|
Plagegeister aller Art und deren Bekämpfung: Werbebanner by Browse to Save - VirusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
16.01.2013, 01:02 | #1 |
| Werbebanner by Browse to Save - Virus Hallo liebes Trojaner-Board Team, ich hoffe Ihr könnt mir weiterhelfen, denn seit kurzem bekomme ich in Webseiten Werbebanner und Links eingeblendet die dort nicht hin gehören. Wie in ähnlichen Beiträgen hier im Forum hab ich als erstes AdwCleaner laufen lassen und bekam folgendes Ergebnis... Code:
ATTFilter # AdwCleaner v2.105 - Datei am 16/01/2013 um 00:44:29 erstellt # Aktualisiert am 08/01/2013 von Xplode # Betriebssystem : Windows 8 Pro (64 bits) # Benutzer : xxx - yyy # Bootmodus : Normal # Ausgeführt unter : C:\Users\xxx\Downloads\adwcleaner2.105.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\v5nho49b.default\extensions\staged Ordner Gelöscht : C:\Users\xxx\AppData\Roaming\pdfforge ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16453 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v17.0.1 (de) Datei : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\v5nho49b.default\prefs.js Gelöscht : user_pref("extensions.50ed2df0e3a02.scode", "(function(){try{if('aol.com,mail.google.com,mystart.inc[...] -\\ Google Chrome v24.0.1312.52 Datei : C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1342 octets] - [16/01/2013 00:34:40] AdwCleaner[S1].txt - [1275 octets] - [16/01/2013 00:44:29] ########## EOF - C:\AdwCleaner[S1].txt - [1335 octets] ########## Schonmal vielen Dank für Eure Hilfe im Vorraus! Schönen Gruß Hannes |
16.01.2013, 14:41 | #2 |
/// Malware-holic | Werbebanner by Browse to Save - Virus Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________
Code:
ATTFilter activex netsvcs msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %systemroot%\*. /mp /s C:\Windows\system32\*.tsp /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\*.dll /lockedfiles %USERPROFILE%\*.* %USERPROFILE%\Local Settings\Temp\*.exe %USERPROFILE%\Local Settings\Temp\*.dll %USERPROFILE%\Application Data\*.exe HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs CREATERESTOREPOINT
__________________ |
16.01.2013, 18:25 | #3 |
| Werbebanner by Browse to Save - Virus Hallo markusg,
__________________danke für deine Hilfe... OTL.txt: Code:
ATTFilter OTL logfile created on: 16.01.2013 18:00:42 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\xxx\Desktop 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16453) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,23 Gb Available Physical Memory | 74,22% Memory free 5,62 Gb Paging File | 4,69 Gb Available in Paging File | 83,33% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 146,48 Gb Total Space | 100,31 Gb Free Space | 68,48% Space Free | Partition Type: NTFS Drive D: | 146,48 Gb Total Space | 20,82 Gb Free Space | 14,21% Space Free | Partition Type: NTFS Drive F: | 638,55 Gb Total Space | 299,65 Gb Free Space | 46,93% Space Free | Partition Type: NTFS Computer Name: yyy | User Name: xxx | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2013.01.16 17:59:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\xxx\Desktop\OTL.exe PRC - [2012.12.18 20:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.11.22 16:58:14 | 001,522,312 | ---- | M] (pdfforge GbR) -- C:\Program Files (x86)\PDF Architect\HelperService.exe PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe PRC - [2012.10.02 23:21:00 | 001,258,856 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2011.01.10 13:49:20 | 000,014,848 | ---- | M] () -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe ========== Modules (No Company Name) ========== ========== Services (SafeList) ========== SRV:64bit: - [2012.12.06 05:23:00 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker) SRV:64bit: - [2012.12.06 05:22:59 | 000,178,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker) SRV:64bit: - [2012.11.06 05:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify) SRV:64bit: - [2012.11.06 05:17:41 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder) SRV:64bit: - [2012.09.20 10:10:47 | 002,367,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService) SRV:64bit: - [2012.09.20 07:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc) SRV:64bit: - [2012.09.20 07:30:41 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure) SRV:64bit: - [2012.07.26 04:08:04 | 001,968,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc) SRV:64bit: - [2012.07.26 04:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc) SRV:64bit: - [2012.07.26 04:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc) SRV:64bit: - [2012.07.26 04:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc) SRV:64bit: - [2012.07.26 04:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc) SRV:64bit: - [2012.07.26 04:06:36 | 000,463,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm) SRV:64bit: - [2012.07.26 04:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon) SRV:64bit: - [2012.07.26 04:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc) SRV:64bit: - [2012.07.26 04:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup) SRV:64bit: - [2012.07.26 04:06:00 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM) SRV:64bit: - [2012.07.26 04:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso) SRV:64bit: - [2012.07.26 04:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS) SRV:64bit: - [2012.07.26 04:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc) SRV:64bit: - [2012.07.26 04:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService) SRV:64bit: - [2012.07.26 04:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent) SRV:64bit: - [2012.07.26 04:05:04 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss) SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync) SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown) SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv) SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange) SRV:64bit: - [2012.07.26 01:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat) SRV - [2012.12.18 20:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.11.29 09:26:17 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012.11.22 16:58:14 | 001,522,312 | ---- | M] (pdfforge GbR) [Auto | Running] -- C:\Program Files (x86)\PDF Architect\HelperService.exe -- (PDF Architect Helper Service) SRV - [2012.11.22 16:56:10 | 000,905,864 | ---- | M] (pdfforge GbR) [Auto | Stopped] -- C:\Program Files (x86)\PDF Architect\ConversionService.exe -- (PDF Architect Service) SRV - [2012.11.06 05:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify) SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012.10.02 23:21:00 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012.07.26 04:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc) SRV - [2011.01.10 13:49:20 | 000,014,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe -- (DokanMounter) ========== Driver Services (SafeList) ========== DRV:64bit: - [2013.01.16 17:56:13 | 000,468,144 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\aswnet.sys -- (aswnet) DRV:64bit: - [2012.11.27 08:00:32 | 000,194,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus) DRV:64bit: - [2012.11.27 04:56:29 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg) DRV:64bit: - [2012.11.27 04:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid) DRV:64bit: - [2012.11.26 16:34:14 | 000,058,360 | ---- | M] (NetFilterSDK.com) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\networx.sys -- (networx) DRV:64bit: - [2012.11.20 05:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c) DRV:64bit: - [2012.11.06 08:52:07 | 000,445,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3) DRV:64bit: - [2012.11.06 08:36:23 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc) DRV:64bit: - [2012.11.06 04:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM) DRV:64bit: - [2012.10.30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:64bit: - [2012.10.30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:64bit: - [2012.10.30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\Drivers\aswMonFlt.sys -- (aswMonFlt) DRV:64bit: - [2012.10.30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:64bit: - [2012.10.15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\aswRdr2.sys -- (aswRdr) DRV:64bit: - [2012.10.12 09:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2012.10.11 08:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor) DRV:64bit: - [2012.10.11 08:13:49 | 000,058,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam) DRV:64bit: - [2012.10.11 06:19:44 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WSDScan.sys -- (WSDScan) DRV:64bit: - [2012.10.02 23:26:46 | 000,066,360 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\LGSHidFilt.Sys -- (LGSHidFilt) DRV:64bit: - [2012.09.20 08:55:33 | 000,337,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI) DRV:64bit: - [2012.09.20 08:55:33 | 000,212,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000) DRV:64bit: - [2012.09.20 08:55:30 | 000,120,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101) DRV:64bit: - [2012.09.20 08:55:29 | 000,028,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32) DRV:64bit: - [2012.09.20 08:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2012.09.20 08:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2012.09.20 08:03:08 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM) DRV:64bit: - [2012.07.26 06:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012.07.26 06:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv) DRV:64bit: - [2012.07.26 06:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID) DRV:64bit: - [2012.07.26 06:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt) DRV:64bit: - [2012.07.26 06:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor) DRV:64bit: - [2012.07.26 06:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex) DRV:64bit: - [2012.07.26 06:00:55 | 000,283,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport) DRV:64bit: - [2012.07.26 06:00:55 | 000,077,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci) DRV:64bit: - [2012.07.26 06:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis) DRV:64bit: - [2012.07.26 06:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2012.07.26 06:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2012.07.26 06:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS) DRV:64bit: - [2012.07.26 06:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2012.07.26 06:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv) DRV:64bit: - [2012.07.26 06:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass) DRV:64bit: - [2012.07.26 06:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2012.07.26 06:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware) DRV:64bit: - [2012.07.26 06:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2012.07.26 06:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2012.07.26 05:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS) DRV:64bit: - [2012.07.26 05:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS) DRV:64bit: - [2012.07.26 05:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci) DRV:64bit: - [2012.07.26 05:44:30 | 000,258,288 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter) DRV:64bit: - [2012.07.26 05:36:15 | 000,034,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot) DRV:64bit: - [2012.07.26 04:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt) DRV:64bit: - [2012.07.26 03:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice) DRV:64bit: - [2012.07.26 03:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf) DRV:64bit: - [2012.07.26 03:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay) DRV:64bit: - [2012.07.26 03:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo) DRV:64bit: - [2012.07.26 03:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender) DRV:64bit: - [2012.07.26 03:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter) DRV:64bit: - [2012.07.26 03:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic) DRV:64bit: - [2012.07.26 03:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime) DRV:64bit: - [2012.07.26 03:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig) DRV:64bit: - [2012.07.26 03:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr) DRV:64bit: - [2012.07.26 03:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr) DRV:64bit: - [2012.07.26 03:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd) DRV:64bit: - [2012.07.26 03:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx) DRV:64bit: - [2012.07.26 03:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx) DRV:64bit: - [2012.07.26 03:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD) DRV:64bit: - [2012.07.26 03:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum) DRV:64bit: - [2012.07.26 03:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc) DRV:64bit: - [2012.07.26 03:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2012.07.26 03:25:26 | 000,203,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Vid.sys -- (Vid) DRV:64bit: - [2012.07.26 03:25:22 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\storvsp.sys -- (storvsp) DRV:64bit: - [2012.07.26 03:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr) DRV:64bit: - [2012.07.26 03:25:12 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmbusr.sys -- (vmbusr) DRV:64bit: - [2012.07.26 03:25:12 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpcivsp.sys -- (vpcivsp) DRV:64bit: - [2012.07.26 03:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform) DRV:64bit: - [2012.07.26 03:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp) DRV:64bit: - [2012.07.26 03:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu) DRV:64bit: - [2012.06.02 15:31:56 | 000,589,824 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168) DRV:64bit: - [2011.01.10 13:51:40 | 000,120,408 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | Auto | Running] -- C:\Windows\SysNative\Drivers\dokan.sys -- (Dokan) DRV:64bit: - [2009.11.24 02:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\LGVirHid.sys -- (LGVirHid) DRV:64bit: - [2009.11.24 02:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\LGBusEnum.sys -- (LGBusEnum) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3C AE FF B4 9F EA CD 01 [binary data] IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.12 FF - prefs.js..extensions.enabledAddons: imagedownload%40Merci.chao:6.0.5 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0-git-20120328-0404: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_38: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com: C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013.01.09 09:23:29 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.01.16 00:10:01 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.01.01 15:10:37 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.01 15:13:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxx\AppData\Roaming\mozilla\Extensions [2013.01.16 00:44:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\v5nho49b.default\extensions [2013.01.01 15:22:28 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\v5nho49b.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013.01.10 11:38:37 | 000,000,000 | ---D | M] (SaveByclick) -- C:\Users\xxx\AppData\Roaming\mozilla\Firefox\Profiles\v5nho49b.default\extensions\50ed2df0e3957@50ed2df0e3990.com [2013.01.12 11:39:44 | 000,052,187 | ---- | M] () (No name found) -- C:\Users\xxx\AppData\Roaming\mozilla\firefox\profiles\v5nho49b.default\extensions\imagedownload@Merci.chao.xpi [2013.01.05 12:01:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2013.01.05 12:01:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} [2012.11.29 09:26:57 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012.11.29 10:19:31 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.11.29 10:19:31 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml [2012.11.29 10:19:31 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml [2012.11.29 10:19:32 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml [2012.11.29 10:19:31 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml [2012.11.29 10:19:31 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml ========== Chrome ========== CHR - homepage: CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter} CHR - homepage: CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll CHR - Extension: Google Drive = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Firebug Lite for Google Chrome\u2122 = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench\1.4.0.11967_0\ CHR - Extension: Google-Suche = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: jQuery Debugger = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhhnnnpaeobfddmlalhnehgclcmjimi\0.1.2.14_0\ CHR - Extension: SaveByclick = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hklphkjdhnfjlegeoocapdcalnkgpmpm\1_0\ CHR - Extension: avast! WebRep = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ CHR - Extension: Firebug Console = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jodfpogckhbcjamkfgjeicoiphpligka\0.1.0.8_0\ CHR - Extension: Google Mail = C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2012.07.26 06:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (SaveByclick) - {912A6653-968D-188A-B0A8-9D146993DC1B} - C:\ProgramData\SaveByclick\50ed2df0e3ae7.dll () O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GbR) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.) O4:64bit: - HKLM..\Run: [NetWorx] C:\Program Files\NetWorx\networx.exe (SoftPerfect Research) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - Startup: C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_38-windows-i586.cab (Java Plug-in 1.6.0_38) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02) O16 - DPF: {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_38-windows-i586.cab (Java Plug-in 1.6.0_38) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_38-windows-i586.cab (Java Plug-in 1.6.0_38) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F087B41-97CC-4992-8E6B-4F8F29223656}: DhcpNameServer = 192.168.2.1 O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL) - File not found O20 - AppInit_DLLs: (C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll) - File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O30 - LSA: Security Packages - (livessp) - File not found O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:64bit: {74166507-F39E-305E-A972-2C3478E47350} - .NET Framework ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework ActiveX: {3A8403F3-90B5-35DC-8926-EB9B907209F9} - .NET Framework ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation) NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation) NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation) NetSvcs:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation) NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2013.01.16 17:59:07 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\xxx\Desktop\OTL.exe [2013.01.16 00:10:31 | 000,370,288 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2013.01.16 00:10:31 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys [2013.01.16 00:10:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.01.16 00:10:30 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys [2013.01.16 00:10:28 | 000,984,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2013.01.16 00:10:28 | 000,468,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswnet.sys [2013.01.16 00:10:28 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2013.01.16 00:10:28 | 000,071,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2013.01.16 00:09:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.01.16 00:09:52 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe [2013.01.16 00:09:39 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software [2013.01.16 00:09:39 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2013.01.09 09:23:51 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\PDF Architect [2013.01.09 09:23:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SaveByclick [2013.01.09 09:23:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SaveByclick [2013.01.09 09:23:33 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\APP_NAME_NON_STRING [2013.01.09 09:23:32 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\PDF Architect Files [2013.01.09 09:23:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect [2013.01.09 09:23:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDF Architect [2013.01.09 09:23:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator [2013.01.09 09:23:15 | 000,103,936 | ---- | C] (pdfforge GbR) -- C:\Windows\SysNative\pdfcmon.dll [2013.01.09 09:23:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDFCreator [2013.01.05 12:02:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2013.01.04 19:42:53 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\ts3overlay_hook_win64 [2013.01.04 19:42:52 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\ts3overlay [2013.01.04 19:21:19 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\TS3Client [2013.01.04 15:06:27 | 000,000,000 | ---D | C] -- C:\Users\xxx\.argouml [2013.01.04 15:06:23 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ArgoUML [2013.01.04 15:06:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArgoUML [2013.01.04 15:06:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ArgoUML [2013.01.04 15:05:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2013.01.04 15:05:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [2013.01.04 13:26:53 | 000,000,000 | -H-D | C] -- C:\Windows\SysNative\CanonIJ Uninstaller Information [2013.01.04 13:26:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5200 series [2013.01.04 13:26:49 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ [2013.01.03 22:26:17 | 000,000,000 | ---D | C] -- C:\Users\xxx\Documents\DVDVideoSoft [2013.01.03 22:26:04 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\DVDVideoSoft [2013.01.03 17:25:22 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Adobe [2013.01.03 13:23:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe [2013.01.03 13:23:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe [2013.01.03 13:21:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2013.01.02 13:33:33 | 000,000,000 | ---D | C] -- C:\Users\xxx\Desktop\Thesis [2013.01.02 12:40:45 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\OpenOffice.org [2013.01.02 12:28:08 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1 [2013.01.02 12:27:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice.org 3 [2013.01.02 01:13:43 | 000,000,000 | ---D | C] -- C:\Users\xxx\Desktop\Neuer Ordner [2013.01.02 01:13:34 | 000,000,000 | ---D | C] -- C:\Users\xxx\dwhelper [2013.01.01 17:50:42 | 000,000,000 | R--D | C] -- C:\Windows\BrowserChoice [2013.01.01 15:13:30 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Mozilla [2013.01.01 15:13:30 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Mozilla [2013.01.01 15:10:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2013.01.01 15:10:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2013.01.01 15:10:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.01.01 15:05:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client [2013.01.01 15:05:13 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client [2013.01.01 15:02:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Tactical Center [2013.01.01 15:02:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Advanced Tactical Center [2013.01.01 14:59:25 | 000,058,360 | ---- | C] (NetFilterSDK.com) -- C:\Windows\SysNative\drivers\networx.sys [2013.01.01 14:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetWorx [2013.01.01 14:59:23 | 000,000,000 | ---D | C] -- C:\ProgramData\SoftPerfect [2013.01.01 14:59:23 | 000,000,000 | ---D | C] -- C:\Program Files\NetWorx [2013.01.01 14:59:07 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Programs [2013.01.01 14:37:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dokan [2013.01.01 14:33:35 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Logitech [2013.01.01 14:33:34 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\NVIDIA [2012.12.30 22:00:04 | 000,000,000 | ---D | C] -- C:\ProgramData\LogiShrd [2012.12.30 22:00:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech [2012.12.30 21:59:48 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech Gaming Software [2012.12.30 21:58:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies [2012.12.30 21:58:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild [2012.12.30 21:58:04 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\XPSViewer [2012.12.30 21:58:00 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies [2012.12.30 21:58:00 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild [2012.12.30 20:54:26 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Logitech [2012.12.30 20:54:26 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Logishrd [2012.12.30 20:44:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2012.12.30 20:34:15 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Wargaming.net [2012.12.30 12:28:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation [2012.12.29 03:39:00 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2012.12.29 03:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation [2012.12.29 03:38:23 | 000,060,776 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll [2012.12.29 03:38:23 | 000,052,584 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll [2012.12.29 03:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation [2012.12.29 03:37:58 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation [2012.12.28 18:13:48 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\vlc [2012.12.28 18:12:51 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2012.12.28 16:47:47 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx [2012.12.28 16:47:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks [2012.12.28 16:46:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2012.12.28 16:44:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google [2012.12.28 16:44:49 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Google [2012.12.28 16:43:17 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Macromedia [2012.12.28 14:18:02 | 000,000,000 | R--D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2012.12.28 14:18:02 | 000,000,000 | R--D | C] -- C:\Users\xxx\Searches [2012.12.28 14:18:02 | 000,000,000 | R--D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2012.12.28 14:17:58 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Adobe [2012.12.28 14:17:19 | 000,000,000 | ---D | C] -- C:\Windows\CSC [2012.12.28 14:16:52 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\VirtualStore [2012.12.28 14:16:37 | 000,000,000 | ---D | C] -- C:\ProgramData\PRICache [2012.12.28 14:16:25 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2012.12.28 14:15:56 | 000,000,000 | --SD | C] -- C:\Users\xxx\AppData\Roaming\Microsoft [2012.12.28 14:15:56 | 000,000,000 | R--D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools [2012.12.28 14:15:56 | 000,000,000 | R--D | C] -- C:\Users\xxx\Favorites [2012.12.28 14:15:56 | 000,000,000 | R--D | C] -- C:\Users\xxx\Desktop [2012.12.28 14:15:56 | 000,000,000 | R--D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2012.12.28 14:15:56 | 000,000,000 | R--D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Vorlagen [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\AppData\Local\Verlauf [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\AppData\Local\Temporary Internet Files [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Startmenü [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\SendTo [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Recent [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Netzwerkumgebung [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Lokale Einstellungen [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Documents\Eigene Videos [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Documents\Eigene Musik [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Eigene Dateien [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Documents\Eigene Bilder [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Druckumgebung [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Cookies [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\AppData\Local\Anwendungsdaten [2012.12.28 14:15:56 | 000,000,000 | -HSD | C] -- C:\Users\xxx\Anwendungsdaten [2012.12.28 14:15:56 | 000,000,000 | -H-D | C] -- C:\Users\xxx\AppData [2012.12.28 14:15:56 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Temp [2012.12.28 14:15:56 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Microsoft [2012.12.28 14:15:56 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente [2012.12.28 14:15:19 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten [2012.12.28 14:11:55 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2012.12.28 14:10:35 | 000,000,000 | -HSD | C] -- C:\Recovery [2012.12.28 14:10:31 | 000,000,000 | ---D | C] -- C:\Windows.old [2012.12.28 14:03:53 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2012.12.28 14:03:32 | 000,000,000 | -H-D | C] -- C:\$SysReset [2012.12.23 22:44:33 | 000,000,000 | ---D | C] -- C:\Games [2012.12.23 20:21:54 | 000,000,000 | ---D | C] -- C:\NVIDIA [2012.12.23 19:50:57 | 000,000,000 | R--D | C] -- C:\Users\xxx\Contacts [2012.12.23 19:50:24 | 000,000,000 | ---D | C] -- C:\Users\xxx\AppData\Local\Packages [2012.12.23 19:50:21 | 000,000,000 | R--D | C] -- C:\Users\xxx\Videos [2012.12.23 19:50:21 | 000,000,000 | R--D | C] -- C:\Users\xxx\Saved Games [2012.12.23 19:50:21 | 000,000,000 | R--D | C] -- C:\Users\xxx\Pictures [2012.12.23 19:50:21 | 000,000,000 | R--D | C] -- C:\Users\xxx\Music [2012.12.23 19:50:21 | 000,000,000 | R--D | C] -- C:\Users\xxx\Links [2012.12.23 19:50:21 | 000,000,000 | R--D | C] -- C:\Users\xxx\Downloads [2012.12.23 19:50:21 | 000,000,000 | R--D | C] -- C:\Users\xxx\Documents [2012.12.23 19:47:41 | 000,000,000 | -HSD | C] -- C:\Programme [2012.12.23 19:47:41 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen [2012.12.23 19:44:01 | 000,000,000 | -HSD | C] -- C:\System Volume Information ========== Files - Modified Within 30 Days ========== [2013.01.16 17:59:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\xxx\Desktop\OTL.exe [2013.01.16 17:56:13 | 000,468,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswnet.sys [2013.01.16 17:56:13 | 000,000,175 | ---- | M] () -- C:\Windows\SysNative\drivers\aswnet.sys.sum [2013.01.16 17:54:13 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.01.16 17:53:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.01.16 00:51:26 | 001,745,416 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.01.16 00:51:26 | 000,751,892 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.01.16 00:51:26 | 000,710,046 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.01.16 00:51:26 | 000,155,620 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.01.16 00:51:26 | 000,132,416 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.01.16 00:49:00 | 000,001,128 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.01.16 00:45:36 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys [2013.01.16 00:45:33 | 2575,712,256 | -HS- | M] () -- C:\hiberfil.sys [2013.01.16 00:14:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2013.01.16 00:10:31 | 000,001,958 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.01.14 23:25:41 | 000,307,904 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.01.13 08:53:27 | 000,002,259 | ---- | M] () -- C:\Users\xxx\Desktop\Google Chrome.lnk [2013.01.07 15:10:02 | 109,241,887 | ---- | M] () -- C:\Users\xxx\Desktop\3k13_alle.mp3 [2013.01.07 14:32:15 | 353,029,924 | ---- | M] () -- C:\Users\xxx\Desktop\109lpt_komplett96k.mp3 [2013.01.05 01:46:59 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf [2013.01.04 15:06:23 | 000,002,254 | ---- | M] () -- C:\Users\xxx\Desktop\ArgoUML.lnk [2013.01.03 18:30:57 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf [2013.01.03 13:21:52 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf [2013.01.02 15:38:43 | 000,007,601 | ---- | M] () -- C:\Users\xxx\AppData\Local\Resmon.ResmonCfg [2013.01.02 12:40:57 | 000,001,239 | ---- | M] () -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013.01.02 12:28:08 | 000,001,172 | ---- | M] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk [2013.01.01 15:10:53 | 000,001,151 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.01.01 15:05:18 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk [2013.01.01 15:02:33 | 000,001,092 | ---- | M] () -- C:\Users\Public\Desktop\Advanced Tactical Center.lnk [2012.12.31 00:40:08 | 000,000,355 | ---- | M] () -- C:\Users\xxx\Desktop\Computer.lnk [2012.12.28 14:16:06 | 000,013,338 | ---- | M] () -- C:\Windows\diagwrn.xml [2012.12.28 14:16:06 | 000,013,338 | ---- | M] () -- C:\Windows\diagerr.xml [2012.12.27 17:47:52 | 000,000,281 | ---- | M] () -- C:\ts.ini [2012.12.25 16:02:25 | 000,001,102 | ---- | M] () -- C:\Users\xxx\Desktop\WoT.lnk [2012.12.23 19:46:15 | 000,052,435 | ---- | M] () -- C:\Windows\SysWow64\license.rtf [2012.12.23 19:46:15 | 000,052,435 | ---- | M] () -- C:\Windows\SysNative\license.rtf ========== Files Created - No Company Name ========== [2013.01.16 17:56:13 | 000,000,175 | ---- | C] () -- C:\Windows\SysNative\drivers\aswnet.sys.sum [2013.01.16 00:10:31 | 000,001,958 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.01.16 00:10:28 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt [2013.01.14 23:25:33 | 000,307,904 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.01.09 21:33:15 | 000,110,592 | ---- | C] () -- C:\Windows\SysNative\OEMLicense.dll [2013.01.09 21:33:15 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll [2013.01.07 15:04:45 | 109,241,887 | ---- | C] () -- C:\Users\xxx\Desktop\3k13_alle.mp3 [2013.01.07 14:09:27 | 353,029,924 | ---- | C] () -- C:\Users\xxx\Desktop\109lpt_komplett96k.mp3 [2013.01.05 01:46:59 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf [2013.01.04 15:06:23 | 000,002,254 | ---- | C] () -- C:\Users\xxx\Desktop\ArgoUML.lnk [2013.01.03 18:30:57 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf [2013.01.03 15:28:09 | 000,001,346 | ---- | C] () -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WoT.lnk [2013.01.03 13:23:47 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk [2013.01.03 13:21:52 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf [2013.01.02 15:38:43 | 000,007,601 | ---- | C] () -- C:\Users\xxx\AppData\Local\Resmon.ResmonCfg [2013.01.02 12:40:57 | 000,001,239 | ---- | C] () -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013.01.02 12:28:08 | 000,001,172 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk [2013.01.02 12:05:26 | 000,385,604 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml [2013.01.01 15:10:53 | 000,001,163 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2013.01.01 15:10:53 | 000,001,151 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2013.01.01 15:05:18 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk [2013.01.01 15:02:33 | 000,001,092 | ---- | C] () -- C:\Users\Public\Desktop\Advanced Tactical Center.lnk [2012.12.31 00:40:08 | 000,000,355 | ---- | C] () -- C:\Users\xxx\Desktop\Computer.lnk [2012.12.28 16:46:44 | 000,002,259 | ---- | C] () -- C:\Users\xxx\Desktop\Google Chrome.lnk [2012.12.28 16:44:56 | 000,001,128 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.12.28 16:44:55 | 000,001,124 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.12.28 14:17:58 | 000,001,442 | ---- | C] () -- C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2012.12.28 14:15:53 | 000,013,338 | ---- | C] () -- C:\Windows\diagwrn.xml [2012.12.28 14:15:53 | 000,013,338 | ---- | C] () -- C:\Windows\diagerr.xml [2012.12.27 17:47:52 | 000,000,281 | ---- | C] () -- C:\ts.ini [2012.12.25 16:02:25 | 000,001,102 | ---- | C] () -- C:\Users\xxx\Desktop\WoT.lnk [2012.12.23 19:46:56 | 2575,712,256 | -HS- | C] () -- C:\hiberfil.sys [2012.12.23 19:44:01 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys [2012.07.26 09:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2012.07.26 09:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2012.07.26 08:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2012.07.26 02:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2012.07.25 21:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2012.07.25 21:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2012.06.02 15:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat ========== ZeroAccess Check ========== [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.11.06 05:19:27 | 019,789,824 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.11.06 05:20:00 | 017,560,576 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 04:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 04:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 04:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.01.09 09:23:33 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\APP_NAME_NON_STRING [2013.01.03 22:27:27 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\DVDVideoSoft [2013.01.02 12:40:45 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\OpenOffice.org [2013.01.09 09:23:58 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\PDF Architect [2013.01.14 23:24:23 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\TS3Client [2013.01.04 19:42:58 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\ts3overlay [2013.01.04 19:48:30 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\ts3overlay_hook_win64 [2012.12.30 20:34:15 | 000,000,000 | ---D | M] -- C:\Users\xxx\AppData\Roaming\Wargaming.net ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*. > [2012.12.28 14:23:40 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2012.12.30 22:37:29 | 000,000,000 | -H-D | M] -- C:\$SysReset [2012.07.26 08:22:08 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2012.12.23 19:47:41 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen [2012.12.23 22:44:33 | 000,000,000 | ---D | M] -- C:\Games [2012.12.23 20:21:54 | 000,000,000 | ---D | M] -- C:\NVIDIA [2012.07.26 08:33:46 | 000,000,000 | ---D | M] -- C:\PerfLogs [2013.01.16 00:09:39 | 000,000,000 | R--D | M] -- C:\Program Files [2013.01.09 09:23:26 | 000,000,000 | R--D | M] -- C:\Program Files (x86) [2013.01.16 00:09:39 | 000,000,000 | -H-D | M] -- C:\ProgramData [2012.12.23 19:47:41 | 000,000,000 | -HSD | M] -- C:\Programme [2012.12.28 14:10:35 | 000,000,000 | -HSD | M] -- C:\Recovery [2013.01.16 00:09:35 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2012.12.28 14:15:56 | 000,000,000 | R--D | M] -- C:\Users [2013.01.16 00:09:53 | 000,000,000 | ---D | M] -- C:\Windows [2013.01.02 15:36:45 | 000,000,000 | ---D | M] -- C:\Windows.old < %PROGRAMFILES%\*.exe > < %LOCALAPPDATA%\*.exe > < %systemroot%\*. /mp /s > < C:\Windows\system32\*.tsp > [2012.07.26 04:21:04 | 000,031,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp [2012.09.20 06:55:30 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp [2012.09.20 06:55:30 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp [2012.07.26 04:21:04 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp [2012.07.26 04:21:04 | 000,276,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp [2012.07.26 08:22:10 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT [2012.12.28 16:44:55 | 000,001,124 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2012.12.28 16:44:56 | 000,001,128 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job < MD5 for: AGP440.SYS > [2012.07.26 06:00:49 | 000,063,216 | ---- | M] (Microsoft Corporation) MD5=01590377A5AB19E792528C628A2A68F9 -- C:\Windows\SysNative\drivers\AGP440.sys [2012.07.26 06:00:49 | 000,063,216 | ---- | M] (Microsoft Corporation) MD5=01590377A5AB19E792528C628A2A68F9 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_81a4c6c9cc9d86a0\AGP440.sys [2012.07.26 06:00:49 | 000,063,216 | ---- | M] (Microsoft Corporation) MD5=01590377A5AB19E792528C628A2A68F9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.2.9200.16384_none_12dc94a048750f71\AGP440.sys < MD5 for: ATAPI.SYS > [2012.07.26 06:00:48 | 000,025,840 | ---- | M] (Microsoft Corporation) MD5=A721FF570C2387E383BDDEA9632863C9 -- C:\Windows\SysNative\drivers\atapi.sys [2012.07.26 06:00:48 | 000,025,840 | ---- | M] (Microsoft Corporation) MD5=A721FF570C2387E383BDDEA9632863C9 -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_69660e2be041f47b\atapi.sys [2012.07.26 06:00:48 | 000,025,840 | ---- | M] (Microsoft Corporation) MD5=A721FF570C2387E383BDDEA9632863C9 -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.2.9200.16384_none_3601cf7eab4e0493\atapi.sys < MD5 for: EXPLORER.EXE > [2012.10.11 06:53:24 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe [2012.10.11 09:09:58 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe [2012.07.26 04:50:01 | 002,114,936 | ---- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe [2012.07.26 05:49:13 | 002,380,440 | ---- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe [2012.10.11 06:56:41 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 -- C:\Windows\SysWOW64\explorer.exe [2012.10.11 06:56:41 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe [2012.10.11 08:35:16 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 -- C:\Windows\explorer.exe [2012.10.11 08:35:16 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe < MD5 for: IASTORV.SYS > [2012.07.26 06:00:52 | 000,411,888 | ---- | M] (Intel Corporation) MD5=5E394EBD26FD68AA9300332C46BEDD62 -- C:\Windows\SysNative\drivers\iaStorV.sys [2012.07.26 06:00:52 | 000,411,888 | ---- | M] (Intel Corporation) MD5=5E394EBD26FD68AA9300332C46BEDD62 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_819876bbe5c3b25f\iaStorV.sys [2012.07.26 06:00:52 | 000,411,888 | ---- | M] (Intel Corporation) MD5=5E394EBD26FD68AA9300332C46BEDD62 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.2.9200.16384_none_07daf9dd118c3086\iaStorV.sys < MD5 for: NETLOGON.DLL > [2012.07.26 04:19:22 | 000,634,368 | ---- | M] (Microsoft Corporation) MD5=EEF9DA64D7B1DD51FB8AB9EFCC560E3E -- C:\Windows\SysWOW64\netlogon.dll [2012.07.26 04:19:22 | 000,634,368 | ---- | M] (Microsoft Corporation) MD5=EEF9DA64D7B1DD51FB8AB9EFCC560E3E -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.2.9200.16384_none_60d608f9f61ee049\netlogon.dll [2012.07.26 04:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) MD5=FDC70965F0FC9DFEBC919627DED5DDFF -- C:\Windows\SysNative\netlogon.dll [2012.07.26 04:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) MD5=FDC70965F0FC9DFEBC919627DED5DDFF -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.2.9200.16384_none_56815ea7c1be1e4e\netlogon.dll < MD5 for: NVSTOR.SYS > [2012.07.26 06:00:55 | 000,168,176 | ---- | M] (NVIDIA Corporation) MD5=27AFC428D1D32ABD04A86763A4EDDEA9 -- C:\Windows\SysNative\drivers\nvstor.sys [2012.07.26 06:00:55 | 000,168,176 | ---- | M] (NVIDIA Corporation) MD5=27AFC428D1D32ABD04A86763A4EDDEA9 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys [2012.07.26 06:00:55 | 000,168,176 | ---- | M] (NVIDIA Corporation) MD5=27AFC428D1D32ABD04A86763A4EDDEA9 -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.2.9200.16384_none_92a46a8c48c2da5e\nvstor.sys < MD5 for: SCECLI.DLL > [2012.07.26 04:07:07 | 000,224,768 | ---- | M] (Microsoft Corporation) MD5=4F6E1CA672370A9BCAC049CE3AB7F666 -- C:\Windows\SysNative\scecli.dll [2012.07.26 04:07:07 | 000,224,768 | ---- | M] (Microsoft Corporation) MD5=4F6E1CA672370A9BCAC049CE3AB7F666 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.2.9200.16384_none_90d789c062dfa509\scecli.dll [2012.07.26 04:19:52 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=B95DC83FF580DD92F487C2F4D0854B6A -- C:\Windows\SysWOW64\scecli.dll [2012.07.26 04:19:52 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=B95DC83FF580DD92F487C2F4D0854B6A -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.2.9200.16384_none_9b2c341297406704\scecli.dll < MD5 for: USER32.DLL > [2012.07.26 04:07:39 | 001,342,464 | ---- | M] (Microsoft Corporation) MD5=1D08594400EE1B500B93256795FE30AE -- C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_6.2.9200.16384_none_260213a5f720b529\user32.dll [2012.09.20 05:09:35 | 001,126,912 | ---- | M] (Microsoft Corporation) MD5=7A4FD11444ABFA9C5D3E17123ABBD8A4 -- C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_6.2.9200.20521_none_311e3b534471206a\user32.dll [2012.07.26 01:02:48 | 001,126,912 | ---- | M] (Microsoft Corporation) MD5=8A93F57772FD24959F76A65FF79D282D -- C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_6.2.9200.16384_none_3056bdf82b817724\user32.dll [2012.09.20 07:33:05 | 001,342,464 | ---- | M] (Microsoft Corporation) MD5=A99AD14F26BDA7D7F27F76BC91B7EED7 -- C:\Windows\SysNative\user32.dll [2012.09.20 07:33:05 | 001,342,464 | ---- | M] (Microsoft Corporation) MD5=A99AD14F26BDA7D7F27F76BC91B7EED7 -- C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_6.2.9200.16420_none_263ef3ebf6f3a54e\user32.dll [2012.09.20 07:32:34 | 001,342,464 | ---- | M] (Microsoft Corporation) MD5=AC192A41414561DA0CABD0D36F54FB22 -- C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_6.2.9200.20521_none_26c9910110105e6f\user32.dll [2012.09.20 05:10:09 | 001,126,912 | ---- | M] (Microsoft Corporation) MD5=BA1C3ACD929A71E88B49C2B6E38F92B3 -- C:\Windows\SysWOW64\user32.dll [2012.09.20 05:10:09 | 001,126,912 | ---- | M] (Microsoft Corporation) MD5=BA1C3ACD929A71E88B49C2B6E38F92B3 -- C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_6.2.9200.16420_none_30939e3e2b546749\user32.dll < MD5 for: USERINIT.EXE > [2012.07.26 04:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\SysNative\userinit.exe [2012.07.26 04:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_34f2617a5b742e02\userinit.exe [2012.07.26 04:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\SysWOW64\userinit.exe [2012.07.26 04:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_d8d3c5f6a316bccc\userinit.exe < MD5 for: WINLOGON.EXE > [2012.09.20 07:33:55 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe [2012.09.20 07:33:17 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe [2012.07.26 04:08:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe [2012.10.11 06:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\SysNative\winlogon.exe [2012.10.11 06:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe [2012.10.11 06:45:27 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe < MD5 for: WS2IFSL.SYS > [2012.07.26 03:29:29 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=58D492F986EC519ECDD54D93618758F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.2.9200.16384_none_a85048395191dc38\ws2ifsl.sys [2012.09.20 07:09:50 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BC8B5CB336E63BB25EAD1CE8EDD34B81 -- C:\Windows\SysNative\drivers\ws2ifsl.sys [2012.09.20 07:09:50 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=BC8B5CB336E63BB25EAD1CE8EDD34B81 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.2.9200.16420_none_a88d287f5164cc5d\ws2ifsl.sys [2012.09.20 07:08:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=FC56FEC8FB233ABC32D110D031CBC8B0 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.2.9200.20521_none_a917c5946a81857e\ws2ifsl.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\system32\*.dll /lockedfiles > < %USERPROFILE%\*.* > [2013.01.16 08:21:06 | 000,786,432 | -HS- | M] () -- C:\Users\xxx\NTUSER.DAT [2012.12.28 14:15:56 | 000,118,784 | -HS- | M] () -- C:\Users\xxx\ntuser.dat.LOG1 [2012.12.28 14:15:56 | 000,000,000 | -HS- | M] () -- C:\Users\xxx\ntuser.dat.LOG2 [2012.12.28 14:15:57 | 000,065,536 | -HS- | M] () -- C:\Users\xxx\NTUSER.DAT{42d1338c-d6ff-11e1-9797-a4badb27af46}.TM.blf [2012.12.28 14:15:57 | 000,524,288 | -HS- | M] () -- C:\Users\xxx\NTUSER.DAT{42d1338c-d6ff-11e1-9797-a4badb27af46}.TMContainer00000000000000000001.regtrans-ms [2012.12.28 14:15:57 | 000,524,288 | -HS- | M] () -- C:\Users\xxx\NTUSER.DAT{42d1338c-d6ff-11e1-9797-a4badb27af46}.TMContainer00000000000000000002.regtrans-ms [2012.12.28 14:16:32 | 000,000,020 | -HS- | M] () -- C:\Users\xxx\ntuser.ini < %USERPROFILE%\Local Settings\Temp\*.exe > < %USERPROFILE%\Local Settings\Temp\*.dll > < %USERPROFILE%\Application Data\*.exe > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 < End of report > Code:
ATTFilter OTL Extras logfile created on: 16.01.2013 18:00:42 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\xxx\Desktop 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16453) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,23 Gb Available Physical Memory | 74,22% Memory free 5,62 Gb Paging File | 4,69 Gb Available in Paging File | 83,33% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 146,48 Gb Total Space | 100,31 Gb Free Space | 68,48% Space Free | Partition Type: NTFS Drive D: | 146,48 Gb Total Space | 20,82 Gb Free Space | 14,21% Space Free | Partition Type: NTFS Drive F: | 638,55 Gb Total Space | 299,65 Gb Free Space | 46,93% Space Free | Partition Type: NTFS Computer Name: yyy| User Name: xxx| Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01E79D64-02A3-4C46-B81C-CB32406E5955}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | "{0E28A9C5-050C-4E73-A1EC-5675AB4497FB}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{0E493877-4A22-4553-BDF4-FCAFB90372B9}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{22FE1AD0-1C15-4CF3-A976-73B6615E99AE}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | "{3A1B98F2-45DF-422A-AAD1-95AA278E8860}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | "{4E06850A-D37F-4E10-8A25-56B2C53F1773}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{58105B8A-6F64-4B79-8D13-B21488B83949}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | "{69EC69A0-495D-4BF7-9F1A-366952431EEA}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | "{73855517-19C7-4F5D-AEDA-D0E80F857314}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | "{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{87E6340F-96D6-467B-9009-89E73FED5F6D}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | "{88F763AB-3D3F-4654-B91D-802DA727CF0C}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | "{9A63A33B-D8E5-4F48-8682-759A9884871A}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{9B60F9E7-1F0D-449D-9EDC-614AA24E9615}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | "{A91CECCC-0772-4C82-97F4-D016B8C7BD56}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | "{AD449C6C-A1DA-44AD-92BE-3022BCA01F4D}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "{CF82C6D3-9BAD-45A1-B973-78F1E55E8D21}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | "{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | "{EAC0D31E-5AE5-453B-BAF6-D10AB836E70C}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | "{F0CCEF2F-2EFD-4873-A23B-8DD03ED69E1C}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | "{F1B3AC7C-5868-4566-8819-0722356C0668}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | "TCP Query User{4B10356A-7F42-4613-BCD9-5A32FDC55E27}C:\games\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | "UDP Query User{EAE2AD2E-657C-4035-8677-5AFD8E180BDF}C:\games\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=c:\games\world_of_tanks\worldoftanks.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series" = Canon MG5200 series MP Drivers "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 306.97 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "Logitech Gaming Software" = Logitech Gaming Software 8.40 "NetWorx_is1" = NetWorx 5.2.7 "TeamSpeak 3 Client" = TeamSpeak 3 Client "VLC media player" = VLC media player 2.1.0-git-20120328-0404 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1" = World of Tanks "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{26A24AE4-039D-4CA4-87B4-2F83216038FF}" = Java(TM) 6 Update 38 "{26B5A6D1-1F75-3B59-5825-E4D4CAE3445D}" = SaveByclick "{30B41B7A-3C9D-44DE-A7A1-949011F33CC3}" = PDF Architect "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.01) - Deutsch "ArgoUML" = ArgoUML 0.34 "ATC_is1" = Advanced Tactical Center™ 1.12 "avast" = avast! Free Antivirus "DokanLibrary" = Dokan Library 0.6.0 "Google Chrome" = Google Chrome "Mozilla Firefox 17.0.1 (x86 de)" = Mozilla Firefox 17.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 07.01.2013 16:13:36 | Computer Name = yyy | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: ATC.exe, Version: 1.12.0.0, Zeitstempel: 0x413ffc3a Name des fehlerhaften Moduls: ts3overlay_hook_win32.dll, Version: 3.7.8.0, Zeitstempel: 0x5075d352 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000431b9 ID des fehlerhaften Prozesses: 0x8c8 Startzeit der fehlerhaften Anwendung: 0x01cded137543db95 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Advanced Tactical Center\ATC.exe Pfad des fehlerhaften Moduls: C:\Program Files\TeamSpeak 3 Client\plugins\ts3overlay\ts3overlay_hook_win32.dll Berichtskennung: b725b708-5906-11e2-be77-001d7dd701fb Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error - 12.01.2013 06:44:04 | Computer Name = yyy | Source = Microsoft-Windows-Immersive-Shell | ID = 2486 Description = Die App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error - 15.01.2013 19:46:26 | Computer Name = yyy | Source = ESENT | ID = 489 Description = taskhostex (1888) Versuch, Datei "C:\Users\xxx\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" für den Lesezugriff zu öffnen, ist mit Systemfehler 32 (0x00000020): "Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Öffnen von Dateien. [ System Events ] Error - 28.12.2012 09:13:08 | Computer Name = yyy | Source = Service Control Manager | ID = 7023 Description = Der Dienst "IP-Hilfsdienst" wurde mit folgendem Fehler beendet: %%1058 Error - 28.12.2012 09:13:10 | Computer Name = yyy | Source = Service Control Manager | ID = 7023 Description = Der Dienst "Netzwerklistendienst" wurde mit folgendem Fehler beendet: %%21 Error - 28.12.2012 11:44:09 | Computer Name = yyy | Source = Schannel | ID = 36888 Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus lautet: 900. Error - 28.12.2012 11:44:27 | Computer Name = yyy | Source = Schannel | ID = 36888 Description = Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 51. Der Windows-SChannel-Fehlerstatus lautet: 900. Error - 01.01.2013 10:32:56 | Computer Name = yyy | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20 Description = Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80246007 fehlgeschlagen: Update für Windows 8 für x64-Systeme (KB2771431) Error - 14.01.2013 13:16:55 | Computer Name = yyy | Source = Service Control Manager | ID = 7023 Description = Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet: %%2147500037 Error - 14.01.2013 18:24:27 | Computer Name = yyy | Source = DCOM | ID = 10010 Description = Error - 14.01.2013 18:24:27 | Computer Name = yyy | Source = DCOM | ID = 10010 Description = Error - 15.01.2013 19:46:22 | Computer Name = yyy | Source = Service Control Manager | ID = 7023 Description = Der Dienst "PDF Architect Service" wurde mit folgendem Fehler beendet: %%2147500037 < End of report > |
16.01.2013, 21:02 | #4 |
/// Malware-holic | Werbebanner by Browse to Save - Virus hi warum hat der PC noch kein Servicepack 1 (windows update)? download tdss killer: http://www.trojaner-board.de/82358-t...entfernen.html Klicke auf Change parameters • Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system • Klick auf OK und anschließend auf Start scan - bei funden erst mal immer skip wählen, log posten c: öffnen, tdsskiller-datum-version.txt öffnen, Inhalt posten
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
16.01.2013, 21:11 | #5 |
| Werbebanner by Browse to Save - Virus Für Windows 8 stehen noch keine Service Packs zur Verfügung. Sagt zumindest die Updateseite... Code:
ATTFilter 21:07:00.0803 1080 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 21:07:02.0041 1080 ============================================================ 21:07:02.0041 1080 Current date / time: 2013/01/16 21:07:02.0041 21:07:02.0041 1080 SystemInfo: 21:07:02.0041 1080 21:07:02.0041 1080 OS Version: 6.2.9200 ServicePack: 0.0 21:07:02.0041 1080 Product type: Workstation 21:07:02.0041 1080 ComputerName: yyy 21:07:02.0041 1080 UserName: xxx 21:07:02.0041 1080 Windows directory: C:\Windows 21:07:02.0041 1080 System windows directory: C:\Windows 21:07:02.0041 1080 Running under WOW64 21:07:02.0041 1080 Processor architecture: Intel x64 21:07:02.0041 1080 Number of processors: 4 21:07:02.0041 1080 Page size: 0x1000 21:07:02.0041 1080 Boot type: Normal boot 21:07:02.0041 1080 ============================================================ 21:07:02.0639 1080 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0CADE00 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 21:07:02.0653 1080 ============================================================ 21:07:02.0653 1080 \Device\Harddisk0\DR0: 21:07:02.0653 1080 MBR partitions: 21:07:02.0653 1080 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x124F6BF3 21:07:02.0653 1080 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x124F7000, BlocksNum 0x124F7000 21:07:02.0653 1080 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x249EE000, BlocksNum 0x4FD17800 21:07:02.0653 1080 ============================================================ 21:07:02.0669 1080 C: <-> \Device\Harddisk0\DR0\Partition2 21:07:02.0691 1080 D: <-> \Device\Harddisk0\DR0\Partition1 21:07:02.0733 1080 F: <-> \Device\Harddisk0\DR0\Partition3 21:07:02.0733 1080 ============================================================ 21:07:02.0733 1080 Initialize success 21:07:02.0733 1080 ============================================================ 21:07:20.0837 4840 ============================================================ 21:07:20.0837 4840 Scan started 21:07:20.0837 4840 Mode: Manual; SigCheck; TDLFS; 21:07:20.0837 4840 ============================================================ 21:07:21.0881 4840 ================ Scan system memory ======================== 21:07:21.0881 4840 System memory - ok 21:07:21.0881 4840 ================ Scan services ============================= 21:07:21.0967 4840 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys 21:07:22.0118 4840 1394ohci - ok 21:07:22.0132 4840 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys 21:07:22.0146 4840 3ware - ok 21:07:22.0166 4840 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys 21:07:22.0187 4840 ACPI - ok 21:07:22.0209 4840 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys 21:07:22.0221 4840 acpiex - ok 21:07:22.0226 4840 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys 21:07:22.0255 4840 acpipagr - ok 21:07:22.0275 4840 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys 21:07:22.0304 4840 AcpiPmi - ok 21:07:22.0314 4840 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys 21:07:22.0331 4840 acpitime - ok 21:07:22.0374 4840 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 21:07:22.0385 4840 AdobeARMservice - ok 21:07:22.0402 4840 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 21:07:22.0424 4840 adp94xx - ok 21:07:22.0443 4840 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys 21:07:22.0463 4840 adpahci - ok 21:07:22.0485 4840 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 21:07:22.0499 4840 adpu320 - ok 21:07:22.0528 4840 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 21:07:22.0543 4840 AeLookupSvc - ok 21:07:22.0572 4840 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\Windows\system32\drivers\afd.sys 21:07:22.0597 4840 AFD - ok 21:07:22.0611 4840 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys 21:07:22.0622 4840 agp440 - ok 21:07:22.0641 4840 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe 21:07:22.0664 4840 ALG - ok 21:07:22.0685 4840 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll 21:07:22.0706 4840 AllUserInstallAgent - ok 21:07:22.0720 4840 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys 21:07:22.0741 4840 AmdK8 - ok 21:07:22.0753 4840 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys 21:07:22.0776 4840 AmdPPM - ok 21:07:22.0787 4840 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys 21:07:22.0799 4840 amdsata - ok 21:07:22.0821 4840 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 21:07:22.0838 4840 amdsbs - ok 21:07:22.0852 4840 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys 21:07:22.0863 4840 amdxata - ok 21:07:22.0886 4840 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys 21:07:22.0907 4840 AppID - ok 21:07:22.0928 4840 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll 21:07:22.0958 4840 AppIDSvc - ok 21:07:22.0983 4840 [ D64C4AFEE8277F35EF729A2B924666B0 ] Appinfo C:\Windows\System32\appinfo.dll 21:07:23.0008 4840 Appinfo - ok 21:07:23.0030 4840 [ 2D14788C5D0836292BEB27BBE109BE56 ] AppMgmt C:\Windows\System32\appmgmts.dll 21:07:23.0064 4840 AppMgmt - ok 21:07:23.0077 4840 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys 21:07:23.0090 4840 arc - ok 21:07:23.0104 4840 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys 21:07:23.0117 4840 arcsas - ok 21:07:23.0141 4840 [ 4FCAEF0C5BE7629AEB878998E0FE959B ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys 21:07:23.0156 4840 aswFsBlk - ok 21:07:23.0186 4840 [ B50CDD87772D6A11CB90924AAD399DF8 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys 21:07:23.0195 4840 aswMonFlt - ok 21:07:23.0223 4840 [ 7415A03DEF5A4D5068112E8782FCEF75 ] aswnet C:\Windows\System32\Drivers\aswnet.sys 21:07:23.0239 4840 aswnet - ok 21:07:23.0258 4840 [ 57768C7DB4681F2510F247F82EF31D4F ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys 21:07:23.0266 4840 aswRdr - ok 21:07:23.0294 4840 [ E71D826A1F3CE9C9DE3E77F2D02AFFBF ] aswSnx C:\Windows\system32\drivers\aswSnx.sys 21:07:23.0320 4840 aswSnx - ok 21:07:23.0336 4840 [ 538A32E2C99BF073D4CA76C30BEDAA60 ] aswSP C:\Windows\system32\drivers\aswSP.sys 21:07:23.0351 4840 aswSP - ok 21:07:23.0368 4840 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 21:07:23.0395 4840 AsyncMac - ok 21:07:23.0403 4840 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys 21:07:23.0414 4840 atapi - ok 21:07:23.0438 4840 [ 810ED88782952228AF9C0985FB7D259E ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll 21:07:23.0463 4840 AudioEndpointBuilder - ok 21:07:23.0481 4840 [ 25CA8B87479A374919563B3EE7136F32 ] Audiosrv C:\Windows\System32\Audiosrv.dll 21:07:23.0505 4840 Audiosrv - ok 21:07:23.0559 4840 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 21:07:23.0570 4840 avast! Antivirus - ok 21:07:23.0587 4840 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll 21:07:23.0612 4840 AxInstSV - ok 21:07:23.0642 4840 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 21:07:23.0665 4840 b06bdrv - ok 21:07:23.0674 4840 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys 21:07:23.0700 4840 BasicDisplay - ok 21:07:23.0710 4840 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys 21:07:23.0733 4840 BasicRender - ok 21:07:23.0758 4840 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll 21:07:23.0784 4840 BDESVC - ok 21:07:23.0795 4840 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys 21:07:23.0814 4840 Beep - ok 21:07:23.0843 4840 [ 9E6A544F465C582AB42444A217CF04DC ] BFE C:\Windows\System32\bfe.dll 21:07:23.0866 4840 BFE - ok 21:07:23.0896 4840 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll 21:07:24.0110 4840 BITS - ok 21:07:24.0127 4840 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys 21:07:24.0151 4840 bowser - ok 21:07:24.0174 4840 [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll 21:07:24.0194 4840 BrokerInfrastructure - ok 21:07:24.0215 4840 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll 21:07:24.0230 4840 Browser - ok 21:07:24.0252 4840 [ 3AA4309EBD9491E516F13FE3DC752FEE ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys 21:07:24.0275 4840 BthAvrcpTg - ok 21:07:24.0291 4840 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys 21:07:24.0320 4840 BthHFEnum - ok 21:07:24.0330 4840 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys 21:07:24.0351 4840 bthhfhid - ok 21:07:24.0375 4840 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys 21:07:24.0399 4840 BTHMODEM - ok 21:07:24.0424 4840 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll 21:07:24.0438 4840 bthserv - ok 21:07:24.0456 4840 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 21:07:24.0481 4840 cdfs - ok 21:07:24.0508 4840 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys 21:07:24.0523 4840 cdrom - ok 21:07:24.0541 4840 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll 21:07:24.0583 4840 CertPropSvc - ok 21:07:24.0607 4840 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys 21:07:24.0641 4840 circlass - ok 21:07:24.0657 4840 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys 21:07:24.0677 4840 CLFS - ok 21:07:24.0694 4840 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys 21:07:24.0714 4840 CmBatt - ok 21:07:24.0735 4840 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys 21:07:24.0760 4840 CNG - ok 21:07:24.0777 4840 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys 21:07:24.0806 4840 CompositeBus - ok 21:07:24.0811 4840 COMSysApp - ok 21:07:24.0830 4840 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys 21:07:24.0849 4840 condrv - ok 21:07:24.0872 4840 [ F0E78B119D12BA81F163D48C0FF30B9A ] CryptSvc C:\Windows\system32\cryptsvc.dll 21:07:24.0894 4840 CryptSvc - ok 21:07:24.0966 4840 [ F2C69C3D98249DE14D4B2832516D4FD5 ] CSC C:\Windows\system32\drivers\csc.sys 21:07:25.0001 4840 CSC - ok 21:07:25.0037 4840 [ 22CCB6AFF617AAC6121DF6CDA5ABF3F4 ] CscService C:\Windows\System32\cscsvc.dll 21:07:25.0078 4840 CscService - ok 21:07:25.0103 4840 [ C4D01BD86D6B207275FC143EEA951D75 ] dam C:\Windows\system32\drivers\dam.sys 21:07:25.0115 4840 dam - ok 21:07:25.0145 4840 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll 21:07:25.0207 4840 DcomLaunch - ok 21:07:25.0221 4840 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll 21:07:25.0245 4840 defragsvc - ok 21:07:25.0264 4840 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll 21:07:25.0293 4840 DeviceAssociationService - ok 21:07:25.0310 4840 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll 21:07:25.0337 4840 DeviceInstall - ok 21:07:25.0347 4840 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys 21:07:25.0375 4840 Dfsc - ok 21:07:25.0395 4840 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll 21:07:25.0413 4840 Dhcp - ok 21:07:25.0423 4840 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys 21:07:25.0441 4840 discache - ok 21:07:25.0456 4840 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys 21:07:25.0469 4840 disk - ok 21:07:25.0493 4840 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys 21:07:25.0511 4840 dmvsc - ok 21:07:25.0527 4840 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll 21:07:25.0552 4840 Dnscache - ok 21:07:25.0573 4840 [ FA122BC1451B1B35B7814FBE1ACF1924 ] Dokan C:\Windows\system32\drivers\dokan.sys 21:07:25.0586 4840 Dokan - ok 21:07:25.0599 4840 [ 8C856E531A1170F53AC6844E89CD0B5F ] DokanMounter C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe 21:07:25.0603 4840 DokanMounter ( UnsignedFile.Multi.Generic ) - warning 21:07:25.0604 4840 DokanMounter - detected UnsignedFile.Multi.Generic (1) 21:07:25.0619 4840 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll 21:07:25.0652 4840 dot3svc - ok 21:07:25.0670 4840 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll 21:07:25.0691 4840 DPS - ok 21:07:25.0712 4840 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 21:07:25.0724 4840 drmkaud - ok 21:07:25.0743 4840 [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll 21:07:25.0766 4840 DsmSvc - ok 21:07:25.0801 4840 [ 898BF1647BBF012B38EF45C7F9F7A67E ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 21:07:25.0846 4840 DXGKrnl - ok 21:07:25.0854 4840 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll 21:07:25.0879 4840 Eaphost - ok 21:07:25.0936 4840 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys 21:07:26.0021 4840 ebdrv - ok 21:07:26.0040 4840 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe 21:07:26.0054 4840 EFS - ok 21:07:26.0078 4840 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys 21:07:26.0091 4840 EhStorClass - ok 21:07:26.0102 4840 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys 21:07:26.0116 4840 EhStorTcgDrv - ok 21:07:26.0124 4840 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys 21:07:26.0152 4840 ErrDev - ok 21:07:26.0180 4840 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll 21:07:26.0206 4840 EventSystem - ok 21:07:26.0221 4840 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys 21:07:26.0252 4840 exfat - ok 21:07:26.0266 4840 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys 21:07:26.0281 4840 fastfat - ok 21:07:26.0315 4840 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe 21:07:26.0342 4840 Fax - ok 21:07:26.0358 4840 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys 21:07:26.0384 4840 fdc - ok 21:07:26.0400 4840 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll 21:07:26.0420 4840 fdPHost - ok 21:07:26.0468 4840 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll 21:07:26.0573 4840 FDResPub - ok 21:07:26.0606 4840 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll 21:07:26.0636 4840 fhsvc - ok 21:07:26.0650 4840 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 21:07:26.0667 4840 FileInfo - ok 21:07:26.0691 4840 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 21:07:26.0720 4840 Filetrace - ok 21:07:26.0733 4840 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys 21:07:26.0754 4840 flpydisk - ok 21:07:26.0771 4840 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 21:07:26.0791 4840 FltMgr - ok 21:07:26.0835 4840 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll 21:07:26.0878 4840 FontCache - ok 21:07:26.0951 4840 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 21:07:26.0975 4840 FontCache3.0.0.0 - ok 21:07:26.0987 4840 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 21:07:26.0999 4840 FsDepends - ok 21:07:27.0005 4840 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 21:07:27.0016 4840 Fs_Rec - ok 21:07:27.0044 4840 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 21:07:27.0066 4840 fvevol - ok 21:07:27.0083 4840 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys 21:07:27.0107 4840 FxPPM - ok 21:07:27.0118 4840 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 21:07:27.0130 4840 gagp30kx - ok 21:07:27.0144 4840 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys 21:07:27.0181 4840 gencounter - ok 21:07:27.0194 4840 [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys 21:07:27.0208 4840 GPIOClx0101 - ok 21:07:27.0241 4840 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll 21:07:27.0283 4840 gpsvc - ok 21:07:27.0317 4840 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 21:07:27.0327 4840 gupdate - ok 21:07:27.0331 4840 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 21:07:27.0338 4840 gupdatem - ok 21:07:27.0360 4840 [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 21:07:27.0393 4840 HdAudAddService - ok 21:07:27.0417 4840 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys 21:07:27.0441 4840 HDAudBus - ok 21:07:27.0464 4840 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys 21:07:27.0481 4840 HidBatt - ok 21:07:27.0508 4840 [ A25BAE8C1F2830C8E5625EC7E4E968BE ] HidBth C:\Windows\System32\drivers\hidbth.sys 21:07:27.0532 4840 HidBth - ok 21:07:27.0543 4840 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys 21:07:27.0563 4840 hidi2c - ok 21:07:27.0577 4840 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys 21:07:27.0609 4840 HidIr - ok 21:07:27.0623 4840 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll 21:07:27.0642 4840 hidserv - ok 21:07:27.0656 4840 [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] HidUsb C:\Windows\System32\drivers\hidusb.sys 21:07:27.0668 4840 HidUsb - ok 21:07:27.0677 4840 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll 21:07:27.0695 4840 hkmsvc - ok 21:07:27.0715 4840 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll 21:07:27.0741 4840 HomeGroupListener - ok 21:07:27.0758 4840 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll 21:07:27.0778 4840 HomeGroupProvider - ok 21:07:27.0796 4840 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 21:07:27.0808 4840 HpSAMD - ok 21:07:27.0842 4840 [ 29CB98187BB5711F7759540976D295FC ] HTTP C:\Windows\system32\drivers\HTTP.sys 21:07:27.0871 4840 HTTP - ok 21:07:27.0890 4840 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 21:07:27.0902 4840 hwpolicy - ok 21:07:27.0918 4840 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys 21:07:27.0935 4840 hyperkbd - ok 21:07:27.0949 4840 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys 21:07:27.0967 4840 HyperVideo - ok 21:07:27.0982 4840 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys 21:07:27.0996 4840 i8042prt - ok 21:07:28.0014 4840 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 21:07:28.0034 4840 iaStorV - ok 21:07:28.0056 4840 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys 21:07:28.0068 4840 iirsp - ok 21:07:28.0103 4840 [ 531B5A98145DA689741A0AC18F14EA94 ] IKEEXT C:\Windows\System32\ikeext.dll 21:07:28.0142 4840 IKEEXT - ok 21:07:28.0161 4840 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys 21:07:28.0172 4840 intelide - ok 21:07:28.0191 4840 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys 21:07:28.0213 4840 intelppm - ok 21:07:28.0226 4840 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 21:07:28.0242 4840 IpFilterDriver - ok 21:07:28.0266 4840 [ CAC5202757EF68C4849B0DFFA75F6D3C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 21:07:28.0306 4840 iphlpsvc - ok 21:07:28.0322 4840 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys 21:07:28.0335 4840 IPMIDRV - ok 21:07:28.0353 4840 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 21:07:28.0380 4840 IPNAT - ok 21:07:28.0388 4840 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys 21:07:28.0413 4840 IRENUM - ok 21:07:28.0425 4840 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys 21:07:28.0437 4840 isapnp - ok 21:07:28.0450 4840 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys 21:07:28.0467 4840 iScsiPrt - ok 21:07:28.0487 4840 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys 21:07:28.0498 4840 kbdclass - ok 21:07:28.0512 4840 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys 21:07:28.0535 4840 kbdhid - ok 21:07:28.0549 4840 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys 21:07:28.0570 4840 kdnic - ok 21:07:28.0581 4840 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe 21:07:28.0607 4840 KeyIso - ok 21:07:28.0625 4840 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 21:07:28.0638 4840 KSecDD - ok 21:07:28.0660 4840 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 21:07:28.0675 4840 KSecPkg - ok 21:07:28.0682 4840 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 21:07:28.0707 4840 ksthunk - ok 21:07:28.0727 4840 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll 21:07:28.0765 4840 KtmRm - ok 21:07:28.0776 4840 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll 21:07:28.0814 4840 LanmanServer - ok 21:07:28.0836 4840 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 21:07:28.0869 4840 LanmanWorkstation - ok 21:07:28.0891 4840 [ FA529FB35694C24BF98A9EF67C1CD9D0 ] LGBusEnum C:\Windows\system32\drivers\LGBusEnum.sys 21:07:28.0899 4840 LGBusEnum - ok 21:07:28.0914 4840 [ F7205E939F50B1C8D16F895916BE6756 ] LGSHidFilt C:\Windows\system32\DRIVERS\LGSHidFilt.Sys 21:07:28.0924 4840 LGSHidFilt - ok 21:07:28.0946 4840 [ 94B29CE153765E768F004FB3440BE2B0 ] LGVirHid C:\Windows\system32\drivers\LGVirHid.sys 21:07:28.0954 4840 LGVirHid - ok 21:07:28.0964 4840 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 21:07:28.0980 4840 lltdio - ok 21:07:28.0996 4840 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll 21:07:29.0017 4840 lltdsvc - ok 21:07:29.0029 4840 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll 21:07:29.0048 4840 lmhosts - ok 21:07:29.0064 4840 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 21:07:29.0078 4840 LSI_SAS - ok 21:07:29.0102 4840 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 21:07:29.0115 4840 LSI_SAS2 - ok 21:07:29.0129 4840 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 21:07:29.0143 4840 LSI_SCSI - ok 21:07:29.0151 4840 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys 21:07:29.0163 4840 LSI_SSS - ok 21:07:29.0178 4840 [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] LSM C:\Windows\System32\lsm.dll 21:07:29.0219 4840 LSM - ok 21:07:29.0233 4840 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys 21:07:29.0254 4840 luafv - ok 21:07:29.0274 4840 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys 21:07:29.0286 4840 megasas - ok 21:07:29.0301 4840 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 21:07:29.0320 4840 MegaSR - ok 21:07:29.0339 4840 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll 21:07:29.0354 4840 MMCSS - ok 21:07:29.0364 4840 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys 21:07:29.0389 4840 Modem - ok 21:07:29.0405 4840 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 21:07:29.0417 4840 monitor - ok 21:07:29.0428 4840 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys 21:07:29.0439 4840 mouclass - ok 21:07:29.0443 4840 [ CB2527B8B87D83E56FBF3944BBB6F606 ] mouhid C:\Windows\System32\drivers\mouhid.sys 21:07:29.0456 4840 mouhid - ok 21:07:29.0462 4840 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 21:07:29.0475 4840 mountmgr - ok 21:07:29.0509 4840 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 21:07:29.0520 4840 MozillaMaintenance - ok 21:07:29.0535 4840 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 21:07:29.0554 4840 mpsdrv - ok 21:07:29.0583 4840 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll 21:07:29.0618 4840 MpsSvc - ok 21:07:29.0634 4840 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 21:07:29.0666 4840 MRxDAV - ok 21:07:29.0690 4840 [ 877D60D6E4156EC4A2E0B6871D41BED9 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 21:07:29.0707 4840 mrxsmb - ok 21:07:29.0723 4840 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 21:07:29.0744 4840 mrxsmb10 - ok 21:07:29.0758 4840 [ E078446D4B8622AA6030C7B8A1A08962 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 21:07:29.0785 4840 mrxsmb20 - ok 21:07:29.0811 4840 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys 21:07:29.0838 4840 MsBridge - ok 21:07:29.0859 4840 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe 21:07:29.0881 4840 MSDTC - ok 21:07:29.0900 4840 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys 21:07:29.0925 4840 Msfs - ok 21:07:29.0952 4840 [ C9BFB0353099B071E70299549C18C8AE ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys 21:07:29.0963 4840 msgpiowin32 - ok 21:07:29.0989 4840 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 21:07:30.0011 4840 mshidkmdf - ok 21:07:30.0021 4840 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys 21:07:30.0043 4840 mshidumdf - ok 21:07:30.0065 4840 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 21:07:30.0076 4840 msisadrv - ok 21:07:30.0101 4840 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll 21:07:30.0128 4840 MSiSCSI - ok 21:07:30.0132 4840 msiserver - ok 21:07:30.0142 4840 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 21:07:30.0154 4840 MSKSSRV - ok 21:07:30.0164 4840 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys 21:07:30.0181 4840 MsLldp - ok 21:07:30.0189 4840 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 21:07:30.0201 4840 MSPCLOCK - ok 21:07:30.0219 4840 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 21:07:30.0231 4840 MSPQM - ok 21:07:30.0250 4840 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 21:07:30.0270 4840 MsRPC - ok 21:07:30.0282 4840 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys 21:07:30.0293 4840 mssmbios - ok 21:07:30.0306 4840 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 21:07:30.0345 4840 MSTEE - ok 21:07:30.0360 4840 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys 21:07:30.0373 4840 MTConfig - ok 21:07:30.0385 4840 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys 21:07:30.0398 4840 Mup - ok 21:07:30.0413 4840 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys 21:07:30.0425 4840 mvumis - ok 21:07:30.0445 4840 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll 21:07:30.0469 4840 napagent - ok 21:07:30.0484 4840 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 21:07:30.0503 4840 NativeWifiP - ok 21:07:30.0515 4840 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll 21:07:30.0532 4840 NcaSvc - ok 21:07:30.0554 4840 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll 21:07:30.0581 4840 NcdAutoSetup - ok 21:07:30.0614 4840 [ 0F89AE618DBA5D8AB7A2DFCC375F4159 ] NDIS C:\Windows\system32\drivers\ndis.sys 21:07:30.0648 4840 NDIS - ok 21:07:30.0653 4840 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 21:07:30.0681 4840 NdisCap - ok 21:07:30.0686 4840 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys 21:07:30.0705 4840 NdisImPlatform - ok 21:07:30.0727 4840 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 21:07:30.0739 4840 NdisTapi - ok 21:07:30.0754 4840 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 21:07:30.0772 4840 Ndisuio - ok 21:07:30.0789 4840 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 21:07:30.0812 4840 NdisWan - ok 21:07:30.0817 4840 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys 21:07:30.0833 4840 NDISWANLEGACY - ok 21:07:30.0849 4840 [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 21:07:30.0862 4840 NDProxy - ok 21:07:30.0886 4840 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys 21:07:30.0912 4840 Ndu - ok 21:07:30.0926 4840 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 21:07:30.0947 4840 NetBIOS - ok 21:07:30.0967 4840 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 21:07:30.0993 4840 NetBT - ok 21:07:31.0008 4840 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe 21:07:31.0022 4840 Netlogon - ok 21:07:31.0044 4840 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll 21:07:31.0076 4840 Netman - ok 21:07:31.0095 4840 [ 20F6FD63E6D456114BC8056D62792786 ] netprofm C:\Windows\System32\netprofmsvc.dll 21:07:31.0127 4840 netprofm - ok 21:07:31.0164 4840 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 21:07:31.0223 4840 NetTcpPortSharing - ok 21:07:31.0244 4840 [ 2D5297BDED9B0E811C6C894EC5A7FAB8 ] networx C:\Windows\system32\drivers\networx.sys 21:07:31.0254 4840 networx - ok 21:07:31.0279 4840 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 21:07:31.0291 4840 nfrd960 - ok 21:07:31.0306 4840 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll 21:07:31.0334 4840 NlaSvc - ok 21:07:31.0350 4840 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys 21:07:31.0363 4840 Npfs - ok 21:07:31.0389 4840 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys 21:07:31.0415 4840 npsvctrig - ok 21:07:31.0426 4840 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll 21:07:31.0451 4840 nsi - ok 21:07:31.0471 4840 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 21:07:31.0495 4840 nsiproxy - ok 21:07:31.0543 4840 [ 4A7EEA9C4AD5CBFDA3C0E5B821C99CAD ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 21:07:31.0613 4840 Ntfs - ok 21:07:31.0631 4840 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys 21:07:31.0648 4840 Null - ok 21:07:31.0861 4840 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 21:07:32.0138 4840 nvlddmkm - ok 21:07:32.0175 4840 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys 21:07:32.0189 4840 nvraid - ok 21:07:32.0206 4840 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys 21:07:32.0221 4840 nvstor - ok 21:07:32.0250 4840 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe 21:07:32.0293 4840 nvsvc - ok 21:07:32.0339 4840 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 21:07:32.0384 4840 nvUpdatusService - ok 21:07:32.0400 4840 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 21:07:32.0414 4840 nv_agp - ok 21:07:32.0440 4840 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 21:07:32.0467 4840 p2pimsvc - ok 21:07:32.0480 4840 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll 21:07:32.0506 4840 p2psvc - ok 21:07:32.0519 4840 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys 21:07:32.0552 4840 Parport - ok 21:07:32.0569 4840 [ C1D7BA7F0DE487DFEEB51BF8D3EC5562 ] partmgr C:\Windows\system32\drivers\partmgr.sys 21:07:32.0581 4840 partmgr - ok 21:07:32.0611 4840 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll 21:07:32.0636 4840 PcaSvc - ok 21:07:32.0657 4840 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys 21:07:32.0673 4840 pci - ok 21:07:32.0682 4840 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys 21:07:32.0693 4840 pciide - ok 21:07:32.0723 4840 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 21:07:32.0739 4840 pcmcia - ok 21:07:32.0763 4840 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys 21:07:32.0775 4840 pcw - ok 21:07:32.0801 4840 [ EF9B4F3136B4C45F421ADE6871659FB6 ] pdc C:\Windows\system32\drivers\pdc.sys 21:07:32.0813 4840 pdc - ok 21:07:32.0837 4840 [ 70DBB6A8B52B3830922F1C5789E1BEEB ] PEAUTH C:\Windows\system32\drivers\peauth.sys 21:07:32.0872 4840 PEAUTH - ok 21:07:32.0915 4840 [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 21:07:32.0970 4840 PeerDistSvc - ok 21:07:33.0032 4840 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe 21:07:33.0091 4840 PerfHost - ok 21:07:33.0139 4840 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll 21:07:33.0198 4840 pla - ok 21:07:33.0217 4840 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 21:07:33.0244 4840 PlugPlay - ok 21:07:33.0267 4840 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 21:07:33.0292 4840 PNRPAutoReg - ok 21:07:33.0299 4840 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 21:07:33.0316 4840 PNRPsvc - ok 21:07:33.0342 4840 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 21:07:33.0382 4840 PolicyAgent - ok 21:07:33.0400 4840 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll 21:07:33.0416 4840 Power - ok 21:07:33.0426 4840 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 21:07:33.0451 4840 PptpMiniport - ok 21:07:33.0547 4840 [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll 21:07:33.0611 4840 PrintNotify - ok 21:07:33.0624 4840 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys 21:07:33.0648 4840 Processor - ok 21:07:33.0657 4840 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll 21:07:33.0690 4840 ProfSvc - ok 21:07:33.0713 4840 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys 21:07:33.0736 4840 Psched - ok 21:07:33.0762 4840 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll 21:07:33.0792 4840 QWAVE - ok 21:07:33.0805 4840 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 21:07:33.0819 4840 QWAVEdrv - ok 21:07:33.0849 4840 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 21:07:33.0882 4840 RasAcd - ok 21:07:33.0905 4840 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 21:07:33.0940 4840 RasAgileVpn - ok 21:07:33.0958 4840 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll 21:07:33.0983 4840 RasAuto - ok 21:07:33.0997 4840 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 21:07:34.0013 4840 Rasl2tp - ok 21:07:34.0036 4840 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll 21:07:34.0066 4840 RasMan - ok 21:07:34.0080 4840 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 21:07:34.0096 4840 RasPppoe - ok 21:07:34.0110 4840 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 21:07:34.0126 4840 RasSstp - ok 21:07:34.0150 4840 [ B72C33DBD5326B3864CF2091AF8B906B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 21:07:34.0173 4840 rdbss - ok 21:07:34.0187 4840 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys 21:07:34.0200 4840 rdpbus - ok 21:07:34.0211 4840 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 21:07:34.0233 4840 RDPDR - ok 21:07:34.0254 4840 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 21:07:34.0265 4840 RdpVideoMiniport - ok 21:07:34.0280 4840 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 21:07:34.0310 4840 RDPWD - ok 21:07:34.0327 4840 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 21:07:34.0342 4840 rdyboost - ok 21:07:34.0364 4840 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll 21:07:34.0395 4840 RemoteAccess - ok 21:07:34.0420 4840 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll 21:07:34.0452 4840 RemoteRegistry - ok 21:07:34.0477 4840 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 21:07:34.0502 4840 RpcEptMapper - ok 21:07:34.0519 4840 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe 21:07:34.0543 4840 RpcLocator - ok 21:07:34.0567 4840 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll 21:07:34.0598 4840 RpcSs - ok 21:07:34.0611 4840 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 21:07:34.0639 4840 rspndr - ok 21:07:34.0667 4840 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys 21:07:34.0699 4840 RTL8168 - ok 21:07:34.0712 4840 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys 21:07:34.0733 4840 s3cap - ok 21:07:34.0741 4840 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe 21:07:34.0756 4840 SamSs - ok 21:07:34.0773 4840 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 21:07:34.0786 4840 sbp2port - ok 21:07:34.0808 4840 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll 21:07:34.0829 4840 SCardSvr - ok 21:07:34.0848 4840 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 21:07:34.0871 4840 scfilter - ok 21:07:34.0900 4840 [ EDCDF4DB82EF825B94B190D544C8C58B ] Schedule C:\Windows\system32\schedsvc.dll 21:07:34.0940 4840 Schedule - ok 21:07:34.0964 4840 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll 21:07:34.0982 4840 SCPolicySvc - ok 21:07:35.0005 4840 [ 66E29CADF9FF6C8325C356BDD617F7EA ] sdbus C:\Windows\System32\drivers\sdbus.sys 21:07:35.0020 4840 sdbus - ok 21:07:35.0031 4840 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll 21:07:35.0048 4840 SDRSVC - ok 21:07:35.0070 4840 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys 21:07:35.0081 4840 sdstor - ok 21:07:35.0096 4840 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 21:07:35.0118 4840 secdrv - ok 21:07:35.0138 4840 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll 21:07:35.0163 4840 seclogon - ok 21:07:35.0185 4840 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll 21:07:35.0216 4840 SENS - ok 21:07:35.0230 4840 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll 21:07:35.0247 4840 SensrSvc - ok 21:07:35.0262 4840 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys 21:07:35.0283 4840 SerCx - ok 21:07:35.0298 4840 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys 21:07:35.0322 4840 Serenum - ok 21:07:35.0334 4840 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys 21:07:35.0356 4840 Serial - ok 21:07:35.0365 4840 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys 21:07:35.0387 4840 sermouse - ok 21:07:35.0413 4840 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll 21:07:35.0432 4840 SessionEnv - ok 21:07:35.0443 4840 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys 21:07:35.0464 4840 sfloppy - ok 21:07:35.0485 4840 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll 21:07:35.0515 4840 SharedAccess - ok 21:07:35.0540 4840 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll 21:07:35.0570 4840 ShellHWDetection - ok 21:07:35.0588 4840 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 21:07:35.0600 4840 SiSRaid2 - ok 21:07:35.0612 4840 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 21:07:35.0625 4840 SiSRaid4 - ok 21:07:35.0650 4840 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 21:07:35.0673 4840 SNMPTRAP - ok 21:07:35.0688 4840 [ 465F3C355CE5ED2779B8F460F14C5A78 ] spaceport C:\Windows\system32\drivers\spaceport.sys 21:07:35.0705 4840 spaceport - ok 21:07:35.0716 4840 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys 21:07:35.0740 4840 SpbCx - ok 21:07:35.0766 4840 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe 21:07:35.0793 4840 Spooler - ok 21:07:35.0890 4840 [ EC84D961501054F87A6878EC5D53388F ] sppsvc C:\Windows\system32\sppsvc.exe 21:07:35.0991 4840 sppsvc - ok 21:07:36.0010 4840 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys 21:07:36.0039 4840 srv - ok 21:07:36.0067 4840 [ C2106BB710AA34A046126AED7BCA6964 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 21:07:36.0092 4840 srv2 - ok 21:07:36.0111 4840 [ 9400C71F5A1A380B494B6922F007D485 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 21:07:36.0126 4840 srvnet - ok 21:07:36.0140 4840 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 21:07:36.0161 4840 SSDPSRV - ok 21:07:36.0184 4840 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll 21:07:36.0203 4840 SstpSvc - ok 21:07:36.0217 4840 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys 21:07:36.0228 4840 stexstor - ok 21:07:36.0263 4840 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll 21:07:36.0286 4840 stisvc - ok 21:07:36.0307 4840 [ C588BBD37B432CE3204E5765B459E6B2 ] storahci C:\Windows\system32\drivers\storahci.sys 21:07:36.0320 4840 storahci - ok 21:07:36.0334 4840 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys 21:07:36.0347 4840 storflt - ok 21:07:36.0364 4840 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll 21:07:36.0379 4840 StorSvc - ok 21:07:36.0388 4840 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys 21:07:36.0400 4840 storvsc - ok 21:07:36.0416 4840 [ 1A36AC469140F87CDE62D7F8524E270C ] storvsp C:\Windows\System32\drivers\storvsp.sys 21:07:36.0429 4840 storvsp - ok 21:07:36.0443 4840 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll 21:07:36.0474 4840 svsvc - ok 21:07:36.0486 4840 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys 21:07:36.0497 4840 swenum - ok 21:07:36.0520 4840 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll 21:07:36.0557 4840 swprv - ok 21:07:36.0589 4840 [ DC21E1F06343773D7E24362DCEF7944B ] SysMain C:\Windows\system32\sysmain.dll 21:07:36.0645 4840 SysMain - ok 21:07:36.0666 4840 [ E219BF7BCCFE4881B0C053C7E0B47ECC ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll 21:07:36.0682 4840 SystemEventsBroker - ok 21:07:36.0697 4840 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll 21:07:36.0715 4840 TabletInputService - ok 21:07:36.0731 4840 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll 21:07:36.0751 4840 TapiSrv - ok 21:07:36.0795 4840 [ 1D644E2D0FC395A055AB1C23C3B43631 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 21:07:36.0856 4840 Tcpip - ok 21:07:36.0885 4840 [ 1D644E2D0FC395A055AB1C23C3B43631 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 21:07:36.0937 4840 TCPIP6 - ok 21:07:36.0950 4840 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 21:07:36.0966 4840 tcpipreg - ok 21:07:36.0984 4840 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 21:07:37.0015 4840 tdx - ok 21:07:37.0030 4840 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys 21:07:37.0041 4840 terminpt - ok 21:07:37.0061 4840 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll 21:07:37.0098 4840 TermService - ok 21:07:37.0117 4840 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll 21:07:37.0139 4840 Themes - ok 21:07:37.0163 4840 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll 21:07:37.0232 4840 THREADORDER - ok 21:07:37.0251 4840 [ FF4135424A79DCC2998276D8E39C9B4D ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll 21:07:37.0275 4840 TimeBroker - ok 21:07:37.0296 4840 [ B44EFE254C0B3719E4037088D24FE4B5 ] TPM C:\Windows\system32\drivers\tpm.sys 21:07:37.0316 4840 TPM - ok 21:07:37.0327 4840 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll 21:07:37.0351 4840 TrkWks - ok 21:07:37.0390 4840 [ 8D516AEF3C1DF980664CF17BB1FF6093 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 21:07:37.0408 4840 TrustedInstaller - ok 21:07:37.0417 4840 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 21:07:37.0429 4840 TsUsbFlt - ok 21:07:37.0440 4840 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys 21:07:37.0453 4840 TsUsbGD - ok 21:07:37.0465 4840 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 21:07:37.0482 4840 tunnel - ok 21:07:37.0504 4840 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys 21:07:37.0516 4840 uagp35 - ok 21:07:37.0531 4840 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys 21:07:37.0544 4840 UASPStor - ok 21:07:37.0561 4840 [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys 21:07:37.0576 4840 UCX01000 - ok 21:07:37.0590 4840 [ DC5A461591C71AF7F19DC048A81E3F88 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 21:07:37.0612 4840 udfs - ok 21:07:37.0632 4840 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe 21:07:37.0652 4840 UI0Detect - ok 21:07:37.0667 4840 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 21:07:37.0680 4840 uliagpkx - ok 21:07:37.0694 4840 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys 21:07:37.0714 4840 umbus - ok 21:07:37.0725 4840 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys 21:07:37.0847 4840 UmPass - ok 21:07:37.0875 4840 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll 21:07:37.0905 4840 UmRdpService - ok 21:07:37.0933 4840 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll 21:07:37.0959 4840 upnphost - ok 21:07:37.0978 4840 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp C:\Windows\System32\drivers\usbccgp.sys 21:07:38.0002 4840 usbccgp - ok 21:07:38.0018 4840 [ B395B62B62F28106218FA6FB17F4C797 ] usbcir C:\Windows\System32\drivers\usbcir.sys 21:07:38.0058 4840 usbcir - ok 21:07:38.0078 4840 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci C:\Windows\System32\drivers\usbehci.sys 21:07:38.0090 4840 usbehci - ok 21:07:38.0104 4840 [ FBB6794E3BBAD92D66D59D206C1F849F ] usbhub C:\Windows\System32\drivers\usbhub.sys 21:07:38.0126 4840 usbhub - ok 21:07:38.0142 4840 [ B7A948501424805571BF562BB0BFE31D ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys 21:07:38.0163 4840 USBHUB3 - ok 21:07:38.0176 4840 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys 21:07:38.0188 4840 usbohci - ok 21:07:38.0198 4840 [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint C:\Windows\System32\drivers\usbprint.sys 21:07:38.0216 4840 usbprint - ok 21:07:38.0232 4840 [ F77177F6C95B2116EE7AD23B5EF57007 ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS 21:07:38.0245 4840 USBSTOR - ok 21:07:38.0254 4840 [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci C:\Windows\System32\drivers\usbuhci.sys 21:07:38.0277 4840 usbuhci - ok 21:07:38.0302 4840 [ 9CD4259AD15F84DE27B94A956C978D6C ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS 21:07:38.0320 4840 USBXHCI - ok 21:07:38.0335 4840 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe 21:07:38.0349 4840 VaultSvc - ok 21:07:38.0365 4840 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 21:07:38.0376 4840 vdrvroot - ok 21:07:38.0401 4840 [ 8A8CDA9E3CF2E0B4C6CC19FBC6FB9A71 ] vds C:\Windows\System32\vds.exe 21:07:38.0426 4840 vds - ok 21:07:38.0449 4840 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys 21:07:38.0462 4840 VerifierExt - ok 21:07:38.0483 4840 [ 8628FA679F0EC4B709CCD1F6B6A3233B ] vhdmp C:\Windows\System32\drivers\vhdmp.sys 21:07:38.0505 4840 vhdmp - ok 21:07:38.0536 4840 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys 21:07:38.0547 4840 viaide - ok 21:07:38.0559 4840 [ 0E43886F01C85B47BA0A3157274BCF59 ] Vid C:\Windows\System32\drivers\Vid.sys 21:07:38.0587 4840 Vid - ok 21:07:38.0602 4840 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys 21:07:38.0616 4840 vmbus - ok 21:07:38.0639 4840 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys 21:07:38.0650 4840 VMBusHID - ok 21:07:38.0662 4840 [ B4F432A51826FFC66F4DF72A83E8E4B1 ] vmbusr C:\Windows\System32\drivers\vmbusr.sys 21:07:38.0675 4840 vmbusr - ok 21:07:38.0697 4840 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll 21:07:38.0715 4840 vmicheartbeat - ok 21:07:38.0721 4840 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll 21:07:38.0737 4840 vmickvpexchange - ok 21:07:38.0743 4840 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll 21:07:38.0759 4840 vmicrdv - ok 21:07:38.0765 4840 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll 21:07:38.0781 4840 vmicshutdown - ok 21:07:38.0787 4840 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll 21:07:38.0803 4840 vmictimesync - ok 21:07:38.0809 4840 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll 21:07:38.0825 4840 vmicvss - ok 21:07:38.0840 4840 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys 21:07:38.0852 4840 volmgr - ok 21:07:38.0866 4840 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 21:07:38.0885 4840 volmgrx - ok 21:07:38.0902 4840 [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE ] volsnap C:\Windows\system32\drivers\volsnap.sys 21:07:38.0920 4840 volsnap - ok 21:07:38.0941 4840 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys 21:07:38.0953 4840 vpci - ok 21:07:38.0966 4840 [ 0190AFFF28F600461C0164353CC7EE27 ] vpcivsp C:\Windows\System32\drivers\vpcivsp.sys 21:07:38.0986 4840 vpcivsp - ok 21:07:39.0002 4840 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 21:07:39.0016 4840 vsmraid - ok 21:07:39.0050 4840 [ EA658570314042C914964FC72AB50E6B ] VSS C:\Windows\system32\vssvc.exe 21:07:39.0110 4840 VSS - ok 21:07:39.0126 4840 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys 21:07:39.0144 4840 VSTXRAID - ok 21:07:39.0154 4840 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 21:07:39.0166 4840 vwifibus - ok 21:07:39.0192 4840 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll 21:07:39.0223 4840 W32Time - ok 21:07:39.0234 4840 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys 21:07:39.0252 4840 WacomPen - ok 21:07:39.0267 4840 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 21:07:39.0290 4840 Wanarp - ok 21:07:39.0293 4840 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 21:07:39.0305 4840 Wanarpv6 - ok 21:07:39.0341 4840 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe 21:07:39.0388 4840 wbengine - ok 21:07:39.0407 4840 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 21:07:39.0451 4840 WbioSrvc - ok 21:07:39.0470 4840 [ D9C1E82651BF19C6FF69CEC6FD400124 ] Wcmsvc C:\Windows\System32\wcmsvc.dll 21:07:39.0489 4840 Wcmsvc - ok 21:07:39.0516 4840 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll 21:07:39.0538 4840 wcncsvc - ok 21:07:39.0550 4840 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 21:07:39.0566 4840 WcsPlugInService - ok 21:07:39.0574 4840 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys 21:07:39.0585 4840 Wd - ok 21:07:39.0612 4840 [ 260F8DFC4D5748F4CCB9B19CFB0E58EA ] WdBoot C:\Windows\system32\drivers\WdBoot.sys 21:07:39.0625 4840 WdBoot - ok 21:07:39.0659 4840 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 21:07:39.0684 4840 Wdf01000 - ok 21:07:39.0710 4840 [ 880FFFC4D5BBBB4187B6B04AB2E8C32A ] WdFilter C:\Windows\system32\drivers\WdFilter.sys 21:07:39.0727 4840 WdFilter - ok 21:07:39.0745 4840 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll 21:07:39.0767 4840 WdiServiceHost - ok 21:07:39.0771 4840 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll 21:07:39.0793 4840 WdiSystemHost - ok 21:07:39.0813 4840 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll 21:07:39.0842 4840 WebClient - ok 21:07:39.0853 4840 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll 21:07:39.0884 4840 Wecsvc - ok 21:07:39.0905 4840 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll 21:07:39.0931 4840 wercplsupport - ok 21:07:39.0941 4840 [ 8E2426162ED6749A127B35D235F21E11 ] WerSvc C:\Windows\System32\WerSvc.dll 21:07:39.0973 4840 WerSvc - ok 21:07:39.0989 4840 [ FE762D3498719C3A23471BBA62F747B4 ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys 21:07:40.0002 4840 WFPLWFS - ok 21:07:40.0018 4840 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll 21:07:40.0035 4840 WiaRpc - ok 21:07:40.0055 4840 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys 21:07:40.0067 4840 WIMMount - ok 21:07:40.0080 4840 WinDefend - ok 21:07:40.0107 4840 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll 21:07:40.0147 4840 WinHttpAutoProxySvc - ok 21:07:40.0175 4840 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 21:07:40.0201 4840 Winmgmt - ok 21:07:40.0255 4840 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll 21:07:40.0320 4840 WinRM - ok 21:07:40.0343 4840 [ BB20956C424531003F7FA6CD36F11D5D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 21:07:40.0374 4840 WinUsb - ok 21:07:40.0406 4840 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll 21:07:40.0456 4840 WlanSvc - ok 21:07:40.0490 4840 [ 08EFA13A2234C8C3B8A99E4B88BE7E9B ] wlidsvc C:\Windows\system32\wlidsvc.dll 21:07:40.0545 4840 wlidsvc - ok 21:07:40.0559 4840 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys 21:07:40.0575 4840 WmiAcpi - ok 21:07:40.0599 4840 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 21:07:40.0615 4840 wmiApSrv - ok 21:07:40.0624 4840 WMPNetworkSvc - ok 21:07:40.0642 4840 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys 21:07:40.0655 4840 wpcfltr - ok 21:07:40.0673 4840 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll 21:07:40.0699 4840 WPCSvc - ok 21:07:40.0718 4840 [ 94AA5150E35B3ABB7191FE641E3C2473 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 21:07:40.0734 4840 WPDBusEnum - ok 21:07:40.0743 4840 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys 21:07:40.0767 4840 WpdUpFltr - ok 21:07:40.0784 4840 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 21:07:40.0802 4840 ws2ifsl - ok 21:07:40.0814 4840 [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] wscsvc C:\Windows\System32\wscsvc.dll 21:07:40.0832 4840 wscsvc - ok 21:07:40.0846 4840 [ 74EFDA0526862C3D8D01A776182798EA ] WSDPrintDevice C:\Windows\System32\drivers\WSDPrint.sys 21:07:40.0876 4840 WSDPrintDevice - ok 21:07:40.0913 4840 [ FA07DF46070F0826139709EF4D31FB71 ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys 21:07:40.0944 4840 WSDScan - ok 21:07:40.0949 4840 WSearch - ok 21:07:41.0051 4840 [ C10BFFEE7E0D7A1366E84F251796C51D ] WSService C:\Windows\System32\WSService.dll 21:07:41.0129 4840 WSService - ok 21:07:41.0217 4840 [ A8484C0CB54DB48180FB7CA00F1C3F8F ] wuauserv C:\Windows\system32\wuaueng.dll 21:07:41.0283 4840 wuauserv - ok 21:07:41.0308 4840 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 21:07:41.0348 4840 WudfPf - ok 21:07:41.0360 4840 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys 21:07:41.0382 4840 WUDFRd - ok 21:07:41.0388 4840 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFSensorLP C:\Windows\system32\DRIVERS\WUDFRd.sys 21:07:41.0402 4840 WUDFSensorLP - ok 21:07:41.0414 4840 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 21:07:41.0439 4840 wudfsvc - ok 21:07:41.0445 4840 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys 21:07:41.0458 4840 WUDFWpdFs - ok 21:07:41.0465 4840 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdMtp C:\Windows\system32\DRIVERS\WUDFRd.sys 21:07:41.0478 4840 WUDFWpdMtp - ok 21:07:41.0500 4840 [ F9D8D2E6ECE08B278621D5BF3A7240A6 ] WwanSvc C:\Windows\System32\wwansvc.dll 21:07:41.0534 4840 WwanSvc - ok 21:07:41.0540 4840 ================ Scan global =============================== 21:07:41.0566 4840 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll 21:07:41.0581 4840 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll 21:07:41.0601 4840 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll 21:07:41.0620 4840 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe 21:07:41.0627 4840 [Global] - ok 21:07:41.0628 4840 ================ Scan MBR ================================== 21:07:41.0644 4840 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 21:07:41.0845 4840 \Device\Harddisk0\DR0 - ok 21:07:41.0845 4840 ================ Scan VBR ================================== 21:07:41.0848 4840 [ 3B49462D10A4147876879F463AE1F144 ] \Device\Harddisk0\DR0\Partition1 21:07:41.0850 4840 \Device\Harddisk0\DR0\Partition1 - ok 21:07:41.0875 4840 [ 76A1224D57C1342363DD7652997BC540 ] \Device\Harddisk0\DR0\Partition2 21:07:41.0876 4840 \Device\Harddisk0\DR0\Partition2 - ok 21:07:41.0890 4840 [ 6DAFC3D82D062347A50DE94FA41AA330 ] \Device\Harddisk0\DR0\Partition3 21:07:41.0891 4840 \Device\Harddisk0\DR0\Partition3 - ok 21:07:41.0892 4840 ============================================================ 21:07:41.0892 4840 Scan finished 21:07:41.0892 4840 ============================================================ 21:07:41.0901 5096 Detected object count: 1 21:07:41.0901 5096 Actual detected object count: 1 21:07:52.0099 5096 DokanMounter ( UnsignedFile.Multi.Generic ) - skipped by user 21:07:52.0099 5096 DokanMounter ( UnsignedFile.Multi.Generic ) - User select action: Skip Geändert von Hannes4487 (16.01.2013 um 21:55 Uhr) |
16.01.2013, 22:35 | #6 |
/// Malware-holic | Werbebanner by Browse to Save - Virus hi sorry, hatte mich bei der Versionsnummer von windows verlesen. ytes: Downloade Dir bitte Malwarebytes
__________________ --> Werbebanner by Browse to Save - Virus |
17.01.2013, 00:22 | #7 |
| Werbebanner by Browse to Save - VirusCode:
ATTFilter Malwarebytes Anti-Malware (Test) 1.70.0.1100 www.malwarebytes.org Datenbank Version: v2013.01.16.09 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16466 xxx:: yyy[Administrator] Schutz: Aktiviert 16.01.2013 22:56:55 mbam-log-2013-01-16 (22-56-55).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 690461 Laufzeit: 1 Stunde(n), 23 Minute(n), 2 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
17.01.2013, 15:29 | #8 |
/// Malware-holic | Werbebanner by Browse to Save - Virus Hi, lade den CCleaner standard: CCleaner - Download - Filepony falls der CCleaner bereits instaliert, überspringen. öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen. hinter, jedes von dir benötigte programm, schreibe notwendig. hinter, jedes, von dir nicht benötigte, unnötig. hinter, dir unbekannte, unbekannt. liste posten.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
17.01.2013, 17:10 | #9 |
| Werbebanner by Browse to Save - VirusCode:
ATTFilter Adobe Reader XI (11.0.01) - Deutsch Adobe Systems Incorporated 10.01.2013 135MB 11.0.01 notwendig Advanced Tactical Center™ 1.12 Foolish Entertainment 01.01.2013 12,6MB 1.1.2.0 notwendig ArgoUML 0.34 04.01.2013 0.34 notwendig avast! Free Antivirus AVAST Software 16.01.2013 7.0.1474.0 notwendig Canon MG5200 series MP Drivers 04.01.2013 notwendig CCleaner Piriform 19.12.2012 3.26 notwendig Dokan Library 0.6.0 01.01.2013 notwendig Google Chrome Google Inc. 28.12.2012 24.0.1312.52 notwendig Java 7 Update 11 (64-bit) Oracle 16.01.2013 127MB 7.0.110 notwendig Java(TM) 6 Update 2 Sun Microsystems, Inc. 04.01.2013 160MB 1.6.0.20 unnötig Java(TM) 6 Update 38 Oracle 05.01.2013 95,7MB 6.0.380 unnötig Logitech Gaming Software 8.40 Logitech Inc. 30.12.2012 89,7MB 8.40.83 notwendig Malwarebytes Anti-Malware Version 1.70.0.1100 Malwarebytes Corporation 16.01.2013 18,5MB 1.70.0.1100 notwendig Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 30.12.2012 13,2MB 9.0.30729 unbekannt Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 02.01.2013 13,2MB 9.0.30729.6161 unbekannt Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 28.12.2012 10,2MB 9.0.30729 unbekannt Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 16.01.2013 9,54MB 9.0.30729.4148 unbekannt Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 02.01.2013 10,1MB 9.0.30729.6161 unbekannt Mozilla Firefox 17.0.1 (x86 de) Mozilla 01.01.2013 41,0MB 17.0.1 notwendig Mozilla Maintenance Service Mozilla 01.01.2013 216KB 17.0.1 unbekannt NetWorx 5.2.7 Softperfect Research 04.01.2013 8,61MB notwendig NVIDIA Grafiktreiber 306.97 NVIDIA Corporation 05.01.2013 306.97 notwendig NVIDIA PhysX-Systemsoftware 9.12.1031 NVIDIA Corporation 30.12.2012 9.12.1031 notwendig NVIDIA Update 1.10.8 NVIDIA Corporation 05.01.2013 1.10.8 unbekannt OpenOffice.org 3.4.1 Apache Software Foundation 02.01.2013 332MB 3.41.9593 notwendig PDFCreator pdfforge 09.01.2013 1.6.1 notwendig SaveByclick SaveByClick 05.08.2012 unbekannt // <-- Das gab ich auch schon im verdacht... TeamSpeak 3 Client TeamSpeak Systems GmbH 01.01.2013 3.0.6 notwendig VLC media player 2.0.5 VideoLAN 16.01.2013 2.0.5 notwendig World of Tanks Wargaming.net 28.12.2012 16,5MB notwendig |
17.01.2013, 18:12 | #10 |
/// Malware-holic | Werbebanner by Browse to Save - Virus deinstaliere: Java alle außer 7 update 11 SaveByclick Öffne CCleaner, analysieren, starten, PC neustarten. Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
17.01.2013, 19:18 | #11 |
| Werbebanner by Browse to Save - VirusCode:
ATTFilter # AdwCleaner v2.106 - Datei am 17/01/2013 um 19:16:53 erstellt # Aktualisiert am 17/01/2013 von Xplode # Betriebssystem : Windows 8 Pro (64 bits) # Benutzer : xxx- yyy # Bootmodus : Normal # Ausgeführt unter : C:\Users\xxx\Desktop\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16453 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v17.0.1 (de) Datei : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\v5nho49b.default\prefs.js Gefunden : user_pref("extensions.50ed2df0e3a02.scode", "(function(){try{if('aol.com,mail.google.com,mystart.inc[...] -\\ Google Chrome v24.0.1312.52 Datei : C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1342 octets] - [16/01/2013 00:34:40] AdwCleaner[R2].txt - [1004 octets] - [17/01/2013 19:16:53] AdwCleaner[S1].txt - [1404 octets] - [16/01/2013 00:44:29] ########## EOF - C:\AdwCleaner[R2].txt - [1124 octets] ########## |
17.01.2013, 20:38 | #12 |
/// Malware-holic | Werbebanner by Browse to Save - Virus hi, Downloade Dir bitte AdwCleaner auf deinen Desktop.
neustarten, testen, wie PC + Programme laufen, auch die Suchfunktion der instalierten Browser.
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
18.01.2013, 12:56 | #13 |
| Werbebanner by Browse to Save - Virus Hier das Logfile: Code:
ATTFilter # AdwCleaner v2.106 - Datei am 18/01/2013 um 12:38:34 erstellt # Aktualisiert am 17/01/2013 von Xplode # Betriebssystem : Windows 8 Pro (64 bits) # Benutzer : xxx - yyy # Bootmodus : Normal # Ausgeführt unter : C:\Users\xxx\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16453 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v17.0.1 (de) Datei : C:\Users\Hannes\AppData\Roaming\Mozilla\Firefox\Profiles\v5nho49b.default\prefs.js Gelöscht : user_pref("extensions.50ed2df0e3a02.scode", "(function(){try{if('aol.com,mail.google.com,mystart.inc[...] -\\ Google Chrome v24.0.1312.52 Datei : C:\Users\Hannes\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1342 octets] - [16/01/2013 00:34:40] AdwCleaner[R2].txt - [1193 octets] - [17/01/2013 19:16:53] AdwCleaner[S1].txt - [1404 octets] - [16/01/2013 00:44:29] AdwCleaner[S2].txt - [1126 octets] - [18/01/2013 12:38:34] ########## EOF - C:\AdwCleaner[S2].txt - [1186 octets] ########## Bis hierher schon mal vielen Dank! |
18.01.2013, 18:05 | #14 |
/// Malware-holic | Werbebanner by Browse to Save - Virus Hi wenns so bleibt: öffne OTL, bereinigen, PC startet neu, Remover werden gelöscht. Lösche über gebliebene Logs, Remover, Setups, leere den Papierkorb. PC absichern: als antimalware programm würde ich emsisoft empfehlen. diese haben für mich den besten schutz kostet aber etwas. Computeractive Software Store - Emsisoft Anti-Malware 7 [1-PC] - 63% off RRP testversion: Meine Antivirus-Empfehlung: Emsisoft Anti-Malware insbesondere wenn du onlinebanking, einkäufe, sonstige zahlungsabwicklungen oder ähnlich wichtiges, wie zb berufliches machst, also sensible daten zu schützen sind, solltest du in sicherheitssoftware investieren. vor dem aktivieren der lizenz die 30 tage testzeitraum ausnutzen. kostenlos, aber eben nicht ganz so gut währe avast zu empfehlen. http://www.trojaner-board.de/110895-...antivirus.html sag mir welches du nutzt, dann gebe ich konfigurationshinweise. bitte dein bisheriges av deinstalieren die folgende anleitung ist umfangreich, dass ist mir klar, sie sollte aber umgesetzt werden, da nur dann dein pc sicher ist. stelle so viele fragen wie nötig, ich arbeite gern alles mit dir durch! http://www.trojaner-board.de/96344-a...-rechners.html Starte bitte mit der Passage, Windows Vista und Windows 7 Bitte beginne damit, Windows Updates zu instalieren. Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst. Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist: - Updates automatisch Instalieren, - Täglich - Uhrzeit wählen - Bitte den gesammten rest anhaken, außer: - detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist. Klicke jetzt die Schaltfläche "OK" Klicke jetzt "nach Updates suchen". Bitte instaliere zunächst wichtige Updates. Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren. Mache das selbe bitte mit den optionalen Updates. Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist. aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen. als browser rate ich dir zu chrome: Installation von Google Chrome für mehrere Nutzerkonten - Google Chrome-Hilfe anleitung lesen bitte falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung anpassen. Sandboxie Die devinition einer Sandbox ist hier nachzulesen: Sandbox Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen. Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen. Download Link: Sandboxie - Download - Filepony anleitung: http://www.trojaner-board.de/71542-a...sandboxie.html ausführliche anleitung als pdf, auch abarbeiten: Sandbox Einstellungen | bitte folgende zusatz konfiguration machen: sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen. dort klicke auf sandbox einstellungen. beschrenkungen, bei programm start und internet zugriff schreibe: chrome.exe dann gehe auf anwendungen, webbrowser, chrome. dort aktiviere alles außer gesammten profil ordner freigeben. Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen. Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate. Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten. Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten. Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar. Weiter mit: Maßnahmen für ALLE Windows-Versionen alles komplett durcharbeiten anmerkung zu file hippo. in den settings zusätzlich auswählen: hide beta updates. Run updateChecker when Windows starts Backup Programm: in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an: http://www.trojaner-board.de/82962-w...en-backup.html Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar. Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist. Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern bitte auch lesen, wie mache ich programme für alle sichtbar: Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox. wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird Sandboxie immer gestartet wenn du nen browser aufrufst. wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser passwort sicherheit: jeder dienst benötigt ein eigenes, mindestens 12-stelliges passwort bei der passwort verwaltung und erstellung hilft roboform Passwort Manager, Formular Ausfueller, Passwort Management | RoboForm Passwort Manager anleitung: RoboForm-Bedienungsanleitung: Passwort-Manager, Verwalten von Passwörtern und persönlichen Daten
__________________ -Verdächtige mails bitte an uns zur Analyse weiterleiten: markusg.trojaner-board@web.de Weiterleiten Anleitung: http://markusg.trojaner-board.de Mails bitte vorerst nach obiger Anleitung an markusg.trojaner-board@web.de Weiterleiten Wenn Ihr uns unterstützen möchtet |
Themen zu Werbebanner by Browse to Save - Virus |
appdata, betriebssystem, browse to save, browser, code, datei, dateien, dienste, explorer, firefox, folge, forum, gelöscht, internet, internet browser, internet explorer, links, löschen, modus, mozilla, ordner, registrierungsdatenbank, roaming, software, trojaner-board, virus, webseiten, windows, windows 8 pro |