Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Windowssystem gesperrt, Malwarebytes ausgeführt (https://www.trojaner-board.de/111953-windowssystem-gesperrt-malwarebytes-ausgefuehrt.html)

Madame 20.03.2012 16:04

Windowssystem gesperrt, Malwarebytes ausgeführt
 
Hallo Ihr Lieben,

bei der aktuellen Welle des (ehemaligen) BKA-Virus hat es mich gestern auch erwischt.
Im Autostart habe ich - wie viele andere, wie ich über die Google-Suche weiß - die SkypePM.exe gefunden, sie deaktiviert und konnte so wieder auf Windows zugreifen.
Ich habe dann das Programm Malwarebytes ausgeführt und die entsprechenden Funde gelöscht bzw. in Quarantäne geschoben.

Jetzt wüsste ich gerne, ob das nun ausreicht und falls nein, was die nächsten Schritte wären.
Hier das OTL- und das Extra-Protokoll:

Code:

OTL logfile created on: 20.03.2012 15:26:10 - Run 1
OTL by OldTimer - Version 3.2.39.1    Folder = C:\Users\Administrator\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,60 Gb Total Physical Memory | 2,33 Gb Available Physical Memory | 64,76% Memory free
7,21 Gb Paging File | 5,54 Gb Available in Paging File | 76,88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 254,14 Gb Total Space | 42,06 Gb Free Space | 16,55% Space Free | Partition Type: NTFS
Drive D: | 29,00 Gb Total Space | 26,97 Gb Free Space | 93,02% Space Free | Partition Type: NTFS
 
Computer Name: SARA-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.03.20 15:25:12 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Downloads\OTL.exe
PRC - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.01.13 14:53:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.11.22 09:59:30 | 000,018,432 | ---- | M] () -- C:\Users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe
PRC - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 13:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.02.27 12:40:21 | 000,329,056 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2010.12.05 02:39:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
PRC - [2010.01.19 11:44:40 | 000,536,576 | ---- | M] (Vimicro) -- C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
PRC - [2009.10.29 06:10:26 | 000,660,136 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
PRC - [2009.10.29 06:10:24 | 000,025,256 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnMsdMon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.02.16 14:08:21 | 012,433,408 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll
MOD - [2012.02.16 14:08:06 | 001,587,200 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll
MOD - [2012.02.16 14:07:23 | 005,453,312 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll
MOD - [2012.02.16 14:07:15 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll
MOD - [2012.02.16 14:07:11 | 007,967,232 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll
MOD - [2011.12.08 04:10:02 | 011,490,304 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011.07.29 00:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.02.27 12:40:20 | 000,013,664 | ---- | M] () -- C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
MOD - [2010.11.13 00:26:08 | 000,315,392 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009.10.29 06:10:26 | 000,660,136 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
MOD - [2009.10.29 06:10:24 | 000,025,256 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnMsdMon.exe
MOD - [2009.07.23 14:49:06 | 000,782,336 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnDRS.dll
MOD - [2009.07.23 14:48:30 | 000,380,928 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnscw.dll
MOD - [2009.05.14 08:46:42 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncaps.dll
MOD - [2009.02.11 12:50:00 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\App4R.Monitor.Core.dll
MOD - [2009.02.11 12:50:00 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\App4R.Monitor.Common.dll
MOD - [2009.02.11 12:49:02 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.dll
MOD - [2007.11.22 03:55:48 | 000,011,776 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll
MOD - [2007.10.02 09:51:10 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncnv4.dll
MOD - [2007.05.29 02:39:08 | 000,589,824 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdndatr.dll
MOD - [2007.03.26 02:39:36 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncats.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2011.01.26 05:00:14 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.01.25 23:48:06 | 000,354,304 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2009.04.28 08:58:54 | 000,029,184 | ---- | M] () [Auto | Stopped] -- C:\windows\SysNative\spool\DRIVERS\x64\3\\lxdnserv.exe -- (lxdnCATSCustConnectService)
SRV:64bit: - [2007.11.28 10:51:42 | 001,039,872 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxdncoms.exe -- (lxdn_device)
SRV - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.11.22 09:59:30 | 000,018,432 | ---- | M] () [Auto | Running] -- C:\Users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe -- (StumbleUponUpdater)
SRV - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.09.23 14:34:00 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.09.22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.09.21 15:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.06.17 06:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.04.28 08:58:54 | 000,029,184 | ---- | M] () [Auto | Stopped] -- C:\windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe -- (lxdnCATSCustConnectService)
SRV - [2007.11.28 10:12:40 | 000,589,824 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysWOW64\lxdncoms.exe -- (lxdn_device)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.02.18 04:45:32 | 000,125,440 | ---- | M] () [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\acedrv07.sys -- (acedrv07)
DRV:64bit: - [2012.02.15 19:15:35 | 000,132,320 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.12.25 00:36:49 | 000,017,280 | ---- | M] (Scott) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBDrv_AMD64.sys -- (usbUDisc)
DRV:64bit: - [2011.12.10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.10.11 14:00:01 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.10.11 14:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.09.20 23:35:11 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.27 13:01:22 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2011.02.27 13:01:11 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2011.02.27 12:58:31 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:64bit: - [2011.02.27 12:58:31 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:64bit: - [2011.01.26 06:51:00 | 008,014,848 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.01.26 04:23:18 | 000,287,232 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.12.10 20:43:40 | 000,234,960 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vm332avs.sys -- (vm332avs)
DRV:64bit: - [2010.12.05 02:39:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010.12.02 06:26:44 | 001,566,848 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2010.11.29 09:50:38 | 000,044,672 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010.11.24 12:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.09.30 09:45:22 | 000,299,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010.09.21 23:04:54 | 000,015,056 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vm2uvcflt.sys -- (vm2uvcflt)
DRV:64bit: - [2010.09.03 06:46:48 | 001,392,688 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.06.25 03:33:36 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010.05.14 23:04:16 | 000,073,856 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2010.05.14 23:04:16 | 000,028,800 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2010.02.18 10:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.08.13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009.07.21 15:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 21:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009.06.10 21:34:36 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010.07.01 18:11:24 | 000,012,352 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Programme\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://isearch.avg.com/search?cid={795488AD-125A-4134-AB67-012AAA5BECD9}&mid=077f49ac5b9e47d1ac6bcd3c4e8ea837-16cb5af7f86408a254de90e74054103a593d2197&lang=en&ds=ins13&pr=sa&d=2012-03-03 23:54:35&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.facebook.com/"
FF - prefs.js..keyword.URL: "hxxp://isearch.avg.com/search?cid=%7B18eece22-d3c7-4b46-ac9a-3345226809a0%7D&mid=077f49ac5b9e47d1ac6bcd3c4e8ea837-16cb5af7f86408a254de90e74054103a593d2197&ds=ins13&v=10.0.0.7&lang=en&pr=sa&d=2012-03-03%2023%3A54%3A35&sap=ku&q="
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Administrator\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.01.12 19:24:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.17 08:09:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.07 09:02:43 | 000,000,000 | ---D | M]
 
[2011.10.16 01:28:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2012.03.07 02:39:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions
[2012.01.27 12:27:29 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.03.04 00:15:05 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.03.07 02:39:01 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\anttoolbar@ant.com
[2011.12.14 20:26:44 | 000,000,000 | ---D | M] (StumbleUpon) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\toolbar@stumbleupon.com
[2012.03.17 08:09:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.09.23 19:32:58 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files (x86)\mozilla firefox\extensions\quickstores@quickstores.de
[2012.01.12 19:24:57 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
() (No name found) -- C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\EXTENSIONS\ICH@MALTEGOETZ.DE.XPI
[2012.03.17 08:09:01 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.28 17:15:00 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.02.12 03:52:07 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.03.03 23:54:29 | 000,003,749 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012.02.12 03:52:06 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.12 03:52:06 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.12 03:52:06 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.12 03:52:06 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.12 03:52:06 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 7.0.10.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 U1 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Administrator\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: StumbleUpon = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgifblbjgdjhcelbanblbhkhmbnnmhfg\3.97.1_0\
CHR - Extension: Google Mail = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (NXIECatcher Class) - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files (x86)\Xi\NetXfer\NXIEHelper.dll (Xi)
O2 - BHO: (StumbleUpon) - {DB616CFF-D989-48A8-9C85-E2A8D56AB2CA} - C:\Users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUpon.dll (StumbleUpon Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (NetXfer) - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files (x86)\Xi\NetXfer\NXToolBar.dll (Xi)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:64bit: - HKLM..\Run: [lxdnamon] C:\Program Files (x86)\Lexmark 2600 Series\lxdnamon.exe ()
O4:64bit: - HKLM..\Run: [lxdnmon.exe] C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332_STI.EXE (Vimicro)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe (CyberLink Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Alles mit NetXfer herunterladen - C:\Program Files (x86)\Xi\NetXfer\NXAddList.html ()
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Herunterladen mit NetXfer - C:\Program Files (x86)\Xi\NetXfer\NXAddLink.html ()
O8 - Extra context menu item: Alles mit NetXfer herunterladen - C:\Program Files (x86)\Xi\NetXfer\NXAddList.html ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Herunterladen mit NetXfer - C:\Program Files (x86)\Xi\NetXfer\NXAddLink.html ()
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{53407ECF-6E90-4F31-92E4-DCC56ED2B80F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6A209DAB-3A96-4BF2-B0DD-4B7197065907}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\Shell - "" = AutoRun
O33 - MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\Shell\AutoRun\command - "" = E:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
 
MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig:64bit - StartUpReg: ICQ - hkey= - key= - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
MsConfig:64bit - StartUpReg: SkypePM - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: Steam - hkey= - key= - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.20 03:43:04 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Malwarebytes
[2012.03.20 03:42:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.20 03:42:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.03.20 03:42:52 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012.03.20 03:42:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.03.20 02:03:46 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Skype
[2012.03.16 19:09:28 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Egypt Documents
[2012.03.15 02:55:51 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\The Secret of Monkey Island
[2012.03.14 19:51:18 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\RenPy
[2012.03.11 00:42:17 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Ein.Tick.anders.German.2011.AC3.DVDRiP.XviD-GMA- D
[2012.03.09 03:04:31 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Supreme Documents
[2012.03.09 02:53:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Hawaii Documents
[2012.03.09 02:52:45 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slingo Quest Hawaii
[2012.03.09 02:52:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Quest Hawaii
[2012.03.09 02:39:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Quest Egypt Beta
[2012.03.09 02:38:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slingo Supreme
[2012.03.09 02:38:18 | 000,000,000 | ---D | C] -- C:\windows\Slingo Supreme
[2012.03.09 02:38:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Supreme
[2012.03.09 02:29:57 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Amazon Documents
[2012.03.09 02:29:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slingo Quest Amazon [UPDATE]
[2012.03.09 02:29:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Quest Amazon [UPDATE]
[2012.03.07 02:32:23 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Hausarbeit Sachenrecht
[2012.03.07 00:46:40 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Documents
[2012.03.07 00:44:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funkitron
[2012.03.05 22:37:27 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\funkitron
[2012.03.05 22:34:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slingo Deluxe
[2012.03.05 20:26:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Audio Pack
[2012.03.05 20:26:38 | 001,212,416 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudioInfos.dll
[2012.03.05 20:26:38 | 000,479,232 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudioVisu.dll
[2012.03.05 20:26:38 | 000,458,752 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudPlayer.dll
[2012.03.05 20:26:38 | 000,454,656 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudioRecord.dll
[2012.03.05 20:26:38 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\WMAFile.dll
[2012.03.05 20:26:37 | 002,084,864 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudDesign.dll
[2012.03.05 20:26:37 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudFile.dll
[2012.03.05 20:26:37 | 000,417,792 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudDisplay.dll
[2012.03.05 20:26:35 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\FreeAudioPack
[2012.03.05 20:26:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free mp3 Wma Converter
[2012.03.04 00:06:46 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Iggels
[2012.03.04 00:00:44 | 000,000,000 | ---D | C] -- C:\Users\Administrator\.junique
[2012.03.04 00:00:35 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\VMLoad
[2012.03.03 23:54:22 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012.03.03 23:07:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Big Fish Games
[2012.03.03 23:07:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pflanzen gegen Zombies
[2012.03.02 18:37:07 | 000,000,000 | ---D | C] -- C:\windows\solcache
[2012.03.02 18:36:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2012.03.02 18:36:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sierra On-Line
[2012.03.02 18:36:27 | 000,000,000 | ---D | C] -- C:\SIERRA
[2012.03.02 18:34:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spawn
[2012.03.02 18:33:45 | 000,118,784 | ---- | C] (Blizzard Entertainment) -- C:\windows\DiabUnin.exe
[2012.03.02 18:33:45 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Diablo
[2012.03.02 18:33:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo
[2012.03.02 18:33:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Diablo
[2012.03.01 20:48:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SpecialBit Games
[2012.03.01 20:48:07 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunted Hotel
[2012.03.01 20:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haunted Hotel
[2012.03.01 20:47:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Big Fish
[2012.03.01 20:47:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bfgclient
[2012.03.01 20:46:22 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache
[2012.02.29 23:01:52 | 000,000,000 | ---D | C] -- C:\Users\Administrator\.gimp-2.6
[2012.02.29 23:01:51 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\gegl-0.0
[2012.02.28 17:24:53 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.02.28 17:21:13 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Google
[2012.02.28 17:15:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.02.26 20:02:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KV Software
[2012.02.26 19:56:09 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\My Pictures
[2012.02.26 19:56:09 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\InterBA
[2012.02.26 19:56:03 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\InterBA
[2012.02.26 19:55:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ophelia's Bingo World
[2012.02.26 19:55:36 | 000,000,000 | ---D | C] -- C:\ProgramData\InterBA
[2012.02.26 19:55:35 | 000,068,232 | ---- | C] (JGsoft - Just Great Software) -- C:\windows\UnDeployV.exe
[2012.02.24 02:09:14 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Unwritten Tales - Viehchroniken
[2012.02.24 01:46:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vieh Chroniken
[2012.02.21 23:28:14 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Unwritten Tales
[2012.02.21 20:24:34 | 000,466,456 | ---- | C] (Creative Labs) -- C:\windows\SysNative\wrap_oal.dll
[2012.02.21 20:24:34 | 000,444,952 | ---- | C] (Creative Labs) -- C:\windows\SysWow64\wrap_oal.dll
[2012.02.21 20:24:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL
[2012.02.21 19:54:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Unwritten Tales
[2012.02.19 19:14:42 | 000,000,000 | ---D | C] -- C:\ProgramData\MythPeople
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.20 15:27:56 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.20 15:27:56 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.20 15:27:08 | 001,613,412 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012.03.20 15:27:08 | 000,697,098 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2012.03.20 15:27:08 | 000,652,376 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012.03.20 15:27:08 | 000,148,362 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2012.03.20 15:27:08 | 000,121,308 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012.03.20 15:26:01 | 000,001,152 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500UA.job
[2012.03.20 15:20:46 | 000,113,055 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2012.03.20 15:20:06 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012.03.20 15:20:02 | 2902,642,688 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.20 03:42:56 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.19 17:26:00 | 000,001,100 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500Core.job
[2012.03.14 20:28:00 | 000,301,280 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012.03.14 17:48:40 | 001,591,306 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012.03.12 18:12:51 | 000,010,458 | ---- | M] () -- C:\Users\Administrator\Desktop\Zombatar_2.jpg
[2012.03.11 20:28:24 | 000,002,436 | ---- | M] () -- C:\Users\Administrator\Desktop\Google Chrome.lnk
[2012.03.09 02:53:10 | 000,001,104 | ---- | M] () -- C:\Users\Administrator\Desktop\Slingo Quest 2 - Hawaii.lnk
[2012.03.09 02:40:15 | 000,002,116 | ---- | M] () -- C:\Users\Public\Desktop\Slingo Quest Egypt.lnk
[2012.03.09 02:38:26 | 000,001,974 | ---- | M] () -- C:\Users\Public\Desktop\Play Slingo Supreme.lnk
[2012.03.09 02:29:31 | 000,001,192 | ---- | M] () -- C:\Users\Public\Desktop\Slingo Quest 3 - Amazon.lnk
[2012.03.09 01:52:11 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.03.07 00:44:26 | 000,000,850 | ---- | M] () -- C:\Users\Administrator\Desktop\Slingo Quest - Deutsch.lnk
[2012.03.06 16:14:23 | 107,006,626 | ---- | M] () -- C:\Users\Administrator\Desktop\Wallis Bird - Encore.mp4
[2012.03.05 20:26:47 | 000,001,296 | ---- | M] () -- C:\Users\Administrator\Desktop\Free Mp3 Wma Converter.lnk
[2012.03.05 19:44:56 | 000,004,096 | ---- | M] () -- C:\windows\d3dx.dat
[2012.03.02 19:28:38 | 000,014,605 | ---- | M] () -- C:\windows\DiabUnin.dat
[2012.03.02 18:37:25 | 000,000,412 | ---- | M] () -- C:\windows\SIERRA.INI
[2012.03.02 18:34:54 | 000,118,784 | ---- | M] (Blizzard Entertainment) -- C:\windows\DiabUnin.exe
[2012.03.02 18:34:54 | 000,002,829 | ---- | M] () -- C:\windows\DiabUnin.pif
[2012.02.24 01:58:15 | 000,466,456 | ---- | M] (Creative Labs) -- C:\windows\SysNative\wrap_oal.dll
[2012.02.24 01:58:14 | 000,444,952 | ---- | M] (Creative Labs) -- C:\windows\SysWow64\wrap_oal.dll
 
========== Files Created - No Company Name ==========
 
[2012.03.20 03:42:56 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.12 18:12:51 | 000,010,458 | ---- | C] () -- C:\Users\Administrator\Desktop\Zombatar_2.jpg
[2012.03.09 02:52:45 | 000,001,104 | ---- | C] () -- C:\Users\Administrator\Desktop\Slingo Quest 2 - Hawaii.lnk
[2012.03.09 02:40:15 | 000,002,116 | ---- | C] () -- C:\Users\Public\Desktop\Slingo Quest Egypt.lnk
[2012.03.09 02:38:26 | 000,001,974 | ---- | C] () -- C:\Users\Public\Desktop\Play Slingo Supreme.lnk
[2012.03.09 02:29:31 | 000,001,192 | ---- | C] () -- C:\Users\Public\Desktop\Slingo Quest 3 - Amazon.lnk
[2012.03.07 13:33:51 | 000,000,850 | ---- | C] () -- C:\Users\Administrator\Desktop\Slingo Quest - Deutsch.lnk
[2012.03.06 15:56:06 | 107,006,626 | ---- | C] () -- C:\Users\Administrator\Desktop\Wallis Bird - Encore.mp4
[2012.03.05 22:32:22 | 000,001,927 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Manager.lnk
[2012.03.05 22:32:22 | 000,001,248 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Weitere fantastische Spiele.lnk
[2012.03.05 20:26:47 | 000,001,296 | ---- | C] () -- C:\Users\Administrator\Desktop\Free Mp3 Wma Converter.lnk
[2012.03.05 20:26:38 | 000,116,296 | ---- | C] () -- C:\windows\SysWow64\NCTWMAProfiles.prx
[2012.03.05 20:26:36 | 000,484,352 | ---- | C] () -- C:\windows\SysWow64\lame_enc.dll
[2012.03.05 19:44:56 | 000,004,096 | ---- | C] () -- C:\windows\d3dx.dat
[2012.03.02 18:35:10 | 000,000,412 | ---- | C] () -- C:\windows\SIERRA.INI
[2012.03.02 18:33:45 | 000,002,829 | ---- | C] () -- C:\windows\DiabUnin.pif
[2012.03.02 18:33:42 | 000,014,605 | ---- | C] () -- C:\windows\DiabUnin.dat
[2012.02.28 17:24:55 | 000,002,436 | ---- | C] () -- C:\Users\Administrator\Desktop\Google Chrome.lnk
[2012.02.28 17:21:16 | 000,001,152 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500UA.job
[2012.02.28 17:21:14 | 000,001,100 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500Core.job
[2012.02.18 04:45:21 | 000,081,920 | ---- | C] () -- C:\windows\SysWow64\acedrv07.dll
[2011.12.05 19:12:44 | 001,591,306 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011.11.22 09:37:19 | 000,032,256 | ---- | C] () -- C:\windows\SysWow64\AVSredirect.dll
[2011.11.22 09:25:24 | 000,107,520 | RHS- | C] () -- C:\windows\SysWow64\TAKDSDecoder.dll
[2011.04.03 02:56:19 | 000,364,544 | ---- | C] ( ) -- C:\windows\SysWow64\lxdninpa.dll
[2011.04.03 02:56:19 | 000,348,160 | ---- | C] () -- C:\windows\SysWow64\LXDNinst.dll
[2011.04.03 02:56:19 | 000,339,968 | ---- | C] ( ) -- C:\windows\SysWow64\lxdniesc.dll
[2011.04.03 02:56:19 | 000,335,872 | ---- | C] () -- C:\windows\SysWow64\lxdncomx.dll
[2011.04.03 02:56:18 | 001,101,824 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnserv.dll
[2011.04.03 02:56:18 | 000,843,776 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnusb1.dll
[2011.04.03 02:56:18 | 000,663,552 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnhbn3.dll
[2011.04.03 02:56:18 | 000,647,168 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnpmui.dll
[2011.04.03 02:56:18 | 000,589,824 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncoms.exe
[2011.04.03 02:56:18 | 000,569,344 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnlmpm.dll
[2011.04.03 02:56:18 | 000,315,392 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnih.exe
[2011.04.03 02:56:18 | 000,053,248 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnprox.dll
[2011.04.03 02:56:17 | 000,851,968 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncomc.dll
[2011.04.03 02:56:17 | 000,376,832 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncomm.dll
[2011.04.03 02:56:17 | 000,360,448 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncfg.exe
[2011.03.20 19:50:44 | 000,000,400 | ---- | C] () -- C:\windows\ODBC.INI
[2011.02.27 13:07:27 | 000,000,512 | ---- | C] () -- C:\windows\previous.bin
[2011.02.27 13:07:27 | 000,000,512 | ---- | C] () -- C:\windows\current.bin
[2011.02.27 12:40:30 | 001,500,512 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011.02.27 12:40:30 | 000,472,416 | ---- | C] () -- C:\windows\SysWow64\Lenovo.VerifaceStub.dll
[2011.02.27 12:40:29 | 002,086,240 | ---- | C] () -- C:\windows\SysWow64\LenovoVeriface.Interface.dll
[2011.02.27 12:40:29 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011.02.27 12:40:14 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011.02.27 12:27:05 | 000,001,823 | ---- | C] () -- C:\windows\vm332Rmv.ini
[2011.02.27 12:27:05 | 000,001,823 | ---- | C] () -- C:\windows\SysWow64\vm332Rmv.ini
[2011.02.27 12:14:30 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011.02.27 12:10:49 | 000,002,888 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
 
========== LOP Check ==========
 
[2012.01.11 02:34:41 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\.minecraft
[2012.01.07 16:51:10 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Amazon
[2011.12.10 00:12:46 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Big Fish Games
[2011.12.27 09:13:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\calibre
[2011.11.02 04:30:51 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Chirurgie Simulation
[2012.03.20 02:45:55 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
[2012.01.27 12:27:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
[2012.01.27 12:27:28 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.12 14:10:23 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\EnchantedCavern2
[2011.11.11 03:45:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Free PDF to Word Converter
[2012.03.05 20:27:00 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\FreeAudioPack
[2012.03.16 19:09:28 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\funkitron
[2012.03.13 17:18:04 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ICQ
[2012.03.04 00:06:46 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Iggels
[2012.03.14 19:51:18 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\RenPy
[2011.11.01 16:36:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ScummVM
[2012.02.16 17:25:23 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\TLOTGT
[2012.01.15 18:00:36 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\URSE Games
[2012.03.19 20:27:56 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\UseNeXT
[2012.03.04 00:03:17 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\VMLoad
[2012.02.09 13:35:40 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Xi
[2012.02.19 01:39:41 | 000,032,632 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*. >
[2011.07.03 01:55:39 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011.03.23 01:16:56 | 000,000,000 | ---D | M] -- C:\70d4adeb9c4bbe7108
[2012.03.05 22:36:28 | 000,000,000 | ---D | M] -- C:\BigFishGamesCache
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011.03.20 18:49:11 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2012.02.04 03:06:24 | 000,000,000 | ---D | M] -- C:\Dosbox
[2011.04.03 02:54:57 | 000,000,000 | ---D | M] -- C:\drivers
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2011.11.22 09:25:06 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.03.20 03:42:52 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2012.03.20 03:42:53 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2011.03.20 18:49:11 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.03.20 18:49:12 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012.03.02 18:36:27 | 000,000,000 | ---D | M] -- C:\SIERRA
[2012.02.08 17:13:39 | 000,000,000 | ---D | M] -- C:\Spiele
[2012.02.09 20:48:16 | 000,000,000 | ---D | M] -- C:\Streamdownloads
[2012.03.20 15:28:51 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.02.27 12:49:32 | 000,000,000 | -HSD | M] -- C:\UserGuidePDF
[2011.10.16 01:16:04 | 000,000,000 | R--D | M] -- C:\Users
[2012.03.20 09:42:20 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< MD5 for: EXPLORER.EXE  >
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2011.02.27 03:17:33 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.27 03:18:55 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2011.02.27 03:17:33 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2011.02.27 03:18:55 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2011.02.27 03:17:33 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2011.02.27 03:18:55 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2011.02.27 03:17:33 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2011.02.27 03:18:55 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
 
< MD5 for: REGEDIT.EXE  >
[2009.07.14 02:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=2E2C937846A0B8789E5E91739284D17A -- C:\Windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe
[2009.07.14 02:39:29 | 000,427,008 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\SysWOW64\regedit.exe
[2009.07.14 02:14:30 | 000,398,336 | ---- | M] (Microsoft Corporation) MD5=8A4883F5E7AC37444F23279239553878 -- C:\Windows\winsxs\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5a78515e29ea6f39\regedit.exe
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2011.02.27 03:37:50 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011.02.27 03:37:50 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoRebootWithLoggedOnUsers" = 1
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 202 bytes -> C:\ProgramData\Temp:F84B8DB5
@Alternate Data Stream - 153 bytes -> C:\ProgramData\Temp:A7DA2BCD
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:CC30FDA5
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:6C031E3E
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:E6537A16
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:D2AF100E
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:4C3D5A8B
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:ED221572
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:E6708F08
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:880F0FEF

< End of report >



Code:

OTL Extras logfile created on: 20.03.2012 15:26:10 - Run 1
OTL by OldTimer - Version 3.2.39.1    Folder = C:\Users\Administrator\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,60 Gb Total Physical Memory | 2,33 Gb Available Physical Memory | 64,76% Memory free
7,21 Gb Paging File | 5,54 Gb Available in Paging File | 76,88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 254,14 Gb Total Space | 42,06 Gb Free Space | 16,55% Space Free | Partition Type: NTFS
Drive D: | 29,00 Gb Total Space | 26,97 Gb Free Space | 93,02% Space Free | Partition Type: NTFS
 
Computer Name: SARA-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4C897CB6-9393-C1DF-089D-7BB33C344362}" = AMD Fuel
"{50F24798-E870-CEE2-64CA-56DD81A27BAC}" = ATI Catalyst Install Manager
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6B31B6C8-383F-2362-5EB4-D950F666D8FD}" = ccc-utility64
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{909EDD8B-F26D-7051-C761-3386A1AFE052}" = ATI AVIVO64 Codecs
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E2A4EF15-22EE-B863-717D-4237AA3C1536}" = WMV9/VC-1 Video Playback
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"EA12B1FB53CE4E387C31A85236C41EF559B5E392" = Windows-Treiberpaket - Lenovo (ACPIVPC) System  (12/02/2010 6.1.0.1)
"Lenovo EE Boot Optimizer" = Lenovo EE Boot Optimizer
"Lexmark 2600 Series" = Lexmark 2600 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Unlocker" = Unlocker 1.9.1-x64
"WinRAR archiver" = WinRAR 4.00 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{070667D2-A6DC-C36C-10D0-4D25F0054B78}" = CCC Help Chinese Standard
"{097E024D-BE30-4D95-B5F3-B6AE9C1568D4}" = PowerXpressHybrid
"{09CB25FF-E950-0699-DA4D-5BDCD5A653EA}" = CCC Help Finnish
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{15EB20D6-5F13-41D0-BEF9-C9C44D6AC620}" = SDFormatter
"{194E63E4-4AA0-F201-3C96-7EFEA0AEFE91}" = CCC Help French
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F3C1281-F291-573B-3913-774993D6F2C6}" = CCC Help Korean
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217001FF}" = Java(TM) 7 Update 1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2BC21CD2-8053-406A-80F6-9AB61717B49D}" = ODF Add-In für Microsoft Office
"{2D2E2AD9-2DD9-FC5E-32A7-2961E5800C58}" = CCC Help English
"{2EEEC858-21F8-419B-8FE2-820621BFFCD7}" = GetDataBack for FAT
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D8D16D-13AC-826F-7494-166EB0CC021F}" = Catalyst Control Center Graphics Previews Common
"{47B5B5D0-2D0D-887B-E3A3-29744258A2F2}" = CCC Help Portuguese
"{47FAF76A-B225-FA71-F0AA-9ACD71A1A6EB}" = CCC Help Norwegian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C0636E0-C17F-FEE2-0704-944EC0315996}" = CCC Help Japanese
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{54DA5204-5F2B-BB6B-3A29-93DB85E71F02}" = CCC Help Czech
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{562817EC-0640-4947-9513-570A53D55877}" = Grey's Anatomy
"{56582EEA-3AEF-4D84-8B9D-C87A3CD9250F}" = GetDataBack for NTFS
"{5B64310E-6C76-10FB-EF2D-D63D7901FE27}" = CCC Help Spanish
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{6429EC24-5976-8B97-0C73-C7C6EEE717BE}" = CCC Help Polish
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}" = ICQ7.4
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7AA63B49-FF6B-D9EC-F578-36AAD863791F}" = CCC Help Hungarian
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C9D4E8-A57A-95C2-8503-2021E9678096}" = CCC Help Thai
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{85DC53E4-8D6E-4C78-A8D6-C41A7C2BBAB2}_is1" = Max Payne Ultimate Edition v1.0
"{86394597-E2A6-B8EE-9E01-5FF6FD919BFB}" = ccc-core-static
"{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E48FF52-082C-4CC2-BB67-6E10D09C0431}" = Windows Live UX Platform Language Pack
"{9F705A4D-B625-1E7E-BD3B-5DB253F4A3AE}" = Catalyst Control Center Profiles Mobile
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.0 - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}" = Lenovo EasyCamera
"{AE557889-A5F1-212B-BC66-2A67D5FB84D7}" = Catalyst Control Center Localization All
"{AF311022-8A9B-41F5-BE54-E361DF2C8AA6}" = Catalyst Control Center - Branding
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"{B6534AA4-E51E-4D0E-AE12-ABFD55890F7C}_is1" = Slingo Quest Amazon [UPDATE]
"{B93DCF58-AA57-41EC-8D69-B05C66C6312D}_is1" = SUPER © v2011.build.49 (July 1st, 2011) Version v2011.build.49
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C601C102-3CF4-B39C-4479-D03BDA605CDB}" = CCC Help Swedish
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6CABAAA-41C5-40F1-3DCC-A15E2DB8600E}" = CCC Help Dutch
"{C8670645-69C0-A438-CDD7-821A54D6C7B0}" = CCC Help Danish
"{CD5CDBC3-D83E-38BF-297B-CF3B54160C6E}" = CCC Help Italian
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D05B0ED7-7C10-49C2-990C-8D984197C1B4_P1}_is1" = Book of Unwritten Tales Patch 1.01
"{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D14AAC37-38FC-4454-9CEC-B3CD081632C4}" = calibre
"{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}" = Atheros Client Installation Program
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6AA424E-0598-45D7-0D92-113ACC44EC50}" = CCC Help Chinese Traditional
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E35E2F85-3E06-ADAD-7774-663DFD300D44}" = Catalyst Control Center InstallProxy
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E9F03F14-2EF3-7E0C-095F-A2056D748271}" = CCC Help Russian
"{EAE6BF35-84C4-F159-268E-9B63BDCDF545}" = CCC Help German
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = Benutzerhandbuch
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F9502EF3-3D89-7CDC-1BB8-9AC33789BCA5}" = CCC Help Greek
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1" = StreamTransport version: 1.0.2.2171
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Amazon Kindle" = Amazon Kindle
"Amazon MP3-Downloader" = Amazon MP3-Downloader 1.0.9
"Avira AntiVir Desktop" = Avira Free Antivirus
"Bauern Glück" = Bauern Glück
"BFGC" = Big Fish Games: Game Manager
"BFG-Haunted Hotel" = Haunted Hotel
"BFG-Slingo Deluxe" = Slingo Deluxe
"DAEMON Tools Lite" = DAEMON Tools Lite
"Diablo" = Diablo
"Die Legende des goldenen Buches" = Die Legende des goldenen Buches
"DivX Setup" = DivX-Setup
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 2.2
"Free YouTube Download_is1" = Free YouTube Download version 3.0.20.1228
"Gemini Lost Deluxe_is1" = Gemini Lost Deluxe
"Hellfire" = Hellfire
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide
"Lenovo Games Console" = Lenovo Games Console
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.1.1000
"Mozilla Firefox 11.0 (x86 de)" = Mozilla Firefox 11.0 (x86 de)
"NetXfer (Multilingual)_is1" = NetXfer 2.72a.437
"OpenAL" = OpenAL
"Ophelia's Bingo World" = Accorg Ophelia's Bingo World 2.21.0
"Pflanzen gegen Zombies" = Pflanzen gegen Zombies
"QuickPar" = QuickPar 0.9
"Sanitarium" = Sanitarium
"ScummVM_is1" = ScummVM 1.2.1
"Season Match" = Season Match
"SecondLifeViewer2" = SecondLifeViewer2 (remove only)
"Sierra Utilities" = Sierra Utilities
"Slingo Quest - Deutsch" = Slingo Quest - Deutsch
"Slingo Quest Egypt Beta1.0.0.68" = Slingo Quest Egypt Beta
"Slingo Supreme1.0" = Slingo Supreme
"UltraStar Deluxe" = UltraStar Deluxe
"UseNeXT_is1" = UseNeXT
"VeriFace" = VeriFace
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite" = Windows Live Essentials
"Woodville Chronicles_is1" = Woodville Chronicles
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Diablo" = Diablo
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >

Im Voraus danke für Eure Mühe und Hilfe!
Madame

cosinus 20.03.2012 17:31

Ohne die Logs von Malwarebytes und Co wird das hier nichts. :glaskugel:
Alles von Malwarebytes (und evtl. anderen Scannern) muss hier gepostet werden.

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Madame 20.03.2012 17:44

Ah okay, kein Problem, hier das Log-File:

Code:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.20.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Administrator :: SARA-PC [Administrator]

Schutz: Aktiviert

20.03.2012 03:45:31
mbam-log-2012-03-20 (03-45-31).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 382741
Laufzeit: 2 Stunde(n), 19 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 2
HKCR\sp (TrojanProxy.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 6
C:\Users\Administrator\AppData\Local\Temp\0.12014093979641083h7i.exe (Spyware.Zbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Administrator\AppData\Local\Temp\0.6316633960352342h7i.exe (Spyware.Zbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Administrator\AppData\Local\Temp\0.918349491718734h7i.exe (Spyware.Zbot) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Administrator\Downloads\VMLoadSetup(1).exe (PUP.BundleInstaller.OI) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Administrator\Downloads\VMLoadSetup(2).exe (PUP.BundleInstaller.OI) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Administrator\Downloads\VMLoadSetup.exe (PUP.BundleInstaller.OI) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Muss allerdings dazu sagen, dass ich die SkypePM.exe schon vor dem Suchlauf manuell gelöscht habe, dazu auch den reg-Eintrag. Hab vorsichtshalber Skype komplett deinstalliert.
SkypePM.exe taucht hier deshalb wohl nicht mehr auf, aber direkt nachdem die weg war - zunächst nur aus dem Autostart - konnte ich wieder auf Windows zugreifen, was ja bekräftigt, dass zumindest ein Teil des Übeltäters dort saß.
Drauf gekommen bin ich dadurch:

hxxp://forum.mindfactory.de/windows/66919-achtung-sicherheitsgr-nden-wurde-windows-blockiert.html

Edit: Warum diese Setup-Datei gleich dreimal vorhanden war, ist mir auch ein Rätsel.. Zweimal hab ich sie auf jeden Fall geladen, weil ich die erste nicht mehr gefunden habe. Ist aber beides eigentlich schon ein bisschen her.

cosinus 20.03.2012 18:02

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

Madame 20.03.2012 18:07

Nein, hab es letzte Nacht erst hier installiert.
Das hier war noch enthalten, auch wenn das vermutlich nicht gemeint ist. Der Vollständigkeit halber trotzdem:

Code:

2012/03/20 03:45:16 +0100        SARA-PC        Administrator        MESSAGE        Starting protection
2012/03/20 03:45:20 +0100        SARA-PC        Administrator        MESSAGE        Protection started successfully
2012/03/20 03:45:23 +0100        SARA-PC        Administrator        MESSAGE        Starting IP protection
2012/03/20 03:45:29 +0100        SARA-PC        Administrator        MESSAGE        IP Protection started successfully
2012/03/20 04:42:48 +0100        SARA-PC        Administrator        MESSAGE        Executing scheduled update:  Daily
2012/03/20 04:43:06 +0100        SARA-PC        Administrator        MESSAGE        Starting database refresh
2012/03/20 04:43:06 +0100        SARA-PC        Administrator        MESSAGE        Scheduled update executed successfully:  database updated from version v2012.03.20.01 to version v2012.03.20.02
2012/03/20 04:43:06 +0100        SARA-PC        Administrator        MESSAGE        Stopping IP protection
2012/03/20 04:49:58 +0100        SARA-PC        Administrator        MESSAGE        IP Protection stopped
2012/03/20 04:50:25 +0100        SARA-PC        Administrator        MESSAGE        Database refreshed successfully
2012/03/20 04:50:25 +0100        SARA-PC        Administrator        MESSAGE        Starting IP protection
2012/03/20 04:50:34 +0100        SARA-PC        Administrator        MESSAGE        IP Protection started successfully
2012/03/20 15:20:48 +0100        SARA-PC        Administrator        MESSAGE        Starting protection
2012/03/20 15:20:54 +0100        SARA-PC        Administrator        MESSAGE        Protection started successfully
2012/03/20 15:20:57 +0100        SARA-PC        Administrator        MESSAGE        Starting IP protection
2012/03/20 15:21:05 +0100        SARA-PC        Administrator        MESSAGE        IP Protection started successfully
2012/03/20 17:58:11 +0100        SARA-PC        Administrator        MESSAGE        Starting database refresh
2012/03/20 17:58:11 +0100        SARA-PC        Administrator        MESSAGE        Stopping IP protection
2012/03/20 18:03:01 +0100        SARA-PC        Administrator        MESSAGE        IP Protection stopped
2012/03/20 18:03:06 +0100        SARA-PC        Administrator        MESSAGE        Database refreshed successfully
2012/03/20 18:03:06 +0100        SARA-PC        Administrator        MESSAGE        Starting IP protection
2012/03/20 18:03:12 +0100        SARA-PC        Administrator        MESSAGE        IP Protection started successfully

Mehr Logdateien hab ich bisher nicht.

cosinus 20.03.2012 18:09

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Madame 20.03.2012 21:02

Ui, da wurde einiges gefunden...

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=7be7c05ece4c3f4a931a39e2bbfe10ea
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-03-20 07:56:44
# local_time=2012-03-20 08:56:44 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 13545987 13545987 0 0
# compatibility_mode=5893 16776573 100 94 3692 83894207 0 0
# compatibility_mode=8192 67108863 100 0 4107 4107 0 0
# scanned=193415
# found=6
# cleaned=0
# scan_time=9047
C:\Users\Administrator\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\6f4102cc-3c66f1d6        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\Administrator\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\7ede12ec-2669f957        Java/Exploit.CVE-2011-3544.AV trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Administrator\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\7ddd93f-5308e5e5        a variant of Java/TrojanDownloader.Agent.AD trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Administrator\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\6ad3cc08-304498ce        a variant of Java/Exploit.CVE-2011-3544.AW trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Administrator\Downloads\SoftonicDownloader_fuer_vmload.exe        a variant of Win32/SoftonicDownloader.D application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Sara\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\383309f4-2b212fbb        a variant of Java/Agent.DP trojan (unable to clean)        00000000000000000000000000000000        I


cosinus 21.03.2012 15:03

Zitat:

C:\Users\Administrator\Downloads\SoftonicDownloader_fuer_vmload.exe
Finger weg von Softonic!!

Softonic ist eine Toolbar- und Adwareschleuder! Finger weg! Software lädt man sich mit oberster Priorität direkt vom Hersteller und nicht von solchen Toolbarklitschen wie Softonic! Im Notfall würde natürlich chip.de gehen


Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Madame 21.03.2012 17:35

Habe bei diesem Scan keine "Extras"-Datei bekommen. Jedenfalls finde ich keine, anders als beim ersten Mal.
Brauchst Du die auch und wenn ja, wo finde ich die zweite jetzt?

Kurze Zwischenfrage: Wenn ich aktuell festgestellt habe, dass ich Dinge nicht mehr benötige (mir fällt hier erst auf, wie viele Spiele noch installiert sind ;) ), kann ich die dann jetzt deinstallieren?

Noch mal Edit: Wenn ich an einem Textdokument weiterarbeiten will, kann ich das dann hier oder lieber nicht so viel dran arbeiten? Kann ich das gefahrlos rüberkopieren?

Hier auf jeden Fall der aktuelle Scan:

Code:

OTL logfile created on: 21.03.2012 16:54:29 - Run 2
OTL by OldTimer - Version 3.2.39.1    Folder = C:\Users\Administrator\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,60 Gb Total Physical Memory | 2,48 Gb Available Physical Memory | 68,73% Memory free
7,21 Gb Paging File | 5,76 Gb Available in Paging File | 79,96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 254,14 Gb Total Space | 39,30 Gb Free Space | 15,46% Space Free | Partition Type: NTFS
Drive D: | 29,00 Gb Total Space | 26,97 Gb Free Space | 93,02% Space Free | Partition Type: NTFS
 
Computer Name: SARA-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.03.20 15:25:12 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\OTL.exe
PRC - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.01.13 14:53:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.11.22 09:59:30 | 000,018,432 | ---- | M] () -- C:\Users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe
PRC - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 13:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.02.27 12:40:21 | 000,329,056 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2010.12.05 02:39:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
PRC - [2010.01.19 11:44:40 | 000,536,576 | ---- | M] (Vimicro) -- C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
PRC - [2009.10.29 06:10:26 | 000,660,136 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
PRC - [2009.10.29 06:10:24 | 000,025,256 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnMsdMon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.02.16 14:08:21 | 012,433,408 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll
MOD - [2012.02.16 14:08:06 | 001,587,200 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll
MOD - [2012.02.16 14:07:23 | 005,453,312 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll
MOD - [2012.02.16 14:07:15 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll
MOD - [2012.02.16 14:07:11 | 007,967,232 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll
MOD - [2011.12.08 04:10:02 | 011,490,304 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011.07.29 00:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 00:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.02.27 12:40:20 | 000,013,664 | ---- | M] () -- C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
MOD - [2010.11.13 00:26:08 | 000,315,392 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009.10.29 06:10:26 | 000,660,136 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
MOD - [2009.10.29 06:10:24 | 000,025,256 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnMsdMon.exe
MOD - [2009.07.23 14:49:06 | 000,782,336 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnDRS.dll
MOD - [2009.07.23 14:48:30 | 000,380,928 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnscw.dll
MOD - [2009.05.14 08:46:42 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncaps.dll
MOD - [2009.02.11 12:50:00 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\App4R.Monitor.Core.dll
MOD - [2009.02.11 12:50:00 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\App4R.Monitor.Common.dll
MOD - [2009.02.11 12:49:02 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.dll
MOD - [2007.11.22 03:55:48 | 000,011,776 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll
MOD - [2007.10.02 09:51:10 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncnv4.dll
MOD - [2007.05.29 02:39:08 | 000,589,824 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdndatr.dll
MOD - [2007.03.26 02:39:36 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncats.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2011.01.26 05:00:14 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.01.25 23:48:06 | 000,354,304 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2009.04.28 08:58:54 | 000,029,184 | ---- | M] () [Auto | Stopped] -- C:\windows\SysNative\spool\DRIVERS\x64\3\\lxdnserv.exe -- (lxdnCATSCustConnectService)
SRV:64bit: - [2007.11.28 10:51:42 | 001,039,872 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxdncoms.exe -- (lxdn_device)
SRV - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.11.22 09:59:30 | 000,018,432 | ---- | M] () [Auto | Running] -- C:\Users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe -- (StumbleUponUpdater)
SRV - [2011.10.11 13:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 13:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.09.23 14:34:00 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.09.22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.09.21 15:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.06.17 06:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.04.28 08:58:54 | 000,029,184 | ---- | M] () [Auto | Stopped] -- C:\windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe -- (lxdnCATSCustConnectService)
SRV - [2007.11.28 10:12:40 | 000,589,824 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysWOW64\lxdncoms.exe -- (lxdn_device)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.02.18 04:45:32 | 000,125,440 | ---- | M] () [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\acedrv07.sys -- (acedrv07)
DRV:64bit: - [2012.02.15 19:15:35 | 000,132,320 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.12.25 00:36:49 | 000,017,280 | ---- | M] (Scott) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBDrv_AMD64.sys -- (usbUDisc)
DRV:64bit: - [2011.12.10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.10.11 14:00:01 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.10.11 14:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.09.20 23:35:11 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.27 13:01:22 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2011.02.27 13:01:11 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2011.02.27 12:58:31 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:64bit: - [2011.02.27 12:58:31 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:64bit: - [2011.01.26 06:51:00 | 008,014,848 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.01.26 04:23:18 | 000,287,232 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.12.10 20:43:40 | 000,234,960 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vm332avs.sys -- (vm332avs)
DRV:64bit: - [2010.12.05 02:39:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010.12.02 06:26:44 | 001,566,848 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2010.11.29 09:50:38 | 000,044,672 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010.11.24 12:33:26 | 002,673,664 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.09.30 09:45:22 | 000,299,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010.09.21 23:04:54 | 000,015,056 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vm2uvcflt.sys -- (vm2uvcflt)
DRV:64bit: - [2010.09.03 06:46:48 | 001,392,688 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.06.25 03:33:36 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010.05.14 23:04:16 | 000,073,856 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2010.05.14 23:04:16 | 000,028,800 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2010.02.18 10:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.08.13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009.07.21 15:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 21:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:64bit: - [2009.06.10 21:34:36 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010.07.01 18:11:24 | 000,012,352 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Programme\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = hxxp://isearch.avg.com/search?cid={795488AD-125A-4134-AB67-012AAA5BECD9}&mid=077f49ac5b9e47d1ac6bcd3c4e8ea837-16cb5af7f86408a254de90e74054103a593d2197&lang=en&ds=ins13&pr=sa&d=2012-03-03 23:54:35&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.facebook.com/"
FF - prefs.js..keyword.URL: "hxxp://isearch.avg.com/search?cid=%7B18eece22-d3c7-4b46-ac9a-3345226809a0%7D&mid=077f49ac5b9e47d1ac6bcd3c4e8ea837-16cb5af7f86408a254de90e74054103a593d2197&ds=ins13&v=10.0.0.7&lang=en&pr=sa&d=2012-03-03%2023%3A54%3A35&sap=ku&q="
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Administrator\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.01.12 19:24:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.17 08:09:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.07 09:02:43 | 000,000,000 | ---D | M]
 
[2011.10.16 01:28:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Extensions
[2012.03.07 02:39:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions
[2012.01.27 12:27:29 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.03.04 00:15:05 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.03.07 02:39:01 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\anttoolbar@ant.com
[2011.12.14 20:26:44 | 000,000,000 | ---D | M] (StumbleUpon) -- C:\Users\Administrator\AppData\Roaming\mozilla\Firefox\Profiles\9grnwodb.default\extensions\toolbar@stumbleupon.com
[2012.03.17 08:09:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.09.23 19:32:58 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files (x86)\mozilla firefox\extensions\quickstores@quickstores.de
[2012.01.12 19:24:57 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
() (No name found) -- C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\EXTENSIONS\ICH@MALTEGOETZ.DE.XPI
[2012.03.17 08:09:01 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.28 17:15:00 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.02.12 03:52:07 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.03.03 23:54:29 | 000,003,749 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012.02.12 03:52:06 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.12 03:52:06 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.12 03:52:06 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.12 03:52:06 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.12 03:52:06 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Administrator\AppData\Local\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 7.0.10.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 U1 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Administrator\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Administrator\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-Suche = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: StumbleUpon = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgifblbjgdjhcelbanblbhkhmbnnmhfg\3.97.1_0\
CHR - Extension: Google Mail = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (NXIECatcher Class) - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files (x86)\Xi\NetXfer\NXIEHelper.dll (Xi)
O2 - BHO: (StumbleUpon) - {DB616CFF-D989-48A8-9C85-E2A8D56AB2CA} - C:\Users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUpon.dll (StumbleUpon Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (NetXfer) - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files (x86)\Xi\NetXfer\NXToolBar.dll (Xi)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:64bit: - HKLM..\Run: [lxdnamon] C:\Program Files (x86)\Lexmark 2600 Series\lxdnamon.exe ()
O4:64bit: - HKLM..\Run: [lxdnmon.exe] C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332_STI.EXE (Vimicro)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Alles mit NetXfer herunterladen - C:\Program Files (x86)\Xi\NetXfer\NXAddList.html ()
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8:64bit: - Extra context menu item: Herunterladen mit NetXfer - C:\Program Files (x86)\Xi\NetXfer\NXAddLink.html ()
O8 - Extra context menu item: Alles mit NetXfer herunterladen - C:\Program Files (x86)\Xi\NetXfer\NXAddList.html ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Herunterladen mit NetXfer - C:\Program Files (x86)\Xi\NetXfer\NXAddLink.html ()
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{53407ECF-6E90-4F31-92E4-DCC56ED2B80F}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6A209DAB-3A96-4BF2-B0DD-4B7197065907}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\Shell - "" = AutoRun
O33 - MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\Shell\AutoRun\command - "" = E:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig:64bit - StartUpReg: ICQ - hkey= - key= - C:\Program Files (x86)\ICQ7.4\ICQ.exe (ICQ, LLC.)
MsConfig:64bit - StartUpReg: SkypePM - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: Steam - hkey= - key= - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: MCODS - Reg Error: Value error.
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: MCODS - Reg Error: Value error.
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: MCODS - Reg Error: Value error.
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.clmp3enc - C:\PROGRA~2\Lenovo\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.03.21 16:53:38 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Users\Administrator\Desktop\OTL.exe
[2012.03.20 18:17:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.03.20 18:16:43 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Administrator\Desktop\esetsmartinstaller_enu.exe
[2012.03.20 03:43:04 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Malwarebytes
[2012.03.20 03:42:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.20 03:42:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.03.20 03:42:52 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012.03.20 03:42:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.03.20 02:03:46 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Skype
[2012.03.16 19:09:28 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Egypt Documents
[2012.03.15 02:55:51 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\The Secret of Monkey Island
[2012.03.14 19:51:18 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\RenPy
[2012.03.09 03:04:31 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Supreme Documents
[2012.03.09 02:53:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Hawaii Documents
[2012.03.09 02:52:45 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slingo Quest Hawaii
[2012.03.09 02:52:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Quest Hawaii
[2012.03.09 02:39:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Quest Egypt Beta
[2012.03.09 02:38:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slingo Supreme
[2012.03.09 02:38:18 | 000,000,000 | ---D | C] -- C:\windows\Slingo Supreme
[2012.03.09 02:38:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Supreme
[2012.03.09 02:29:57 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Amazon Documents
[2012.03.09 02:29:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slingo Quest Amazon [UPDATE]
[2012.03.09 02:29:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Slingo Quest Amazon [UPDATE]
[2012.03.07 02:32:23 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Desktop\Hausarbeit Sachenrecht
[2012.03.07 00:46:40 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Slingo Quest Documents
[2012.03.07 00:44:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funkitron
[2012.03.05 22:37:27 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\funkitron
[2012.03.05 22:34:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Slingo Deluxe
[2012.03.05 20:26:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Audio Pack
[2012.03.05 20:26:38 | 001,212,416 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudioInfos.dll
[2012.03.05 20:26:38 | 000,479,232 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudioVisu.dll
[2012.03.05 20:26:38 | 000,458,752 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudPlayer.dll
[2012.03.05 20:26:38 | 000,454,656 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudioRecord.dll
[2012.03.05 20:26:38 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\WMAFile.dll
[2012.03.05 20:26:37 | 002,084,864 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudDesign.dll
[2012.03.05 20:26:37 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudFile.dll
[2012.03.05 20:26:37 | 000,417,792 | ---- | C] (NCT Company Ltd.) -- C:\windows\SysWow64\AudDisplay.dll
[2012.03.05 20:26:35 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\FreeAudioPack
[2012.03.05 20:26:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free mp3 Wma Converter
[2012.03.04 00:06:46 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Iggels
[2012.03.04 00:00:44 | 000,000,000 | ---D | C] -- C:\Users\Administrator\.junique
[2012.03.04 00:00:35 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\VMLoad
[2012.03.03 23:54:22 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012.03.03 23:07:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Big Fish Games
[2012.03.03 23:07:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pflanzen gegen Zombies
[2012.03.02 18:37:07 | 000,000,000 | ---D | C] -- C:\windows\solcache
[2012.03.02 18:36:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2012.03.02 18:36:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sierra On-Line
[2012.03.02 18:36:27 | 000,000,000 | ---D | C] -- C:\SIERRA
[2012.03.02 18:34:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spawn
[2012.03.02 18:33:45 | 000,118,784 | ---- | C] (Blizzard Entertainment) -- C:\windows\DiabUnin.exe
[2012.03.02 18:33:45 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Diablo
[2012.03.02 18:33:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo
[2012.03.02 18:33:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Diablo
[2012.03.01 20:48:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SpecialBit Games
[2012.03.01 20:48:07 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunted Hotel
[2012.03.01 20:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haunted Hotel
[2012.03.01 20:47:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Big Fish
[2012.03.01 20:47:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bfgclient
[2012.03.01 20:46:22 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache
[2012.02.29 23:01:52 | 000,000,000 | ---D | C] -- C:\Users\Administrator\.gimp-2.6
[2012.02.29 23:01:51 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\gegl-0.0
[2012.02.28 17:24:53 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.02.28 17:21:13 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Google
[2012.02.28 17:15:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012.02.26 20:02:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KV Software
[2012.02.26 19:56:09 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\My Pictures
[2012.02.26 19:56:09 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\InterBA
[2012.02.26 19:56:03 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\InterBA
[2012.02.26 19:55:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ophelia's Bingo World
[2012.02.26 19:55:36 | 000,000,000 | ---D | C] -- C:\ProgramData\InterBA
[2012.02.26 19:55:35 | 000,068,232 | ---- | C] (JGsoft - Just Great Software) -- C:\windows\UnDeployV.exe
[2012.02.24 02:09:14 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Unwritten Tales - Viehchroniken
[2012.02.24 01:46:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vieh Chroniken
[2012.02.21 23:28:14 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Unwritten Tales
[2012.02.21 20:24:34 | 000,466,456 | ---- | C] (Creative Labs) -- C:\windows\SysNative\wrap_oal.dll
[2012.02.21 20:24:34 | 000,444,952 | ---- | C] (Creative Labs) -- C:\windows\SysWow64\wrap_oal.dll
[2012.02.21 20:24:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL
[2012.02.21 19:54:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Unwritten Tales
 
========== Files - Modified Within 30 Days ==========
 
[2012.03.21 16:26:02 | 000,001,152 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500UA.job
[2012.03.21 15:14:05 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.21 15:14:05 | 000,013,424 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.21 14:44:07 | 001,613,412 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012.03.21 14:44:07 | 000,697,098 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2012.03.21 14:44:07 | 000,652,376 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012.03.21 14:44:07 | 000,148,362 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2012.03.21 14:44:07 | 000,121,308 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012.03.20 23:11:06 | 000,123,213 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2012.03.20 23:08:12 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012.03.20 23:08:08 | 2902,642,688 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.20 18:16:59 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Administrator\Desktop\esetsmartinstaller_enu.exe
[2012.03.20 17:26:00 | 000,001,100 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500Core.job
[2012.03.20 15:25:12 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\OTL.exe
[2012.03.20 03:42:56 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.14 20:28:00 | 000,301,280 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012.03.14 17:48:40 | 001,591,306 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012.03.12 18:12:51 | 000,010,458 | ---- | M] () -- C:\Users\Administrator\Desktop\Zombatar_2.jpg
[2012.03.11 20:28:24 | 000,002,436 | ---- | M] () -- C:\Users\Administrator\Desktop\Google Chrome.lnk
[2012.03.09 02:53:10 | 000,001,104 | ---- | M] () -- C:\Users\Administrator\Desktop\Slingo Quest 2 - Hawaii.lnk
[2012.03.09 02:40:15 | 000,002,116 | ---- | M] () -- C:\Users\Public\Desktop\Slingo Quest Egypt.lnk
[2012.03.09 02:38:26 | 000,001,974 | ---- | M] () -- C:\Users\Public\Desktop\Play Slingo Supreme.lnk
[2012.03.09 02:29:31 | 000,001,192 | ---- | M] () -- C:\Users\Public\Desktop\Slingo Quest 3 - Amazon.lnk
[2012.03.09 01:52:11 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.03.07 00:44:26 | 000,000,850 | ---- | M] () -- C:\Users\Administrator\Desktop\Slingo Quest - Deutsch.lnk
[2012.03.05 20:26:47 | 000,001,296 | ---- | M] () -- C:\Users\Administrator\Desktop\Free Mp3 Wma Converter.lnk
[2012.03.05 19:44:56 | 000,004,096 | ---- | M] () -- C:\windows\d3dx.dat
[2012.03.02 19:28:38 | 000,014,605 | ---- | M] () -- C:\windows\DiabUnin.dat
[2012.03.02 18:37:25 | 000,000,412 | ---- | M] () -- C:\windows\SIERRA.INI
[2012.03.02 18:34:54 | 000,118,784 | ---- | M] (Blizzard Entertainment) -- C:\windows\DiabUnin.exe
[2012.03.02 18:34:54 | 000,002,829 | ---- | M] () -- C:\windows\DiabUnin.pif
[2012.02.24 01:58:15 | 000,466,456 | ---- | M] (Creative Labs) -- C:\windows\SysNative\wrap_oal.dll
[2012.02.24 01:58:14 | 000,444,952 | ---- | M] (Creative Labs) -- C:\windows\SysWow64\wrap_oal.dll
 
========== Files Created - No Company Name ==========
 
[2012.03.20 03:42:56 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.12 18:12:51 | 000,010,458 | ---- | C] () -- C:\Users\Administrator\Desktop\Zombatar_2.jpg
[2012.03.09 02:52:45 | 000,001,104 | ---- | C] () -- C:\Users\Administrator\Desktop\Slingo Quest 2 - Hawaii.lnk
[2012.03.09 02:40:15 | 000,002,116 | ---- | C] () -- C:\Users\Public\Desktop\Slingo Quest Egypt.lnk
[2012.03.09 02:38:26 | 000,001,974 | ---- | C] () -- C:\Users\Public\Desktop\Play Slingo Supreme.lnk
[2012.03.09 02:29:31 | 000,001,192 | ---- | C] () -- C:\Users\Public\Desktop\Slingo Quest 3 - Amazon.lnk
[2012.03.07 13:33:51 | 000,000,850 | ---- | C] () -- C:\Users\Administrator\Desktop\Slingo Quest - Deutsch.lnk
[2012.03.05 22:32:22 | 000,001,927 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Manager.lnk
[2012.03.05 22:32:22 | 000,001,248 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Weitere fantastische Spiele.lnk
[2012.03.05 20:26:47 | 000,001,296 | ---- | C] () -- C:\Users\Administrator\Desktop\Free Mp3 Wma Converter.lnk
[2012.03.05 20:26:38 | 000,116,296 | ---- | C] () -- C:\windows\SysWow64\NCTWMAProfiles.prx
[2012.03.05 20:26:36 | 000,484,352 | ---- | C] () -- C:\windows\SysWow64\lame_enc.dll
[2012.03.05 19:44:56 | 000,004,096 | ---- | C] () -- C:\windows\d3dx.dat
[2012.03.02 18:35:10 | 000,000,412 | ---- | C] () -- C:\windows\SIERRA.INI
[2012.03.02 18:33:45 | 000,002,829 | ---- | C] () -- C:\windows\DiabUnin.pif
[2012.03.02 18:33:42 | 000,014,605 | ---- | C] () -- C:\windows\DiabUnin.dat
[2012.02.28 17:24:55 | 000,002,436 | ---- | C] () -- C:\Users\Administrator\Desktop\Google Chrome.lnk
[2012.02.28 17:21:16 | 000,001,152 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500UA.job
[2012.02.28 17:21:14 | 000,001,100 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500Core.job
[2012.02.18 04:45:21 | 000,081,920 | ---- | C] () -- C:\windows\SysWow64\acedrv07.dll
[2011.12.05 19:12:44 | 001,591,306 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011.11.22 09:37:19 | 000,032,256 | ---- | C] () -- C:\windows\SysWow64\AVSredirect.dll
[2011.11.22 09:25:24 | 000,107,520 | RHS- | C] () -- C:\windows\SysWow64\TAKDSDecoder.dll
[2011.04.03 02:56:19 | 000,364,544 | ---- | C] ( ) -- C:\windows\SysWow64\lxdninpa.dll
[2011.04.03 02:56:19 | 000,348,160 | ---- | C] () -- C:\windows\SysWow64\LXDNinst.dll
[2011.04.03 02:56:19 | 000,339,968 | ---- | C] ( ) -- C:\windows\SysWow64\lxdniesc.dll
[2011.04.03 02:56:19 | 000,335,872 | ---- | C] () -- C:\windows\SysWow64\lxdncomx.dll
[2011.04.03 02:56:18 | 001,101,824 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnserv.dll
[2011.04.03 02:56:18 | 000,843,776 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnusb1.dll
[2011.04.03 02:56:18 | 000,663,552 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnhbn3.dll
[2011.04.03 02:56:18 | 000,647,168 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnpmui.dll
[2011.04.03 02:56:18 | 000,589,824 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncoms.exe
[2011.04.03 02:56:18 | 000,569,344 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnlmpm.dll
[2011.04.03 02:56:18 | 000,315,392 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnih.exe
[2011.04.03 02:56:18 | 000,053,248 | ---- | C] ( ) -- C:\windows\SysWow64\lxdnprox.dll
[2011.04.03 02:56:17 | 000,851,968 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncomc.dll
[2011.04.03 02:56:17 | 000,376,832 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncomm.dll
[2011.04.03 02:56:17 | 000,360,448 | ---- | C] ( ) -- C:\windows\SysWow64\lxdncfg.exe
[2011.03.20 19:50:44 | 000,000,400 | ---- | C] () -- C:\windows\ODBC.INI
[2011.02.27 13:07:27 | 000,000,512 | ---- | C] () -- C:\windows\previous.bin
[2011.02.27 13:07:27 | 000,000,512 | ---- | C] () -- C:\windows\current.bin
[2011.02.27 12:40:30 | 001,500,512 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011.02.27 12:40:30 | 000,472,416 | ---- | C] () -- C:\windows\SysWow64\Lenovo.VerifaceStub.dll
[2011.02.27 12:40:29 | 002,086,240 | ---- | C] () -- C:\windows\SysWow64\LenovoVeriface.Interface.dll
[2011.02.27 12:40:29 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011.02.27 12:40:14 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011.02.27 12:27:05 | 000,001,823 | ---- | C] () -- C:\windows\vm332Rmv.ini
[2011.02.27 12:27:05 | 000,001,823 | ---- | C] () -- C:\windows\SysWow64\vm332Rmv.ini
[2011.02.27 12:14:30 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011.02.27 12:10:49 | 000,002,888 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
 
========== LOP Check ==========
 
[2012.01.11 02:34:41 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\.minecraft
[2012.01.07 16:51:10 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Amazon
[2011.12.10 00:12:46 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Big Fish Games
[2011.12.27 09:13:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\calibre
[2011.11.02 04:30:51 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Chirurgie Simulation
[2012.03.20 02:45:55 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
[2012.01.27 12:27:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
[2012.01.27 12:27:28 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.12 14:10:23 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\EnchantedCavern2
[2011.11.11 03:45:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Free PDF to Word Converter
[2012.03.05 20:27:00 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\FreeAudioPack
[2012.03.16 19:09:28 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\funkitron
[2012.03.21 00:16:21 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ICQ
[2012.03.04 00:06:46 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Iggels
[2012.03.14 19:51:18 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\RenPy
[2011.11.01 16:36:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ScummVM
[2012.02.16 17:25:23 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\TLOTGT
[2012.01.15 18:00:36 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\URSE Games
[2012.03.04 00:03:17 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\VMLoad
[2012.02.09 13:35:40 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Xi
[2011.09.24 03:24:32 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Awem
[2011.10.14 09:05:35 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\DAEMON Tools Lite
[2011.06.25 04:07:57 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Firestorm
[2011.10.13 19:42:52 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\ICQ
[2011.04.03 03:03:27 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Lexmark Productivity Studio
[2011.03.22 17:13:50 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\PlayFirst
[2011.04.09 13:04:59 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\ScummVM
[2011.06.25 03:57:42 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\SecondLife
[2011.09.24 02:56:47 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\URSE Games
[2012.02.19 01:39:41 | 000,032,632 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.01.11 02:34:41 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\.minecraft
[2011.10.19 00:36:06 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Adobe
[2012.01.07 16:51:10 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Amazon
[2012.02.09 15:55:42 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Apple Computer
[2011.10.16 01:18:09 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ATI
[2011.10.16 01:17:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Avira
[2011.12.10 00:12:46 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Big Fish Games
[2011.12.27 09:13:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\calibre
[2011.11.02 04:30:51 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Chirurgie Simulation
[2012.03.20 02:45:55 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
[2012.02.09 15:57:16 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DivX
[2011.12.09 01:04:06 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\dvdcss
[2012.01.27 12:27:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
[2012.01.27 12:27:28 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.12 14:10:23 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\EnchantedCavern2
[2011.11.11 03:45:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Free PDF to Word Converter
[2012.03.05 20:27:00 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\FreeAudioPack
[2012.03.16 19:09:28 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\funkitron
[2012.03.21 00:16:21 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ICQ
[2011.10.16 01:16:38 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Identities
[2012.03.04 00:06:46 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Iggels
[2011.10.16 01:34:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Macromedia
[2012.03.20 03:43:04 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Malwarebytes
[2009.07.29 08:23:49 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Media Center Programs
[2012.03.08 23:32:30 | 000,000,000 | --SD | M] -- C:\Users\Administrator\AppData\Roaming\Microsoft
[2011.10.16 01:28:01 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Mozilla
[2011.11.19 06:52:47 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Nero
[2012.03.14 19:51:18 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\RenPy
[2011.11.01 16:36:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ScummVM
[2012.03.20 03:35:32 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Skype
[2012.02.16 17:25:23 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\TLOTGT
[2012.01.15 18:00:36 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\URSE Games
[2011.10.16 09:21:00 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\vlc
[2012.03.04 00:03:17 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\VMLoad
[2011.10.16 21:57:29 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\WinRAR
[2012.02.09 13:35:40 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Xi
 
< %APPDATA%\*.exe /s >
[2011.12.05 19:15:09 | 000,010,134 | R--- | M] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.02.27 03:50:26 | 000,410,504 | ---- | M] (Intel Corporation) MD5=513DC087CFED7D2BB82F005385D3531F -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16592_none_0af87721a183cb70\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
[2011.02.27 03:50:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=E353CF970C5D4D6A092911E15FB78C07 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20712_none_0bd89532ba6088d9\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.02.27 03:50:26 | 000,166,280 | ---- | M] (NVIDIA Corporation) MD5=0AF7B8136794E23E87BE138992880E64 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16592_none_95c1e7d0d8ba7548\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.02.27 03:50:26 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=CE76755AF933E728CEBA6C7A970838A4 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20712_none_96a205e1f19732b1\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\windows\SysNative\wininit.exe
[2009.07.14 02:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009.07.14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2011.02.27 03:37:50 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011.02.27 03:37:50 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 202 bytes -> C:\ProgramData\Temp:F84B8DB5
@Alternate Data Stream - 153 bytes -> C:\ProgramData\Temp:A7DA2BCD
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:CC30FDA5
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:6C031E3E
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:E6537A16
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:D2AF100E
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:4C3D5A8B
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:ED221572
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:E6708F08
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:880F0FEF

< End of report >


cosinus 21.03.2012 18:03

Zitat:

O2 - BHO: (DivX Plus Web Player HTML5 <video>)
Gehörst du auch zur der Fraktion, die sich Serien und Kinofilme über dubiose Portale anschaut?
Wenn ja: in Zukunft Finger weg, diese illegalen Portale verbreiten Malware und wenn du in Zukunft malwarefrei sein wilst, musst du auf legale Alternativen ausweichen und auf solche riskanten Streamingseiten verzichten!

Madame 21.03.2012 18:22

Nicht jeder Stream, der sich mit dem Player abspielen lässt, ist illegal!
Broadcasts, kommentierte Livestreams (also man hört den Ton von was auch immer und sieht dazu Leute, die kommentieren etc. pp - muss man nicht mögen, ist aber völlig legal.).

cosinus 21.03.2012 18:27

Zitat:

Nicht jeder Stream, der sich mit dem Player abspielen lässt, ist illegal!
Hab ich das irgendwo behauptet!
Ich hatte einfach die Frage ob du auch illegale Livestreams von den neuen Ablegern bzw. Alternativen wie zB kino.to machst! Wenn ja, dann ist wäre das eine sehr wahrscheinliche Ursache für die Sperrung des Windows-Rechners!

Wir müssen das hier am Tag 100x posten und du bist da keine Ausnahme wenn ich so einen DivX Webplayer im Log sehe!

Madame 21.03.2012 18:33

Fühl Dich nicht angegriffen, so war das gar nicht gemeint. ;)
Sorry, falls das so rüberkam. Wollte das nur anmerken, um Deine Frage zu beantworten, hätte allerdings vielleicht einen Smiley anfügen sollen.

Bin doch dankbar für Deine Hilfe und Nachfragen sind ja selbstverständlich.
Brauchtest Du jetzt eigentlich eine Extra-Datei? Wenn ja, wo finde ich die vom zweiten Scan?

cosinus 21.03.2012 20:42

Ich fühl mich nicht angegriffen, ich muss nur Tag für Tag sehr deutliche Worte für sowas finden. Und ob du es glaubst oder nicht, oft kommen solche Ausreden wie "so einen Shice mach ich nicht" oder "das stimmt nicht" oder "ich hab das garnicht installiert" http://cheesebuerger.de/images/midi/froehlich/a048.gif


Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={795488AD-125A-4134-AB67-012AAA5BECD9}&mid=077f49ac5b9e47d1ac6bcd3c4e8ea837-16cb5af7f86408a254de90e74054103a593d2197&lang=en&ds=ins13&pr=sa&d=2012-03-03 23:54:35&v=10.0.0.7&sap=dsp&q={searchTerms}
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B18eece22-d3c7-4b46-ac9a-3345226809a0%7D&mid=077f49ac5b9e47d1ac6bcd3c4e8ea837-16cb5af7f86408a254de90e74054103a593d2197&ds=ins13&v=10.0.0.7&lang=en&pr=sa&d=2012-03-03%2023%3A54%3A35&sap=ku&q="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
[2012.01.12 19:24:57 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (NetXfer) - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files (x86)\Xi\NetXfer\NXToolBar.dll (Xi)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\Shell - "" = AutoRun
O33 - MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\Shell\AutoRun\command - "" = E:\Setup.exe
@Alternate Data Stream - 202 bytes -> C:\ProgramData\Temp:F84B8DB5
@Alternate Data Stream - 153 bytes -> C:\ProgramData\Temp:A7DA2BCD
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:CC30FDA5
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:6C031E3E
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:E6537A16
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:D2AF100E
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:4C3D5A8B
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:ED221572
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:E6708F08
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:880F0FEF
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Madame 21.03.2012 21:03

Klar, ist ja auch verständlich. :)

Neustart erfolgt, hier das Logfile:

Code:

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKU\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Prefs.js: "hxxp://www.facebook.com/" removed from browser.startup.homepage
Prefs.js: "hxxp://isearch.avg.com/search?cid=%7B18eece22-d3c7-4b46-ac9a-3345226809a0%7D&mid=077f49ac5b9e47d1ac6bcd3c4e8ea837-16cb5af7f86408a254de90e74054103a593d2197&ds=ins13&v=10.0.0.7&lang=en&pr=sa&d=2012-03-03%2023%3A54%3A35&sap=ku&q=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0\ deleted successfully.
C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0\ deleted successfully.
C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\Adobe Reader\ deleted successfully.
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll moved successfully.
C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5\chrome\content\images folder moved successfully.
C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5\chrome\content folder moved successfully.
C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5\chrome folder moved successfully.
C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5 folder moved successfully.
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll moved successfully.
File C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll not found.
File C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{326E768D-4182-46FD-9C16-1449A49795F4}\ deleted successfully.
C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A}\ deleted successfully.
C:\Program Files (x86)\Xi\NetXfer\NXToolBar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c8aedf32-e188-11e0-b84d-1c75086a41c4}\ not found.
File E:\Setup.exe not found.
ADS C:\ProgramData\Temp:F84B8DB5 deleted successfully.
ADS C:\ProgramData\Temp:A7DA2BCD deleted successfully.
ADS C:\ProgramData\Temp:CC30FDA5 deleted successfully.
ADS C:\ProgramData\Temp:4B244549 deleted successfully.
ADS C:\ProgramData\Temp:6C031E3E deleted successfully.
ADS C:\ProgramData\Temp:E6537A16 deleted successfully.
ADS C:\ProgramData\Temp:D2AF100E deleted successfully.
ADS C:\ProgramData\Temp:4C3D5A8B deleted successfully.
ADS C:\ProgramData\Temp:ED221572 deleted successfully.
ADS C:\ProgramData\Temp:E6708F08 deleted successfully.
ADS C:\ProgramData\Temp:880F0FEF deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 15068 bytes
->Temporary Internet Files folder emptied: 4486846 bytes
->Java cache emptied: 132587000 bytes
->FireFox cache emptied: 753801496 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 2808 bytes
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Sara
->Temp folder emptied: 1578048 bytes
->Temporary Internet Files folder emptied: 5645946 bytes
->Java cache emptied: 2717128 bytes
->FireFox cache emptied: 169604012 bytes
->Flash cache emptied: 1761 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 35186 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1.021,00 mb
 
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.39.1 log created on 03212012_204704

Files\Folders moved on Reboot...
C:\Users\Administrator\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...


cosinus 22.03.2012 11:42

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

Madame 22.03.2012 16:08

Hier das Log-File:

Code:

16:02:42.0293 4592        TDSS rootkit removing tool 2.7.22.0 Mar 21 2012 17:40:00
16:02:42.0449 4592        ============================================================
16:02:42.0449 4592        Current date / time: 2012/03/22 16:02:42.0449
16:02:42.0449 4592        SystemInfo:
16:02:42.0449 4592       
16:02:42.0449 4592        OS Version: 6.1.7601 ServicePack: 1.0
16:02:42.0449 4592        Product type: Workstation
16:02:42.0449 4592        ComputerName: SARA-PC
16:02:42.0449 4592        UserName: Administrator
16:02:42.0449 4592        Windows directory: C:\windows
16:02:42.0449 4592        System windows directory: C:\windows
16:02:42.0449 4592        Running under WOW64
16:02:42.0449 4592        Processor architecture: Intel x64
16:02:42.0449 4592        Number of processors: 2
16:02:42.0449 4592        Page size: 0x1000
16:02:42.0449 4592        Boot type: Normal boot
16:02:42.0449 4592        ============================================================
16:02:44.0197 4592        Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:02:44.0212 4592        \Device\Harddisk0\DR0:
16:02:44.0212 4592        MBR used
16:02:44.0212 4592        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
16:02:44.0212 4592        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x1FC49800
16:02:44.0228 4592        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1FCAE800, BlocksNum 0x39FD800
16:02:44.0415 4592        Initialize success
16:02:44.0415 4592        ============================================================
16:03:38.0843 4480        ============================================================
16:03:38.0843 4480        Scan started
16:03:38.0843 4480        Mode: Manual; SigCheck; TDLFS;
16:03:38.0843 4480        ============================================================
16:03:39.0374 4480        1394ohci        (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
16:03:39.0577 4480        1394ohci - ok
16:03:39.0733 4480        acedrv07        (6e9c8b324980afe454c6f7762e2b4478) C:\windows\system32\drivers\acedrv07.sys
16:03:39.0748 4480        acedrv07 ( UnsignedFile.Multi.Generic ) - warning
16:03:39.0748 4480        acedrv07 - detected UnsignedFile.Multi.Generic (1)
16:03:39.0857 4480        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
16:03:39.0889 4480        ACPI - ok
16:03:39.0951 4480        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
16:03:40.0045 4480        AcpiPmi - ok
16:03:40.0154 4480        ACPIVPC        (5bbff8b826ec38d32c26334e079c7efc) C:\windows\system32\DRIVERS\AcpiVpc.sys
16:03:40.0232 4480        ACPIVPC - ok
16:03:40.0357 4480        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys
16:03:40.0388 4480        adp94xx - ok
16:03:40.0513 4480        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys
16:03:40.0544 4480        adpahci - ok
16:03:40.0591 4480        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys
16:03:40.0606 4480        adpu320 - ok
16:03:40.0684 4480        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
16:03:40.0840 4480        AeLookupSvc - ok
16:03:40.0965 4480        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
16:03:41.0043 4480        AFD - ok
16:03:41.0137 4480        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
16:03:41.0168 4480        agp440 - ok
16:03:41.0230 4480        ALG            (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
16:03:41.0308 4480        ALG - ok
16:03:41.0433 4480        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
16:03:41.0449 4480        aliide - ok
16:03:41.0558 4480        AMD External Events Utility (e47d00b8d7d0081eeac333041660bcfb) C:\windows\system32\atiesrxx.exe
16:03:41.0636 4480        AMD External Events Utility - ok
16:03:41.0823 4480        AMD FUEL Service - ok
16:03:41.0870 4480        AMD Reservation Manager (dd27f6c3de9bfe50635c721e09edc5dd) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
16:03:41.0886 4480        AMD Reservation Manager - ok
16:03:41.0995 4480        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
16:03:42.0010 4480        amdide - ok
16:03:42.0057 4480        amdiox64        (6a2eeb0c4133b20773bb3dd0b7b377b4) C:\windows\system32\DRIVERS\amdiox64.sys
16:03:42.0073 4480        amdiox64 - ok
16:03:42.0166 4480        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys
16:03:42.0213 4480        AmdK8 - ok
16:03:42.0478 4480        amdkmdag        (59e31f22450ba39d640ecc7e7ab720e4) C:\windows\system32\DRIVERS\atikmdag.sys
16:03:42.0775 4480        amdkmdag - ok
16:03:42.0868 4480        amdkmdap        (d54e78d9166e27a833f6e6e325080960) C:\windows\system32\DRIVERS\atikmpag.sys
16:03:42.0915 4480        amdkmdap - ok
16:03:43.0040 4480        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys
16:03:43.0071 4480        AmdPPM - ok
16:03:43.0165 4480        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
16:03:43.0196 4480        amdsata - ok
16:03:43.0321 4480        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys
16:03:43.0336 4480        amdsbs - ok
16:03:43.0383 4480        amdxata        (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
16:03:43.0399 4480        amdxata - ok
16:03:43.0492 4480        amd_sata        (08e8a4172c57abd7693a6915cf1e7a99) C:\windows\system32\DRIVERS\amd_sata.sys
16:03:43.0508 4480        amd_sata - ok
16:03:43.0524 4480        amd_xata        (9866af4e4ad7f16e810b6c0b8473f9cd) C:\windows\system32\DRIVERS\amd_xata.sys
16:03:43.0539 4480        amd_xata - ok
16:03:43.0633 4480        AntiVirSchedulerService (a122d68ea2541453f787f341877cb40b) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
16:03:43.0648 4480        AntiVirSchedulerService - ok
16:03:43.0758 4480        AntiVirService  (2fe359edeb34efcf42574752f8aebd3f) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
16:03:43.0789 4480        AntiVirService - ok
16:03:43.0960 4480        AppID          (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
16:03:44.0132 4480        AppID - ok
16:03:44.0226 4480        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
16:03:44.0304 4480        AppIDSvc - ok
16:03:44.0413 4480        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
16:03:44.0475 4480        Appinfo - ok
16:03:44.0538 4480        arc            (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys
16:03:44.0553 4480        arc - ok
16:03:44.0647 4480        arcsas          (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys
16:03:44.0678 4480        arcsas - ok
16:03:44.0787 4480        aspnet_state    (9217d874131ae6ff8f642f124f00a555) C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
16:03:44.0803 4480        aspnet_state - ok
16:03:44.0896 4480        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
16:03:44.0990 4480        AsyncMac - ok
16:03:45.0115 4480        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
16:03:45.0130 4480        atapi - ok
16:03:45.0224 4480        athr            (782d36bad8ddbf008d02e055dbe70f82) C:\windows\system32\DRIVERS\athrx.sys
16:03:45.0333 4480        athr - ok
16:03:45.0489 4480        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
16:03:45.0598 4480        AudioEndpointBuilder - ok
16:03:45.0661 4480        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
16:03:45.0739 4480        AudioSrv - ok
16:03:45.0848 4480        avgntflt        (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\windows\system32\DRIVERS\avgntflt.sys
16:03:45.0879 4480        avgntflt - ok
16:03:45.0988 4480        avipbb          (852e3c0a60d368c487949e55ad52a47f) C:\windows\system32\DRIVERS\avipbb.sys
16:03:46.0020 4480        avipbb - ok
16:03:46.0113 4480        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\windows\system32\DRIVERS\avkmgr.sys
16:03:46.0129 4480        avkmgr - ok
16:03:46.0238 4480        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
16:03:46.0316 4480        AxInstSV - ok
16:03:46.0456 4480        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys
16:03:46.0519 4480        b06bdrv - ok
16:03:46.0644 4480        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
16:03:46.0690 4480        b57nd60a - ok
16:03:46.0815 4480        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
16:03:46.0862 4480        BDESVC - ok
16:03:46.0971 4480        Beep            (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
16:03:47.0049 4480        Beep - ok
16:03:47.0190 4480        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
16:03:47.0268 4480        BFE - ok
16:03:47.0408 4480        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\windows\System32\qmgr.dll
16:03:47.0517 4480        BITS - ok
16:03:47.0626 4480        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
16:03:47.0673 4480        blbdrive - ok
16:03:47.0798 4480        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
16:03:47.0845 4480        bowser - ok
16:03:47.0954 4480        BPntDrv        (aaa4f992f879977a000fe8b8c730cd2c) C:\windows\system32\drivers\BPntDrv.sys
16:03:47.0970 4480        BPntDrv - ok
16:03:48.0032 4480        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys
16:03:48.0126 4480        BrFiltLo - ok
16:03:48.0219 4480        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys
16:03:48.0250 4480        BrFiltUp - ok
16:03:48.0375 4480        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
16:03:48.0438 4480        Browser - ok
16:03:48.0547 4480        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
16:03:48.0625 4480        Brserid - ok
16:03:48.0734 4480        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
16:03:48.0765 4480        BrSerWdm - ok
16:03:48.0874 4480        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
16:03:48.0937 4480        BrUsbMdm - ok
16:03:49.0030 4480        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
16:03:49.0077 4480        BrUsbSer - ok
16:03:49.0186 4480        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\windows\system32\drivers\BthEnum.sys
16:03:49.0249 4480        BthEnum - ok
16:03:49.0342 4480        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys
16:03:49.0374 4480        BTHMODEM - ok
16:03:49.0467 4480        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\windows\system32\DRIVERS\bthpan.sys
16:03:49.0514 4480        BthPan - ok
16:03:49.0639 4480        BTHPORT        (64c198198501f7560ee41d8d1efa7952) C:\windows\System32\Drivers\BTHport.sys
16:03:49.0701 4480        BTHPORT - ok
16:03:49.0795 4480        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
16:03:49.0873 4480        bthserv - ok
16:03:49.0935 4480        BTHUSB          (f188b7394d81010767b6df3178519a37) C:\windows\System32\Drivers\BTHUSB.sys
16:03:49.0982 4480        BTHUSB - ok
16:03:50.0107 4480        cdfs            (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
16:03:50.0200 4480        cdfs - ok
16:03:50.0310 4480        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\DRIVERS\cdrom.sys
16:03:50.0341 4480        cdrom - ok
16:03:50.0450 4480        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
16:03:50.0544 4480        CertPropSvc - ok
16:03:50.0622 4480        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys
16:03:50.0668 4480        circlass - ok
16:03:50.0762 4480        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
16:03:50.0793 4480        CLFS - ok
16:03:50.0902 4480        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:03:50.0918 4480        clr_optimization_v2.0.50727_32 - ok
16:03:50.0965 4480        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
16:03:50.0996 4480        clr_optimization_v2.0.50727_64 - ok
16:03:51.0121 4480        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:03:51.0168 4480        clr_optimization_v4.0.30319_32 - ok
16:03:51.0277 4480        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
16:03:51.0324 4480        clr_optimization_v4.0.30319_64 - ok
16:03:51.0433 4480        clwvd          (50f92c943f18b070f166d019dfab3d9a) C:\windows\system32\DRIVERS\clwvd.sys
16:03:51.0448 4480        clwvd - ok
16:03:51.0480 4480        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
16:03:51.0526 4480        CmBatt - ok
16:03:51.0604 4480        cmdide          (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
16:03:51.0636 4480        cmdide - ok
16:03:51.0698 4480        CNG            (c4943b6c962e4b82197542447ad599f4) C:\windows\system32\Drivers\cng.sys
16:03:51.0745 4480        CNG - ok
16:03:51.0870 4480        CnxtHdAudService (a9078365cce6ddf02dd9e5a3591df1f5) C:\windows\system32\drivers\CHDRT64.sys
16:03:51.0932 4480        CnxtHdAudService - ok
16:03:52.0041 4480        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
16:03:52.0057 4480        Compbatt - ok
16:03:52.0119 4480        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\windows\system32\drivers\CompositeBus.sys
16:03:52.0150 4480        CompositeBus - ok
16:03:52.0213 4480        COMSysApp - ok
16:03:52.0291 4480        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys
16:03:52.0306 4480        crcdisk - ok
16:03:52.0431 4480        CryptSvc        (15597883fbe9b056f276ada3ad87d9af) C:\windows\system32\cryptsvc.dll
16:03:52.0509 4480        CryptSvc - ok
16:03:52.0618 4480        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
16:03:52.0712 4480        DcomLaunch - ok
16:03:52.0790 4480        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
16:03:52.0884 4480        defragsvc - ok
16:03:52.0993 4480        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
16:03:53.0071 4480        DfsC - ok
16:03:53.0196 4480        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
16:03:53.0274 4480        Dhcp - ok
16:03:53.0336 4480        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
16:03:53.0430 4480        discache - ok
16:03:53.0523 4480        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys
16:03:53.0554 4480        Disk - ok
16:03:53.0601 4480        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
16:03:53.0648 4480        Dnscache - ok
16:03:53.0742 4480        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
16:03:53.0835 4480        dot3svc - ok
16:03:53.0898 4480        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
16:03:53.0976 4480        DPS - ok
16:03:54.0069 4480        drmkaud        (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
16:03:54.0116 4480        drmkaud - ok
16:03:54.0241 4480        dtsoftbus01    (d3d64cf7b2bceaa34a270f45a3fffb36) C:\windows\system32\DRIVERS\dtsoftbus01.sys
16:03:54.0256 4480        dtsoftbus01 - ok
16:03:54.0319 4480        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
16:03:54.0381 4480        DXGKrnl - ok
16:03:54.0475 4480        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
16:03:54.0553 4480        EapHost - ok
16:03:54.0678 4480        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys
16:03:54.0834 4480        ebdrv - ok
16:03:54.0912 4480        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
16:03:54.0958 4480        EFS - ok
16:03:55.0052 4480        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
16:03:55.0161 4480        ehRecvr - ok
16:03:55.0224 4480        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
16:03:55.0255 4480        ehSched - ok
16:03:55.0348 4480        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys
16:03:55.0380 4480        elxstor - ok
16:03:55.0489 4480        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
16:03:55.0520 4480        ErrDev - ok
16:03:55.0629 4480        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
16:03:55.0707 4480        EventSystem - ok
16:03:55.0770 4480        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
16:03:55.0848 4480        exfat - ok
16:03:55.0941 4480        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
16:03:56.0019 4480        fastfat - ok
16:03:56.0144 4480        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
16:03:56.0206 4480        Fax - ok
16:03:56.0316 4480        fbfmon          (3191aca33088ee2481044fc0db736442) C:\windows\system32\drivers\fbfmon.sys
16:03:56.0331 4480        fbfmon - ok
16:03:56.0362 4480        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys
16:03:56.0394 4480        fdc - ok
16:03:56.0456 4480        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
16:03:56.0550 4480        fdPHost - ok
16:03:56.0581 4480        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
16:03:56.0659 4480        FDResPub - ok
16:03:56.0752 4480        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
16:03:56.0768 4480        FileInfo - ok
16:03:56.0815 4480        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
16:03:56.0893 4480        Filetrace - ok
16:03:56.0971 4480        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys
16:03:57.0002 4480        flpydisk - ok
16:03:57.0064 4480        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
16:03:57.0096 4480        FltMgr - ok
16:03:57.0174 4480        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\windows\system32\FntCache.dll
16:03:57.0252 4480        FontCache - ok
16:03:57.0376 4480        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:03:57.0392 4480        FontCache3.0.0.0 - ok
16:03:57.0454 4480        FsDepends      (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
16:03:57.0470 4480        FsDepends - ok
16:03:57.0532 4480        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys
16:03:57.0548 4480        Fs_Rec - ok
16:03:57.0626 4480        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
16:03:57.0657 4480        fvevol - ok
16:03:57.0766 4480        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys
16:03:57.0782 4480        gagp30kx - ok
16:03:57.0860 4480        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
16:03:57.0954 4480        gpsvc - ok
16:03:58.0047 4480        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
16:03:58.0094 4480        hcw85cir - ok
16:03:58.0203 4480        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
16:03:58.0250 4480        HdAudAddService - ok
16:03:58.0375 4480        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\drivers\HDAudBus.sys
16:03:58.0437 4480        HDAudBus - ok
16:03:58.0468 4480        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys
16:03:58.0500 4480        HidBatt - ok
16:03:58.0593 4480        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys
16:03:58.0640 4480        HidBth - ok
16:03:58.0749 4480        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys
16:03:58.0796 4480        HidIr - ok
16:03:58.0874 4480        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\windows\system32\hidserv.dll
16:03:58.0952 4480        hidserv - ok
16:03:59.0046 4480        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\DRIVERS\hidusb.sys
16:03:59.0077 4480        HidUsb - ok
16:03:59.0155 4480        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
16:03:59.0233 4480        hkmsvc - ok
16:03:59.0358 4480        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
16:03:59.0420 4480        HomeGroupListener - ok
16:03:59.0467 4480        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
16:03:59.0514 4480        HomeGroupProvider - ok
16:03:59.0623 4480        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
16:03:59.0654 4480        HpSAMD - ok
16:03:59.0748 4480        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
16:03:59.0841 4480        HTTP - ok
16:03:59.0950 4480        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
16:03:59.0966 4480        hwpolicy - ok
16:04:00.0044 4480        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\drivers\i8042prt.sys
16:04:00.0075 4480        i8042prt - ok
16:04:00.0169 4480        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
16:04:00.0200 4480        iaStorV - ok
16:04:00.0356 4480        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
16:04:00.0403 4480        idsvc - ok
16:04:00.0606 4480        igfx            (a87261ef1546325b559374f5689cf5bc) C:\windows\system32\DRIVERS\igdkmd64.sys
16:04:00.0871 4480        igfx - ok
16:04:00.0996 4480        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys
16:04:01.0027 4480        iirsp - ok
16:04:01.0105 4480        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
16:04:01.0198 4480        IKEEXT - ok
16:04:01.0323 4480        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
16:04:01.0339 4480        intelide - ok
16:04:01.0401 4480        intelppm        (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
16:04:01.0432 4480        intelppm - ok
16:04:01.0495 4480        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
16:04:01.0573 4480        IPBusEnum - ok
16:04:01.0635 4480        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
16:04:01.0729 4480        IpFilterDriver - ok
16:04:01.0822 4480        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
16:04:01.0900 4480        iphlpsvc - ok
16:04:02.0010 4480        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
16:04:02.0056 4480        IPMIDRV - ok
16:04:02.0088 4480        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
16:04:02.0166 4480        IPNAT - ok
16:04:02.0259 4480        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
16:04:02.0322 4480        IRENUM - ok
16:04:02.0431 4480        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
16:04:02.0446 4480        isapnp - ok
16:04:02.0478 4480        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
16:04:02.0509 4480        iScsiPrt - ok
16:04:02.0618 4480        k57nd60a        (7dbafe10c1b777305c80bea42fbda710) C:\windows\system32\DRIVERS\k57nd60a.sys
16:04:02.0665 4480        k57nd60a - ok
16:04:02.0774 4480        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\drivers\kbdclass.sys
16:04:02.0790 4480        kbdclass - ok
16:04:02.0868 4480        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\drivers\kbdhid.sys
16:04:02.0914 4480        kbdhid - ok
16:04:03.0008 4480        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
16:04:03.0024 4480        KeyIso - ok
16:04:03.0055 4480        KSecDD          (da1e991a61cfdd755a589e206b97644b) C:\windows\system32\Drivers\ksecdd.sys
16:04:03.0070 4480        KSecDD - ok
16:04:03.0102 4480        KSecPkg        (7e33198d956943a4f11a5474c1e9106f) C:\windows\system32\Drivers\ksecpkg.sys
16:04:03.0117 4480        KSecPkg - ok
16:04:03.0211 4480        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
16:04:03.0304 4480        ksthunk - ok
16:04:03.0336 4480        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
16:04:03.0429 4480        KtmRm - ok
16:04:03.0523 4480        L1C            (32980b4e711d2ef7128c44dc2cf85706) C:\windows\system32\DRIVERS\L1C62x64.sys
16:04:03.0538 4480        L1C - ok
16:04:03.0648 4480        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\system32\srvsvc.dll
16:04:03.0741 4480        LanmanServer - ok
16:04:03.0850 4480        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
16:04:03.0928 4480        LanmanWorkstation - ok
16:04:03.0991 4480        LHDmgr          (be166935083f9c38edfdc21b9a7a679b) C:\windows\system32\DRIVERS\LhdX64.sys
16:04:04.0006 4480        LHDmgr - ok
16:04:04.0084 4480        lltdio          (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
16:04:04.0162 4480        lltdio - ok
16:04:04.0256 4480        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
16:04:04.0350 4480        lltdsvc - ok
16:04:04.0396 4480        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
16:04:04.0474 4480        lmhosts - ok
16:04:04.0568 4480        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys
16:04:04.0584 4480        LSI_FC - ok
16:04:04.0646 4480        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys
16:04:04.0662 4480        LSI_SAS - ok
16:04:04.0755 4480        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys
16:04:04.0771 4480        LSI_SAS2 - ok
16:04:04.0802 4480        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys
16:04:04.0833 4480        LSI_SCSI - ok
16:04:04.0927 4480        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
16:04:05.0005 4480        luafv - ok
16:04:05.0114 4480        lxdnCATSCustConnectService (4208b958e35f0e596aa241efb664636b) C:\windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe
16:04:05.0176 4480        lxdnCATSCustConnectService - ok
16:04:05.0254 4480        lxdn_device - ok
16:04:05.0395 4480        MBAMProtector  (79da94b35371b9e7104460c7693dcb2c) C:\windows\system32\drivers\mbam.sys
16:04:05.0410 4480        MBAMProtector - ok
16:04:05.0488 4480        MBAMService    (056b19651bd7b7ce5f89a3ac46dbdc08) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
16:04:05.0520 4480        MBAMService - ok
16:04:05.0660 4480        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
16:04:05.0691 4480        Mcx2Svc - ok
16:04:05.0769 4480        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys
16:04:05.0785 4480        megasas - ok
16:04:05.0816 4480        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys
16:04:05.0847 4480        MegaSR - ok
16:04:05.0894 4480        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
16:04:05.0972 4480        MMCSS - ok
16:04:06.0050 4480        Modem          (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
16:04:06.0128 4480        Modem - ok
16:04:06.0237 4480        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
16:04:06.0268 4480        monitor - ok
16:04:06.0378 4480        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\drivers\mouclass.sys
16:04:06.0393 4480        mouclass - ok
16:04:06.0518 4480        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
16:04:06.0549 4480        mouhid - ok
16:04:06.0658 4480        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
16:04:06.0690 4480        mountmgr - ok
16:04:06.0736 4480        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
16:04:06.0752 4480        mpio - ok
16:04:06.0861 4480        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
16:04:06.0939 4480        mpsdrv - ok
16:04:07.0064 4480        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\windows\system32\mpssvc.dll
16:04:07.0158 4480        MpsSvc - ok
16:04:07.0282 4480        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
16:04:07.0329 4480        MRxDAV - ok
16:04:07.0470 4480        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
16:04:07.0501 4480        mrxsmb - ok
16:04:07.0594 4480        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
16:04:07.0626 4480        mrxsmb10 - ok
16:04:07.0688 4480        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
16:04:07.0704 4480        mrxsmb20 - ok
16:04:07.0828 4480        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
16:04:07.0844 4480        msahci - ok
16:04:07.0891 4480        msdsm          (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
16:04:07.0922 4480        msdsm - ok
16:04:08.0094 4480        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
16:04:08.0234 4480        MSDTC - ok
16:04:08.0406 4480        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
16:04:08.0468 4480        Msfs - ok
16:04:08.0577 4480        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
16:04:08.0640 4480        mshidkmdf - ok
16:04:08.0671 4480        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
16:04:08.0702 4480        msisadrv - ok
16:04:08.0796 4480        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
16:04:08.0874 4480        MSiSCSI - ok
16:04:08.0889 4480        msiserver - ok
16:04:08.0983 4480        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
16:04:09.0076 4480        MSKSSRV - ok
16:04:09.0186 4480        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
16:04:09.0264 4480        MSPCLOCK - ok
16:04:09.0357 4480        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
16:04:09.0435 4480        MSPQM - ok
16:04:09.0498 4480        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
16:04:09.0529 4480        MsRPC - ok
16:04:09.0607 4480        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\drivers\mssmbios.sys
16:04:09.0638 4480        mssmbios - ok
16:04:09.0669 4480        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
16:04:09.0763 4480        MSTEE - ok
16:04:09.0841 4480        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys
16:04:09.0856 4480        MTConfig - ok
16:04:09.0903 4480        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
16:04:09.0919 4480        Mup - ok
16:04:10.0012 4480        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
16:04:10.0106 4480        napagent - ok
16:04:10.0231 4480        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
16:04:10.0278 4480        NativeWifiP - ok
16:04:10.0434 4480        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\windows\system32\drivers\ndis.sys
16:04:10.0480 4480        NDIS - ok
16:04:10.0574 4480        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
16:04:10.0652 4480        NdisCap - ok
16:04:10.0761 4480        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
16:04:10.0824 4480        NdisTapi - ok
16:04:10.0902 4480        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
16:04:10.0980 4480        Ndisuio - ok
16:04:11.0073 4480        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
16:04:11.0167 4480        NdisWan - ok
16:04:11.0276 4480        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
16:04:11.0354 4480        NDProxy - ok
16:04:11.0463 4480        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
16:04:11.0557 4480        NetBIOS - ok
16:04:11.0604 4480        NetBT          (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
16:04:11.0682 4480        NetBT - ok
16:04:11.0775 4480        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
16:04:11.0791 4480        Netlogon - ok
16:04:11.0838 4480        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
16:04:11.0916 4480        Netman - ok
16:04:12.0025 4480        NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:04:12.0040 4480        NetMsmqActivator - ok
16:04:12.0056 4480        NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:04:12.0072 4480        NetPipeActivator - ok
16:04:12.0118 4480        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
16:04:12.0228 4480        netprofm - ok
16:04:12.0337 4480        NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:04:12.0352 4480        NetTcpActivator - ok
16:04:12.0368 4480        NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:04:12.0384 4480        NetTcpPortSharing - ok
16:04:12.0602 4480        netw5v64        (64428dfdaf6e88366cb51f45a79c5f69) C:\windows\system32\DRIVERS\netw5v64.sys
16:04:12.0805 4480        netw5v64 - ok
16:04:12.0898 4480        nfrd960        (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys
16:04:12.0914 4480        nfrd960 - ok
16:04:13.0008 4480        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
16:04:13.0101 4480        NlaSvc - ok
16:04:13.0164 4480        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
16:04:13.0242 4480        Npfs - ok
16:04:13.0304 4480        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
16:04:13.0366 4480        nsi - ok
16:04:13.0429 4480        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
16:04:13.0507 4480        nsiproxy - ok
16:04:13.0616 4480        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
16:04:13.0678 4480        Ntfs - ok
16:04:13.0772 4480        Null            (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
16:04:13.0850 4480        Null - ok
16:04:13.0944 4480        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
16:04:13.0975 4480        nvraid - ok
16:04:13.0990 4480        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
16:04:14.0022 4480        nvstor - ok
16:04:14.0146 4480        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
16:04:14.0162 4480        nv_agp - ok
16:04:14.0287 4480        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
16:04:14.0318 4480        ohci1394 - ok
16:04:14.0380 4480        ose            (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:04:14.0396 4480        ose - ok
16:04:14.0458 4480        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
16:04:14.0505 4480        p2pimsvc - ok
16:04:14.0536 4480        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
16:04:14.0583 4480        p2psvc - ok
16:04:14.0661 4480        Parport        (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys
16:04:14.0692 4480        Parport - ok
16:04:14.0755 4480        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\windows\system32\drivers\partmgr.sys
16:04:14.0770 4480        partmgr - ok
16:04:14.0833 4480        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
16:04:14.0880 4480        PcaSvc - ok
16:04:14.0958 4480        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
16:04:14.0973 4480        pci - ok
16:04:15.0067 4480        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
16:04:15.0082 4480        pciide - ok
16:04:15.0129 4480        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys
16:04:15.0160 4480        pcmcia - ok
16:04:15.0207 4480        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
16:04:15.0238 4480        pcw - ok
16:04:15.0285 4480        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
16:04:15.0379 4480        PEAUTH - ok
16:04:15.0472 4480        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
16:04:15.0519 4480        PerfHost - ok
16:04:15.0628 4480        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
16:04:15.0738 4480        pla - ok
16:04:15.0847 4480        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
16:04:15.0909 4480        PlugPlay - ok
16:04:15.0987 4480        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
16:04:16.0018 4480        PNRPAutoReg - ok
16:04:16.0050 4480        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
16:04:16.0081 4480        PNRPsvc - ok
16:04:16.0174 4480        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
16:04:16.0268 4480        PolicyAgent - ok
16:04:16.0346 4480        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
16:04:16.0424 4480        Power - ok
16:04:16.0502 4480        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
16:04:16.0580 4480        PptpMiniport - ok
16:04:16.0642 4480        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys
16:04:16.0689 4480        Processor - ok
16:04:16.0783 4480        ProfSvc        (5c78838b4d166d1a27db3a8a820c799a) C:\windows\system32\profsvc.dll
16:04:16.0861 4480        ProfSvc - ok
16:04:16.0908 4480        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
16:04:16.0939 4480        ProtectedStorage - ok
16:04:17.0048 4480        Psched          (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
16:04:17.0126 4480        Psched - ok
16:04:17.0188 4480        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys
16:04:17.0251 4480        ql2300 - ok
16:04:17.0329 4480        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys
16:04:17.0360 4480        ql40xx - ok
16:04:17.0407 4480        QWAVE          (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
16:04:17.0454 4480        QWAVE - ok
16:04:17.0532 4480        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
16:04:17.0578 4480        QWAVEdrv - ok
16:04:17.0672 4480        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
16:04:17.0750 4480        RasAcd - ok
16:04:17.0859 4480        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
16:04:17.0922 4480        RasAgileVpn - ok
16:04:17.0953 4480        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
16:04:18.0031 4480        RasAuto - ok
16:04:18.0140 4480        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
16:04:18.0234 4480        Rasl2tp - ok
16:04:18.0343 4480        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
16:04:18.0421 4480        RasMan - ok
16:04:18.0483 4480        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
16:04:18.0561 4480        RasPppoe - ok
16:04:18.0670 4480        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
16:04:18.0748 4480        RasSstp - ok
16:04:18.0858 4480        rdbss          (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
16:04:18.0936 4480        rdbss - ok
16:04:18.0967 4480        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys
16:04:19.0014 4480        rdpbus - ok
16:04:19.0138 4480        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
16:04:19.0201 4480        RDPCDD - ok
16:04:19.0248 4480        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
16:04:19.0326 4480        RDPENCDD - ok
16:04:19.0419 4480        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
16:04:19.0497 4480        RDPREFMP - ok
16:04:19.0544 4480        RDPWD          (6d76e6433574b058adcb0c50df834492) C:\windows\system32\drivers\RDPWD.sys
16:04:19.0591 4480        RDPWD - ok
16:04:19.0716 4480        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
16:04:19.0731 4480        rdyboost - ok
16:04:19.0840 4480        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
16:04:19.0918 4480        RemoteAccess - ok
16:04:19.0965 4480        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
16:04:20.0043 4480        RemoteRegistry - ok
16:04:20.0137 4480        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\windows\system32\DRIVERS\rfcomm.sys
16:04:20.0199 4480        RFCOMM - ok
16:04:20.0308 4480        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
16:04:20.0386 4480        RpcEptMapper - ok
16:04:20.0418 4480        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
16:04:20.0449 4480        RpcLocator - ok
16:04:20.0558 4480        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
16:04:20.0636 4480        RpcSs - ok
16:04:20.0714 4480        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
16:04:20.0808 4480        rspndr - ok
16:04:20.0932 4480        RSUSBVSTOR      (89dfb71b370d82dfe75183f677043cee) C:\windows\system32\Drivers\RtsUVStor.sys
16:04:20.0964 4480        RSUSBVSTOR - ok
16:04:21.0010 4480        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
16:04:21.0042 4480        SamSs - ok
16:04:21.0135 4480        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
16:04:21.0151 4480        sbp2port - ok
16:04:21.0198 4480        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
16:04:21.0276 4480        SCardSvr - ok
16:04:21.0369 4480        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
16:04:21.0432 4480        scfilter - ok
16:04:21.0510 4480        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
16:04:21.0619 4480        Schedule - ok
16:04:21.0712 4480        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
16:04:21.0775 4480        SCPolicySvc - ok
16:04:21.0806 4480        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
16:04:21.0868 4480        SDRSVC - ok
16:04:21.0962 4480        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
16:04:22.0040 4480        secdrv - ok
16:04:22.0134 4480        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
16:04:22.0212 4480        seclogon - ok
16:04:22.0243 4480        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\windows\System32\sens.dll
16:04:22.0336 4480        SENS - ok
16:04:22.0414 4480        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
16:04:22.0461 4480        SensrSvc - ok
16:04:22.0508 4480        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys
16:04:22.0539 4480        Serenum - ok
16:04:22.0664 4480        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys
16:04:22.0711 4480        Serial - ok
16:04:22.0820 4480        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys
16:04:22.0851 4480        sermouse - ok
16:04:22.0914 4480        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
16:04:22.0992 4480        SessionEnv - ok
16:04:23.0101 4480        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
16:04:23.0148 4480        sffdisk - ok
16:04:23.0272 4480        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
16:04:23.0288 4480        sffp_mmc - ok
16:04:23.0319 4480        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
16:04:23.0350 4480        sffp_sd - ok
16:04:23.0444 4480        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys
16:04:23.0475 4480        sfloppy - ok
16:04:23.0522 4480        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
16:04:23.0616 4480        SharedAccess - ok
16:04:23.0709 4480        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
16:04:23.0787 4480        ShellHWDetection - ok
16:04:23.0881 4480        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys
16:04:23.0912 4480        SiSRaid2 - ok
16:04:23.0943 4480        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys
16:04:23.0959 4480        SiSRaid4 - ok
16:04:24.0052 4480        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
16:04:24.0130 4480        Smb - ok
16:04:24.0224 4480        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
16:04:24.0271 4480        SNMPTRAP - ok
16:04:24.0318 4480        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
16:04:24.0333 4480        spldr - ok
16:04:24.0442 4480        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
16:04:24.0520 4480        Spooler - ok
16:04:24.0692 4480        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
16:04:24.0864 4480        sppsvc - ok
16:04:24.0957 4480        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
16:04:25.0051 4480        sppuinotify - ok
16:04:25.0113 4480        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
16:04:25.0160 4480        srv - ok
16:04:25.0254 4480        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
16:04:25.0300 4480        srv2 - ok
16:04:25.0378 4480        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
16:04:25.0441 4480        srvnet - ok
16:04:25.0534 4480        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
16:04:25.0612 4480        SSDPSRV - ok
16:04:25.0644 4480        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
16:04:25.0722 4480        SstpSvc - ok
16:04:25.0784 4480        Steam Client Service - ok
16:04:25.0846 4480        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys
16:04:25.0878 4480        stexstor - ok
16:04:25.0940 4480        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
16:04:26.0002 4480        stisvc - ok
16:04:26.0143 4480        StumbleUponUpdater (3fb1d84d673b4a9af3856c8843c7a464) C:\Users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe
16:04:26.0158 4480        StumbleUponUpdater ( UnsignedFile.Multi.Generic ) - warning
16:04:26.0158 4480        StumbleUponUpdater - detected UnsignedFile.Multi.Generic (1)
16:04:26.0252 4480        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\drivers\swenum.sys
16:04:26.0268 4480        swenum - ok
16:04:26.0314 4480        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
16:04:26.0408 4480        swprv - ok
16:04:26.0517 4480        SynTP          (b3ad15fa10ebeafc1275f34050e4e230) C:\windows\system32\DRIVERS\SynTP.sys
16:04:26.0580 4480        SynTP - ok
16:04:26.0720 4480        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
16:04:26.0814 4480        SysMain - ok
16:04:26.0892 4480        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
16:04:26.0938 4480        TabletInputService - ok
16:04:26.0970 4480        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
16:04:27.0063 4480        TapiSrv - ok
16:04:27.0094 4480        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
16:04:27.0157 4480        TBS - ok
16:04:27.0266 4480        Tcpip          (fc62769e7bff2896035aeed399108162) C:\windows\system32\drivers\tcpip.sys
16:04:27.0344 4480        Tcpip - ok
16:04:27.0500 4480        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\windows\system32\DRIVERS\tcpip.sys
16:04:27.0562 4480        TCPIP6 - ok
16:04:27.0672 4480        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
16:04:27.0750 4480        tcpipreg - ok
16:04:27.0812 4480        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
16:04:27.0843 4480        TDPIPE - ok
16:04:27.0921 4480        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
16:04:27.0952 4480        TDTCP - ok
16:04:28.0015 4480        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
16:04:28.0093 4480        tdx - ok
16:04:28.0155 4480        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\drivers\termdd.sys
16:04:28.0186 4480        TermDD - ok
16:04:28.0280 4480        TermService    (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
16:04:28.0358 4480        TermService - ok
16:04:28.0436 4480        Themes          (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
16:04:28.0483 4480        Themes - ok
16:04:28.0530 4480        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
16:04:28.0592 4480        THREADORDER - ok
16:04:28.0654 4480        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
16:04:28.0748 4480        TrkWks - ok
16:04:28.0810 4480        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\windows\servicing\TrustedInstaller.exe
16:04:28.0873 4480        TrustedInstaller - ok
16:04:28.0966 4480        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
16:04:29.0044 4480        tssecsrv - ok
16:04:29.0091 4480        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
16:04:29.0138 4480        TsUsbFlt - ok
16:04:29.0247 4480        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
16:04:29.0310 4480        tunnel - ok
16:04:29.0356 4480        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys
16:04:29.0372 4480        uagp35 - ok
16:04:29.0481 4480        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
16:04:29.0559 4480        udfs - ok
16:04:29.0622 4480        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\windows\system32\UI0Detect.exe
16:04:29.0653 4480        UI0Detect - ok
16:04:29.0762 4480        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
16:04:29.0793 4480        uliagpkx - ok
16:04:29.0887 4480        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\drivers\umbus.sys
16:04:29.0918 4480        umbus - ok
16:04:29.0949 4480        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys
16:04:29.0996 4480        UmPass - ok
16:04:30.0105 4480        UnlockerDriver5 (9dc07e73a4abb9acf692113b36a5009f) C:\Program Files\Unlocker\UnlockerDriver5.sys
16:04:30.0121 4480        UnlockerDriver5 - ok
16:04:30.0214 4480        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\windows\System32\upnphost.dll
16:04:30.0292 4480        upnphost - ok
16:04:30.0402 4480        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
16:04:30.0448 4480        usbccgp - ok
16:04:30.0573 4480        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
16:04:30.0620 4480        usbcir - ok
16:04:30.0651 4480        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\DRIVERS\usbehci.sys
16:04:30.0698 4480        usbehci - ok
16:04:30.0792 4480        usbfilter      (76e2ffad301490ba27b947c6507752fb) C:\windows\system32\DRIVERS\usbfilter.sys
16:04:30.0807 4480        usbfilter - ok
16:04:30.0870 4480        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\DRIVERS\usbhub.sys
16:04:30.0916 4480        usbhub - ok
16:04:30.0994 4480        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\DRIVERS\usbohci.sys
16:04:31.0041 4480        usbohci - ok
16:04:31.0119 4480        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys
16:04:31.0166 4480        usbprint - ok
16:04:31.0260 4480        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys
16:04:31.0291 4480        usbscan - ok
16:04:31.0322 4480        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
16:04:31.0369 4480        USBSTOR - ok
16:04:31.0462 4480        usbUDisc        (6d14d8ec1dd33a072653e75e3b28b062) C:\windows\system32\DRIVERS\USBDrv_AMD64.sys
16:04:31.0478 4480        usbUDisc - ok
16:04:31.0525 4480        usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\windows\system32\DRIVERS\usbuhci.sys
16:04:31.0556 4480        usbuhci - ok
16:04:31.0681 4480        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\windows\System32\Drivers\usbvideo.sys
16:04:31.0743 4480        usbvideo - ok
16:04:31.0821 4480        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\windows\System32\uxsms.dll
16:04:31.0915 4480        UxSms - ok
16:04:31.0977 4480        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
16:04:32.0008 4480        VaultSvc - ok
16:04:32.0102 4480        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
16:04:32.0133 4480        vdrvroot - ok
16:04:32.0211 4480        vds            (8d6b481601d01a456e75c3210f1830be) C:\windows\System32\vds.exe
16:04:32.0289 4480        vds - ok
16:04:32.0367 4480        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
16:04:32.0398 4480        vga - ok
16:04:32.0430 4480        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
16:04:32.0508 4480        VgaSave - ok
16:04:32.0617 4480        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
16:04:32.0632 4480        vhdmp - ok
16:04:32.0679 4480        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
16:04:32.0695 4480        viaide - ok
16:04:32.0788 4480        vm2uvcflt      (5cb80afa98111fc6ed6e8702a0d7ac5b) C:\windows\system32\Drivers\vm2uvcflt.sys
16:04:32.0804 4480        vm2uvcflt - ok
16:04:32.0851 4480        vm332avs        (fe75ed0244aedff9b278a2a09ac06ca9) C:\windows\system32\Drivers\vm332avs.sys
16:04:32.0866 4480        vm332avs - ok
16:04:32.0929 4480        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
16:04:32.0944 4480        volmgr - ok
16:04:33.0054 4480        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
16:04:33.0085 4480        volmgrx - ok
16:04:33.0132 4480        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\windows\system32\drivers\volsnap.sys
16:04:33.0163 4480        volsnap - ok
16:04:33.0241 4480        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys
16:04:33.0256 4480        vsmraid - ok
16:04:33.0366 4480        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\windows\system32\vssvc.exe
16:04:33.0475 4480        VSS - ok
16:04:33.0553 4480        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
16:04:33.0600 4480        vwifibus - ok
16:04:33.0631 4480        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
16:04:33.0678 4480        vwififlt - ok
16:04:33.0771 4480        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\windows\system32\DRIVERS\vwifimp.sys
16:04:33.0802 4480        vwifimp - ok
16:04:33.0849 4480        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\windows\system32\w32time.dll
16:04:33.0927 4480        W32Time - ok
16:04:34.0021 4480        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys
16:04:34.0052 4480        WacomPen - ok
16:04:34.0177 4480        WANARP          (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
16:04:34.0239 4480        WANARP - ok
16:04:34.0255 4480        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
16:04:34.0333 4480        Wanarpv6 - ok
16:04:34.0411 4480        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\windows\system32\wbengine.exe
16:04:34.0473 4480        wbengine - ok
16:04:34.0567 4480        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\windows\System32\wbiosrvc.dll
16:04:34.0598 4480        WbioSrvc - ok
16:04:34.0676 4480        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\windows\System32\wcncsvc.dll
16:04:34.0738 4480        wcncsvc - ok
16:04:34.0816 4480        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\windows\System32\WcsPlugInService.dll
16:04:34.0848 4480        WcsPlugInService - ok
16:04:34.0879 4480        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys
16:04:34.0910 4480        Wd - ok
16:04:34.0988 4480        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
16:04:35.0019 4480        Wdf01000 - ok
16:04:35.0097 4480        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
16:04:35.0191 4480        WdiServiceHost - ok
16:04:35.0206 4480        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
16:04:35.0253 4480        WdiSystemHost - ok
16:04:35.0347 4480        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\windows\System32\webclnt.dll
16:04:35.0394 4480        WebClient - ok
16:04:35.0440 4480        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\windows\system32\wecsvc.dll
16:04:35.0518 4480        Wecsvc - ok
16:04:35.0596 4480        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\windows\System32\wercplsupport.dll
16:04:35.0674 4480        wercplsupport - ok
16:04:35.0768 4480        WerSvc          (6d137963730144698cbd10f202e9f251) C:\windows\System32\WerSvc.dll
16:04:35.0830 4480        WerSvc - ok
16:04:35.0893 4480        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
16:04:35.0955 4480        WfpLwf - ok
16:04:36.0018 4480        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
16:04:36.0033 4480        WIMMount - ok
16:04:36.0064 4480        WinDefend - ok
16:04:36.0096 4480        WinHttpAutoProxySvc - ok
16:04:36.0174 4480        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\windows\system32\wbem\WMIsvc.dll
16:04:36.0252 4480        Winmgmt - ok
16:04:36.0376 4480        WinRM          (bcb1310604aa415c4508708975b3931e) C:\windows\system32\WsmSvc.dll
16:04:36.0486 4480        WinRM - ok
16:04:36.0610 4480        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\windows\system32\DRIVERS\WinUsb.sys
16:04:36.0642 4480        WinUsb - ok
16:04:36.0704 4480        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\windows\System32\wlansvc.dll
16:04:36.0751 4480        Wlansvc - ok
16:04:36.0813 4480        wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
16:04:36.0829 4480        wlcrasvc - ok
16:04:36.0891 4480        wlidsvc        (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
16:04:36.0969 4480        wlidsvc - ok
16:04:37.0078 4480        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\drivers\wmiacpi.sys
16:04:37.0110 4480        WmiAcpi - ok
16:04:37.0203 4480        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\windows\system32\wbem\WmiApSrv.exe
16:04:37.0250 4480        wmiApSrv - ok
16:04:37.0281 4480        WMPNetworkSvc - ok
16:04:37.0359 4480        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\windows\System32\wpcsvc.dll
16:04:37.0390 4480        WPCSvc - ok
16:04:37.0453 4480        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\windows\system32\wpdbusenum.dll
16:04:37.0484 4480        WPDBusEnum - ok
16:04:37.0546 4480        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
16:04:37.0624 4480        ws2ifsl - ok
16:04:37.0671 4480        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\windows\System32\wscsvc.dll
16:04:37.0718 4480        wscsvc - ok
16:04:37.0749 4480        WSearch - ok
16:04:37.0858 4480        wsvd            (83575c43b2bfe9ab0661a7f957e843c0) C:\windows\system32\DRIVERS\wsvd.sys
16:04:37.0890 4480        wsvd - ok
16:04:37.0983 4480        wuauserv        (9df12edbc698b0bc353b3ef84861e430) C:\windows\system32\wuaueng.dll
16:04:38.0108 4480        wuauserv - ok
16:04:38.0217 4480        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
16:04:38.0295 4480        WudfPf - ok
16:04:38.0420 4480        WUDFRd          (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
16:04:38.0498 4480        WUDFRd - ok
16:04:38.0576 4480        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\windows\System32\WUDFSvc.dll
16:04:38.0654 4480        wudfsvc - ok
16:04:38.0685 4480        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\windows\System32\wwansvc.dll
16:04:38.0732 4480        WwanSvc - ok
16:04:38.0841 4480        xusb21          (2ee48cfce7ca8e0db4c44c7476c0943b) C:\windows\system32\DRIVERS\xusb21.sys
16:04:38.0888 4480        xusb21 - ok
16:04:38.0919 4480        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
16:04:39.0028 4480        \Device\Harddisk0\DR0 - ok
16:04:39.0044 4480        Boot (0x1200)  (ee1a14302dfbcb09c099bca907471a44) \Device\Harddisk0\DR0\Partition0
16:04:39.0044 4480        \Device\Harddisk0\DR0\Partition0 - ok
16:04:39.0075 4480        Boot (0x1200)  (1d2361db500e76e26a26fc8d37ab7c12) \Device\Harddisk0\DR0\Partition1
16:04:39.0075 4480        \Device\Harddisk0\DR0\Partition1 - ok
16:04:39.0106 4480        Boot (0x1200)  (f8fbbf31f610bd4b6ab29dfed0fc497e) \Device\Harddisk0\DR0\Partition2
16:04:39.0106 4480        \Device\Harddisk0\DR0\Partition2 - ok
16:04:39.0106 4480        ============================================================
16:04:39.0106 4480        Scan finished
16:04:39.0106 4480        ============================================================
16:04:39.0122 3544        Detected object count: 2
16:04:39.0122 3544        Actual detected object count: 2
16:04:55.0533 3544        acedrv07 ( UnsignedFile.Multi.Generic ) - skipped by user
16:04:55.0533 3544        acedrv07 ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:04:55.0533 3544        StumbleUponUpdater ( UnsignedFile.Multi.Generic ) - skipped by user
16:04:55.0533 3544        StumbleUponUpdater ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:07:11.0067 2084        Deinitialize success


cosinus 22.03.2012 16:26

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Madame 22.03.2012 17:13

EDIT: Ach, verdammt.. -.- Hatte den Windows Defender vergessen/übersehen... Noch mal mit Combofix deshalb oder geht das trotzdem?

Ging ohne Fehlermeldungen und schnell über die Bühne:

Code:

ComboFix 12-03-22.01 - Administrator 22.03.2012  16:54:02.1.2 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3691.2338 [GMT 1:00]
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\IsUn0407.exe
c:\windows\s.bat
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-02-22 bis 2012-03-22  ))))))))))))))))))))))))))))))
.
.
2012-03-22 16:03 . 2012-03-22 16:03        --------        d-----w-        c:\users\Sara\AppData\Local\temp
2012-03-22 16:03 . 2012-03-22 16:03        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-03-22 15:02 . 2012-03-22 15:02        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{DFFB39D9-A341-4186-B8AF-045F35EC84D0}\offreg.dll
2012-03-21 19:47 . 2012-03-21 19:47        --------        d-----w-        C:\_OTL
2012-03-20 17:17 . 2012-03-20 17:17        --------        d-----w-        c:\program files (x86)\ESET
2012-03-20 17:14 . 2012-02-08 07:13        8643640        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{DFFB39D9-A341-4186-B8AF-045F35EC84D0}\mpengine.dll
2012-03-20 02:43 . 2012-03-20 02:43        --------        d-----w-        c:\users\Administrator\AppData\Roaming\Malwarebytes
2012-03-20 02:42 . 2012-03-20 02:42        --------        d-----w-        c:\programdata\Malwarebytes
2012-03-20 02:42 . 2012-03-20 02:42        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-20 02:42 . 2011-12-10 14:24        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-03-20 01:03 . 2012-03-20 02:35        --------        d-----w-        c:\users\Administrator\AppData\Roaming\Skype
2012-03-17 07:09 . 2012-03-17 07:09        592824        ----a-w-        c:\program files (x86)\Mozilla Firefox\gkmedias.dll
2012-03-17 07:09 . 2012-03-17 07:09        44472        ----a-w-        c:\program files (x86)\Mozilla Firefox\mozglue.dll
2012-03-14 18:51 . 2012-03-14 18:51        --------        d-----w-        c:\users\Administrator\AppData\Roaming\RenPy
2012-03-14 16:55 . 2011-11-19 15:20        5559152        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-03-14 16:55 . 2011-11-19 14:50        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 16:55 . 2011-11-19 14:50        3913584        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 05:50 . 2012-02-03 04:34        3145728        ----a-w-        c:\windows\system32\win32k.sys
2012-03-14 05:50 . 2012-02-10 06:36        1544192        ----a-w-        c:\windows\system32\DWrite.dll
2012-03-14 05:50 . 2012-02-10 05:38        1077248        ----a-w-        c:\windows\SysWow64\DWrite.dll
2012-03-14 05:17 . 2012-01-25 06:38        77312        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-03-14 05:17 . 2012-01-25 06:38        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-03-14 05:17 . 2012-01-25 06:33        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-03-14 05:17 . 2012-02-17 06:38        1031680        ----a-w-        c:\windows\system32\rdpcore.dll
2012-03-14 05:17 . 2012-02-17 05:34        826880        ----a-w-        c:\windows\SysWow64\rdpcore.dll
2012-03-14 05:17 . 2012-02-17 04:58        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-03-14 05:17 . 2012-02-17 04:57        23552        ----a-w-        c:\windows\system32\drivers\tdtcp.sys
2012-03-09 01:52 . 2012-03-10 03:59        --------        d-----w-        c:\program files (x86)\Slingo Quest Hawaii
2012-03-09 01:39 . 2012-03-09 01:40        --------        d-----w-        c:\program files (x86)\Slingo Quest Egypt Beta
2012-03-09 01:38 . 2012-03-09 01:38        --------        d-----w-        c:\program files (x86)\Slingo Supreme
2012-03-09 01:38 . 2012-03-09 01:38        --------        d-----w-        c:\windows\Slingo Supreme
2012-03-09 01:29 . 2012-03-09 01:29        --------        d-----w-        c:\program files (x86)\Slingo Quest Amazon [UPDATE]
2012-03-06 23:44 . 2012-03-06 23:44        --------        d-----w-        c:\program files (x86)\Funkitron
2012-03-05 22:20 . 2012-02-28 16:15        611224        ----a-w-        c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2012-03-05 21:37 . 2012-03-16 18:09        --------        d-----w-        c:\users\Administrator\AppData\Roaming\funkitron
2012-03-03 23:06 . 2012-03-03 23:06        --------        d-----w-        c:\users\Administrator\AppData\Roaming\Iggels
2012-03-03 23:00 . 2012-03-03 23:03        --------        d-----w-        c:\users\Administrator\.junique
2012-03-03 23:00 . 2012-03-03 23:03        --------        d-----w-        c:\users\Administrator\AppData\Roaming\VMLoad
2012-03-03 22:54 . 2012-03-03 22:54        --------        d--h--w-        c:\programdata\Common Files
2012-03-03 22:07 . 2012-03-05 21:32        --------        d-----w-        c:\programdata\Big Fish Games
2012-03-03 22:07 . 2012-03-03 22:07        --------        d-----w-        c:\program files (x86)\Pflanzen gegen Zombies
2012-03-02 17:37 . 2012-03-02 17:37        --------        d-----w-        c:\windows\solcache
2012-03-02 17:36 . 2012-03-02 17:36        --------        d-----w-        c:\program files (x86)\Sierra On-Line
2012-03-02 17:36 . 2012-03-02 17:36        --------        d-----w-        C:\SIERRA
2012-03-02 17:35 . 1997-05-12 16:53        314368        ----a-w-        c:\windows\IsUninst.exe
2012-03-02 17:34 . 2012-03-02 18:17        --------        d-----w-        c:\program files (x86)\Spawn
2012-03-02 17:33 . 2012-03-02 17:34        2829        ----a-w-        c:\windows\DiabUnin.pif
2012-03-02 17:33 . 2012-03-02 17:34        118784        ----a-w-        c:\windows\DiabUnin.exe
2012-03-02 17:33 . 2012-03-03 21:03        --------        d-----w-        c:\program files (x86)\Diablo
2012-03-01 19:48 . 2012-03-01 19:48        --------        d-----w-        c:\programdata\SpecialBit Games
2012-03-01 19:47 . 2012-03-05 21:34        --------        d-----w-        c:\program files (x86)\Big Fish
2012-03-01 19:47 . 2012-03-05 21:32        --------        d-----w-        c:\program files (x86)\bfgclient
2012-03-01 19:46 . 2012-03-05 21:36        --------        d-----w-        C:\BigFishGamesCache
2012-02-29 22:01 . 2012-02-29 22:03        --------        d-----w-        c:\users\Administrator\.gimp-2.6
2012-02-28 16:21 . 2012-02-28 16:24        --------        d-----w-        c:\users\Administrator\AppData\Local\Google
2012-02-28 16:15 . 2012-02-28 16:15        --------        d-----w-        c:\program files (x86)\Common Files\Java
2012-02-26 19:02 . 2012-02-26 19:02        --------        d-----w-        c:\program files (x86)\KV Software
2012-02-26 18:56 . 2012-02-26 18:56        --------        d-----w-        c:\users\Administrator\AppData\Local\InterBA
2012-02-26 18:55 . 2012-02-26 18:56        --------        d-----w-        c:\programdata\InterBA
2012-02-26 18:55 . 2009-02-09 01:10        68232        ----a-w-        c:\windows\UnDeployV.exe
2012-02-24 00:46 . 2012-02-28 01:31        --------        d-----w-        c:\program files (x86)\Vieh Chroniken
2012-02-21 19:24 . 2012-02-24 00:58        466456        ----a-w-        c:\windows\system32\wrap_oal.dll
2012-02-21 19:24 . 2012-02-24 00:58        444952        ----a-w-        c:\windows\SysWow64\wrap_oal.dll
2012-02-21 19:24 . 2012-02-24 00:58        122904        ----a-w-        c:\windows\system32\OpenAL32.dll
2012-02-21 19:24 . 2012-02-24 00:58        109080        ----a-w-        c:\windows\SysWow64\OpenAL32.dll
2012-02-21 19:24 . 2012-02-21 19:24        --------        d-----w-        c:\program files (x86)\OpenAL
2012-02-21 19:23 . 2008-07-12 07:18        467984        ----a-w-        c:\windows\SysWow64\d3dx10_39.dll
2012-02-21 19:23 . 2008-07-12 07:18        1493528        ----a-w-        c:\windows\SysWow64\D3DCompiler_39.dll
2012-02-21 19:23 . 2008-07-12 07:18        540688        ----a-w-        c:\windows\system32\d3dx10_39.dll
2012-02-21 19:23 . 2008-07-12 07:18        1942552        ----a-w-        c:\windows\system32\D3DCompiler_39.dll
2012-02-21 19:23 . 2008-07-12 07:18        3851784        ----a-w-        c:\windows\SysWow64\D3DX9_39.dll
2012-02-21 19:23 . 2008-07-12 07:18        4992520        ----a-w-        c:\windows\system32\D3DX9_39.dll
2012-02-21 18:54 . 2012-02-24 00:45        --------        d-----w-        c:\program files (x86)\Unwritten Tales
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-28 16:14 . 2011-04-01 22:01        544656        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-02-23 08:18 . 2011-03-20 18:24        279656        ------w-        c:\windows\system32\MpSigStub.exe
2012-02-20 22:05 . 2011-05-13 12:36        414368        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-18 03:45 . 2012-02-18 03:45        125440        ----a-w-        c:\windows\system32\drivers\acedrv07.sys
2012-02-18 03:45 . 2012-02-18 03:45        81920        ----a-w-        c:\windows\SysWow64\acedrv07.dll
2012-02-15 18:15 . 2011-10-15 22:39        132320        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-01-04 10:44 . 2012-02-15 08:33        509952        ----a-w-        c:\windows\system32\ntshrui.dll
2012-01-04 08:58 . 2012-02-15 08:33        442880        ----a-w-        c:\windows\SysWow64\ntshrui.dll
2012-01-04 00:48 . 2012-01-04 00:48        354176        ----a-w-        c:\windows\SysWow64\DivXControlPanelApplet.cpl
2011-12-30 06:26 . 2012-02-15 08:32        515584        ----a-w-        c:\windows\system32\timedate.cpl
2011-12-30 05:27 . 2012-02-15 08:32        478720        ----a-w-        c:\windows\SysWow64\timedate.cpl
2011-12-28 03:59 . 2012-02-15 08:32        498688        ----a-w-        c:\windows\system32\drivers\afd.sys
2011-12-24 23:36 . 2011-12-24 23:36        17280        ----a-w-        c:\windows\system32\drivers\USBDrv_AMD64.sys
2006-05-03 11:06        163328        --sha-r-        c:\windows\SysWOW64\flvDX.dll
2007-02-21 12:47        31232        --sha-r-        c:\windows\SysWOW64\msfDX.dll
2008-03-16 14:30        216064        --sha-r-        c:\windows\SysWOW64\nbDX.dll
2010-01-06 23:00        107520        --sha-r-        c:\windows\SysWOW64\TAKDSDecoder.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}]
2011-11-22 08:59        269824        ----a-w-        c:\users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUpon.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-25 336384]
"332BigDog"="c:\program files (x86)\USB Camera2\VM332_STI.EXE" [2010-01-19 536576]
"VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2011-02-27 329056]
"YouCam Mirage"="c:\program files (x86)\Lenovo\YouCam\YCMMirage.exe" [2010-12-05 136488]
"YouCam Tray"="c:\program files (x86)\Lenovo\YouCam\YouCam.exe" [2010-12-05 224352]
"UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2010-07-26 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 258512]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe [2009-04-28 29184]
R2 StumbleUponUpdater;StumbleUpon Updater;c:\users\Administrator\AppData\LocalLow\StumbleUpon\IE\StumbleUponUpdater.exe [2011-11-22 18432]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 usbUDisc;usbUDisc;c:\windows\system32\DRIVERS\USBDrv_AMD64.sys [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [x]
S0 fbfmon;fbfmon;c:\windows\system32\drivers\fbfmon.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 BPntDrv;BPntDrv;c:\windows\system32\drivers\BPntDrv.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-01-25 354304]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2007-11-28 1039872]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
S3 vm2uvcflt;Vimicro USB Camera Filter 2;c:\windows\system32\Drivers\vm2uvcflt.sys [x]
S3 vm332avs;Lenovo Camera2;c:\windows\system32\Drivers\vm332avs.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 59171905
*Deregistered* - 59171905
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
2010-11-20 12:17        302592        ----a-w-        c:\windows\System32\cmd.exe
.
Inhalt des "geplante Tasks" Ordners
.
2012-03-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500Core.job
- c:\users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-28 16:21]
.
2012-03-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2395561902-1479221695-1832656523-500UA.job
- c:\users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-28 16:21]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2011-02-27 11:40        1508192        ----a-w-        c:\windows\System32\IcnOvrly.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"Lenovo EE Boot Optimizer"="c:\program files (x86)\Lenovo\Boot Optimizer\PopWnd.exe" [2011-02-27 114688]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2011-02-27 9744800]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2011-02-27 5399456]
"lxdnmon.exe"="c:\program files (x86)\Lexmark 2600 Series\lxdnmon.exe" [2009-10-29 660136]
"lxdnamon"="c:\program files (x86)\Lexmark 2600 Series\lxdnamon.exe" [2009-10-29 16040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uStart Page =
uLocal Page = c:\windows\system32\blank.htm
mStart Page =
mLocal Page =
IE: Alles mit NetXfer herunterladen - c:\program files (x86)\Xi\NetXfer\NXAddList.html
IE: Free YouTube Download - c:\users\Administrator\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Herunterladen mit NetXfer - c:\program files (x86)\Xi\NetXfer\NXAddLink.html
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files (x86)\ICQ7.4\ICQ.exe
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9grnwodb.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Sanitarium - c:\windows\IsUn0407.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:75,54,15,24,9b,8b,cc,01
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dd,3f,1e,3d,bb,c5,bf,45,be,07,37,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dd,3f,1e,3d,bb,c5,bf,45,be,07,37,\
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="divx_avi_file"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.div\UserChoice]
@Denied: (2) (Administrator)
"Progid"="divx_div_file"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="divx_divx_file"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.INF\UserChoice]
@Denied: (2) (Administrator)
"Progid"="inffile"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="divx_mkv_file"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tix\UserChoice]
@Denied: (2) (Administrator)
"Progid"="divx_tix_file"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-2395561902-1479221695-1832656523-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-03-22  17:08:04
ComboFix-quarantined-files.txt  2012-03-22 16:08
.
Vor Suchlauf: 14 Verzeichnis(se), 37.116.379.136 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 36.745.515.008 Bytes frei
.
- - End Of File - - C78C93785E3411FB82EF7B8CF4B4A705


cosinus 23.03.2012 20:44

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Madame 23.03.2012 21:15

Hmm, scheint nichts gefunden zu haben!?

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-23 20:56:11
-----------------------------
20:56:11.308    OS Version: Windows x64 6.1.7601 Service Pack 1
20:56:11.308    Number of processors: 2 586 0x100
20:56:11.308    ComputerName: SARA-PC  UserName:
20:56:12.649    Initialze error C000010E - driver not loaded
20:56:19.950    AVAST engine defs: 12032301
20:56:20.434    Service scanning
20:57:01.431    Modules scanning
20:57:01.431    Disk 0 trace - called modules:
20:57:01.431   
20:57:02.741    AVAST engine scan C:\windows
20:57:06.828    AVAST engine scan C:\windows\system32
21:01:49.844    AVAST engine scan C:\windows\system32\drivers
21:02:08.533    AVAST engine scan C:\Users\Administrator
21:11:53.238    AVAST engine scan C:\ProgramData
21:13:18.679    Scan finished successfully
21:13:31.611    The log file has been saved successfully to "C:\Users\Administrator\Desktop\Scan1.txt"


cosinus 23.03.2012 22:00

Du hast das irgendwie falsch ausgeführt. Wiederhol das bitte, halte dich an die Anleitung

Madame 23.03.2012 22:07

Also beim ersten Mal war unten "Quickscan" ausgewählt, dazu stand aber auch nichts in der Anleitung. :/
Habe es jetzt beim zweiten Mal auf "[none]" gestellt.
Ging nun noch schneller, sieht aber anders aus.
Hoffe, Du kannst damit was anfangen!?
Habe sonst alles gemacht wie in der Anleitung.

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-23 22:02:34
-----------------------------
22:02:34.807    OS Version: Windows x64 6.1.7601 Service Pack 1
22:02:34.807    Number of processors: 2 586 0x100
22:02:34.807    ComputerName: SARA-PC  UserName:
22:02:35.915    Initialize success
22:02:43.294    AVAST engine defs: 12032301
22:02:53.590    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000068
22:02:53.590    Disk 0 Vendor: HITACHI_ PB3Z Size: 305245MB BusType: 11
22:02:53.605    Disk 0 MBR read successfully
22:02:53.621    Disk 0 MBR scan
22:02:53.621    Disk 0 Windows 7 default MBR code
22:02:53.636    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          200 MB offset 2048
22:02:53.652    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      260243 MB offset 411648
22:02:53.668    Disk 0 Partition - 00    0F Extended LBA            29692 MB offset 533389312
22:02:53.714    Disk 0 Partition 3 00    12  Compaq diag NTFS        15109 MB offset 594198528
22:02:53.761    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS        29691 MB offset 533391360
22:02:53.808    Disk 0 scanning C:\windows\system32\drivers
22:03:10.235    Service scanning
22:03:51.201    Modules scanning
22:03:51.216    Disk 0 trace - called modules:
22:03:51.263    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys ACPI.sys storport.sys hal.dll amd_sata.sys
22:03:51.263    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004090060]
22:03:51.279    3 CLASSPNP.SYS[fffff8800166543f] -> nt!IofCallDriver -> [0xfffffa8003c11af0]
22:03:51.294    5 amd_xata.sys[fffff880011027a8] -> nt!IofCallDriver -> [0xfffffa8003c0fa20]
22:03:51.294    7 ACPI.sys[fffff88000f1e7a1] -> nt!IofCallDriver -> \Device\00000068[0xfffffa8003c0d060]
22:03:51.310    Scan finished successfully
22:04:11.933    Disk 0 MBR has been saved successfully to "C:\Users\Administrator\Desktop\MBR.dat"
22:04:11.949    The log file has been saved successfully to "C:\Users\Administrator\Desktop\Scan2.txt"


cosinus 24.03.2012 18:08

Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Madame 25.03.2012 15:52

So, hier die Logs.
Hab mich bei dem SUPERAntispyware-Log etwas erschrocken, aber scheinen ja alles Cookies zu sein!? Wie verfahre ich damit? Oder sind die egal?

Wenn jetzt alles so weit okay zu sein scheint.. Eine Frage hätte ich da noch. Mit ESET hatte ich ja 6 Funde, vor allem ja in den Java-Ordnern. Sind die jetzt durch die Combofix-Aktion auch weg? Ich frage weil die ja vorher mit Malwarebytes auch nicht angezeigt worden waren.

Grüße und nochmals VIELEN DANK für die Hilfe!


Code:

Malwarebytes Anti-Malware (Test) 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.03.25.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Administrator :: SARA-PC [Administrator]

Schutz: Aktiviert

25.03.2012 05:56:27
mbam-log-2012-03-25 (05-56-27).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 384996
Laufzeit: 2 Stunde(n), 8 Minute(n), 32 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 03/25/2012 at 01:13 PM

Application Version : 5.0.1146

Core Rules Database Version : 8377
Trace Rules Database Version: 6189

Scan type      : Complete Scan
Total Scan Time : 02:38:12

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC Off - Administrator

Memory items scanned      : 769
Memory threats detected  : 0
Registry items scanned    : 65720
Registry threats detected : 0
File items scanned        : 193613
File threats detected    : 227

Adware.Tracking Cookie
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\SHIXBGKX.txt [ /apmebf.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\IWF8L71Q.txt [ /forum.usenext.de ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\KJDKRBXG.txt [ /doubleclick.net ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\YFPHTPU1.txt [ /fastclick.net ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\MQH65QB8.txt [ /mediaplex.com ]
        C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\F435VQAJ.txt [ /smartadserver.com ]
        C:\USERS\ADMINISTRATOR\Cookies\SHIXBGKX.txt [ Cookie:administrator@apmebf.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\KJDKRBXG.txt [ Cookie:administrator@doubleclick.net/ ]
        C:\USERS\ADMINISTRATOR\Cookies\YFPHTPU1.txt [ Cookie:administrator@fastclick.net/ ]
        C:\USERS\ADMINISTRATOR\Cookies\MQH65QB8.txt [ Cookie:administrator@mediaplex.com/ ]
        C:\USERS\ADMINISTRATOR\Cookies\F435VQAJ.txt [ Cookie:administrator@smartadserver.com/ ]
        .paypal.112.2o7.net [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .apmebf.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        ad3.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unister-adservices.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .unister-adservices.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .mediaplex.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .atdmt.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .revsci.net [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .bs.serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
        .doubleclick.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ads.ersamedia.ch [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .at.atwola.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        1xxx.cqcounter.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ADMINISTRATOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9GRNWODB.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        stats.computecmedia.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad1.emediate.dk [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad1.emediate.dk [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .zanox.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .conrad.122.2o7.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ww251.smartadserver.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .ads.quartermedia.de [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\SARA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9APB6FBC.DEFAULT\COOKIES.SQLITE ]

PUP.SoftonicDownloader
        C:\USERS\ADMINISTRATOR\DOWNLOADS\SOFTONICDOWNLOADER_FUER_VMLOAD.EXE


cosinus 25.03.2012 16:03

Sieht ok aus, da wurden nur Cookies gefunden. Naja und 1x Softonic-Müll! :pfui: Finger weg in Zukunft von Softonic
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Madame 25.03.2012 16:06

Nein, sonst keine Probleme mehr.
Die damals mit ESET gefundenen Sachen sind mit Combofix erledigt worden? Die wurden ja mit Malwarebytes vorher auch nicht gefunden.
Meine die, die in den Java-Ordnern saßen. 6 waren das gleich und ESET hat die das erste Mal aufgebracht. Kein anderer Scan vorher.
Also muss ich mir da noch Sorgen machhen?
Sonst läuft alles prima, besser als vorher, meine ich.

cosinus 25.03.2012 17:39

Den Javaordner kannst du doch einfach manuell leeren, wo ist da das Problem


Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Madame 25.03.2012 18:15

Alles klar, wird gemacht. :)
Vielen Dank für Deine Hilfe, Ihr alle macht einen großartigen Job!
Ohne Euch wären so einige Leute aufgeschmissen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:46 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131