0-C6AC3EA44824} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{937F343C-C9C2-4235-B544-7FC4DA2F2594} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4EB4BD89-4701-4106-A78C-3C01E8CD02D1} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DA5BD2D3CA2D6943A1A233CD3F88CE7 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC9EFC5C3366B4DB850DAB49330C52 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E98451C7CA808F47AFE467BDABD02FA Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFD11FD45FC7B9E46A8F4B69F3A66E35 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5979AD63CA2D6943A1A233CD3F88CE7 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF9BD2952384A9C49B4A5D3D95329890 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FABA2A33488410A4AA40489BD2224282 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193 Schlüssel Gefunden : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83AA2913-C123-4146-85BD-AD8F93971D39} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChatZum Toolbar Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Suche_Deutschland Toolbar Schlüssel Gefunden : HKLM\Software\Suche_Deutschland Schlüssel Gefunden : HKU\S-1-5-21-2900932004-3961150359-2209842598-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gefunden : HKU\S-1-5-21-2900932004-3961150359-2209842598-1000\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} Schlüssel Gefunden : HKU\S-1-5-21-2900932004-3961150359-2209842598-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{937F343C-C9C2-4235-B544-7FC4DA2F2594}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}] Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{937F343C-C9C2-4235-B544-7FC4DA2F2594}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{937F343C-C9C2-4235-B544-7FC4DA2F2594}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{937F343C-C9C2-4235-B544-7FC4DA2F2594}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16457 [HKCU\Software\Microsoft\Internet Explorer\Main - Backup.Old.Start Page] = hxxp://search.babylon.com/?affID=112843&babsrc=HP_ss&mntrId=5ed31ef70000000000000017c47d807f [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.chatzum.com/ -\\ Mozilla Firefox v18.0.1 (de) Datei : C:\Users\Kirstin\AppData\Roaming\Mozilla\Firefox\Profiles\emn4ri5p.default\prefs.js Gefunden : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Gefunden : user_pref("browser.newtab.url", "search.chatzum.com"); Gefunden : user_pref("browser.search.defaultengine", "Ask.com"); Gefunden : user_pref("browser.search.defaultthis.engineName", "Suche Deutschland Customized Web Search"); Gefunden : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2303923&Sea[...] Gefunden : user_pref("extensions.BabylonToolbar.admin", false); Gefunden : user_pref("extensions.BabylonToolbar.aflt", "orgnl"); Gefunden : user_pref("extensions.BabylonToolbar.bbDpng", 18); Gefunden : user_pref("extensions.BabylonToolbar.dfltLng", "de"); Gefunden : user_pref("extensions.BabylonToolbar.dfltSrch", false); Gefunden : user_pref("extensions.BabylonToolbar.hmpg", false); Gefunden : user_pref("extensions.BabylonToolbar.lastDP", 18); Gefunden : user_pref("extensions.BabylonToolbar.lastVrsnTs", ""); Gefunden : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "13.0"); Gefunden : user_pref("extensions.BabylonToolbar.newTab", true); Gefunden : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?affID=112843&babsrc=NT_[...] Gefunden : user_pref("extensions.BabylonToolbar.noFFXTlbr", false); Gefunden : user_pref("extensions.BabylonToolbar.propectorlck", 81160409); Gefunden : user_pref("extensions.BabylonToolbar.prtkDS", 1); Gefunden : user_pref("extensions.BabylonToolbar.smplGrp", "free"); Gefunden : user_pref("extensions.BabylonToolbar_i.newTab", true); Gefunden : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=112843&babsrc=N[...] Gefunden : user_pref("extensions.asktb.FeaturePageVersion", "1"); Gefunden : user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\"); Gefunden : user_pref("extensions.asktb.OOBEVersion", "1"); Gefunden : user_pref("extensions.asktb.apn_dbr", "ff_16.0.2"); Gefunden : user_pref("extensions.asktb.autofill-text-highlight-enabled", true); Gefunden : user_pref("extensions.asktb.cbid", "^AGS"); Gefunden : user_pref("extensions.asktb.config-updated", false); Gefunden : user_pref("extensions.asktb.cr-o", "APN10261"); Gefunden : user_pref("extensions.asktb.crumb", "2012.11.06+23.12.45-toolbar009iad-DE-SGFtYnVyZyxHZXJtYW55"); Gefunden : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://avira-int.ask.com/web?q={query}&qsrc=[...] Gefunden : user_pref("extensions.asktb.domain", "avira-int.ask.com"); Gefunden : user_pref("extensions.asktb.domainName", "avira-int.ask.com"); Gefunden : user_pref("extensions.asktb.dtid", "^YYYYYY^YY^DE"); Gefunden : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.finduny.com?client=mozilla-firefox[...] Gefunden : user_pref("extensions.asktb.first-launch-url", "hxxp://redirect.avira.com/?operationtype=install&lng[...] Gefunden : user_pref("extensions.asktb.fresh-install", false); Gefunden : user_pref("extensions.asktb.guid", "c499b9f8-8ea2-43a8-b166-8e5718f8f42b"); Gefunden : user_pref("extensions.asktb.hpr", "YES"); Gefunden : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...] Gefunden : user_pref("extensions.asktb.if", "first"); Gefunden : user_pref("extensions.asktb.l", "dis"); Gefunden : user_pref("extensions.asktb.last-config-req", "1358670022551"); Gefunden : user_pref("extensions.asktb.last-search-timestamp", "1353970746319"); Gefunden : user_pref("extensions.asktb.locale", "de_DE"); Gefunden : user_pref("extensions.asktb.localePref", true); Gefunden : user_pref("extensions.asktb.location", "Hamburg,Germany"); Gefunden : user_pref("extensions.asktb.nthp", "YES"); Gefunden : user_pref("extensions.asktb.nthp_prev", "1"); Gefunden : user_pref("extensions.asktb.o", "APN10261"); Gefunden : user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Gefunden : user_pref("extensions.asktb.qsrc", "2871"); Gefunden : user_pref("extensions.asktb.r", "5"); Gefunden : user_pref("extensions.asktb.sa", "YES"); Gefunden : user_pref("extensions.asktb.saguid", "B51F3D41-F8DA-4BC7-A3B0-29FCBD8F8293"); Gefunden : user_pref("extensions.asktb.search-history-queries", "horsemanshipschule||info@stapeline.com||info@p[...] Gefunden : user_pref("extensions.asktb.search-suggestions-enabled", true); Gefunden : user_pref("extensions.asktb.silent-upgrade", true); Gefunden : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); Gefunden : user_pref("extensions.asktb.socialmini-first", true); Gefunden : user_pref("extensions.asktb.socialmini-interval", "1200000"); Gefunden : user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); Gefunden : user_pref("extensions.asktb.socialmini-max-items", "30"); Gefunden : user_pref("extensions.asktb.socialmini-native-on", true); Gefunden : user_pref("extensions.asktb.socialmini-speed", "5000"); Gefunden : user_pref("extensions.asktb.themeid", ""); Gefunden : user_pref("extensions.asktb.timeinstalled", "07.11.2012 08:15:02"); Gefunden : user_pref("extensions.asktb.to", ""); Gefunden : user_pref("extensions.asktb.v", "3.15.13.100015"); Gefunden : user_pref("extensions.asktb.version", "5.15.13.33021"); Gefunden : user_pref("extensions.enabledAddons", "adblockpopups%40jessehakanen.net:0.5,browserlab%40adobe.com:1[...] Gefunden : user_pref("extensions.funmoods.aflt", "sware"); Gefunden : user_pref("extensions.funmoods.autoRvrt", false); Gefunden : user_pref("extensions.funmoods.cntry", "DE"); Gefunden : user_pref("extensions.funmoods.cv", "cv5"); Gefunden : user_pref("extensions.funmoods.dfltLng", ""); Gefunden : user_pref("extensions.funmoods.dfltSrch", true); Gefunden : user_pref("extensions.funmoods.dnsErr", true); Gefunden : user_pref("extensions.funmoods.envrmnt", "production"); Gefunden : user_pref("extensions.funmoods.excTlbr", false); Gefunden : user_pref("extensions.funmoods.hdrMd5", "AF77880F1E50D17D9E790BD397E75F81"); Gefunden : user_pref("extensions.funmoods.hmpg", true); Gefunden : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=sware&chnl=sware&cd=2Xzuy[...] Gefunden : user_pref("extensions.funmoods.id", "001F1698B70E1EF7"); Gefunden : user_pref("extensions.funmoods.instlDay", "15580"); Gefunden : user_pref("extensions.funmoods.instlRef", "sware"); Gefunden : user_pref("extensions.funmoods.isdcmntcmplt", true); Gefunden : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2223:24:55"); Gefunden : user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); Gefunden : user_pref("extensions.funmoods.newTab", true); Gefunden : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=sware&chnl=sware&cd=2Xz[...] Gefunden : user_pref("extensions.funmoods.prdct", "funmoods"); Gefunden : user_pref("extensions.funmoods.prtnrId", "funmoods"); Gefunden : user_pref("extensions.funmoods.sg", "none"); Gefunden : user_pref("extensions.funmoods.smplGrp", "none"); Gefunden : user_pref("extensions.funmoods.srchPrvdr", "Search"); Gefunden : user_pref("extensions.funmoods.tlbrId", "base"); Gefunden : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/?f=3&a=sware&chnl=sware&cd=2[...] Gefunden : user_pref("extensions.funmoods.vrsn", "1.5.23.22"); Gefunden : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2223:24:55"); Gefunden : user_pref("extensions.funmoods.vrsni", "1.5.23.22"); Gefunden : user_pref("extensions.funmoods_i.newTab", true); Gefunden : user_pref("extensions.funmoods_i.smplGrp", "none"); Gefunden : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2223:24:55"); Gefunden : user_pref("extensions.toolbar@ask.com.install-event-fired", true); Gefunden : user_pref("id_chatzum_installed_version", "1.0.17"); Gefunden : user_pref("id_chatzum_tabpage", "hxxp%3A//searchsafer.com/"); Gefunden : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-4&o=APN10261&loc[...] -\\ Google Chrome v24.0.1312.52 Datei : C:\Users\Kirstin\AppData\Local\Google\Chrome\User Data\Default\Preferences Gefunden [l.8] : homepage = "hxxp://start.funmoods.com/?f=1&a=sware&chnl=sware&cd=2XzuyEtN2Y1L1QzutDtDtC0FtCyCzyzz0ByBtD0EtC0E0FyBtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1891229338", Gefunden [l.12] : urls_to_restore_on_startup = [ "hxxp://search.chatzum.com" ] Gefunden [l.1835] : homepage = "hxxp://start.funmoods.com/?f=1&a=sware&chnl=sware&cd=2XzuyEtN2Y1L1QzutDtDtC0FtCyCzyzz0ByBtD0EtC0E0FyBtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1891229338", Gefunden [l.2258] : urls_to_restore_on_startup = [ "hxxp://search.chatzum.com" ] ************************* AdwCleaner[R1].txt - [35456 octets] - [20/01/2013 19:17:46] ########## EOF - C:\AdwCleaner[R1].txt - [35517 octets] ########## |
Themen zu Malwarebytes bricht ständig ab |
abbruch, brauche, browser, einfach, entferne, entfernen, firefox, forum, geladen, gen, gestern, googeln, home, komischer, kurzem, malwarebytes, meldung, probleme, programm, runter, service, system, verschoben, vista, vista home premium |