Hallo t'john,
nachdem mein Rechner nicht stabil lief und immer wieder runtergefahren ist. Habe ich mich dazu entschlossen meinen Rechner neu aufzusetzen.
Da ich nicht sicher bin ob ich richtig vorgegangen bin und damit auch den Trojaner los geworden bin wollte ich mich bei dir nochmal vergewissern.
1) Win7 Installation und die Partitionen gelöscht und 2 neue eingerichtet (1 für Programme, 2 für Dateien).
2) zuerst avast und malebyteware installiert (man lernt ja dazu ;-) )
3) alle notwendigen Treiber für meinen Notebook installiert sowie ein paar Programme wie Firefox usw.
4) HINWEIS: Avast hat mich während ich online ware dann doch vor einem Trojaner gewarnt als eine URL aufgerufen wurde, die verdächtig so aussah wie die, als ich mir den Trojaner eingefangen habe. Deshalb habe ich die Befürchtung, dass der Trojaner doch noch irgendwo schlummert.
Aus diesem Grund habe ich OTL nochmals ausgeführt und schicke Dir die beiden neuen Logfiles OTL
OTL Logfile: Code:
OTL logfile created on: 18.11.2012 22:11:33 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\oh\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,30 Gb Total Physical Memory | 1,17 Gb Available Physical Memory | 50,75% Memory free
4,60 Gb Paging File | 3,43 Gb Available in Paging File | 74,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,66 Gb Total Space | 83,46 Gb Free Space | 85,46% Space Free | Partition Type: NTFS
Drive D: | 187,33 Gb Total Space | 187,01 Gb Free Space | 99,83% Space Free | Partition Type: NTFS
Drive F: | 15,05 Gb Total Space | 1,71 Gb Free Space | 11,37% Space Free | Partition Type: FAT32
Drive G: | 644,12 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive H: | 930,86 Gb Total Space | 4,06 Gb Free Space | 0,44% Space Free | Partition Type: NTFS
Computer Name: XMV | User Name: oh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.11.18 22:10:00 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\oh\Downloads\OTL.exe
PRC - [2012.11.18 21:51:22 | 000,233,472 | ---- | M] (Alcor Micro Corp.) -- C:\Programme\AmIcoSingLun\AmIcoSinglun.exe
PRC - [2012.11.18 21:39:59 | 000,496,184 | ---- | M] (Conexant Systems, Inc.) -- C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.10.30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\afwServ.exe
PRC - [2012.10.24 18:49:10 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2011.01.05 15:24:16 | 000,468,360 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer ePower Management\ePowerEvent.exe
PRC - [2010.12.03 14:47:42 | 000,701,832 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerTray.exe
PRC - [2010.12.03 14:47:40 | 000,701,824 | ---- | M] (Acer Incorporated) -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe
PRC - [2009.07.14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.07.14 02:14:17 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dinotify.exe
PRC - [2009.07.14 02:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
========== Modules (No Company Name) ==========
MOD - [2012.10.24 18:49:23 | 002,295,264 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
========== Services (SafeList) ==========
SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.10.30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2012.10.24 18:49:17 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2010.12.03 14:47:40 | 000,701,824 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Acer\Acer PowerSmart Manager\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.07.14 02:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
========== Driver Services (SafeList) ==========
DRV - [2012.11.18 21:57:56 | 000,029,232 | ---- | M] (EgisTec) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\FPSensor.sys -- (FPSensor)
DRV - [2012.11.18 21:40:06 | 000,520,760 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.10.30 23:51:58 | 000,199,320 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
DRV - [2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.10.30 23:51:57 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012.10.30 23:51:56 | 000,106,560 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
DRV - [2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.10.30 23:51:56 | 000,020,624 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2012.10.15 17:59:28 | 000,044,784 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2012.09.30 11:54:13 | 009,945,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.07.13 12:47:41 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis.sys -- (aswNdis)
DRV - [2009.09.17 19:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2009.07.14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009.07.14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009.07.14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009.07.14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5B E4 23 FB C4 C5 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.11.18 21:25:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012.11.18 21:25:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\oh\AppData\Roaming\mozilla\Extensions
[2012.11.18 22:07:18 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2012.11.18 22:07:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
[2012.10.24 18:50:04 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.10.24 23:03:12 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.10.24 23:03:11 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.10.24 23:03:12 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.10.24 23:03:12 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.10.24 23:03:12 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.10.24 23:03:11 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage:
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
O4 - HKLM..\Run: [AmIcoSinglun] C:\Programme\AmIcoSingLun\AmIcoSinglun.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [BrowserChoice] C:\Windows\System32\browserchoice.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{297483FD-D1E7-47FD-A238-DD5B0743CE77}: DhcpNameServer = 192.168.178.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.06.18 22:12:18 | 000,000,088 | ---- | M] () - G:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{8cc37f36-31b5-11e2-aeac-edee0ccccdeb}\Shell - "" = AutoRun
O33 - MountPoints2\{8cc37f36-31b5-11e2-aeac-edee0ccccdeb}\Shell\AutoRun\command - "" = G:\WD SmartWare.exe -- [2009.10.14 22:28:45 | 003,271,968 | ---- | M] (Western Digital)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.11.18 22:07:57 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XMind
[2012.11.18 22:07:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XMind
[2012.11.18 22:07:43 | 000,000,000 | ---D | C] -- C:\Users\oh\Application Data
[2012.11.18 22:07:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012.11.18 22:07:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012.11.18 22:07:11 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012.11.18 22:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\XMind
[2012.11.18 21:57:25 | 000,000,000 | ---D | C] -- C:\Windows\LastGood
[2012.11.18 21:55:25 | 000,000,000 | ---D | C] -- C:\ProgramData\OEM
[2012.11.18 21:55:18 | 000,000,000 | ---D | C] -- C:\Program Files\Acer
[2012.11.18 21:53:42 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2012.11.18 21:53:39 | 000,000,000 | ---D | C] -- C:\ProgramData\AmUStor
[2012.11.18 21:53:39 | 000,000,000 | ---D | C] -- C:\Program Files\AmIcoSingLun
[2012.11.18 21:53:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye webcam
[2012.11.18 21:53:06 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\Liteon
[2012.11.18 21:53:06 | 000,000,000 | ---D | C] -- C:\Program Files\Acer Crystal Eye webcam
[2012.11.18 21:41:04 | 000,000,000 | ---D | C] -- C:\Program Files\CONEXANT
[2012.11.18 21:41:02 | 000,168,648 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\EED32A.dll
[2012.11.18 21:41:02 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\EEL32A.dll
[2012.11.18 21:41:02 | 000,062,664 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\EEG32A.dll
[2012.11.18 21:31:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012.11.18 21:30:24 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012.11.18 21:25:54 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\Mozilla
[2012.11.18 21:25:54 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Local\Mozilla
[2012.11.18 21:25:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012.11.18 21:25:45 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012.11.18 21:25:43 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.11.18 21:24:31 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Local\Google
[2012.11.18 21:24:16 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Local\Deployment
[2012.11.18 21:24:16 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Local\Apps
[2012.11.18 21:09:34 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2012.11.18 20:59:16 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\Malwarebytes
[2012.11.18 20:59:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.11.18 20:59:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.11.18 20:59:04 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.11.18 20:59:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.11.18 20:47:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012.11.18 20:47:29 | 000,361,032 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012.11.18 20:47:29 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012.11.18 20:47:26 | 000,106,560 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2012.11.18 20:47:18 | 000,199,320 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2012.11.18 20:47:17 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012.11.18 20:47:17 | 000,044,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys
[2012.11.18 20:47:17 | 000,020,624 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2012.11.18 20:47:16 | 000,738,504 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012.11.18 20:47:13 | 000,058,680 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012.11.18 20:46:35 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012.11.18 20:46:35 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.11.18 20:46:35 | 000,012,112 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2012.11.18 20:46:23 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.11.18 20:46:23 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.11.18 20:35:31 | 000,000,000 | ---D | C] -- C:\Program Files\Cisco
[2012.11.18 20:35:28 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012.11.18 20:34:55 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2012.11.18 20:34:53 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\InstallShield
[2012.11.18 20:29:10 | 000,000,000 | R--D | C] -- C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012.11.18 20:29:10 | 000,000,000 | R--D | C] -- C:\Users\oh\Searches
[2012.11.18 20:29:10 | 000,000,000 | R--D | C] -- C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012.11.18 20:28:57 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\Identities
[2012.11.18 20:28:56 | 000,000,000 | R--D | C] -- C:\Users\oh\Contacts
[2012.11.18 20:28:47 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Local\VirtualStore
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Vorlagen
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\AppData\Local\Verlauf
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\AppData\Local\Temporary Internet Files
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Startmenü
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\SendTo
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Recent
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Netzwerkumgebung
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Lokale Einstellungen
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Documents\Eigene Videos
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Documents\Eigene Musik
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Eigene Dateien
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Documents\Eigene Bilder
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Druckumgebung
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Cookies
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\AppData\Local\Anwendungsdaten
[2012.11.18 20:28:44 | 000,000,000 | -HSD | C] -- C:\Users\oh\Anwendungsdaten
[2012.11.18 20:28:43 | 000,000,000 | --SD | C] -- C:\Users\oh\AppData\Roaming\Microsoft
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Videos
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Saved Games
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Pictures
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Music
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Links
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Favorites
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Downloads
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Documents
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\Desktop
[2012.11.18 20:28:43 | 000,000,000 | R--D | C] -- C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012.11.18 20:28:43 | 000,000,000 | -H-D | C] -- C:\Users\oh\AppData
[2012.11.18 20:28:43 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Local\Temp
[2012.11.18 20:28:43 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Local\Microsoft
[2012.11.18 20:28:43 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\Media Center Programs
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Vorlagen
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Startmenü
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\Programme
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\Program Files\Gemeinsame Dateien
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoriten
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Videos
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Musik
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Eigene Bilder
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\Dokumente und Einstellungen
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumente
[2012.11.18 20:28:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Anwendungsdaten
[2012.11.18 20:23:38 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012.11.18 20:20:56 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012.11.18 20:20:33 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012.11.18 20:19:57 | 000,000,000 | ---D | C] -- C:\Windows\Panther
========== Files - Modified Within 30 Days ==========
[2012.11.18 22:07:57 | 000,000,915 | ---- | M] () -- C:\Users\oh\Desktop\XMind.lnk
[2012.11.18 21:57:56 | 000,029,232 | ---- | M] (EgisTec) -- C:\Windows\System32\drivers\FPSensor.sys
[2012.11.18 21:40:06 | 000,308,128 | ---- | M] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2012.11.18 21:40:00 | 000,001,096 | ---- | M] () -- C:\Windows\System32\drivers\SamSfPa.dat
[2012.11.18 21:35:11 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.11.18 21:35:06 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.11.18 21:31:15 | 000,002,227 | ---- | M] () -- C:\Users\oh\Desktop\Google Chrome.lnk
[2012.11.18 21:26:40 | 000,643,866 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.11.18 21:26:40 | 000,607,190 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.11.18 21:26:40 | 000,126,394 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.11.18 21:26:40 | 000,103,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.11.18 21:25:47 | 000,001,105 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.11.18 21:23:07 | 000,012,384 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.18 21:23:07 | 000,012,384 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.18 21:21:35 | 000,001,750 | ---- | M] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2012.11.18 21:20:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.18 21:20:31 | 1853,149,184 | -HS- | M] () -- C:\hiberfil.sys
[2012.11.18 21:17:35 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012.11.18 20:56:56 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012.11.18 20:47:30 | 000,002,075 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012.11.18 20:35:14 | 000,707,378 | ---- | M] () -- C:\Windows\System32\oem1.inf
[2012.11.18 20:34:51 | 000,006,656 | ---- | M] () -- C:\Windows\System32\bcmwlrc.dll
[2012.11.18 20:31:47 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.11.18 20:24:55 | 000,265,640 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.11.18 20:23:43 | 000,057,050 | ---- | M] () -- C:\Windows\System32\license.rtf
[2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012.10.30 23:51:58 | 000,199,320 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012.10.30 23:51:57 | 000,058,680 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012.10.30 23:51:56 | 000,106,560 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012.10.30 23:51:56 | 000,020,624 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2012.10.30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.10.30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
========== Files Created - No Company Name ==========
[2012.11.18 22:07:57 | 000,000,915 | ---- | C] () -- C:\Users\oh\Desktop\XMind.lnk
[2012.11.18 21:41:21 | 000,001,096 | ---- | C] () -- C:\Windows\System32\drivers\SamSfPa.dat
[2012.11.18 21:31:15 | 000,002,227 | ---- | C] () -- C:\Users\oh\Desktop\Google Chrome.lnk
[2012.11.18 21:30:29 | 000,001,090 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.11.18 21:30:28 | 000,001,086 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.11.18 21:25:47 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.11.18 21:25:47 | 000,001,105 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.11.18 21:21:35 | 000,001,750 | ---- | C] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2012.11.18 21:17:35 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012.11.18 20:47:30 | 000,002,075 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012.11.18 20:35:18 | 000,707,378 | ---- | C] () -- C:\Windows\System32\oem1.inf
[2012.11.18 20:34:56 | 000,006,656 | ---- | C] () -- C:\Windows\System32\bcmwlrc.dll
[2012.11.18 20:31:47 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.11.18 20:29:11 | 000,001,409 | ---- | C] () -- C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012.11.18 20:23:36 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.11.18 20:23:25 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.11.18 20:20:33 | 1853,149,184 | -HS- | C] () -- C:\hiberfil.sys
[2012.11.18 19:52:04 | 000,020,757 | ---- | C] () -- C:\Windows\System32\nvdisp_IH.nvu
[2012.11.18 19:52:00 | 001,921,265 | ---- | C] () -- C:\Windows\System32\iglhxa32.cpa
[2012.11.18 19:52:00 | 000,874,048 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2012.11.18 19:52:00 | 000,060,254 | ---- | C] () -- C:\Windows\System32\iglhxg32.vp
[2012.11.18 19:52:00 | 000,060,226 | ---- | C] () -- C:\Windows\System32\iglhxc32.vp
[2012.11.18 19:52:00 | 000,060,015 | ---- | C] () -- C:\Windows\System32\iglhxo32.vp
[2012.11.18 19:52:00 | 000,051,632 | ---- | C] () -- C:\Windows\System32\iglhxs32.vp
[2012.11.18 19:52:00 | 000,001,090 | ---- | C] () -- C:\Windows\System32\iglhxa32.vp
[2012.11.18 19:51:59 | 000,104,796 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2012.11.18 19:51:59 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2012.11.18 19:51:58 | 000,127,868 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2012.11.18 19:51:57 | 000,189,494 | ---- | C] () -- C:\Windows\System32\Gfxres.th-TH.resources
[2012.11.18 19:51:57 | 000,165,337 | ---- | C] () -- C:\Windows\System32\Gfxres.ru-RU.resources
[2012.11.18 19:51:57 | 000,136,343 | ---- | C] () -- C:\Windows\System32\Gfxres.ja-JP.resources
[2012.11.18 19:51:57 | 000,125,500 | ---- | C] () -- C:\Windows\System32\Gfxres.it-IT.resources
[2012.11.18 19:51:57 | 000,123,172 | ---- | C] () -- C:\Windows\System32\Gfxres.ko-KR.resources
[2012.11.18 19:51:57 | 000,121,115 | ---- | C] () -- C:\Windows\System32\Gfxres.tr-TR.resources
[2012.11.18 19:51:57 | 000,120,308 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-BR.resources
[2012.11.18 19:51:57 | 000,119,558 | ---- | C] () -- C:\Windows\System32\Gfxres.hu-HU.resources
[2012.11.18 19:51:57 | 000,119,528 | ---- | C] () -- C:\Windows\System32\Gfxres.nl-NL.resources
[2012.11.18 19:51:57 | 000,119,302 | ---- | C] () -- C:\Windows\System32\Gfxres.sv-SE.resources
[2012.11.18 19:51:57 | 000,119,009 | ---- | C] () -- C:\Windows\System32\Gfxres.pt-PT.resources
[2012.11.18 19:51:57 | 000,118,351 | ---- | C] () -- C:\Windows\System32\Gfxres.pl-PL.resources
[2012.11.18 19:51:57 | 000,118,000 | ---- | C] () -- C:\Windows\System32\Gfxres.sk-SK.resources
[2012.11.18 19:51:57 | 000,114,794 | ---- | C] () -- C:\Windows\System32\Gfxres.nb-NO.resources
[2012.11.18 19:51:57 | 000,114,314 | ---- | C] () -- C:\Windows\System32\Gfxres.sl-SI.resources
[2012.11.18 19:51:57 | 000,103,986 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-TW.resources
[2012.11.18 19:51:57 | 000,102,825 | ---- | C] () -- C:\Windows\System32\Gfxres.zh-CN.resources
[2012.11.18 19:51:57 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2012.11.18 19:51:56 | 000,178,349 | ---- | C] () -- C:\Windows\System32\Gfxres.el-GR.resources
[2012.11.18 19:51:56 | 000,139,851 | ---- | C] () -- C:\Windows\System32\Gfxres.ar-SA.resources
[2012.11.18 19:51:56 | 000,133,688 | ---- | C] () -- C:\Windows\System32\Gfxres.he-IL.resources
[2012.11.18 19:51:56 | 000,122,869 | ---- | C] () -- C:\Windows\System32\Gfxres.es-ES.resources
[2012.11.18 19:51:56 | 000,122,651 | ---- | C] () -- C:\Windows\System32\Gfxres.de-DE.resources
[2012.11.18 19:51:56 | 000,120,742 | ---- | C] () -- C:\Windows\System32\Gfxres.fr-FR.resources
[2012.11.18 19:51:56 | 000,118,687 | ---- | C] () -- C:\Windows\System32\Gfxres.cs-CZ.resources
[2012.11.18 19:51:56 | 000,118,639 | ---- | C] () -- C:\Windows\System32\Gfxres.fi-FI.resources
[2012.11.18 19:51:56 | 000,114,203 | ---- | C] () -- C:\Windows\System32\Gfxres.da-DK.resources
[2012.11.18 19:51:56 | 000,110,156 | ---- | C] () -- C:\Windows\System32\Gfxres.en-US.resources
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.11.18 21:53:06 | 000,000,000 | ---D | M] -- C:\Users\oh\AppData\Roaming\Liteon
========== Purity Check ==========
< End of report > --- --- --- Extras
OTL Logfile: Code:
OTL Extras logfile created on: 18.11.2012 22:11:33 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\oh\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
2,30 Gb Total Physical Memory | 1,17 Gb Available Physical Memory | 50,75% Memory free
4,60 Gb Paging File | 3,43 Gb Available in Paging File | 74,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,66 Gb Total Space | 83,46 Gb Free Space | 85,46% Space Free | Partition Type: NTFS
Drive D: | 187,33 Gb Total Space | 187,01 Gb Free Space | 99,83% Space Free | Partition Type: NTFS
Drive F: | 15,05 Gb Total Space | 1,71 Gb Free Space | 11,37% Space Free | Partition Type: FAT32
Drive G: | 644,12 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive H: | 930,86 Gb Total Space | 4,06 Gb Free Space | 0,44% Space Free | Partition Type: NTFS
Computer Name: XMV | User Name: oh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 32
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer PowerSmart Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{51F026FA-5146-4232-A8BA-1364740BD053}" = Acer Crystal Eye webcam
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{BC15023B-48DB-4F71-9C25-CFE1A8BB7202}" = Alcor Micro USB Card Reader
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"avast" = avast! Internet Security
"Broadcom 802.11 Network Adapter" = Broadcom 802.11 Network Adapter
"CNXT_AUDIO_HDA" = Conexant HD Audio
"Google Chrome" = Google Chrome
"InstallShield_{BC15023B-48DB-4F71-9C25-CFE1A8BB7202}" = Alcor Micro USB Card Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.1.1000
"Mozilla Firefox 16.0.2 (x86 de)" = Mozilla Firefox 16.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"XMind" = XMind
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 18.11.2012 16:51:39 | Computer Name = xmv | Source = VSS | ID = 8194
Description =
Error - 18.11.2012 17:02:32 | Computer Name = xmv | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: ePowerSvc.exe, Version: 5.0.3009.0,
Zeitstempel: 0x4d241b0f Name des fehlerhaften Moduls: ePowerSvc.exe, Version: 5.0.3009.0,
Zeitstempel: 0x4d241b0f Ausnahmecode: 0xc0000005 Fehleroffset: 0x000097fb ID des fehlerhaften
Prozesses: 0xeac Startzeit der fehlerhaften Anwendung: 0x01cdc5cf0b1b5897 Pfad der
fehlerhaften Anwendung: C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
Pfad
des fehlerhaften Moduls: C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
Berichtskennung:
44e77285-31c3-11e2-8ace-83bdd0ba5d92
[ System Events ]
Error - 18.11.2012 15:50:36 | Computer Name = xmv | Source = DCOM | ID = 10010
Description =
Error - 18.11.2012 16:00:42 | Computer Name = xmv | Source = DCOM | ID = 10010
Description =
Error - 18.11.2012 17:02:34 | Computer Name = xmv | Source = Service Control Manager | ID = 7034
Description = Dienst "Acer ePower Service" wurde unerwartet beendet. Dies ist bereits
1 Mal passiert.
< End of report > --- --- --- |