Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   RunDLL "Das angegebene Modul wurde nicht gefunden." (https://www.trojaner-board.de/113258-rundll-angegebene-modul-wurde-gefunden.html)

Vintage 07.04.2012 09:56

RunDLL "Das angegebene Modul wurde nicht gefunden."
 
Hallo!

Seit 4 Tagen habe ich Probleme mit meinem Laptop.
Zu erst konnte ich meinen Mozilla Firefox nicht öffnen und dann kam das Popup-Fenster, in dem stand:

"Problem beim Starten von
C:\\User\NAME\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IES\FP76GQ1P191[1].exe.tmp
Das angegebene Modul wurde nicht gefunden."

Der Titel des Fensters lautet RunDLL.
Ich habe den Windows Defender immer an und zusätzlich Ad Aware und Avira. Avira hatte auch einen Trojaner gefunden, der RunDLL hieß.
Ich dachte, der Trojaner wäre weg, doch am nächsten Tag erschien wieder das gleiche Popup-Fenster.
Jetzt habe ich auch noch das Viren Program Maleware bytes (Tip aus diesem Forum).
Ich habe die Virenprogramme jetzt schon mehrmals laufen lassen. Es wird immer ein Trojaner gefunden, den verschiebe ich dann in Quarantäne und lösche ihn, dann lasse ich nochmal das Virenprogramm laufen (es wird kein Virus mehr angezeigt) und am nächsten morgen erscheint wieder das Popup-Fenster und mein Virenprogram finder wieder einen Trojaner.

Ich habe einen Samsung RV720 Laptop, Windows 7 und ein 64-Bit Betriebssystem.

Ich hoffe, mir kann einer helfen!!

LG.

cosinus 07.04.2012 19:14

Ohne die Logs von Malwarebytes und Co wird das hier nichts. :glaskugel:
Alles von Malwarebytes (und evtl. anderen Scannern) muss hier gepostet werden.

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Vintage 07.04.2012 21:26

Hallo Cosinus,
danke für deine Antowort. Ich habe Avira und Malwéwarebytes nochmal durchlaufen lassen. Dieses mal haben sie keinen Trojaner gefunden. Allerdings erscheint weiterhin das Popup-Fenster und mein Laptop ist ziemlich langsam.
Hier sind die Logs:
Avira
Code:

Avira Free Antivirus
Erstellungsdatum der Reportdatei: Samstag, 7. April 2012  18:03

Es wird nach 3597466 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  : Avira AntiVir Personal - Free Antivirus
Seriennummer  : 0000149996-ADJIE-0000001
Plattform      : Windows 7 x64
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus    : Normal gebootet
Benutzername  : Melina
Computername  : MELINA-PC

Versionsinformationen:
BUILD.DAT      : 12.0.0.898          Bytes  31.01.2012 13:51:00
AVSCAN.EXE    : 12.1.0.20    492496 Bytes  15.02.2012 19:28:35
AVSCAN.DLL    : 12.1.0.18      65744 Bytes  15.02.2012 19:28:33
LUKE.DLL      : 12.1.0.19      68304 Bytes  15.02.2012 19:28:36
AVSCPLR.DLL    : 12.1.0.22    100048 Bytes  15.02.2012 19:28:39
AVREG.DLL      : 12.1.0.36    229128 Bytes  05.04.2012 22:11:59
VBASE000.VDF  : 7.10.0.0    19875328 Bytes  06.11.2009 18:18:34
VBASE001.VDF  : 7.11.0.0    13342208 Bytes  14.12.2010 09:07:39
VBASE002.VDF  : 7.11.19.170 14374912 Bytes  20.12.2011 05:12:43
VBASE003.VDF  : 7.11.21.238  4472832 Bytes  01.02.2012 19:30:17
VBASE004.VDF  : 7.11.26.44  4329472 Bytes  28.03.2012 08:47:44
VBASE005.VDF  : 7.11.26.45      2048 Bytes  28.03.2012 08:47:44
VBASE006.VDF  : 7.11.26.46      2048 Bytes  28.03.2012 08:47:44
VBASE007.VDF  : 7.11.26.47      2048 Bytes  28.03.2012 08:47:45
VBASE008.VDF  : 7.11.26.48      2048 Bytes  28.03.2012 08:47:45
VBASE009.VDF  : 7.11.26.49      2048 Bytes  28.03.2012 08:47:45
VBASE010.VDF  : 7.11.26.50      2048 Bytes  28.03.2012 08:47:45
VBASE011.VDF  : 7.11.26.51      2048 Bytes  28.03.2012 08:47:46
VBASE012.VDF  : 7.11.26.52      2048 Bytes  28.03.2012 08:47:46
VBASE013.VDF  : 7.11.26.53      2048 Bytes  28.03.2012 08:47:46
VBASE014.VDF  : 7.11.26.107  221696 Bytes  30.03.2012 09:28:04
VBASE015.VDF  : 7.11.26.179  224768 Bytes  02.04.2012 14:40:12
VBASE016.VDF  : 7.11.26.241  142336 Bytes  04.04.2012 14:40:03
VBASE017.VDF  : 7.11.26.242    2048 Bytes  04.04.2012 14:40:03
VBASE018.VDF  : 7.11.26.243    2048 Bytes  04.04.2012 14:40:03
VBASE019.VDF  : 7.11.26.244    2048 Bytes  04.04.2012 14:40:04
VBASE020.VDF  : 7.11.26.245    2048 Bytes  04.04.2012 14:40:04
VBASE021.VDF  : 7.11.26.246    2048 Bytes  04.04.2012 14:40:04
VBASE022.VDF  : 7.11.26.247    2048 Bytes  04.04.2012 14:40:04
VBASE023.VDF  : 7.11.26.248    2048 Bytes  04.04.2012 14:40:04
VBASE024.VDF  : 7.11.26.249    2048 Bytes  04.04.2012 14:40:04
VBASE025.VDF  : 7.11.26.250    2048 Bytes  04.04.2012 14:40:05
VBASE026.VDF  : 7.11.26.251    2048 Bytes  04.04.2012 14:40:05
VBASE027.VDF  : 7.11.26.252    2048 Bytes  04.04.2012 14:40:05
VBASE028.VDF  : 7.11.26.253    2048 Bytes  04.04.2012 14:40:05
VBASE029.VDF  : 7.11.26.254    2048 Bytes  04.04.2012 14:40:05
VBASE030.VDF  : 7.11.26.255    2048 Bytes  04.04.2012 14:40:06
VBASE031.VDF  : 7.11.27.38    201216 Bytes  06.04.2012 22:11:52
Engineversion  : 8.2.10.38
AEVDF.DLL      : 8.1.2.2      106868 Bytes  28.10.2011 18:37:43
AESCRIPT.DLL  : 8.1.4.16      446842 Bytes  05.04.2012 22:11:58
AESCN.DLL      : 8.1.8.2      131444 Bytes  27.01.2012 15:20:24
AESBX.DLL      : 8.2.5.5      606579 Bytes  12.03.2012 19:27:06
AERDL.DLL      : 8.1.9.15      639348 Bytes  08.09.2011 21:16:06
AEPACK.DLL    : 8.2.16.9      807287 Bytes  31.03.2012 09:27:35
AEOFFICE.DLL  : 8.1.2.27      201082 Bytes  05.04.2012 22:11:58
AEHEUR.DLL    : 8.1.4.12    4604278 Bytes  05.04.2012 22:11:58
AEHELP.DLL    : 8.1.19.1      254327 Bytes  03.04.2012 14:40:14
AEGEN.DLL      : 8.1.5.23      409973 Bytes  07.03.2012 18:48:17
AEEXP.DLL      : 8.1.0.28      82292 Bytes  05.04.2012 22:11:59
AEEMU.DLL      : 8.1.3.0      393589 Bytes  01.09.2011 21:46:01
AECORE.DLL    : 8.1.25.6      201078 Bytes  15.03.2012 20:48:57
AEBB.DLL      : 8.1.1.0        53618 Bytes  01.09.2011 21:46:01
AVWINLL.DLL    : 12.1.0.17      27344 Bytes  11.10.2011 12:59:41
AVPREF.DLL    : 12.1.0.17      51920 Bytes  11.10.2011 12:59:38
AVREP.DLL      : 12.1.0.17    179408 Bytes  11.10.2011 12:59:38
AVARKT.DLL    : 12.1.0.23    209360 Bytes  15.02.2012 19:28:32
AVEVTLOG.DLL  : 12.1.0.17    169168 Bytes  11.10.2011 12:59:37
SQLITE3.DLL    : 3.7.0.0      398288 Bytes  11.10.2011 12:59:51
AVSMTP.DLL    : 12.1.0.17      62928 Bytes  11.10.2011 12:59:39
NETNT.DLL      : 12.1.0.17      17104 Bytes  11.10.2011 12:59:47
RCIMAGE.DLL    : 12.1.0.17    4447952 Bytes  11.10.2011 13:00:00
RCTEXT.DLL    : 12.1.0.16      98512 Bytes  11.10.2011 13:00:00

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Vollständige Systemprüfung
Konfigurationsdatei...................: C:\Program Files (x86)\Avira\AntiVir Desktop\sysscan.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, D:,
Durchsuche aktive Programme...........: ein
Laufende Programme erweitert..........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: ein
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert

Beginn des Suchlaufs: Samstag, 7. April 2012  18:03

Der Suchlauf über die Masterbootsektoren wird begonnen:
Masterbootsektor HD0
    [INFO]      Es wurde kein Virus gefunden!
    [INFO]      Bitte starten Sie den Suchlauf erneut mit Administratorrechten

Der Suchlauf über die Bootsektoren wird begonnen:
Bootsektor 'C:\'
    [INFO]      Es wurde kein Virus gefunden!
    [INFO]      Bitte starten Sie den Suchlauf erneut mit Administratorrechten
Bootsektor 'D:\'
    [INFO]      Es wurde kein Virus gefunden!
    [INFO]      Bitte starten Sie den Suchlauf erneut mit Administratorrechten

Der Suchlauf nach versteckten Objekten wird begonnen.

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'avscan.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '82' Modul(e) wurden durchsucht
Durchsuche Prozess 'MovieColorEnhancer.exe' - '41' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '117' Modul(e) wurden durchsucht
Durchsuche Prozess 'YCMMirage.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'AAWTray.exe' - '25' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '25' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '68' Modul(e) wurden durchsucht
Durchsuche Prozess 'CLMLSvc.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'Media+Player10Serv.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'ONENOTEM.EXE' - '22' Modul(e) wurden durchsucht
Durchsuche Prozess 'NPSAgent.exe' - '39' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '584' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\'
Beginne mit der Suche in 'D:\'


Ende des Suchlaufs: Samstag, 7. April 2012  19:10
Benötigte Zeit:  1:07:12 Stunde(n)

Der Suchlauf wurde vollständig durchgeführt.

  23545 Verzeichnisse wurden überprüft
 403294 Dateien wurden geprüft
      0 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 403294 Dateien ohne Befall
  4054 Archive wurden durchsucht
      0 Warnungen
      0 Hinweise
 637275 Objekte wurden beim Rootkitscan durchsucht
      0 Versteckte Objekte wurden gefunden

Malewarebytes
Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.07.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

07.04.2012 18:18:46
mbam-log-2012-04-07 (18-18-46).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 333384
Laufzeit: 53 Minute(n), 20 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Soll ich nochmal die Logs posten, wo Viren gefunden worden??

Danke =)

Mach ich jetzt einfach mal =)

MWB
Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.04.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

04.04.2012 19:01:41
mbam-log-2012-04-04 (19-01-41).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 332327
Laufzeit: 57 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ctfmon.exe (Trojan.Agent) -> Daten: C:\windows\system32\rundll32.exe C:\PROGRA~3\arjlonlonje.dat,StartAs -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Avira
Code:



Avira Free Antivirus
Erstellungsdatum der Reportdatei: Freitag, 6. April 2012  12:00

Es wird nach 3596409 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  : Avira AntiVir Personal - Free Antivirus
Seriennummer  : 0000149996-ADJIE-0000001
Plattform      : Windows 7 x64
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus    : Normal gebootet
Benutzername  : SYSTEM
Computername  : MELINA-PC

Versionsinformationen:
BUILD.DAT      : 12.0.0.898    41963 Bytes  31.01.2012 13:51:00
AVSCAN.EXE    : 12.1.0.20    492496 Bytes  15.02.2012 19:28:35
AVSCAN.DLL    : 12.1.0.18      65744 Bytes  15.02.2012 19:28:33
LUKE.DLL      : 12.1.0.19      68304 Bytes  15.02.2012 19:28:36
AVSCPLR.DLL    : 12.1.0.22    100048 Bytes  15.02.2012 19:28:39
AVREG.DLL      : 12.1.0.36    229128 Bytes  05.04.2012 22:11:59
VBASE000.VDF  : 7.10.0.0    19875328 Bytes  06.11.2009 18:18:34
VBASE001.VDF  : 7.11.0.0    13342208 Bytes  14.12.2010 09:07:39
VBASE002.VDF  : 7.11.19.170 14374912 Bytes  20.12.2011 05:12:43
VBASE003.VDF  : 7.11.21.238  4472832 Bytes  01.02.2012 19:30:17
VBASE004.VDF  : 7.11.26.44  4329472 Bytes  28.03.2012 08:47:44
VBASE005.VDF  : 7.11.26.45      2048 Bytes  28.03.2012 08:47:44
VBASE006.VDF  : 7.11.26.46      2048 Bytes  28.03.2012 08:47:44
VBASE007.VDF  : 7.11.26.47      2048 Bytes  28.03.2012 08:47:45
VBASE008.VDF  : 7.11.26.48      2048 Bytes  28.03.2012 08:47:45
VBASE009.VDF  : 7.11.26.49      2048 Bytes  28.03.2012 08:47:45
VBASE010.VDF  : 7.11.26.50      2048 Bytes  28.03.2012 08:47:45
VBASE011.VDF  : 7.11.26.51      2048 Bytes  28.03.2012 08:47:46
VBASE012.VDF  : 7.11.26.52      2048 Bytes  28.03.2012 08:47:46
VBASE013.VDF  : 7.11.26.53      2048 Bytes  28.03.2012 08:47:46
VBASE014.VDF  : 7.11.26.107  221696 Bytes  30.03.2012 09:28:04
VBASE015.VDF  : 7.11.26.179  224768 Bytes  02.04.2012 14:40:12
VBASE016.VDF  : 7.11.26.241  142336 Bytes  04.04.2012 14:40:03
VBASE017.VDF  : 7.11.26.242    2048 Bytes  04.04.2012 14:40:03
VBASE018.VDF  : 7.11.26.243    2048 Bytes  04.04.2012 14:40:03
VBASE019.VDF  : 7.11.26.244    2048 Bytes  04.04.2012 14:40:04
VBASE020.VDF  : 7.11.26.245    2048 Bytes  04.04.2012 14:40:04
VBASE021.VDF  : 7.11.26.246    2048 Bytes  04.04.2012 14:40:04
VBASE022.VDF  : 7.11.26.247    2048 Bytes  04.04.2012 14:40:04
VBASE023.VDF  : 7.11.26.248    2048 Bytes  04.04.2012 14:40:04
VBASE024.VDF  : 7.11.26.249    2048 Bytes  04.04.2012 14:40:04
VBASE025.VDF  : 7.11.26.250    2048 Bytes  04.04.2012 14:40:05
VBASE026.VDF  : 7.11.26.251    2048 Bytes  04.04.2012 14:40:05
VBASE027.VDF  : 7.11.26.252    2048 Bytes  04.04.2012 14:40:05
VBASE028.VDF  : 7.11.26.253    2048 Bytes  04.04.2012 14:40:05
VBASE029.VDF  : 7.11.26.254    2048 Bytes  04.04.2012 14:40:05
VBASE030.VDF  : 7.11.26.255    2048 Bytes  04.04.2012 14:40:06
VBASE031.VDF  : 7.11.27.28    181248 Bytes  05.04.2012 22:11:52
Engineversion  : 8.2.10.38
AEVDF.DLL      : 8.1.2.2      106868 Bytes  28.10.2011 18:37:43
AESCRIPT.DLL  : 8.1.4.16      446842 Bytes  05.04.2012 22:11:58
AESCN.DLL      : 8.1.8.2      131444 Bytes  27.01.2012 15:20:24
AESBX.DLL      : 8.2.5.5      606579 Bytes  12.03.2012 19:27:06
AERDL.DLL      : 8.1.9.15      639348 Bytes  08.09.2011 21:16:06
AEPACK.DLL    : 8.2.16.9      807287 Bytes  31.03.2012 09:27:35
AEOFFICE.DLL  : 8.1.2.27      201082 Bytes  05.04.2012 22:11:58
AEHEUR.DLL    : 8.1.4.12    4604278 Bytes  05.04.2012 22:11:58
AEHELP.DLL    : 8.1.19.1      254327 Bytes  03.04.2012 14:40:14
AEGEN.DLL      : 8.1.5.23      409973 Bytes  07.03.2012 18:48:17
AEEXP.DLL      : 8.1.0.28      82292 Bytes  05.04.2012 22:11:59
AEEMU.DLL      : 8.1.3.0      393589 Bytes  01.09.2011 21:46:01
AECORE.DLL    : 8.1.25.6      201078 Bytes  15.03.2012 20:48:57
AEBB.DLL      : 8.1.1.0        53618 Bytes  01.09.2011 21:46:01
AVWINLL.DLL    : 12.1.0.17      27344 Bytes  11.10.2011 12:59:41
AVPREF.DLL    : 12.1.0.17      51920 Bytes  11.10.2011 12:59:38
AVREP.DLL      : 12.1.0.17    179408 Bytes  11.10.2011 12:59:38
AVARKT.DLL    : 12.1.0.23    209360 Bytes  15.02.2012 19:28:32
AVEVTLOG.DLL  : 12.1.0.17    169168 Bytes  11.10.2011 12:59:37
SQLITE3.DLL    : 3.7.0.0      398288 Bytes  11.10.2011 12:59:51
AVSMTP.DLL    : 12.1.0.17      62928 Bytes  11.10.2011 12:59:39
NETNT.DLL      : 12.1.0.17      17104 Bytes  11.10.2011 12:59:47
RCIMAGE.DLL    : 12.1.0.17    4447952 Bytes  11.10.2011 13:00:00
RCTEXT.DLL    : 12.1.0.16      98512 Bytes  11.10.2011 13:00:00

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Lokale Festplatten
Konfigurationsdatei...................: C:\Program Files (x86)\Avira\AntiVir Desktop\alldiscs.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, D:,
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Intelligente Dateiauswahl
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert

Beginn des Suchlaufs: Freitag, 6. April 2012  12:00

Der Suchlauf über die Masterbootsektoren wird begonnen:
Masterbootsektor HD0
    [INFO]      Es wurde kein Virus gefunden!

Der Suchlauf über die Bootsektoren wird begonnen:
Bootsektor 'C:\'
    [INFO]      Es wurde kein Virus gefunden!
Bootsektor 'D:\'
    [INFO]      Es wurde kein Virus gefunden!

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'SUPBackground.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'UNS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'SSCKbdHk.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'MovieColorEnhancer.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'LMS.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'WCScheduler.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'EasySpeedUpManager.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'AAWTray.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'WifiManager.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'YCMMirage.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'dmhkcore.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'ONENOTEM.EXE' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'CLMLSvc.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'Media+Player10Serv.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'NPSAgent.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'RichVideo.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht
Durchsuche Prozess 'AAWService.exe' - '1' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '668' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\'
C:\ProgramData\jmdoexeaim.dat
  [FUND]      Ist das Trojanische Pferd TR/Malagent.A.1248
Beginne mit der Suche in 'D:\'

Beginne mit der Desinfektion:
C:\ProgramData\jmdoexeaim.dat
  [FUND]      Ist das Trojanische Pferd TR/Malagent.A.1248
  [HINWEIS]  Die Datei konnte nicht ins Quarantäneverzeichnis verschoben werden!
  [HINWEIS]  Die Datei existiert nicht!


Ende des Suchlaufs: Freitag, 6. April 2012  13:14
Benötigte Zeit: 48:45 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

  23847 Verzeichnisse wurden überprüft
 428561 Dateien wurden geprüft
      1 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 428560 Dateien ohne Befall
  4277 Archive wurden durchsucht
      0 Warnungen
      1 Hinweise


cosinus 08.04.2012 16:21

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

Vintage 08.04.2012 16:50

MWB habe ich am 04.04. erst runtergeladen. Seit dem habe ich es 5 mal durchlaufen lassen:
04.04.
Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.04.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

04.04.2012 19:01:41
mbam-log-2012-04-04 (19-01-41).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 332327
Laufzeit: 57 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ctfmon.exe (Trojan.Agent) -> Daten: C:\windows\system32\rundll32.exe C:\PROGRA~3\arjlonlonje.dat,StartAs -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

04.04.
Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.04.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

04.04.2012 20:26:00
mbam-log-2012-04-04 (20-26-00).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 331832
Laufzeit: 1 Stunde(n), 33 Minute(n), 32 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

06.04.
Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.04.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

06.04.2012 10:55:22
mbam-log-2012-04-06 (10-55-22).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 331960
Laufzeit: 57 Minute(n), 32 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.04.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

07.04.2012 13:46:57
mbam-log-2012-04-07 (13-46-57).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 332409
Laufzeit: 1 Stunde(n), 6 Minute(n), 25 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.07.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

07.04.2012 22:17:24
mbam-log-2012-04-07 (22-17-24).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 33523
Laufzeit: 3 Minute(n), 53 Sekunde(n) [Abgebrochen]

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Nur beim ersten Mal wurde etwas gefunden. Mit Avira habe ich öfters einen Trojaner gefunden. Jetzt wurde dort auch schon länger nichts gefunden, aber das Popup-Fenster erscheint immer noch. Habe ich den Trojaner denn noch, auch wenn nichts mehr im Antivirusprogrammen gefunden wird??

LG :)

cosinus 08.04.2012 17:14

Führ bitte auch ESET aus, danach sehen wir weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Vintage 08.04.2012 19:12

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=0000258721bbfa47add0e6e1bed86986
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-04-08 05:56:43
# local_time=2012-04-08 07:56:43 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 14075242 14075242 0 0
# compatibility_mode=5893 16776573 100 94 199388 85532101 0 0
# compatibility_mode=8192 67108863 100 0 188 188 0 0
# scanned=151148
# found=0
# cleaned=0
# scan_time=5573

Hier wurden wieder keine Viren gefunden..

cosinus 08.04.2012 19:57

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

Vintage 08.04.2012 20:33

Der normale Modus funktioniert uneingeschränkt und mein Startmenü ist auch vollkommen normal..

cosinus 08.04.2012 20:37

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Vintage 08.04.2012 21:04

OTL Logfile:
Code:

OTL logfile created on: 4/8/2012 9:46:55 PM - Run 1
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Users\Melina\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5.98 Gb Total Physical Memory | 4.50 Gb Available Physical Memory | 75.19% Memory free
11.96 Gb Paging File | 10.50 Gb Available in Paging File | 87.78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 230.00 Gb Total Space | 139.47 Gb Free Space | 60.64% Space Free | Partition Type: NTFS
Drive D: | 342.27 Gb Total Space | 342.18 Gb Free Space | 99.97% Space Free | Partition Type: NTFS
 
Computer Name: MELINA-PC | User Name: Melina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/04/08 21:42:05 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Melina\Desktop\OTL.exe
PRC - [2011/10/28 20:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/10/28 20:35:26 | 001,187,072 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/10/11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011/10/11 14:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/10/11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/02/14 12:15:38 | 004,394,576 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2011/02/07 11:55:24 | 001,757,264 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2011/01/04 15:06:42 | 007,060,560 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
PRC - [2010/12/23 08:07:58 | 000,945,232 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2010/12/21 04:30:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010/12/21 04:30:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010/11/29 07:42:38 | 000,775,848 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
PRC - [2010/11/10 01:03:52 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2010/09/20 05:24:42 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
PRC - [2010/08/27 03:52:12 | 002,782,064 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
PRC - [2010/07/29 09:47:08 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2010/02/10 16:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009/11/02 07:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010/07/05 12:42:58 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll
MOD - [2010/05/07 16:22:18 | 001,636,864 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2009/11/02 07:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
MOD - [2009/11/02 07:20:10 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2006/08/12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010/09/22 11:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/08/09 21:04:12 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2011/10/28 20:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/10/11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/10/11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/12/21 04:30:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010/12/21 04:30:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012/02/15 21:28:37 | 000,132,320 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011/10/28 20:35:28 | 000,069,376 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
DRV:64bit: - [2011/10/11 15:00:01 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011/10/11 15:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011/07/06 08:16:24 | 000,289,704 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2011/05/23 17:24:22 | 002,750,464 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/04 09:59:18 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/02/18 01:11:54 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/01/27 07:35:26 | 000,425,064 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/13 00:23:38 | 000,138,024 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2010/11/10 01:04:14 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/10/20 02:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010/10/07 04:59:00 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV:64bit: - [2010/07/05 09:24:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010/04/27 04:25:16 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV:64bit: - [2010/04/27 04:25:16 | 000,127,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV:64bit: - [2010/04/27 04:25:16 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/06/10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/04/29 17:28:30 | 000,030,208 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2011/11/01 10:50:55 | 000,017,152 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys -- (Lavasoft Kernexplorer)
DRV - [2011/09/08 08:23:41 | 000,015,144 | ---- | M] (Windows (R) 2003 DDK 3790 provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\rtport.sys -- (rtport)
DRV - [2010/07/05 09:24:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/04/04 15:42:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011/10/28 18:57:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melina\AppData\Roaming\mozilla\Extensions
[2012/04/04 15:42:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/03/13 06:38:06 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/13 07:23:34 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/03/13 07:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/13 07:23:34 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012/03/13 07:23:34 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/03/13 07:23:34 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/03/13 07:23:34 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Samsung BHO Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [NPSStartup]  File not found
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001..\Run: [AutoStartNPSAgent] C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A768083D-4D72-43D5-9594-3C1F15309156}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Install.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/04/08 21:42:03 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Melina\Desktop\OTL.exe
[2012/04/08 18:21:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/04/08 18:19:48 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Melina\Desktop\esetsmartinstaller_enu.exe
[2012/04/04 19:00:22 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Roaming\Malwarebytes
[2012/04/04 19:00:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/04/04 19:00:06 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/04/04 19:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/04/04 15:42:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/04/01 23:17:58 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Roaming\Dropbox
[2012/03/30 14:30:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/03/29 22:13:16 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Local\{25A392AD-2EC1-4873-AC22-AE86F78DA5DF}
[2012/03/29 15:18:15 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\NPS
[2012/03/29 15:18:03 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\My Art
[2012/03/29 15:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung New PC Studio
[2012/03/29 15:08:14 | 000,161,280 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bmdm.sys
[2012/03/29 15:08:14 | 000,127,488 | ---- | C] (MCCI) -- C:\windows\SysNative\drivers\ss_bbus.sys
[2012/03/29 15:08:14 | 000,018,944 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bmdfl.sys
[2012/03/29 15:08:14 | 000,015,872 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bwhnt.sys
[2012/03/29 15:08:14 | 000,015,872 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bwh.sys
[2012/03/29 15:08:14 | 000,015,360 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bcmnt.sys
[2012/03/29 15:08:14 | 000,015,360 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bcm.sys
[2012/03/29 15:07:13 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\Samsung
[2012/03/29 15:06:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2012/03/29 14:44:23 | 000,025,960 | ---- | C] (Teruten Inc) -- C:\windows\SysWow64\FsExService64.Exe
[2012/03/29 14:44:23 | 000,016,448 | ---- | C] (Teruten Inc) -- C:\windows\SysWow64\drivers\TFsExDisk.Sys
[2012/03/29 14:44:22 | 000,025,960 | ---- | C] (Teruten Inc) -- C:\windows\SysNative\FsExService64.exe
[2012/03/29 14:44:22 | 000,016,448 | ---- | C] (Teruten Inc) -- C:\windows\SysNative\drivers\TFsExDisk.sys
[2012/03/29 14:44:16 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\My NPS Files
[2012/03/29 14:44:15 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Roaming\Samsung
[2012/03/29 14:19:55 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Local\Downloaded Installations
[2012/03/29 11:36:28 | 000,000,000 | ---D | C] -- C:\Users\Melina\Desktop\Practigo
[2012/03/27 00:29:03 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Local\Diagnostics
[2012/03/16 19:12:44 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Samsung_USB_Drivers
[2011/12/14 04:57:20 | 021,563,253 | -H-- | C] (Microsoft Corporation) -- C:\ProgramData\fo32dimali.dat
[2011/12/14 04:57:20 | 002,624,425 | -H-- | C] (Microsoft Corporation) -- C:\ProgramData\jeaimaim32.dat
[2011/12/14 04:57:20 | 002,576,560 | -H-- | C] (Mozilla Corporation) -- C:\ProgramData\loarjtemtem.dat
[2011/12/14 04:57:20 | 001,981,017 | -H-- | C] (Mozilla Corporation) -- C:\ProgramData\mnjeso32lo.dat
[2011/12/14 04:57:20 | 001,148,993 | -H-- | C] (Microsoft Corporation) -- C:\ProgramData\arjsimmnjje.dat
[2011/12/14 04:57:20 | 001,112,225 | -H-- | C] (Microsoft Corporation) -- C:\ProgramData\orfoqwefil.dat
[2011/12/14 04:57:20 | 001,026,028 | -H-- | C] (Microsoft Corporation) -- C:\ProgramData\cracometulon.dat
[2011/12/14 04:57:20 | 000,895,193 | -H-- | C] (Microsoft Corporation) -- C:\ProgramData\arjlonlonje.dat
[2011/12/14 04:57:20 | 000,510,662 | -H-- | C] (Mozilla Corporation) -- C:\ProgramData\aimmnjebxmnj.dat
 
========== Files - Modified Within 30 Days ==========
 
[2012/04/08 21:42:05 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Melina\Desktop\OTL.exe
[2012/04/08 20:54:56 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/08 20:54:56 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/08 20:47:15 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/04/08 20:47:11 | 2126,036,991 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/08 18:19:52 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Melina\Desktop\esetsmartinstaller_enu.exe
[2012/04/07 13:19:01 | 000,000,064 | ---- | M] () -- C:\windows\SysWow64\rp_stats.dat
[2012/04/07 13:19:01 | 000,000,044 | ---- | M] () -- C:\windows\SysWow64\rp_rules.dat
[2012/04/06 00:07:14 | 000,199,680 | --S- | M] () -- C:\ProgramData\d4nulalije.dat
[2012/04/05 10:44:33 | 000,199,680 | --S- | M] () -- C:\ProgramData\je5151j8.dat
[2012/04/05 10:44:26 | 000,199,680 | --S- | M] () -- C:\ProgramData\doquiquilop.dat
[2012/04/05 10:41:32 | 000,199,680 | --S- | M] () -- C:\ProgramData\arja1dv557.dat
[2012/04/05 10:34:29 | 000,199,680 | --S- | M] () -- C:\ProgramData\toebxwid4.dat
[2012/04/05 10:31:30 | 000,199,680 | --S- | M] () -- C:\ProgramData\j65nularjdm.dat
[2012/04/05 10:24:27 | 000,199,680 | --S- | M] () -- C:\ProgramData\jmjelodim.dat
[2012/04/05 10:21:29 | 000,199,680 | --S- | M] () -- C:\ProgramData\d4nulcodo.dat
[2012/04/05 10:14:25 | 000,199,680 | --S- | M] () -- C:\ProgramData\32simd4a1.dat
[2012/04/05 10:11:27 | 000,199,680 | --S- | M] () -- C:\ProgramData\rimwisim124.dat
[2012/04/05 10:04:24 | 000,199,680 | --S- | M] () -- C:\ProgramData\51rimco64.dat
[2012/04/05 10:01:25 | 000,199,680 | --S- | M] () -- C:\ProgramData\zxcb3jenulnul.dat
[2012/04/05 09:54:22 | 000,199,680 | --S- | M] () -- C:\ProgramData\yh3wij32m52.dat
[2012/04/05 09:51:24 | 000,199,680 | --S- | M] () -- C:\ProgramData\32m52mnjk53.dat
[2012/04/05 09:44:20 | 000,199,680 | --S- | M] () -- C:\ProgramData\133jtoj32.dat
[2012/04/05 09:41:22 | 000,199,680 | --S- | M] () -- C:\ProgramData\x3d4zxcb3mnj.dat
[2012/04/05 09:25:57 | 000,199,680 | --S- | M] () -- C:\ProgramData\124hsdetusim.dat
[2012/04/05 09:15:26 | 000,199,680 | --S- | M] () -- C:\ProgramData\51k53j65lop.dat
[2012/04/05 09:05:23 | 000,199,680 | --S- | M] () -- C:\ProgramData\dohsdnirim.dat
[2012/04/05 08:55:22 | 000,199,680 | --S- | M] () -- C:\ProgramData\dimcojem52.dat
[2012/04/05 08:45:20 | 000,199,680 | --S- | M] () -- C:\ProgramData\jeetuyh3jm.dat
[2012/04/04 22:50:41 | 000,199,680 | --S- | M] () -- C:\ProgramData\mnjwiqui13.dat
[2012/04/04 22:40:40 | 000,199,680 | --S- | M] () -- C:\ProgramData\mnjk53d4j65.dat
[2012/04/04 22:30:38 | 000,199,680 | --S- | M] () -- C:\ProgramData\folopm52k53.dat
[2012/04/04 22:24:41 | 000,199,680 | --S- | M] () -- C:\ProgramData\j65yh332m52.dat
[2012/04/04 22:24:38 | 000,199,680 | --S- | M] () -- C:\ProgramData\to557jmj8.dat
[2012/04/04 22:24:20 | 000,199,680 | --S- | M] () -- C:\ProgramData\mnjni513j.dat
[2012/04/04 22:14:39 | 000,199,680 | --S- | M] () -- C:\ProgramData\nulfofojm.dat
[2012/04/04 22:14:37 | 000,199,680 | --S- | M] () -- C:\ProgramData\dva1lo557.dat
[2012/04/04 22:04:35 | 000,199,680 | --S- | M] () -- C:\ProgramData\doalinulali.dat
[2012/04/04 22:04:25 | 000,199,680 | --S- | M] () -- C:\ProgramData\eturimnula1.dat
[2012/04/04 21:54:33 | 000,199,680 | --S- | M] () -- C:\ProgramData\j65lodmebx.dat
[2012/04/04 21:54:21 | 000,199,680 | --S- | M] () -- C:\ProgramData\d4j65j65x3.dat
[2012/04/04 21:44:31 | 000,199,680 | --S- | M] () -- C:\ProgramData\lod4jmjm.dat
[2012/04/04 21:44:19 | 000,199,680 | --S- | M] () -- C:\ProgramData\x3rimyh3jm.dat
[2012/04/04 21:34:29 | 000,199,680 | --S- | M] () -- C:\ProgramData\k53sim124arj.dat
[2012/04/04 21:34:16 | 000,199,680 | --S- | M] () -- C:\ProgramData\nij8etujm.dat
[2012/04/04 21:24:26 | 000,199,680 | --S- | M] () -- C:\ProgramData\lopk53nidm.dat
[2012/04/04 21:24:15 | 000,199,680 | --S- | M] () -- C:\ProgramData\lonilopco.dat
[2012/04/04 21:14:24 | 000,199,680 | --S- | M] () -- C:\ProgramData\lo55712413.dat
[2012/04/04 21:04:22 | 000,199,680 | --S- | M] () -- C:\ProgramData\j3232k53co.dat
[2012/04/04 20:54:20 | 000,199,680 | --S- | M] () -- C:\ProgramData\arjlo51wi.dat
[2012/04/04 20:44:18 | 000,199,680 | --S- | M] () -- C:\ProgramData\51hsdquinul.dat
[2012/04/04 20:34:16 | 000,199,680 | --S- | M] () -- C:\ProgramData\mnjm5213wi.dat
[2012/04/04 20:24:13 | 000,199,680 | --S- | M] () -- C:\ProgramData\d4lopmnjrim.dat
[2012/04/04 19:00:09 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/04 15:42:54 | 000,001,094 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/04 12:16:40 | 076,004,920 | -H-- | M] () -- C:\ProgramData\ejnolnoljra.dat
[2012/04/04 12:15:04 | 076,004,920 | -H-- | M] () -- C:\ProgramData\miaexeodmj.dat
[2012/04/04 07:48:15 | 076,004,920 | -H-- | M] () -- C:\ProgramData\23miamiaej.dat
[2012/04/04 07:29:39 | 000,001,975 | --S- | M] () -- C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
[2012/04/03 17:25:37 | 001,507,106 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/04/03 17:25:37 | 000,657,676 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2012/04/03 17:25:37 | 000,618,912 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/04/03 17:25:37 | 000,131,016 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2012/04/03 17:25:37 | 000,107,232 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/03/29 15:17:32 | 001,526,948 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/03/29 15:15:55 | 000,001,184 | ---- | M] () -- C:\Users\Public\Desktop\Samsung New PC Studio.lnk
[2012/03/29 15:10:13 | 000,002,898 | ---- | M] () -- C:\aqua_bitmap.cpp
[2012/03/15 12:02:31 | 000,425,000 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
 
========== Files Created - No Company Name ==========
 
[2012/04/06 00:07:13 | 000,199,680 | --S- | C] () -- C:\ProgramData\d4nulalije.dat
[2012/04/05 10:44:30 | 000,199,680 | --S- | C] () -- C:\ProgramData\je5151j8.dat
[2012/04/05 10:44:23 | 000,199,680 | --S- | C] () -- C:\ProgramData\doquiquilop.dat
[2012/04/05 10:41:31 | 000,199,680 | --S- | C] () -- C:\ProgramData\arja1dv557.dat
[2012/04/05 10:34:28 | 000,199,680 | --S- | C] () -- C:\ProgramData\toebxwid4.dat
[2012/04/05 10:31:29 | 000,199,680 | --S- | C] () -- C:\ProgramData\j65nularjdm.dat
[2012/04/05 10:24:26 | 000,199,680 | --S- | C] () -- C:\ProgramData\jmjelodim.dat
[2012/04/05 10:21:28 | 000,199,680 | --S- | C] () -- C:\ProgramData\d4nulcodo.dat
[2012/04/05 10:14:24 | 000,199,680 | --S- | C] () -- C:\ProgramData\32simd4a1.dat
[2012/04/05 10:11:26 | 000,199,680 | --S- | C] () -- C:\ProgramData\rimwisim124.dat
[2012/04/05 10:04:23 | 000,199,680 | --S- | C] () -- C:\ProgramData\51rimco64.dat
[2012/04/05 10:01:24 | 000,199,680 | --S- | C] () -- C:\ProgramData\zxcb3jenulnul.dat
[2012/04/05 09:54:21 | 000,199,680 | --S- | C] () -- C:\ProgramData\yh3wij32m52.dat
[2012/04/05 09:51:22 | 000,199,680 | --S- | C] () -- C:\ProgramData\32m52mnjk53.dat
[2012/04/05 09:44:19 | 000,199,680 | --S- | C] () -- C:\ProgramData\133jtoj32.dat
[2012/04/05 09:41:21 | 000,199,680 | --S- | C] () -- C:\ProgramData\x3d4zxcb3mnj.dat
[2012/04/05 09:25:56 | 000,199,680 | --S- | C] () -- C:\ProgramData\124hsdetusim.dat
[2012/04/05 09:15:25 | 000,199,680 | --S- | C] () -- C:\ProgramData\51k53j65lop.dat
[2012/04/05 09:05:22 | 000,199,680 | --S- | C] () -- C:\ProgramData\dohsdnirim.dat
[2012/04/05 08:55:21 | 000,199,680 | --S- | C] () -- C:\ProgramData\dimcojem52.dat
[2012/04/05 08:45:19 | 000,199,680 | --S- | C] () -- C:\ProgramData\jeetuyh3jm.dat
[2012/04/04 22:50:40 | 000,199,680 | --S- | C] () -- C:\ProgramData\mnjwiqui13.dat
[2012/04/04 22:40:39 | 000,199,680 | --S- | C] () -- C:\ProgramData\mnjk53d4j65.dat
[2012/04/04 22:30:37 | 000,199,680 | --S- | C] () -- C:\ProgramData\folopm52k53.dat
[2012/04/04 22:24:39 | 000,199,680 | --S- | C] () -- C:\ProgramData\j65yh332m52.dat
[2012/04/04 22:24:37 | 000,199,680 | --S- | C] () -- C:\ProgramData\to557jmj8.dat
[2012/04/04 22:24:18 | 000,199,680 | --S- | C] () -- C:\ProgramData\mnjni513j.dat
[2012/04/04 22:14:36 | 000,199,680 | --S- | C] () -- C:\ProgramData\nulfofojm.dat
[2012/04/04 22:14:35 | 000,199,680 | --S- | C] () -- C:\ProgramData\dva1lo557.dat
[2012/04/04 22:04:34 | 000,199,680 | --S- | C] () -- C:\ProgramData\doalinulali.dat
[2012/04/04 22:04:24 | 000,199,680 | --S- | C] () -- C:\ProgramData\eturimnula1.dat
[2012/04/04 21:54:31 | 000,199,680 | --S- | C] () -- C:\ProgramData\j65lodmebx.dat
[2012/04/04 21:54:19 | 000,199,680 | --S- | C] () -- C:\ProgramData\d4j65j65x3.dat
[2012/04/04 21:44:29 | 000,199,680 | --S- | C] () -- C:\ProgramData\lod4jmjm.dat
[2012/04/04 21:44:17 | 000,199,680 | --S- | C] () -- C:\ProgramData\x3rimyh3jm.dat
[2012/04/04 21:34:27 | 000,199,680 | --S- | C] () -- C:\ProgramData\k53sim124arj.dat
[2012/04/04 21:34:15 | 000,199,680 | --S- | C] () -- C:\ProgramData\nij8etujm.dat
[2012/04/04 21:24:25 | 000,199,680 | --S- | C] () -- C:\ProgramData\lopk53nidm.dat
[2012/04/04 21:24:13 | 000,199,680 | --S- | C] () -- C:\ProgramData\lonilopco.dat
[2012/04/04 21:14:22 | 000,199,680 | --S- | C] () -- C:\ProgramData\lo55712413.dat
[2012/04/04 21:04:20 | 000,199,680 | --S- | C] () -- C:\ProgramData\j3232k53co.dat
[2012/04/04 20:54:18 | 000,199,680 | --S- | C] () -- C:\ProgramData\arjlo51wi.dat
[2012/04/04 20:44:16 | 000,199,680 | --S- | C] () -- C:\ProgramData\51hsdquinul.dat
[2012/04/04 20:34:15 | 000,199,680 | --S- | C] () -- C:\ProgramData\mnjm5213wi.dat
[2012/04/04 20:24:12 | 000,199,680 | --S- | C] () -- C:\ProgramData\d4lopmnjrim.dat
[2012/04/04 19:00:09 | 000,001,073 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/04 15:42:54 | 000,001,094 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/04 15:42:53 | 000,001,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/04/04 07:29:39 | 000,001,975 | --S- | C] () -- C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
[2012/03/29 15:17:32 | 001,526,948 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/03/29 15:10:13 | 000,002,898 | ---- | C] () -- C:\aqua_bitmap.cpp
[2012/03/29 15:08:45 | 000,001,184 | ---- | C] () -- C:\Users\Public\Desktop\Samsung New PC Studio.lnk
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\ol23osejnm.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\nolutemocarc.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\miaexeodmj.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\metmetjraol.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\lifewqofro.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\jnmxbejnmmia.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\ilamid23of.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\ejnolnoljra.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\ejjnmmisjra.dat
[2011/12/14 04:57:20 | 076,004,920 | -H-- | C] () -- C:\ProgramData\23miamiaej.dat
[2011/11/10 09:56:18 | 000,000,064 | ---- | C] () -- C:\windows\SysWow64\rp_stats.dat
[2011/11/10 09:56:18 | 000,000,044 | ---- | C] () -- C:\windows\SysWow64\rp_rules.dat
[2011/10/31 22:01:36 | 000,000,076 | ---- | C] () -- C:\windows\SysWow64\net32gdilib.dll
[2011/07/28 20:44:58 | 000,258,864 | ---- | C] () -- C:\windows\SUPDRun.exe
[2011/07/28 06:55:27 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2011/07/28 06:07:29 | 000,000,918 | ---- | C] () -- C:\windows\HotFixList.ini
[2011/07/28 05:54:15 | 000,142,128 | ---- | C] () -- C:\windows\wiainst64.exe
 
========== LOP Check ==========
 
[2012/04/02 10:23:42 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Dropbox
[2011/11/01 10:46:05 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\J River
[2012/03/29 14:44:15 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Samsung
[2012/04/07 15:06:13 | 000,032,632 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011/10/28 20:17:33 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Adobe
[2011/10/28 20:37:09 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Avira
[2011/10/29 13:51:08 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\CyberLink
[2012/04/02 10:23:42 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Dropbox
[2011/10/28 18:50:24 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Identities
[2011/11/01 10:46:05 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\J River
[2011/10/28 18:52:16 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Macromedia
[2012/04/04 19:00:22 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Malwarebytes
[2011/07/28 20:56:59 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Media Center Programs
[2012/04/02 16:43:46 | 000,000,000 | --SD | M] -- C:\Users\Melina\AppData\Roaming\Microsoft
[2011/10/28 18:57:10 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Mozilla
[2012/03/29 14:44:15 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Samsung
 
< %APPDATA%\*.exe /s >
[2012/03/29 14:41:59 | 000,069,632 | ---- | M] () -- C:\Users\Melina\AppData\Roaming\Samsung\New PC Studio\DriverChecker.exe
[2012/03/29 15:09:13 | 000,704,512 | ---- | M] (TODO: <Company name>) -- C:\Users\Melina\AppData\Roaming\Samsung\New PC Studio\LiveUpdate\NPSUpdateAgent.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\drivers\AGP440.sys
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\drivers\atapi.sys
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\windows\SysNative\cngaudit.dll
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2008/06/06 07:03:52 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTOR.SYS  >
[2011/02/18 01:11:54 | 000,439,320 | ---- | M] (Intel Corporation) MD5=53CC5BF8B5A219119953C7ABB19A7705 -- C:\windows\SysNative\drivers\iaStor.sys
[2011/02/18 01:11:54 | 000,439,320 | ---- | M] (Intel Corporation) MD5=53CC5BF8B5A219119953C7ABB19A7705 -- C:\windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_52b32c0ad3e84c62\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\windows\SysNative\drivers\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\windows\SysNative\netlogon.dll
[2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011/03/11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\windows\SysNative\drivers\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\windows\SysNative\scecli.dll
[2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010/11/21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010/11/21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010/11/21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\windows\SysNative\user32.dll
[2010/11/21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\windows\SysNative\userinit.exe
[2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009/07/14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\windows\SysNative\wininit.exe
[2009/07/14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009/07/14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009/07/14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\windows\SysNative\winlogon.exe
[2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/01/13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\windows\SysNative\drivers\ws2ifsl.sys
[2009/07/14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---


Die ganzen Daten, die ich hier poste, damit kann sich keiner in meinen PC hacken oder mich ausspionieren oder so, richtig? :wtf:

cosinus 08.04.2012 21:13

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Install.exe
[2012/04/04 07:29:39 | 000,001,975 | --S- | M] () -- C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk
:Files
C:\ProgramData\*.dat
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Vintage 08.04.2012 21:27

Code:

All processes killed
========== OTL ==========
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c7023dbf-d9e2-11e0-8c3a-806e6f6e6963}\ not found.
File E:\Install.exe not found.
C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk moved successfully.
========== FILES ==========
C:\ProgramData\124hsdetusim.dat moved successfully.
C:\ProgramData\133jtoj32.dat moved successfully.
C:\ProgramData\23miamiaej.dat moved successfully.
C:\ProgramData\32m52mnjk53.dat moved successfully.
C:\ProgramData\32simd4a1.dat moved successfully.
C:\ProgramData\51hsdquinul.dat moved successfully.
C:\ProgramData\51k53j65lop.dat moved successfully.
C:\ProgramData\51rimco64.dat moved successfully.
C:\ProgramData\aimmnjebxmnj.dat moved successfully.
C:\ProgramData\arja1dv557.dat moved successfully.
C:\ProgramData\arjlo51wi.dat moved successfully.
C:\ProgramData\arjlonlonje.dat moved successfully.
C:\ProgramData\arjsimmnjje.dat moved successfully.
C:\ProgramData\cracometulon.dat moved successfully.
C:\ProgramData\d4j65j65x3.dat moved successfully.
C:\ProgramData\d4lopmnjrim.dat moved successfully.
C:\ProgramData\d4nulalije.dat moved successfully.
C:\ProgramData\d4nulcodo.dat moved successfully.
C:\ProgramData\dimcojem52.dat moved successfully.
C:\ProgramData\doalinulali.dat moved successfully.
C:\ProgramData\dohsdnirim.dat moved successfully.
C:\ProgramData\doquiquilop.dat moved successfully.
C:\ProgramData\dva1lo557.dat moved successfully.
C:\ProgramData\ejjnmmisjra.dat moved successfully.
C:\ProgramData\ejnolnoljra.dat moved successfully.
C:\ProgramData\eturimnula1.dat moved successfully.
C:\ProgramData\fo32dimali.dat moved successfully.
C:\ProgramData\folopm52k53.dat moved successfully.
C:\ProgramData\ilamid23of.dat moved successfully.
C:\ProgramData\j3232k53co.dat moved successfully.
C:\ProgramData\j65lodmebx.dat moved successfully.
C:\ProgramData\j65nularjdm.dat moved successfully.
C:\ProgramData\j65yh332m52.dat moved successfully.
C:\ProgramData\je5151j8.dat moved successfully.
C:\ProgramData\jeaimaim32.dat moved successfully.
C:\ProgramData\jeetuyh3jm.dat moved successfully.
C:\ProgramData\jmjelodim.dat moved successfully.
C:\ProgramData\jnmxbejnmmia.dat moved successfully.
C:\ProgramData\k53sim124arj.dat moved successfully.
C:\ProgramData\lifewqofro.dat moved successfully.
C:\ProgramData\lo55712413.dat moved successfully.
C:\ProgramData\loarjtemtem.dat moved successfully.
C:\ProgramData\lod4jmjm.dat moved successfully.
C:\ProgramData\lonilopco.dat moved successfully.
C:\ProgramData\lopk53nidm.dat moved successfully.
C:\ProgramData\metmetjraol.dat moved successfully.
C:\ProgramData\miaexeodmj.dat moved successfully.
C:\ProgramData\mnjeso32lo.dat moved successfully.
C:\ProgramData\mnjk53d4j65.dat moved successfully.
C:\ProgramData\mnjm5213wi.dat moved successfully.
C:\ProgramData\mnjni513j.dat moved successfully.
C:\ProgramData\mnjwiqui13.dat moved successfully.
C:\ProgramData\nij8etujm.dat moved successfully.
C:\ProgramData\nolutemocarc.dat moved successfully.
C:\ProgramData\nulfofojm.dat moved successfully.
C:\ProgramData\ol23osejnm.dat moved successfully.
C:\ProgramData\orfoqwefil.dat moved successfully.
C:\ProgramData\rimwisim124.dat moved successfully.
C:\ProgramData\to557jmj8.dat moved successfully.
C:\ProgramData\toebxwid4.dat moved successfully.
C:\ProgramData\x3d4zxcb3mnj.dat moved successfully.
C:\ProgramData\x3rimyh3jm.dat moved successfully.
C:\ProgramData\yh3wij32m52.dat moved successfully.
C:\ProgramData\zxcb3jenulnul.dat moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Melina
->Temp folder emptied: 256329605 bytes
->Temporary Internet Files folder emptied: 13216357 bytes
->Java cache emptied: 1159981 bytes
->FireFox cache emptied: 79006830 bytes
->Flash cache emptied: 641 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 306174893 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50568 bytes
RecycleBin emptied: 50176 bytes
 
Total Files Cleaned = 626.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Melina
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0.00 mb
 
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.39.2 log created on 04082012_222349

Files\Folders moved on Reboot...
C:\Users\Melina\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...


cosinus 08.04.2012 21:53

Ich brauch zur Kontrolle ein neues OTL-Log

CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Vintage 08.04.2012 23:06

OTL Logfile:
Code:

OTL logfile created on: 4/8/2012 11:58:47 PM - Run 2
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Users\Melina\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5.98 Gb Total Physical Memory | 4.39 Gb Available Physical Memory | 73.36% Memory free
11.96 Gb Paging File | 10.35 Gb Available in Paging File | 86.56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 230.00 Gb Total Space | 140.16 Gb Free Space | 60.94% Space Free | Partition Type: NTFS
Drive D: | 342.27 Gb Total Space | 342.18 Gb Free Space | 99.97% Space Free | Partition Type: NTFS
 
Computer Name: MELINA-PC | User Name: Melina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/04/08 21:42:05 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Melina\Desktop\OTL.exe
PRC - [2011/10/28 20:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/10/28 20:35:26 | 001,187,072 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/10/11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011/10/11 14:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/10/11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/02/14 12:15:38 | 004,394,576 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2011/02/07 11:55:24 | 001,757,264 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2011/01/04 15:06:42 | 007,060,560 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
PRC - [2010/12/23 08:07:58 | 000,945,232 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2010/12/21 04:30:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010/12/21 04:30:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010/11/29 07:42:38 | 000,775,848 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
PRC - [2010/11/10 01:03:52 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2010/09/20 05:24:42 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
PRC - [2010/08/27 03:52:12 | 002,782,064 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
PRC - [2010/07/29 09:47:08 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2010/02/10 16:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009/11/02 07:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2010/07/05 12:42:58 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll
MOD - [2010/05/07 16:22:18 | 001,636,864 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2009/11/02 07:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
MOD - [2009/11/02 07:20:10 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2006/08/12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010/09/22 11:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/08/09 21:04:12 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2011/10/28 20:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/10/11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/10/11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/12/21 04:30:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010/12/21 04:30:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012/02/15 21:28:37 | 000,132,320 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011/10/28 20:35:28 | 000,069,376 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
DRV:64bit: - [2011/10/11 15:00:01 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011/10/11 15:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011/07/06 08:16:24 | 000,289,704 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2011/05/23 17:24:22 | 002,750,464 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/04 09:59:18 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/02/18 01:11:54 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/01/27 07:35:26 | 000,425,064 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/13 00:23:38 | 000,138,024 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2010/11/10 01:04:14 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/10/20 02:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R)
DRV:64bit: - [2010/10/07 04:59:00 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV:64bit: - [2010/07/05 09:24:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010/04/27 04:25:16 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV:64bit: - [2010/04/27 04:25:16 | 000,127,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV:64bit: - [2010/04/27 04:25:16 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/06/10 22:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/04/29 17:28:30 | 000,030,208 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2011/11/01 10:50:55 | 000,017,152 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys -- (Lavasoft Kernexplorer)
DRV - [2011/09/08 08:23:41 | 000,015,144 | ---- | M] (Windows (R) 2003 DDK 3790 provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\rtport.sys -- (rtport)
DRV - [2010/07/05 09:24:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/04/04 15:42:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011/10/28 18:57:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Melina\AppData\Roaming\mozilla\Extensions
[2012/04/04 15:42:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/03/13 06:38:06 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/13 07:23:34 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/03/13 07:06:36 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/13 07:23:34 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012/03/13 07:23:34 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/03/13 07:23:34 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/03/13 07:23:34 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012/04/08 22:24:55 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1      localhost
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Samsung BHO Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [NPSStartup]  File not found
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2027592733-4161651481-1790285415-1001..\Run: [AutoStartNPSAgent] C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A768083D-4D72-43D5-9594-3C1F15309156}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/04/08 22:23:49 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/04/08 21:42:03 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Melina\Desktop\OTL.exe
[2012/04/08 18:21:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/04/08 18:19:48 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Melina\Desktop\esetsmartinstaller_enu.exe
[2012/04/07 19:53:31 | 000,000,000 | ---D | C] -- C:\Users\Melina\Desktop\Amsterdam, Juni 2011
[2012/04/04 19:00:22 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Roaming\Malwarebytes
[2012/04/04 19:00:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/04/04 19:00:06 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/04/04 19:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/04/04 15:42:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/04/01 23:17:58 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Roaming\Dropbox
[2012/03/30 14:30:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/03/29 22:13:16 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Local\{25A392AD-2EC1-4873-AC22-AE86F78DA5DF}
[2012/03/29 15:18:15 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\NPS
[2012/03/29 15:18:03 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\My Art
[2012/03/29 15:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung New PC Studio
[2012/03/29 15:08:14 | 000,161,280 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bmdm.sys
[2012/03/29 15:08:14 | 000,127,488 | ---- | C] (MCCI) -- C:\windows\SysNative\drivers\ss_bbus.sys
[2012/03/29 15:08:14 | 000,018,944 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bmdfl.sys
[2012/03/29 15:08:14 | 000,015,872 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bwhnt.sys
[2012/03/29 15:08:14 | 000,015,872 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bwh.sys
[2012/03/29 15:08:14 | 000,015,360 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bcmnt.sys
[2012/03/29 15:08:14 | 000,015,360 | ---- | C] (MCCI Corporation) -- C:\windows\SysNative\drivers\ss_bcm.sys
[2012/03/29 15:07:13 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\Samsung
[2012/03/29 15:06:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2012/03/29 14:44:23 | 000,025,960 | ---- | C] (Teruten Inc) -- C:\windows\SysWow64\FsExService64.Exe
[2012/03/29 14:44:23 | 000,016,448 | ---- | C] (Teruten Inc) -- C:\windows\SysWow64\drivers\TFsExDisk.Sys
[2012/03/29 14:44:22 | 000,025,960 | ---- | C] (Teruten Inc) -- C:\windows\SysNative\FsExService64.exe
[2012/03/29 14:44:22 | 000,016,448 | ---- | C] (Teruten Inc) -- C:\windows\SysNative\drivers\TFsExDisk.sys
[2012/03/29 14:44:16 | 000,000,000 | ---D | C] -- C:\Users\Melina\Documents\My NPS Files
[2012/03/29 14:44:15 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Roaming\Samsung
[2012/03/29 14:19:55 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Local\Downloaded Installations
[2012/03/29 11:36:28 | 000,000,000 | ---D | C] -- C:\Users\Melina\Desktop\Practigo
[2012/03/27 00:29:03 | 000,000,000 | ---D | C] -- C:\Users\Melina\AppData\Local\Diagnostics
[2012/03/16 19:12:44 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Samsung_USB_Drivers
 
========== Files - Modified Within 30 Days ==========
 
[2012/04/08 22:33:09 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/08 22:33:09 | 000,020,992 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/08 22:25:33 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/04/08 22:25:31 | 2126,036,991 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/08 22:24:55 | 000,000,098 | ---- | M] () -- C:\windows\SysNative\drivers\etc\Hosts
[2012/04/08 21:42:05 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Melina\Desktop\OTL.exe
[2012/04/08 20:08:22 | 000,021,298 | ---- | M] () -- C:\Users\Melina\Desktop\Letter_of_Motivation.pdf
[2012/04/08 18:19:52 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Melina\Desktop\esetsmartinstaller_enu.exe
[2012/04/07 13:19:01 | 000,000,064 | ---- | M] () -- C:\windows\SysWow64\rp_stats.dat
[2012/04/07 13:19:01 | 000,000,044 | ---- | M] () -- C:\windows\SysWow64\rp_rules.dat
[2012/04/04 19:00:09 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/04 15:42:54 | 000,001,094 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/03 17:25:37 | 001,507,106 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/04/03 17:25:37 | 000,657,676 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2012/04/03 17:25:37 | 000,618,912 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/04/03 17:25:37 | 000,131,016 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2012/04/03 17:25:37 | 000,107,232 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/03/29 15:17:32 | 001,526,948 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/03/29 15:15:55 | 000,001,184 | ---- | M] () -- C:\Users\Public\Desktop\Samsung New PC Studio.lnk
[2012/03/29 15:10:13 | 000,002,898 | ---- | M] () -- C:\aqua_bitmap.cpp
[2012/03/15 12:02:31 | 000,425,000 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/03/14 20:13:55 | 000,195,177 | ---- | M] () -- C:\Users\Melina\Desktop\SBBescheidEinsSoSeXII.pdf
 
========== Files Created - No Company Name ==========
 
[2012/04/08 20:08:22 | 000,021,298 | ---- | C] () -- C:\Users\Melina\Desktop\Letter_of_Motivation.pdf
[2012/04/04 19:00:09 | 000,001,073 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/04 15:42:54 | 000,001,094 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/04 15:42:53 | 000,001,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/03/29 22:31:44 | 003,315,214 | ---- | C] () -- C:\Users\Melina\Desktop\Weezers- Beverly Hills.m4p
[2012/03/29 22:31:29 | 003,867,750 | ---- | C] () -- C:\Users\Melina\Desktop\03 Swing, Swing.m4p
[2012/03/29 22:28:16 | 002,756,341 | ---- | C] () -- C:\Users\Melina\Desktop\03 The Middle.m4p
[2012/03/29 15:17:32 | 001,526,948 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/03/29 15:10:13 | 000,002,898 | ---- | C] () -- C:\aqua_bitmap.cpp
[2012/03/29 15:08:45 | 000,001,184 | ---- | C] () -- C:\Users\Public\Desktop\Samsung New PC Studio.lnk
[2012/03/14 20:13:35 | 000,195,177 | ---- | C] () -- C:\Users\Melina\Desktop\SBBescheidEinsSoSeXII.pdf
[2011/11/10 09:56:18 | 000,000,064 | ---- | C] () -- C:\windows\SysWow64\rp_stats.dat
[2011/11/10 09:56:18 | 000,000,044 | ---- | C] () -- C:\windows\SysWow64\rp_rules.dat
[2011/10/31 22:01:36 | 000,000,076 | ---- | C] () -- C:\windows\SysWow64\net32gdilib.dll
[2011/07/28 20:44:58 | 000,258,864 | ---- | C] () -- C:\windows\SUPDRun.exe
[2011/07/28 06:55:27 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2011/07/28 06:07:29 | 000,000,918 | ---- | C] () -- C:\windows\HotFixList.ini
[2011/07/28 05:54:15 | 000,142,128 | ---- | C] () -- C:\windows\wiainst64.exe
 
========== LOP Check ==========
 
[2012/04/02 10:23:42 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Dropbox
[2011/11/01 10:46:05 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\J River
[2012/03/29 14:44:15 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Samsung
[2012/04/07 15:06:13 | 000,032,632 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011/10/28 20:17:33 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Adobe
[2011/10/28 20:37:09 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Avira
[2011/10/29 13:51:08 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\CyberLink
[2012/04/02 10:23:42 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Dropbox
[2011/10/28 18:50:24 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Identities
[2011/11/01 10:46:05 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\J River
[2011/10/28 18:52:16 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Macromedia
[2012/04/04 19:00:22 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Malwarebytes
[2011/07/28 20:56:59 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Media Center Programs
[2012/04/02 16:43:46 | 000,000,000 | --SD | M] -- C:\Users\Melina\AppData\Roaming\Microsoft
[2011/10/28 18:57:10 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Mozilla
[2012/03/29 14:44:15 | 000,000,000 | ---D | M] -- C:\Users\Melina\AppData\Roaming\Samsung
 
< %APPDATA%\*.exe /s >
[2012/03/29 14:41:59 | 000,069,632 | ---- | M] () -- C:\Users\Melina\AppData\Roaming\Samsung\New PC Studio\DriverChecker.exe
[2012/03/29 15:09:13 | 000,704,512 | ---- | M] (TODO: <Company name>) -- C:\Users\Melina\AppData\Roaming\Samsung\New PC Studio\LiveUpdate\NPSUpdateAgent.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\drivers\AGP440.sys
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\drivers\atapi.sys
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\windows\SysNative\cngaudit.dll
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2008/06/06 07:03:52 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTOR.SYS  >
[2011/02/18 01:11:54 | 000,439,320 | ---- | M] (Intel Corporation) MD5=53CC5BF8B5A219119953C7ABB19A7705 -- C:\windows\SysNative\drivers\iaStor.sys
[2011/02/18 01:11:54 | 000,439,320 | ---- | M] (Intel Corporation) MD5=53CC5BF8B5A219119953C7ABB19A7705 -- C:\windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_52b32c0ad3e84c62\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/03/11 08:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\windows\SysNative\drivers\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 08:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\windows\SysNative\netlogon.dll
[2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011/03/11 08:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\windows\SysNative\drivers\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 08:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\windows\SysNative\scecli.dll
[2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010/11/21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010/11/21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010/11/21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\windows\SysNative\user32.dll
[2010/11/21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\windows\SysNative\userinit.exe
[2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009/07/14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\windows\SysNative\wininit.exe
[2009/07/14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009/07/14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\SysWOW64\wininit.exe
[2009/07/14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\windows\SysNative\winlogon.exe
[2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/01/13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\windows\SysNative\drivers\ws2ifsl.sys
[2009/07/14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---

cosinus 08.04.2012 23:13

Das sieht gut aus :)

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

Vintage 08.04.2012 23:28

Ich musst den Log teilen, der ist zu groß:

1.
Code:

00:21:58.0118 2920        TDSS rootkit removing tool 2.7.26.0 Apr  4 2012 19:52:02
00:21:58.0227 2920        ============================================================
00:21:58.0227 2920        Current date / time: 2012/04/09 00:21:58.0227
00:21:58.0227 2920        SystemInfo:
00:21:58.0227 2920       
00:21:58.0227 2920        OS Version: 6.1.7601 ServicePack: 1.0
00:21:58.0227 2920        Product type: Workstation
00:21:58.0227 2920        ComputerName: MELINA-PC
00:21:58.0227 2920        UserName: Melina
00:21:58.0227 2920        Windows directory: C:\windows
00:21:58.0227 2920        System windows directory: C:\windows
00:21:58.0227 2920        Running under WOW64
00:21:58.0227 2920        Processor architecture: Intel x64
00:21:58.0227 2920        Number of processors: 4
00:21:58.0227 2920        Page size: 0x1000
00:21:58.0227 2920        Boot type: Normal boot
00:21:58.0227 2920        ============================================================
00:21:58.0523 2920        Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
00:21:58.0539 2920        \Device\Harddisk0\DR0:
00:21:58.0539 2920        MBR used
00:21:58.0539 2920        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
00:21:58.0539 2920        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1CC00000
00:21:58.0554 2920        \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1CC33000, BlocksNum 0x2AC8C800
00:21:58.0617 2920        Initialize success
00:21:58.0617 2920        ============================================================
00:22:17.0009 1552        ============================================================
00:22:17.0009 1552        Scan started
00:22:17.0009 1552        Mode: Manual;
00:22:17.0009 1552        ============================================================
00:22:17.0337 1552        1394ohci        (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
00:22:17.0337 1552        1394ohci - ok
00:22:17.0368 1552        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
00:22:17.0384 1552        ACPI - ok
00:22:17.0415 1552        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
00:22:17.0415 1552        AcpiPmi - ok
00:22:17.0462 1552        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\drivers\adp94xx.sys
00:22:17.0462 1552        adp94xx - ok
00:22:17.0509 1552        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\drivers\adpahci.sys
00:22:17.0509 1552        adpahci - ok
00:22:17.0540 1552        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\drivers\adpu320.sys
00:22:17.0540 1552        adpu320 - ok
00:22:17.0587 1552        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
00:22:17.0587 1552        AeLookupSvc - ok
00:22:17.0633 1552        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
00:22:17.0649 1552        AFD - ok
00:22:17.0680 1552        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
00:22:17.0680 1552        agp440 - ok
00:22:17.0696 1552        ALG            (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
00:22:17.0696 1552        ALG - ok
00:22:17.0743 1552        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
00:22:17.0743 1552        aliide - ok
00:22:17.0758 1552        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
00:22:17.0758 1552        amdide - ok
00:22:17.0758 1552        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\drivers\amdk8.sys
00:22:17.0774 1552        AmdK8 - ok
00:22:17.0774 1552        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\drivers\amdppm.sys
00:22:17.0774 1552        AmdPPM - ok
00:22:17.0821 1552        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
00:22:17.0821 1552        amdsata - ok
00:22:17.0867 1552        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\drivers\amdsbs.sys
00:22:17.0867 1552        amdsbs - ok
00:22:17.0899 1552        amdxata        (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
00:22:17.0899 1552        amdxata - ok
00:22:17.0961 1552        AntiVirSchedulerService (a122d68ea2541453f787f341877cb40b) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
00:22:17.0961 1552        AntiVirSchedulerService - ok
00:22:18.0039 1552        AntiVirService  (2fe359edeb34efcf42574752f8aebd3f) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
00:22:18.0039 1552        AntiVirService - ok
00:22:18.0164 1552        AppID          (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
00:22:18.0164 1552        AppID - ok
00:22:18.0195 1552        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
00:22:18.0195 1552        AppIDSvc - ok
00:22:18.0242 1552        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
00:22:18.0242 1552        Appinfo - ok
00:22:18.0289 1552        arc            (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\drivers\arc.sys
00:22:18.0289 1552        arc - ok
00:22:18.0304 1552        arcsas          (019af6924aefe7839f61c830227fe79c) C:\windows\system32\drivers\arcsas.sys
00:22:18.0304 1552        arcsas - ok
00:22:18.0335 1552        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
00:22:18.0335 1552        AsyncMac - ok
00:22:18.0351 1552        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
00:22:18.0367 1552        atapi - ok
00:22:18.0460 1552        athr            (de9fb3dade8fd39ae2c587df22d36b8e) C:\windows\system32\DRIVERS\athrx.sys
00:22:18.0476 1552        athr - ok
00:22:18.0835 1552        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
00:22:18.0850 1552        AudioEndpointBuilder - ok
00:22:18.0866 1552        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
00:22:18.0866 1552        AudioSrv - ok
00:22:18.0959 1552        avgntflt        (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\windows\system32\DRIVERS\avgntflt.sys
00:22:18.0975 1552        avgntflt - ok
00:22:19.0006 1552        avipbb          (852e3c0a60d368c487949e55ad52a47f) C:\windows\system32\DRIVERS\avipbb.sys
00:22:19.0022 1552        avipbb - ok
00:22:19.0037 1552        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\windows\system32\DRIVERS\avkmgr.sys
00:22:19.0037 1552        avkmgr - ok
00:22:19.0100 1552        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
00:22:19.0100 1552        AxInstSV - ok
00:22:19.0147 1552        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\windows\system32\drivers\bxvbda.sys
00:22:19.0147 1552        b06bdrv - ok
00:22:19.0193 1552        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
00:22:19.0193 1552        b57nd60a - ok
00:22:19.0225 1552        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
00:22:19.0225 1552        BDESVC - ok
00:22:19.0240 1552        Beep            (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
00:22:19.0240 1552        Beep - ok
00:22:19.0303 1552        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
00:22:19.0303 1552        BFE - ok
00:22:19.0365 1552        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\windows\System32\qmgr.dll
00:22:19.0381 1552        BITS - ok
00:22:19.0443 1552        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
00:22:19.0443 1552        blbdrive - ok
00:22:19.0490 1552        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
00:22:19.0490 1552        bowser - ok
00:22:19.0521 1552        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\drivers\BrFiltLo.sys
00:22:19.0521 1552        BrFiltLo - ok
00:22:19.0521 1552        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\drivers\BrFiltUp.sys
00:22:19.0521 1552        BrFiltUp - ok
00:22:19.0568 1552        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
00:22:19.0568 1552        Browser - ok
00:22:19.0599 1552        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
00:22:19.0615 1552        Brserid - ok
00:22:19.0615 1552        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
00:22:19.0630 1552        BrSerWdm - ok
00:22:19.0630 1552        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
00:22:19.0630 1552        BrUsbMdm - ok
00:22:19.0646 1552        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
00:22:19.0646 1552        BrUsbSer - ok
00:22:19.0693 1552        BtFilter        (9d95f74875491cecbf9e10a5936a570e) C:\windows\system32\DRIVERS\btfilter.sys
00:22:19.0693 1552        BtFilter - ok
00:22:19.0724 1552        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\windows\system32\drivers\BthEnum.sys
00:22:19.0724 1552        BthEnum - ok
00:22:19.0755 1552        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\drivers\bthmodem.sys
00:22:19.0755 1552        BTHMODEM - ok
00:22:19.0786 1552        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\windows\system32\DRIVERS\bthpan.sys
00:22:19.0786 1552        BthPan - ok
00:22:19.0833 1552        BTHPORT        (64c198198501f7560ee41d8d1efa7952) C:\windows\System32\Drivers\BTHport.sys
00:22:19.0833 1552        BTHPORT - ok
00:22:19.0864 1552        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
00:22:19.0864 1552        bthserv - ok
00:22:19.0911 1552        BTHUSB          (f188b7394d81010767b6df3178519a37) C:\windows\System32\Drivers\BTHUSB.sys
00:22:19.0911 1552        BTHUSB - ok
00:22:19.0942 1552        cdfs            (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
00:22:19.0942 1552        cdfs - ok
00:22:19.0973 1552        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\DRIVERS\cdrom.sys
00:22:19.0989 1552        cdrom - ok
00:22:20.0020 1552        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
00:22:20.0020 1552        CertPropSvc - ok
00:22:20.0036 1552        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\drivers\circlass.sys
00:22:20.0036 1552        circlass - ok
00:22:20.0083 1552        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
00:22:20.0098 1552        CLFS - ok
00:22:20.0145 1552        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:22:20.0161 1552        clr_optimization_v2.0.50727_32 - ok
00:22:20.0223 1552        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
00:22:20.0223 1552        clr_optimization_v2.0.50727_64 - ok
00:22:20.0317 1552        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
00:22:20.0332 1552        clr_optimization_v4.0.30319_32 - ok
00:22:20.0363 1552        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
00:22:20.0379 1552        clr_optimization_v4.0.30319_64 - ok
00:22:20.0457 1552        clwvd          (50f92c943f18b070f166d019dfab3d9a) C:\windows\system32\DRIVERS\clwvd.sys
00:22:20.0473 1552        clwvd - ok
00:22:20.0504 1552        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
00:22:20.0504 1552        CmBatt - ok
00:22:20.0535 1552        cmdide          (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
00:22:20.0535 1552        cmdide - ok
00:22:20.0582 1552        CNG            (c4943b6c962e4b82197542447ad599f4) C:\windows\system32\Drivers\cng.sys
00:22:20.0582 1552        CNG - ok
00:22:20.0613 1552        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
00:22:20.0613 1552        Compbatt - ok
00:22:20.0660 1552        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\windows\system32\DRIVERS\CompositeBus.sys
00:22:20.0660 1552        CompositeBus - ok
00:22:20.0675 1552        COMSysApp - ok
00:22:20.0691 1552        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\windows\system32\drivers\crcdisk.sys
00:22:20.0691 1552        crcdisk - ok
00:22:20.0738 1552        CryptSvc        (15597883fbe9b056f276ada3ad87d9af) C:\windows\system32\cryptsvc.dll
00:22:20.0738 1552        CryptSvc - ok
00:22:20.0800 1552        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
00:22:20.0816 1552        DcomLaunch - ok
00:22:20.0847 1552        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
00:22:20.0863 1552        defragsvc - ok
00:22:20.0925 1552        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
00:22:20.0925 1552        DfsC - ok
00:22:20.0972 1552        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
00:22:20.0987 1552        Dhcp - ok
00:22:21.0003 1552        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
00:22:21.0003 1552        discache - ok
00:22:21.0034 1552        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\drivers\disk.sys
00:22:21.0034 1552        Disk - ok
00:22:21.0065 1552        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
00:22:21.0065 1552        Dnscache - ok
00:22:21.0097 1552        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
00:22:21.0097 1552        dot3svc - ok
00:22:21.0112 1552        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
00:22:21.0128 1552        DPS - ok
00:22:21.0143 1552        drmkaud        (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
00:22:21.0143 1552        drmkaud - ok
00:22:21.0190 1552        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
00:22:21.0190 1552        DXGKrnl - ok
00:22:21.0237 1552        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
00:22:21.0237 1552        EapHost - ok
00:22:21.0331 1552        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\drivers\evbda.sys
00:22:21.0362 1552        ebdrv - ok
00:22:21.0455 1552        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
00:22:21.0455 1552        EFS - ok
00:22:21.0518 1552        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
00:22:21.0518 1552        ehRecvr - ok
00:22:21.0533 1552        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
00:22:21.0533 1552        ehSched - ok
00:22:21.0627 1552        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\drivers\elxstor.sys
00:22:21.0643 1552        elxstor - ok
00:22:21.0658 1552        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
00:22:21.0658 1552        ErrDev - ok
00:22:21.0705 1552        ETD            (9d8739a2a2173c9d27c499a3fc6eda3f) C:\windows\system32\DRIVERS\ETD.sys
00:22:21.0705 1552        ETD - ok
00:22:21.0767 1552        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
00:22:21.0767 1552        EventSystem - ok
00:22:21.0814 1552        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
00:22:21.0814 1552        exfat - ok
00:22:21.0830 1552        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
00:22:21.0830 1552        fastfat - ok
00:22:21.0861 1552        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
00:22:21.0877 1552        Fax - ok
00:22:21.0892 1552        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\drivers\fdc.sys
00:22:21.0892 1552        fdc - ok
00:22:21.0923 1552        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
00:22:21.0923 1552        fdPHost - ok
00:22:21.0939 1552        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
00:22:21.0939 1552        FDResPub - ok
00:22:21.0970 1552        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
00:22:21.0970 1552        FileInfo - ok
00:22:21.0986 1552        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
00:22:21.0986 1552        Filetrace - ok
00:22:22.0001 1552        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\drivers\flpydisk.sys
00:22:22.0001 1552        flpydisk - ok
00:22:22.0017 1552        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
00:22:22.0017 1552        FltMgr - ok
00:22:22.0064 1552        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\windows\system32\FntCache.dll
00:22:22.0079 1552        FontCache - ok
00:22:22.0157 1552        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
00:22:22.0157 1552        FontCache3.0.0.0 - ok
00:22:22.0267 1552        FsDepends      (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
00:22:22.0267 1552        FsDepends - ok
00:22:22.0313 1552        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys
00:22:22.0313 1552        Fs_Rec - ok
00:22:22.0345 1552        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
00:22:22.0360 1552        fvevol - ok
00:22:22.0376 1552        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\drivers\gagp30kx.sys
00:22:22.0376 1552        gagp30kx - ok
00:22:22.0438 1552        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
00:22:22.0454 1552        gpsvc - ok
00:22:22.0469 1552        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
00:22:22.0469 1552        hcw85cir - ok
00:22:22.0501 1552        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
00:22:22.0516 1552        HdAudAddService - ok
00:22:22.0547 1552        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\DRIVERS\HDAudBus.sys
00:22:22.0563 1552        HDAudBus - ok
00:22:22.0579 1552        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\drivers\HidBatt.sys
00:22:22.0579 1552        HidBatt - ok
00:22:22.0594 1552        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\drivers\hidbth.sys
00:22:22.0594 1552        HidBth - ok
00:22:22.0625 1552        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\drivers\hidir.sys
00:22:22.0625 1552        HidIr - ok
00:22:22.0657 1552        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\windows\system32\hidserv.dll
00:22:22.0657 1552        hidserv - ok
00:22:22.0703 1552        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\DRIVERS\hidusb.sys
00:22:22.0703 1552        HidUsb - ok
00:22:22.0735 1552        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
00:22:22.0750 1552        hkmsvc - ok
00:22:22.0766 1552        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
00:22:22.0781 1552        HomeGroupListener - ok
00:22:22.0813 1552        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
00:22:22.0813 1552        HomeGroupProvider - ok
00:22:22.0844 1552        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
00:22:22.0844 1552        HpSAMD - ok
00:22:22.0891 1552        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
00:22:22.0891 1552        HTTP - ok
00:22:22.0922 1552        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
00:22:22.0922 1552        hwpolicy - ok
00:22:22.0953 1552        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys
00:22:22.0953 1552        i8042prt - ok
00:22:22.0984 1552        iaStor          (53cc5bf8b5a219119953c7abb19a7705) C:\windows\system32\DRIVERS\iaStor.sys
00:22:23.0000 1552        iaStor - ok
00:22:23.0047 1552        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
00:22:23.0047 1552        iaStorV - ok
00:22:23.0140 1552        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
00:22:23.0156 1552        idsvc - ok
00:22:23.0405 1552        igfx            (a87261ef1546325b559374f5689cf5bc) C:\windows\system32\DRIVERS\igdkmd64.sys
00:22:23.0437 1552        igfx - ok
00:22:23.0515 1552        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\drivers\iirsp.sys
00:22:23.0530 1552        iirsp - ok
00:22:23.0561 1552        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
00:22:23.0577 1552        IKEEXT - ok
00:22:23.0717 1552        IntcAzAudAddService (65f70696be5abc11634fcf96af7d7896) C:\windows\system32\drivers\RTKVHD64.sys
00:22:23.0733 1552        IntcAzAudAddService - ok
00:22:23.0827 1552        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
00:22:23.0827 1552        intelide - ok
00:22:23.0873 1552        intelppm        (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
00:22:23.0873 1552        intelppm - ok
00:22:23.0920 1552        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
00:22:23.0920 1552        IPBusEnum - ok
00:22:23.0951 1552        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
00:22:23.0967 1552        IpFilterDriver - ok
00:22:23.0998 1552        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
00:22:24.0014 1552        iphlpsvc - ok
00:22:24.0029 1552        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
00:22:24.0029 1552        IPMIDRV - ok
00:22:24.0029 1552        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
00:22:24.0045 1552        IPNAT - ok
00:22:24.0061 1552        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
00:22:24.0061 1552        IRENUM - ok
00:22:24.0092 1552        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
00:22:24.0092 1552        isapnp - ok
00:22:24.0123 1552        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
00:22:24.0123 1552        iScsiPrt - ok
00:22:24.0154 1552        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys
00:22:24.0154 1552        kbdclass - ok
00:22:24.0185 1552        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\DRIVERS\kbdhid.sys
00:22:24.0185 1552        kbdhid - ok
00:22:24.0232 1552        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:22:24.0232 1552        KeyIso - ok
00:22:24.0279 1552        KMWDFILTER      (07071c1e3cd8f0f9114aac8b072ca1e5) C:\windows\system32\DRIVERS\KMWDFILTER.sys
00:22:24.0279 1552        KMWDFILTER - ok
00:22:24.0310 1552        KSecDD          (da1e991a61cfdd755a589e206b97644b) C:\windows\system32\Drivers\ksecdd.sys
00:22:24.0310 1552        KSecDD - ok
00:22:24.0341 1552        KSecPkg        (7e33198d956943a4f11a5474c1e9106f) C:\windows\system32\Drivers\ksecpkg.sys
00:22:24.0341 1552        KSecPkg - ok
00:22:24.0388 1552        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
00:22:24.0388 1552        ksthunk - ok
00:22:24.0435 1552        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
00:22:24.0451 1552        KtmRm - ok
00:22:24.0513 1552        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\system32\srvsvc.dll
00:22:24.0529 1552        LanmanServer - ok
00:22:24.0560 1552        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
00:22:24.0560 1552        LanmanWorkstation - ok
00:22:24.0685 1552        Lavasoft Ad-Aware Service (ea38136981c61c571d52c380daad46ef) C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
00:22:24.0716 1552        Lavasoft Ad-Aware Service - ok
00:22:24.0809 1552        Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys
00:22:24.0809 1552        Lavasoft Kernexplorer - ok
00:22:24.0934 1552        Lbd            (c8b3131857931ae76798a741cc52b021) C:\windows\system32\DRIVERS\Lbd.sys
00:22:24.0950 1552        Lbd - ok
00:22:24.0997 1552        lltdio          (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
00:22:24.0997 1552        lltdio - ok
00:22:25.0043 1552        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
00:22:25.0059 1552        lltdsvc - ok
00:22:25.0090 1552        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
00:22:25.0090 1552        lmhosts - ok
00:22:25.0184 1552        LMS            (2ed1786b7542cda261029f6b526edf44) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
00:22:25.0184 1552        LMS - ok
00:22:25.0262 1552        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\drivers\lsi_fc.sys
00:22:25.0262 1552        LSI_FC - ok
00:22:25.0293 1552        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\drivers\lsi_sas.sys
00:22:25.0293 1552        LSI_SAS - ok
00:22:25.0309 1552        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\drivers\lsi_sas2.sys
00:22:25.0309 1552        LSI_SAS2 - ok
00:22:25.0340 1552        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\drivers\lsi_scsi.sys
00:22:25.0340 1552        LSI_SCSI - ok
00:22:25.0371 1552        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
00:22:25.0371 1552        luafv - ok
00:22:25.0402 1552        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
00:22:25.0402 1552        Mcx2Svc - ok
00:22:25.0433 1552        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\drivers\megasas.sys
00:22:25.0433 1552        megasas - ok
00:22:25.0480 1552        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\drivers\MegaSR.sys
00:22:25.0480 1552        MegaSR - ok
00:22:25.0527 1552        MEIx64          (a6518dcc42f7a6e999bb3bea8fd87567) C:\windows\system32\DRIVERS\HECIx64.sys
00:22:25.0527 1552        MEIx64 - ok
00:22:25.0558 1552        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
00:22:25.0558 1552        MMCSS - ok
00:22:25.0574 1552        Modem          (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
00:22:25.0589 1552        Modem - ok
00:22:25.0621 1552        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
00:22:25.0621 1552        monitor - ok
00:22:25.0667 1552        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
00:22:25.0667 1552        mouclass - ok
00:22:25.0699 1552        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
00:22:25.0699 1552        mouhid - ok
00:22:25.0714 1552        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
00:22:25.0730 1552        mountmgr - ok
00:22:25.0745 1552        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
00:22:25.0745 1552        mpio - ok
00:22:25.0777 1552        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
00:22:25.0777 1552        mpsdrv - ok
00:22:25.0823 1552        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\windows\system32\mpssvc.dll
00:22:25.0839 1552        MpsSvc - ok
00:22:25.0870 1552        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
00:22:25.0870 1552        MRxDAV - ok
00:22:25.0901 1552        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
00:22:25.0901 1552        mrxsmb - ok
00:22:25.0948 1552        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
00:22:25.0964 1552        mrxsmb10 - ok
00:22:25.0979 1552        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
00:22:25.0979 1552        mrxsmb20 - ok
00:22:25.0995 1552        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
00:22:25.0995 1552        msahci - ok
00:22:26.0026 1552        msdsm          (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
00:22:26.0026 1552        msdsm - ok
00:22:26.0057 1552        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
00:22:26.0057 1552        MSDTC - ok
00:22:26.0104 1552        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
00:22:26.0104 1552        Msfs - ok
00:22:26.0151 1552        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
00:22:26.0151 1552        mshidkmdf - ok
00:22:26.0182 1552        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
00:22:26.0182 1552        msisadrv - ok
00:22:26.0213 1552        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
00:22:26.0213 1552        MSiSCSI - ok
00:22:26.0229 1552        msiserver - ok
00:22:26.0260 1552        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
00:22:26.0260 1552        MSKSSRV - ok
00:22:26.0291 1552        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
00:22:26.0291 1552        MSPCLOCK - ok
00:22:26.0307 1552        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
00:22:26.0307 1552        MSPQM - ok
00:22:26.0338 1552        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
00:22:26.0354 1552        MsRPC - ok
00:22:26.0385 1552        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys
00:22:26.0385 1552        mssmbios - ok
00:22:26.0401 1552        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
00:22:26.0401 1552        MSTEE - ok
00:22:26.0432 1552        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\drivers\MTConfig.sys
00:22:26.0432 1552        MTConfig - ok
00:22:26.0447 1552        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
00:22:26.0447 1552        Mup - ok
00:22:26.0494 1552        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
00:22:26.0494 1552        napagent - ok
00:22:26.0541 1552        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
00:22:26.0557 1552        NativeWifiP - ok
00:22:26.0635 1552        NDIS            (c38b8ae57f78915905064a9a24dc1586) C:\windows\system32\drivers\ndis.sys
00:22:26.0650 1552        NDIS - ok
00:22:26.0681 1552        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
00:22:26.0681 1552        NdisCap - ok
00:22:26.0713 1552        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
00:22:26.0713 1552        NdisTapi - ok
00:22:26.0759 1552        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
00:22:26.0759 1552        Ndisuio - ok
00:22:26.0791 1552        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
00:22:26.0791 1552        NdisWan - ok
00:22:26.0822 1552        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
00:22:26.0822 1552        NDProxy - ok
00:22:26.0837 1552        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
00:22:26.0837 1552        NetBIOS - ok
00:22:26.0853 1552        NetBT          (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
00:22:26.0869 1552        NetBT - ok
00:22:26.0900 1552        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:22:26.0900 1552        Netlogon - ok
00:22:26.0931 1552        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
00:22:26.0947 1552        Netman - ok
00:22:26.0962 1552        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
00:22:26.0978 1552        netprofm - ok
00:22:27.0056 1552        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
00:22:27.0056 1552        NetTcpPortSharing - ok
00:22:27.0087 1552        nfrd960        (77889813be4d166cdab78ddba990da92) C:\windows\system32\drivers\nfrd960.sys
00:22:27.0087 1552        nfrd960 - ok
00:22:27.0118 1552        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
00:22:27.0118 1552        NlaSvc - ok
00:22:27.0134 1552        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
00:22:27.0134 1552        Npfs - ok
00:22:27.0181 1552        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
00:22:27.0181 1552        nsi - ok
00:22:27.0196 1552        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
00:22:27.0196 1552        nsiproxy - ok
00:22:27.0243 1552        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
00:22:27.0259 1552        Ntfs - ok
00:22:27.0352 1552        Null            (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
00:22:27.0352 1552        Null - ok
00:22:27.0399 1552        NVHDA          (f2662fdc20518ee8a8eed4f61ba42349) C:\windows\system32\drivers\nvhda64v.sys
00:22:27.0399 1552        NVHDA - ok
00:22:27.0727 1552        nvlddmkm        (e4c35efde340f3a18123ae85104b2b82) C:\windows\system32\DRIVERS\nvlddmkm.sys
00:22:27.0805 1552        nvlddmkm - ok
00:22:27.0929 1552        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
00:22:27.0929 1552        nvraid - ok
00:22:27.0976 1552        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
00:22:27.0976 1552        nvstor - ok
00:22:28.0039 1552        NVSvc          (7e4d066d8be847723807ef161b78bf07) C:\windows\system32\nvvsvc.exe
00:22:28.0054 1552        NVSvc - ok
00:22:28.0179 1552        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
00:22:28.0179 1552        nv_agp - ok
00:22:28.0195 1552        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
00:22:28.0195 1552        ohci1394 - ok
00:22:28.0273 1552        ose            (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
00:22:28.0273 1552        ose - ok
00:22:28.0413 1552        osppsvc        (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
00:22:28.0444 1552        osppsvc - ok
00:22:28.0538 1552        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
00:22:28.0538 1552        p2pimsvc - ok
00:22:28.0569 1552        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
00:22:28.0585 1552        p2psvc - ok
00:22:28.0631 1552        Parport        (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\drivers\parport.sys
00:22:28.0631 1552        Parport - ok
00:22:28.0663 1552        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\windows\system32\drivers\partmgr.sys
00:22:28.0663 1552        partmgr - ok
00:22:28.0694 1552        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
00:22:28.0694 1552        PcaSvc - ok
00:22:28.0709 1552        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
00:22:28.0709 1552        pci - ok
00:22:28.0725 1552        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
00:22:28.0725 1552        pciide - ok
00:22:28.0756 1552        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\drivers\pcmcia.sys
00:22:28.0756 1552        pcmcia - ok
00:22:28.0756 1552        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
00:22:28.0756 1552        pcw - ok
00:22:28.0803 1552        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
00:22:28.0803 1552        PEAUTH - ok
00:22:28.0897 1552        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
00:22:28.0897 1552        PerfHost - ok
00:22:28.0975 1552        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
00:22:28.0990 1552        pla - ok
00:22:29.0084 1552        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
00:22:29.0099 1552        PlugPlay - ok
00:22:29.0131 1552        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
00:22:29.0131 1552        PNRPAutoReg - ok
00:22:29.0146 1552        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
00:22:29.0162 1552        PNRPsvc - ok
00:22:29.0193 1552        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
00:22:29.0193 1552        PolicyAgent - ok
00:22:29.0240 1552        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
00:22:29.0240 1552        Power - ok
00:22:29.0287 1552        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
00:22:29.0287 1552        PptpMiniport - ok
00:22:29.0318 1552        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\drivers\processr.sys
00:22:29.0318 1552        Processor - ok
00:22:29.0349 1552        ProfSvc        (5c78838b4d166d1a27db3a8a820c799a) C:\windows\system32\profsvc.dll
00:22:29.0365 1552        ProfSvc - ok
00:22:29.0396 1552        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:22:29.0396 1552        ProtectedStorage - ok
00:22:29.0427 1552        Psched          (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
00:22:29.0427 1552        Psched - ok
00:22:29.0505 1552        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\drivers\ql2300.sys
00:22:29.0521 1552        ql2300 - ok
00:22:29.0645 1552        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\drivers\ql40xx.sys
00:22:29.0645 1552        ql40xx - ok
00:22:29.0677 1552        QWAVE          (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
00:22:29.0677 1552        QWAVE - ok
00:22:29.0692 1552        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
00:22:29.0692 1552        QWAVEdrv - ok
00:22:29.0708 1552        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
00:22:29.0708 1552        RasAcd - ok
00:22:29.0739 1552        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
00:22:29.0739 1552        RasAgileVpn - ok
00:22:29.0770 1552        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
00:22:29.0770 1552        RasAuto - ok
00:22:29.0801 1552        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
00:22:29.0801 1552        Rasl2tp - ok
00:22:29.0833 1552        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
00:22:29.0833 1552        RasMan - ok
00:22:29.0848 1552        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
00:22:29.0848 1552        RasPppoe - ok
00:22:29.0848 1552        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
00:22:29.0848 1552        RasSstp - ok
00:22:29.0879 1552        rdbss          (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
00:22:29.0879 1552        rdbss - ok
00:22:29.0895 1552        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\drivers\rdpbus.sys
00:22:29.0895 1552        rdpbus - ok
00:22:29.0942 1552        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
00:22:29.0942 1552        RDPCDD - ok
00:22:29.0973 1552        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
00:22:29.0973 1552        RDPENCDD - ok
00:22:29.0989 1552        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
00:22:29.0989 1552        RDPREFMP - ok
00:22:30.0020 1552        RDPWD          (6d76e6433574b058adcb0c50df834492) C:\windows\system32\drivers\RDPWD.sys
00:22:30.0035 1552        RDPWD - ok
00:22:30.0067 1552        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
00:22:30.0067 1552        rdyboost - ok
00:22:30.0098 1552        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
00:22:30.0098 1552        RemoteAccess - ok
00:22:30.0145 1552        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
00:22:30.0145 1552        RemoteRegistry - ok
00:22:30.0223 1552        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\windows\system32\DRIVERS\rfcomm.sys
00:22:30.0223 1552        RFCOMM - ok
00:22:30.0316 1552        RichVideo      (f12a68ed55053940cadd59ca5e3468dd) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
00:22:30.0332 1552        RichVideo - ok
00:22:30.0363 1552        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
00:22:30.0363 1552        RpcEptMapper - ok
00:22:30.0394 1552        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
00:22:30.0394 1552        RpcLocator - ok
00:22:30.0441 1552        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
00:22:30.0441 1552        RpcSs - ok
00:22:30.0519 1552        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
00:22:30.0519 1552        rspndr - ok
00:22:30.0566 1552        RTL8167        (ea5532868ba76923d75bcb2a1448d810) C:\windows\system32\DRIVERS\Rt64win7.sys
00:22:30.0581 1552        RTL8167 - ok
00:22:30.0675 1552        rtport          (4ca0dba9e224473d664c25e411f5a3bd) C:\windows\SysWOW64\drivers\rtport.sys
00:22:30.0675 1552        rtport - ok
00:22:30.0706 1552        SABI            (62db6cc4b0818f1b5f3441241b098f12) C:\windows\system32\Drivers\SABI.sys
00:22:30.0706 1552        SABI - ok
00:22:30.0737 1552        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:22:30.0753 1552        SamSs - ok
00:22:30.0784 1552        Samsung UPD Service (d641337b75b9a9d5ae10687aa1097755) C:\windows\System32\SUPDSvc.exe
00:22:30.0784 1552        Samsung UPD Service - ok
00:22:30.0831 1552        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
00:22:30.0831 1552        sbp2port - ok
00:22:30.0862 1552        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
00:22:30.0878 1552        SCardSvr - ok
00:22:30.0893 1552        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
00:22:30.0893 1552        scfilter - ok
00:22:30.0940 1552        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
00:22:30.0956 1552        Schedule - ok
00:22:30.0987 1552        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
00:22:30.0987 1552        SCPolicySvc - ok
00:22:31.0018 1552        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
00:22:31.0018 1552        SDRSVC - ok
00:22:31.0081 1552        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
00:22:31.0081 1552        secdrv - ok
00:22:31.0112 1552        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
00:22:31.0112 1552        seclogon - ok
00:22:31.0127 1552        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\windows\System32\sens.dll
00:22:31.0127 1552        SENS - ok
00:22:31.0159 1552        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
00:22:31.0159 1552        SensrSvc - ok
00:22:31.0190 1552        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\drivers\serenum.sys
00:22:31.0190 1552        Serenum - ok
00:22:31.0205 1552        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\drivers\serial.sys
00:22:31.0205 1552        Serial - ok
00:22:31.0252 1552        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\drivers\sermouse.sys
00:22:31.0252 1552        sermouse - ok
00:22:31.0283 1552        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
00:22:31.0283 1552        SessionEnv - ok
00:22:31.0283 1552        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
00:22:31.0283 1552        sffdisk - ok
00:22:31.0299 1552        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
00:22:31.0299 1552        sffp_mmc - ok
00:22:31.0330 1552        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
00:22:31.0330 1552        sffp_sd - ok
00:22:31.0330 1552        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\drivers\sfloppy.sys
00:22:31.0330 1552        sfloppy - ok
00:22:31.0377 1552        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
00:22:31.0377 1552        SharedAccess - ok
00:22:31.0424 1552        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
00:22:31.0439 1552        ShellHWDetection - ok
00:22:31.0455 1552        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\drivers\SiSRaid2.sys
00:22:31.0455 1552        SiSRaid2 - ok
00:22:31.0486 1552        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\drivers\sisraid4.sys
00:22:31.0486 1552        SiSRaid4 - ok
00:22:31.0517 1552        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
00:22:31.0517 1552        Smb - ok
00:22:31.0564 1552        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
00:22:31.0564 1552        SNMPTRAP - ok
00:22:31.0580 1552        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
00:22:31.0580 1552        spldr - ok
00:22:31.0595 1552        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
00:22:31.0611 1552        Spooler - ok
00:22:31.0705 1552        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
00:22:31.0736 1552        sppsvc - ok
00:22:31.0829 1552        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
00:22:31.0829 1552        sppuinotify - ok
00:22:31.0892 1552        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
00:22:31.0907 1552        srv - ok
00:22:31.0923 1552        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
00:22:31.0923 1552        srv2 - ok
00:22:31.0954 1552        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
00:22:31.0954 1552        srvnet - ok
00:22:32.0001 1552        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
00:22:32.0001 1552        SSDPSRV - ok
00:22:32.0017 1552        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
00:22:32.0032 1552        SstpSvc - ok
00:22:32.0079 1552        ss_bbus        (ef806d212d34b0e173baeb3564d53e37) C:\windows\system32\DRIVERS\ss_bbus.sys
00:22:32.0079 1552        ss_bbus - ok
00:22:32.0157 1552        ss_bmdfl        (08b1b34abebeb6ac2dea06900c56411e) C:\windows\system32\DRIVERS\ss_bmdfl.sys
00:22:32.0157 1552        ss_bmdfl - ok
00:22:32.0188 1552        ss_bmdm        (71a9da6beaa4cb54dfb827fb78600a5d) C:\windows\system32\DRIVERS\ss_bmdm.sys
00:22:32.0204 1552        ss_bmdm - ok
00:22:32.0251 1552        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\drivers\stexstor.sys
00:22:32.0251 1552        stexstor - ok
00:22:32.0282 1552        StillCam        (decacb6921ded1a38642642685d77dac) C:\windows\system32\DRIVERS\serscan.sys
00:22:32.0282 1552        StillCam - ok
00:22:32.0344 1552        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
00:22:32.0344 1552        stisvc - ok
00:22:32.0375 1552        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys
00:22:32.0375 1552        swenum - ok
00:22:32.0407 1552        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
00:22:32.0407 1552        swprv - ok
00:22:32.0453 1552        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
00:22:32.0469 1552        SysMain - ok
00:22:32.0500 1552        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
00:22:32.0500 1552        TabletInputService - ok
00:22:32.0531 1552        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
00:22:32.0531 1552        TapiSrv - ok
00:22:32.0547 1552        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
00:22:32.0547 1552        TBS - ok
00:22:32.0672 1552        Tcpip          (fc62769e7bff2896035aeed399108162) C:\windows\system32\drivers\tcpip.sys
00:22:32.0687 1552        Tcpip - ok
00:22:32.0859 1552        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\windows\system32\DRIVERS\tcpip.sys
00:22:32.0875 1552        TCPIP6 - ok
00:22:32.0984 1552        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
00:22:32.0984 1552        tcpipreg - ok
00:22:32.0999 1552        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
00:22:32.0999 1552        TDPIPE - ok
00:22:33.0046 1552        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
00:22:33.0046 1552        TDTCP - ok
00:22:33.0077 1552        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
00:22:33.0077 1552        tdx - ok
00:22:33.0093 1552        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\DRIVERS\termdd.sys
00:22:33.0093 1552        TermDD - ok
00:22:33.0140 1552        TermService    (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
00:22:33.0155 1552        TermService - ok
00:22:33.0202 1552        TFsExDisk      (48d9d00c2e0e72c3d4f52772c80355f6) C:\windows\System32\Drivers\TFsExDisk.sys
00:22:33.0202 1552        TFsExDisk - ok
00:22:33.0218 1552        Themes          (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
00:22:33.0218 1552        Themes - ok
00:22:33.0249 1552        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
00:22:33.0249 1552        THREADORDER - ok
00:22:33.0265 1552        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
00:22:33.0280 1552        TrkWks - ok
00:22:33.0280 1552        Scan interrupted by user!
00:22:33.0280 1552        Scan interrupted by user!
00:22:33.0280 1552        Scan interrupted by user!
00:22:33.0280 1552        ============================================================
00:22:33.0280 1552        Scan finished
00:22:33.0280 1552        ============================================================
00:22:33.0280 0900        Detected object count: 0
00:22:33.0280 0900        Actual detected object count: 0
00:22:40.0955 1064        ============================================================
00:22:40.0955 1064        Scan started
00:22:40.0955 1064        Mode: Manual; SigCheck; TDLFS;
00:22:40.0955 1064        ============================================================
00:22:41.0158 1064        1394ohci        (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
00:22:41.0221 1064        1394ohci - ok
00:22:41.0236 1064        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
00:22:41.0252 1064        ACPI - ok
00:22:41.0283 1064        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
00:22:41.0314 1064        AcpiPmi - ok
00:22:41.0345 1064        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\drivers\adp94xx.sys
00:22:41.0361 1064        adp94xx - ok
00:22:41.0392 1064        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\drivers\adpahci.sys
00:22:41.0408 1064        adpahci - ok
00:22:41.0423 1064        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\drivers\adpu320.sys
00:22:41.0439 1064        adpu320 - ok
00:22:41.0486 1064        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
00:22:41.0533 1064        AeLookupSvc - ok
00:22:41.0564 1064        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
00:22:41.0611 1064        AFD - ok
00:22:41.0642 1064        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
00:22:41.0657 1064        agp440 - ok
00:22:41.0673 1064        ALG            (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
00:22:41.0704 1064        ALG - ok
00:22:41.0720 1064        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
00:22:41.0735 1064        aliide - ok
00:22:41.0735 1064        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
00:22:41.0751 1064        amdide - ok
00:22:41.0751 1064        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\drivers\amdk8.sys
00:22:41.0798 1064        AmdK8 - ok
00:22:41.0813 1064        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\drivers\amdppm.sys
00:22:41.0829 1064        AmdPPM - ok
00:22:41.0876 1064        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
00:22:41.0876 1064        amdsata - ok
00:22:41.0923 1064        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\drivers\amdsbs.sys
00:22:41.0938 1064        amdsbs - ok
00:22:41.0954 1064        amdxata        (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
00:22:41.0954 1064        amdxata - ok
00:22:42.0016 1064        AntiVirSchedulerService (a122d68ea2541453f787f341877cb40b) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
00:22:42.0032 1064        AntiVirSchedulerService - ok
00:22:42.0063 1064        AntiVirService  (2fe359edeb34efcf42574752f8aebd3f) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
00:22:42.0063 1064        AntiVirService - ok
00:22:42.0094 1064        AppID          (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
00:22:42.0172 1064        AppID - ok
00:22:42.0203 1064        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
00:22:42.0235 1064        AppIDSvc - ok
00:22:42.0266 1064        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
00:22:42.0328 1064        Appinfo - ok
00:22:42.0375 1064        arc            (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\drivers\arc.sys
00:22:42.0391 1064        arc - ok
00:22:42.0406 1064        arcsas          (019af6924aefe7839f61c830227fe79c) C:\windows\system32\drivers\arcsas.sys
00:22:42.0422 1064        arcsas - ok
00:22:42.0437 1064        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
00:22:42.0484 1064        AsyncMac - ok
00:22:42.0500 1064        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
00:22:42.0515 1064        atapi - ok
00:22:42.0578 1064        athr            (de9fb3dade8fd39ae2c587df22d36b8e) C:\windows\system32\DRIVERS\athrx.sys
00:22:42.0625 1064        athr - ok
00:22:42.0718 1064        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
00:22:42.0812 1064        AudioEndpointBuilder - ok
00:22:42.0812 1064        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
00:22:42.0859 1064        AudioSrv - ok
00:22:42.0890 1064        avgntflt        (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\windows\system32\DRIVERS\avgntflt.sys
00:22:42.0905 1064        avgntflt - ok
00:22:42.0921 1064        avipbb          (852e3c0a60d368c487949e55ad52a47f) C:\windows\system32\DRIVERS\avipbb.sys
00:22:42.0937 1064        avipbb - ok
00:22:42.0952 1064        avkmgr          (248db59fc86de44d2779f4c7fb1a567d) C:\windows\system32\DRIVERS\avkmgr.sys
00:22:42.0968 1064        avkmgr - ok
00:22:42.0983 1064        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
00:22:43.0030 1064        AxInstSV - ok
00:22:43.0077 1064        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\windows\system32\drivers\bxvbda.sys
00:22:43.0108 1064        b06bdrv - ok
00:22:43.0124 1064        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
00:22:43.0186 1064        b57nd60a - ok
00:22:43.0217 1064        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
00:22:43.0264 1064        BDESVC - ok
00:22:43.0280 1064        Beep            (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
00:22:43.0342 1064        Beep - ok
00:22:43.0358 1064        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
00:22:43.0420 1064        BFE - ok
00:22:43.0467 1064        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\windows\System32\qmgr.dll
00:22:43.0529 1064        BITS - ok
00:22:43.0592 1064        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
00:22:43.0623 1064        blbdrive - ok
00:22:43.0639 1064        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
00:22:43.0685 1064        bowser - ok
00:22:43.0701 1064        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\drivers\BrFiltLo.sys
00:22:43.0732 1064        BrFiltLo - ok
00:22:43.0732 1064        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\drivers\BrFiltUp.sys
00:22:43.0763 1064        BrFiltUp - ok
00:22:43.0795 1064        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
00:22:43.0888 1064        Browser - ok
00:22:43.0919 1064        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
00:22:43.0935 1064        Brserid - ok
00:22:43.0951 1064        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
00:22:43.0966 1064        BrSerWdm - ok
00:22:43.0982 1064        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
00:22:43.0997 1064        BrUsbMdm - ok
00:22:44.0013 1064        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
00:22:44.0029 1064        BrUsbSer - ok
00:22:44.0044 1064        BtFilter        (9d95f74875491cecbf9e10a5936a570e) C:\windows\system32\DRIVERS\btfilter.sys
00:22:44.0075 1064        BtFilter - ok
00:22:44.0091 1064        BthEnum        (cf98190a94f62e405c8cb255018b2315) C:\windows\system32\drivers\BthEnum.sys
00:22:44.0138 1064        BthEnum - ok
00:22:44.0153 1064        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\drivers\bthmodem.sys
00:22:44.0185 1064        BTHMODEM - ok
00:22:44.0216 1064        BthPan          (02dd601b708dd0667e1331fa8518e9ff) C:\windows\system32\DRIVERS\bthpan.sys
00:22:44.0231 1064        BthPan - ok
00:22:44.0263 1064        BTHPORT        (64c198198501f7560ee41d8d1efa7952) C:\windows\System32\Drivers\BTHport.sys
00:22:44.0294 1064        BTHPORT - ok
00:22:44.0325 1064        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
00:22:44.0356 1064        bthserv - ok
00:22:44.0387 1064        BTHUSB          (f188b7394d81010767b6df3178519a37) C:\windows\System32\Drivers\BTHUSB.sys
00:22:44.0419 1064        BTHUSB - ok
00:22:44.0450 1064        cdfs            (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
00:22:44.0528 1064        cdfs - ok
00:22:44.0543 1064        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\DRIVERS\cdrom.sys
00:22:44.0543 1064        cdrom - ok
00:22:44.0575 1064        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
00:22:44.0621 1064        CertPropSvc - ok
00:22:44.0637 1064        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\drivers\circlass.sys
00:22:44.0653 1064        circlass - ok
00:22:44.0699 1064        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
00:22:44.0731 1064        CLFS - ok
00:22:44.0793 1064        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:22:44.0809 1064        clr_optimization_v2.0.50727_32 - ok
00:22:44.0855 1064        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
00:22:44.0887 1064        clr_optimization_v2.0.50727_64 - ok
00:22:44.0933 1064        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
00:22:44.0965 1064        clr_optimization_v4.0.30319_32 - ok
00:22:44.0996 1064        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
00:22:45.0011 1064        clr_optimization_v4.0.30319_64 - ok
00:22:45.0105 1064        clwvd          (50f92c943f18b070f166d019dfab3d9a) C:\windows\system32\DRIVERS\clwvd.sys
00:22:45.0121 1064        clwvd - ok
00:22:45.0152 1064        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
00:22:45.0183 1064        CmBatt - ok
00:22:45.0214 1064        cmdide          (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
00:22:45.0214 1064        cmdide - ok
00:22:45.0261 1064        CNG            (c4943b6c962e4b82197542447ad599f4) C:\windows\system32\Drivers\cng.sys
00:22:45.0292 1064        CNG - ok
00:22:45.0323 1064        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
00:22:45.0323 1064        Compbatt - ok
00:22:45.0339 1064        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\windows\system32\DRIVERS\CompositeBus.sys
00:22:45.0370 1064        CompositeBus - ok
00:22:45.0386 1064        COMSysApp - ok
00:22:45.0401 1064        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\windows\system32\drivers\crcdisk.sys
00:22:45.0417 1064        crcdisk - ok
00:22:45.0448 1064        CryptSvc        (15597883fbe9b056f276ada3ad87d9af) C:\windows\system32\cryptsvc.dll
00:22:45.0495 1064        CryptSvc - ok
00:22:45.0542 1064        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
00:22:45.0604 1064        DcomLaunch - ok
00:22:45.0651 1064        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
00:22:45.0745 1064        defragsvc - ok
00:22:45.0807 1064        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
00:22:45.0885 1064        DfsC - ok
00:22:45.0916 1064        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
00:22:45.0979 1064        Dhcp - ok
00:22:45.0994 1064        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
00:22:46.0072 1064        discache - ok
00:22:46.0072 1064        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\drivers\disk.sys
00:22:46.0088 1064        Disk - ok
00:22:46.0119 1064        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
00:22:46.0150 1064        Dnscache - ok
00:22:46.0181 1064        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
00:22:46.0275 1064        dot3svc - ok
00:22:46.0291 1064        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
00:22:46.0353 1064        DPS - ok
00:22:46.0415 1064        drmkaud        (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
00:22:46.0462 1064        drmkaud - ok
00:22:46.0509 1064        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
00:22:46.0556 1064        DXGKrnl - ok
00:22:46.0587 1064        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
00:22:46.0634 1064        EapHost - ok
00:22:46.0774 1064        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\drivers\evbda.sys
00:22:46.0837 1064        ebdrv - ok
00:22:46.0930 1064        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
00:22:46.0977 1064        EFS - ok
00:22:47.0039 1064        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
00:22:47.0086 1064        ehRecvr - ok
00:22:47.0102 1064        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
00:22:47.0133 1064        ehSched - ok
00:22:47.0211 1064        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\drivers\elxstor.sys
00:22:47.0227 1064        elxstor - ok
00:22:47.0242 1064        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
00:22:47.0258 1064        ErrDev - ok
00:22:47.0305 1064        ETD            (9d8739a2a2173c9d27c499a3fc6eda3f) C:\windows\system32\DRIVERS\ETD.sys
00:22:47.0336 1064        ETD - ok
00:22:47.0367 1064        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
00:22:47.0445 1064        EventSystem - ok
00:22:47.0461 1064        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
00:22:47.0507 1064        exfat - ok
00:22:47.0523 1064        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
00:22:47.0570 1064        fastfat - ok
00:22:47.0601 1064        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
00:22:47.0632 1064        Fax - ok
00:22:47.0632 1064        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\drivers\fdc.sys
00:22:47.0663 1064        fdc - ok
00:22:47.0679 1064        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
00:22:47.0726 1064        fdPHost - ok
00:22:47.0757 1064        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
00:22:47.0804 1064        FDResPub - ok
00:22:47.0819 1064        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
00:22:47.0835 1064        FileInfo - ok
00:22:47.0851 1064        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
00:22:47.0913 1064        Filetrace - ok
00:22:47.0929 1064        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\drivers\flpydisk.sys
00:22:47.0929 1064        flpydisk - ok
00:22:47.0944 1064        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
00:22:47.0960 1064        FltMgr - ok
00:22:48.0007 1064        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\windows\system32\FntCache.dll
00:22:48.0038 1064        FontCache - ok
00:22:48.0131 1064        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
00:22:48.0147 1064        FontCache3.0.0.0 - ok
00:22:48.0225 1064        FsDepends      (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
00:22:48.0256 1064        FsDepends - ok
00:22:48.0272 1064        Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys
00:22:48.0287 1064        Fs_Rec - ok
00:22:48.0319 1064        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
00:22:48.0334 1064        fvevol - ok
00:22:48.0365 1064        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\drivers\gagp30kx.sys
00:22:48.0365 1064        gagp30kx - ok
00:22:48.0428 1064        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
00:22:48.0490 1064        gpsvc - ok
00:22:48.0506 1064        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
00:22:48.0521 1064        hcw85cir - ok
00:22:48.0537 1064        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
00:22:48.0568 1064        HdAudAddService - ok
00:22:48.0584 1064        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\DRIVERS\HDAudBus.sys
00:22:48.0615 1064        HDAudBus - ok
00:22:48.0631 1064        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\drivers\HidBatt.sys
00:22:48.0662 1064        HidBatt - ok
00:22:48.0662 1064        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\drivers\hidbth.sys
00:22:48.0693 1064        HidBth - ok
00:22:48.0709 1064        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\drivers\hidir.sys
00:22:48.0724 1064        HidIr - ok
00:22:48.0740 1064        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\windows\system32\hidserv.dll
00:22:48.0818 1064        hidserv - ok
00:22:48.0849 1064        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\DRIVERS\hidusb.sys
00:22:48.0865 1064        HidUsb - ok
00:22:48.0880 1064        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
00:22:48.0927 1064        hkmsvc - ok
00:22:48.0943 1064        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
00:22:48.0958 1064        HomeGroupListener - ok
00:22:49.0005 1064        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
00:22:49.0021 1064        HomeGroupProvider - ok
00:22:49.0036 1064        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
00:22:49.0052 1064        HpSAMD - ok
00:22:49.0083 1064        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
00:22:49.0130 1064        HTTP - ok
00:22:49.0145 1064        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
00:22:49.0161 1064        hwpolicy - ok
00:22:49.0161 1064        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys
00:22:49.0177 1064        i8042prt - ok
00:22:49.0208 1064        iaStor          (53cc5bf8b5a219119953c7abb19a7705) C:\windows\system32\DRIVERS\iaStor.sys
00:22:49.0223 1064        iaStor - ok
00:22:49.0270 1064        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
00:22:49.0270 1064        iaStorV - ok
00:22:49.0364 1064        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
00:22:49.0411 1064        idsvc - ok
00:22:49.0567 1064        igfx            (a87261ef1546325b559374f5689cf5bc) C:\windows\system32\DRIVERS\igdkmd64.sys
00:22:49.0645 1064        igfx - ok
00:22:49.0754 1064        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\drivers\iirsp.sys
00:22:49.0769 1064        iirsp - ok
00:22:49.0816 1064        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
00:22:49.0879 1064        IKEEXT - ok
00:22:50.0003 1064        IntcAzAudAddService (65f70696be5abc11634fcf96af7d7896) C:\windows\system32\drivers\RTKVHD64.sys
00:22:50.0050 1064        IntcAzAudAddService - ok
00:22:50.0159 1064        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
00:22:50.0175 1064        intelide - ok
00:22:50.0191 1064        intelppm        (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
00:22:50.0222 1064        intelppm - ok
00:22:50.0269 1064        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
00:22:50.0331 1064        IPBusEnum - ok
00:22:50.0347 1064        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
00:22:50.0378 1064        IpFilterDriver - ok
00:22:50.0409 1064        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
00:22:50.0471 1064        iphlpsvc - ok
00:22:50.0471 1064        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
00:22:50.0487 1064        IPMIDRV - ok
00:22:50.0487 1064        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
00:22:50.0534 1064        IPNAT - ok
00:22:50.0549 1064        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
00:22:50.0581 1064        IRENUM - ok
00:22:50.0596 1064        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
00:22:50.0596 1064        isapnp - ok
00:22:50.0627 1064        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
00:22:50.0643 1064        iScsiPrt - ok
00:22:50.0659 1064        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys
00:22:50.0674 1064        kbdclass - ok
00:22:50.0690 1064        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\DRIVERS\kbdhid.sys
00:22:50.0705 1064        kbdhid - ok
00:22:50.0737 1064        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:22:50.0752 1064        KeyIso - ok
00:22:50.0783 1064        KMWDFILTER      (07071c1e3cd8f0f9114aac8b072ca1e5) C:\windows\system32\DRIVERS\KMWDFILTER.sys
00:22:50.0783 1064        KMWDFILTER - ok
00:22:50.0815 1064        KSecDD          (da1e991a61cfdd755a589e206b97644b) C:\windows\system32\Drivers\ksecdd.sys
00:22:50.0815 1064        KSecDD - ok
00:22:50.0846 1064        KSecPkg        (7e33198d956943a4f11a5474c1e9106f) C:\windows\system32\Drivers\ksecpkg.sys
00:22:50.0846 1064        KSecPkg - ok
00:22:50.0861 1064        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
00:22:50.0924 1064        ksthunk - ok
00:22:50.0955 1064        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
00:22:51.0002 1064        KtmRm - ok
00:22:51.0033 1064        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\system32\srvsvc.dll
00:22:51.0095 1064        LanmanServer - ok
00:22:51.0111 1064        LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
00:22:51.0158 1064        LanmanWorkstation - ok
00:22:51.0283 1064        Lavasoft Ad-Aware Service (ea38136981c61c571d52c380daad46ef) C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
00:22:51.0329 1064        Lavasoft Ad-Aware Service - ok
00:22:51.0392 1064        Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys
00:22:51.0407 1064        Lavasoft Kernexplorer - ok
00:22:51.0501 1064        Lbd            (c8b3131857931ae76798a741cc52b021) C:\windows\system32\DRIVERS\Lbd.sys
00:22:51.0517 1064        Lbd - ok
00:22:51.0548 1064        lltdio          (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
00:22:51.0626 1064        lltdio - ok
00:22:51.0657 1064        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
00:22:51.0704 1064        lltdsvc - ok
00:22:51.0735 1064        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
00:22:51.0782 1064        lmhosts - ok
00:22:51.0860 1064        LMS            (2ed1786b7542cda261029f6b526edf44) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
00:22:51.0875 1064        LMS - ok
00:22:51.0953 1064        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\drivers\lsi_fc.sys
00:22:51.0969 1064        LSI_FC - ok
00:22:52.0000 1064        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\drivers\lsi_sas.sys
00:22:52.0000 1064        LSI_SAS - ok
00:22:52.0031 1064        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\drivers\lsi_sas2.sys
00:22:52.0031 1064        LSI_SAS2 - ok
00:22:52.0047 1064        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\drivers\lsi_scsi.sys
00:22:52.0063 1064        LSI_SCSI - ok
00:22:52.0094 1064        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
00:22:52.0187 1064        luafv - ok
00:22:52.0203 1064        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
00:22:52.0265 1064        Mcx2Svc - ok
00:22:52.0281 1064        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\drivers\megasas.sys
00:22:52.0297 1064        megasas - ok
00:22:52.0312 1064        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\drivers\MegaSR.sys
00:22:52.0328 1064        MegaSR - ok
00:22:52.0359 1064        MEIx64          (a6518dcc42f7a6e999bb3bea8fd87567) C:\windows\system32\DRIVERS\HECIx64.sys
00:22:52.0375 1064        MEIx64 - ok
00:22:52.0406 1064        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
00:22:52.0453 1064        MMCSS - ok
00:22:52.0468 1064        Modem          (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
00:22:52.0515 1064        Modem - ok
00:22:52.0531 1064        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
00:22:52.0546 1064        monitor - ok
00:22:52.0562 1064        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
00:22:52.0577 1064        mouclass - ok
00:22:52.0609 1064        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
00:22:52.0640 1064        mouhid - ok
00:22:52.0640 1064        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
00:22:52.0655 1064        mountmgr - ok
00:22:52.0671 1064        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
00:22:52.0671 1064        mpio - ok
00:22:52.0687 1064        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
00:22:52.0733 1064        mpsdrv - ok
00:22:52.0780 1064        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\windows\system32\mpssvc.dll
00:22:52.0827 1064        MpsSvc - ok
00:22:52.0858 1064        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
00:22:52.0889 1064        MRxDAV - ok
00:22:52.0905 1064        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
00:22:52.0936 1064        mrxsmb - ok
00:22:52.0967 1064        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
00:22:52.0999 1064        mrxsmb10 - ok
00:22:53.0014 1064        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
00:22:53.0030 1064        mrxsmb20 - ok
00:22:53.0045 1064        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
00:22:53.0061 1064        msahci - ok
00:22:53.0077 1064        msdsm          (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
00:22:53.0092 1064        msdsm - ok
00:22:53.0123 1064        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
00:22:53.0155 1064        MSDTC - ok
00:22:53.0170 1064        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
00:22:53.0217 1064        Msfs - ok
00:22:53.0233 1064        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
00:22:53.0295 1064        mshidkmdf - ok
00:22:53.0311 1064        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
00:22:53.0311 1064        msisadrv - ok
00:22:53.0342 1064        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
00:22:53.0373 1064        MSiSCSI - ok
00:22:53.0389 1064        msiserver - ok
00:22:53.0404 1064        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
00:22:53.0451 1064        MSKSSRV - ok
00:22:53.0467 1064        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
00:22:53.0513 1064        MSPCLOCK - ok
00:22:53.0529 1064        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
00:22:53.0576 1064        MSPQM - ok
00:22:53.0607 1064        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys


Vintage 08.04.2012 23:29

2.
Code:

00:22:53.0607 1064        MsRPC - ok
00:22:53.0638 1064        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys
00:22:53.0654 1064        mssmbios - ok
00:22:53.0669 1064        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
00:22:53.0716 1064        MSTEE - ok
00:22:53.0732 1064        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\drivers\MTConfig.sys
00:22:53.0763 1064        MTConfig - ok
00:22:53.0763 1064        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
00:22:53.0779 1064        Mup - ok
00:22:53.0810 1064        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
00:22:53.0857 1064        napagent - ok
00:22:53.0888 1064        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
00:22:53.0919 1064        NativeWifiP - ok
00:22:53.0997 1064        NDIS            (c38b8ae57f78915905064a9a24dc1586) C:\windows\system32\drivers\ndis.sys
00:22:54.0028 1064        NDIS - ok
00:22:54.0059 1064        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
00:22:54.0106 1064        NdisCap - ok
00:22:54.0122 1064        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
00:22:54.0184 1064        NdisTapi - ok
00:22:54.0200 1064        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
00:22:54.0262 1064        Ndisuio - ok
00:22:54.0293 1064        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
00:22:54.0340 1064        NdisWan - ok
00:22:54.0340 1064        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
00:22:54.0387 1064        NDProxy - ok
00:22:54.0403 1064        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
00:22:54.0449 1064        NetBIOS - ok
00:22:54.0465 1064        NetBT          (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
00:22:54.0512 1064        NetBT - ok
00:22:54.0543 1064        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:22:54.0559 1064        Netlogon - ok
00:22:54.0605 1064        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
00:22:54.0652 1064        Netman - ok
00:22:54.0668 1064        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
00:22:54.0715 1064        netprofm - ok
00:22:54.0808 1064        NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
00:22:54.0808 1064        NetTcpPortSharing - ok
00:22:54.0871 1064        nfrd960        (77889813be4d166cdab78ddba990da92) C:\windows\system32\drivers\nfrd960.sys
00:22:54.0886 1064        nfrd960 - ok
00:22:54.0933 1064        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
00:22:54.0995 1064        NlaSvc - ok
00:22:55.0011 1064        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
00:22:55.0042 1064        Npfs - ok
00:22:55.0058 1064        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
00:22:55.0105 1064        nsi - ok
00:22:55.0136 1064        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
00:22:55.0167 1064        nsiproxy - ok
00:22:55.0245 1064        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
00:22:55.0276 1064        Ntfs - ok
00:22:55.0307 1064        Null            (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
00:22:55.0354 1064        Null - ok
00:22:55.0385 1064        NVHDA          (f2662fdc20518ee8a8eed4f61ba42349) C:\windows\system32\drivers\nvhda64v.sys
00:22:55.0401 1064        NVHDA - ok
00:22:55.0697 1064        nvlddmkm        (e4c35efde340f3a18123ae85104b2b82) C:\windows\system32\DRIVERS\nvlddmkm.sys
00:22:55.0916 1064        nvlddmkm - ok
00:22:56.0009 1064        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
00:22:56.0041 1064        nvraid - ok
00:22:56.0072 1064        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
00:22:56.0087 1064        nvstor - ok
00:22:56.0134 1064        NVSvc          (7e4d066d8be847723807ef161b78bf07) C:\windows\system32\nvvsvc.exe
00:22:56.0150 1064        NVSvc - ok
00:22:56.0212 1064        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
00:22:56.0243 1064        nv_agp - ok
00:22:56.0259 1064        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
00:22:56.0306 1064        ohci1394 - ok
00:22:56.0368 1064        ose            (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
00:22:56.0399 1064        ose - ok
00:22:56.0555 1064        osppsvc        (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
00:22:56.0633 1064        osppsvc - ok
00:22:56.0727 1064        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
00:22:56.0758 1064        p2pimsvc - ok
00:22:56.0789 1064        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
00:22:56.0821 1064        p2psvc - ok
00:22:56.0867 1064        Parport        (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\drivers\parport.sys
00:22:56.0883 1064        Parport - ok
00:22:56.0899 1064        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\windows\system32\drivers\partmgr.sys
00:22:56.0914 1064        partmgr - ok
00:22:56.0945 1064        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
00:22:56.0977 1064        PcaSvc - ok
00:22:56.0977 1064        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
00:22:56.0992 1064        pci - ok
00:22:57.0008 1064        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
00:22:57.0008 1064        pciide - ok
00:22:57.0039 1064        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\drivers\pcmcia.sys
00:22:57.0039 1064        pcmcia - ok
00:22:57.0055 1064        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
00:22:57.0055 1064        pcw - ok
00:22:57.0101 1064        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
00:22:57.0148 1064        PEAUTH - ok
00:22:57.0211 1064        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
00:22:57.0257 1064        PerfHost - ok
00:22:57.0320 1064        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
00:22:57.0382 1064        pla - ok
00:22:57.0476 1064        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
00:22:57.0523 1064        PlugPlay - ok
00:22:57.0538 1064        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
00:22:57.0569 1064        PNRPAutoReg - ok
00:22:57.0601 1064        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
00:22:57.0632 1064        PNRPsvc - ok
00:22:57.0663 1064        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
00:22:57.0725 1064        PolicyAgent - ok
00:22:57.0757 1064        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
00:22:57.0819 1064        Power - ok
00:22:57.0881 1064        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
00:22:57.0928 1064        PptpMiniport - ok
00:22:57.0959 1064        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\drivers\processr.sys
00:22:57.0975 1064        Processor - ok
00:22:58.0006 1064        ProfSvc        (5c78838b4d166d1a27db3a8a820c799a) C:\windows\system32\profsvc.dll
00:22:58.0069 1064        ProfSvc - ok
00:22:58.0100 1064        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:22:58.0100 1064        ProtectedStorage - ok
00:22:58.0115 1064        Psched          (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
00:22:58.0178 1064        Psched - ok
00:22:58.0209 1064        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\drivers\ql2300.sys
00:22:58.0256 1064        ql2300 - ok
00:22:58.0271 1064        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\drivers\ql40xx.sys
00:22:58.0287 1064        ql40xx - ok
00:22:58.0303 1064        QWAVE          (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
00:22:58.0334 1064        QWAVE - ok
00:22:58.0349 1064        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
00:22:58.0365 1064        QWAVEdrv - ok
00:22:58.0381 1064        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
00:22:58.0412 1064        RasAcd - ok
00:22:58.0443 1064        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
00:22:58.0521 1064        RasAgileVpn - ok
00:22:58.0537 1064        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
00:22:58.0583 1064        RasAuto - ok
00:22:58.0599 1064        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
00:22:58.0646 1064        Rasl2tp - ok
00:22:58.0661 1064        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
00:22:58.0708 1064        RasMan - ok
00:22:58.0708 1064        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
00:22:58.0755 1064        RasPppoe - ok
00:22:58.0771 1064        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
00:22:58.0802 1064        RasSstp - ok
00:22:58.0833 1064        rdbss          (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
00:22:58.0880 1064        rdbss - ok
00:22:58.0895 1064        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\drivers\rdpbus.sys
00:22:58.0911 1064        rdpbus - ok
00:22:58.0927 1064        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
00:22:58.0973 1064        RDPCDD - ok
00:22:58.0989 1064        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
00:22:59.0036 1064        RDPENCDD - ok
00:22:59.0051 1064        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
00:22:59.0098 1064        RDPREFMP - ok
00:22:59.0129 1064        RDPWD          (6d76e6433574b058adcb0c50df834492) C:\windows\system32\drivers\RDPWD.sys
00:22:59.0145 1064        RDPWD - ok
00:22:59.0176 1064        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
00:22:59.0176 1064        rdyboost - ok
00:22:59.0207 1064        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
00:22:59.0285 1064        RemoteAccess - ok
00:22:59.0317 1064        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
00:22:59.0363 1064        RemoteRegistry - ok
00:22:59.0410 1064        RFCOMM          (3dd798846e2c28102b922c56e71b7932) C:\windows\system32\DRIVERS\rfcomm.sys
00:22:59.0441 1064        RFCOMM - ok
00:22:59.0551 1064        RichVideo      (f12a68ed55053940cadd59ca5e3468dd) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
00:22:59.0566 1064        RichVideo - ok
00:22:59.0597 1064        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
00:22:59.0644 1064        RpcEptMapper - ok
00:22:59.0675 1064        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
00:22:59.0707 1064        RpcLocator - ok
00:22:59.0738 1064        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
00:22:59.0785 1064        RpcSs - ok
00:22:59.0831 1064        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
00:22:59.0909 1064        rspndr - ok
00:22:59.0956 1064        RTL8167        (ea5532868ba76923d75bcb2a1448d810) C:\windows\system32\DRIVERS\Rt64win7.sys
00:22:59.0972 1064        RTL8167 - ok
00:23:00.0034 1064        rtport          (4ca0dba9e224473d664c25e411f5a3bd) C:\windows\SysWOW64\drivers\rtport.sys
00:23:00.0050 1064        rtport - ok
00:23:00.0081 1064        SABI            (62db6cc4b0818f1b5f3441241b098f12) C:\windows\system32\Drivers\SABI.sys
00:23:00.0112 1064        SABI - ok
00:23:00.0143 1064        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:23:00.0175 1064        SamSs - ok
00:23:00.0206 1064        Samsung UPD Service (d641337b75b9a9d5ae10687aa1097755) C:\windows\System32\SUPDSvc.exe
00:23:00.0221 1064        Samsung UPD Service - ok
00:23:00.0253 1064        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
00:23:00.0268 1064        sbp2port - ok
00:23:00.0299 1064        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
00:23:00.0362 1064        SCardSvr - ok
00:23:00.0377 1064        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
00:23:00.0424 1064        scfilter - ok
00:23:00.0455 1064        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
00:23:00.0518 1064        Schedule - ok
00:23:00.0549 1064        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
00:23:00.0611 1064        SCPolicySvc - ok
00:23:00.0658 1064        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
00:23:00.0689 1064        SDRSVC - ok
00:23:00.0736 1064        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
00:23:00.0814 1064        secdrv - ok
00:23:00.0830 1064        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
00:23:00.0877 1064        seclogon - ok
00:23:00.0908 1064        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\windows\System32\sens.dll
00:23:00.0955 1064        SENS - ok
00:23:00.0986 1064        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
00:23:01.0001 1064        SensrSvc - ok
00:23:01.0064 1064        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\drivers\serenum.sys
00:23:01.0095 1064        Serenum - ok
00:23:01.0126 1064        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\drivers\serial.sys
00:23:01.0157 1064        Serial - ok
00:23:01.0189 1064        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\drivers\sermouse.sys
00:23:01.0204 1064        sermouse - ok
00:23:01.0235 1064        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
00:23:01.0282 1064        SessionEnv - ok
00:23:01.0298 1064        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
00:23:01.0313 1064        sffdisk - ok
00:23:01.0313 1064        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
00:23:01.0345 1064        sffp_mmc - ok
00:23:01.0345 1064        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
00:23:01.0360 1064        sffp_sd - ok
00:23:01.0376 1064        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\drivers\sfloppy.sys
00:23:01.0407 1064        sfloppy - ok
00:23:01.0423 1064        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
00:23:01.0485 1064        SharedAccess - ok
00:23:01.0532 1064        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
00:23:01.0594 1064        ShellHWDetection - ok
00:23:01.0610 1064        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\drivers\SiSRaid2.sys
00:23:01.0610 1064        SiSRaid2 - ok
00:23:01.0625 1064        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\drivers\sisraid4.sys
00:23:01.0641 1064        SiSRaid4 - ok
00:23:01.0657 1064        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
00:23:01.0703 1064        Smb - ok
00:23:01.0719 1064        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
00:23:01.0750 1064        SNMPTRAP - ok
00:23:01.0844 1064        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
00:23:01.0859 1064        spldr - ok
00:23:01.0937 1064        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
00:23:02.0000 1064        Spooler - ok
00:23:02.0187 1064        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
00:23:02.0265 1064        sppsvc - ok
00:23:02.0421 1064        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
00:23:02.0499 1064        sppuinotify - ok
00:23:02.0561 1064        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
00:23:02.0608 1064        srv - ok
00:23:02.0624 1064        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
00:23:02.0671 1064        srv2 - ok
00:23:02.0702 1064        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
00:23:02.0733 1064        srvnet - ok
00:23:02.0764 1064        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
00:23:02.0827 1064        SSDPSRV - ok
00:23:02.0842 1064        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
00:23:02.0889 1064        SstpSvc - ok
00:23:02.0920 1064        ss_bbus        (ef806d212d34b0e173baeb3564d53e37) C:\windows\system32\DRIVERS\ss_bbus.sys
00:23:02.0920 1064        ss_bbus - ok
00:23:02.0951 1064        ss_bmdfl        (08b1b34abebeb6ac2dea06900c56411e) C:\windows\system32\DRIVERS\ss_bmdfl.sys
00:23:02.0951 1064        ss_bmdfl - ok
00:23:02.0983 1064        ss_bmdm        (71a9da6beaa4cb54dfb827fb78600a5d) C:\windows\system32\DRIVERS\ss_bmdm.sys
00:23:02.0998 1064        ss_bmdm - ok
00:23:03.0029 1064        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\drivers\stexstor.sys
00:23:03.0029 1064        stexstor - ok
00:23:03.0061 1064        StillCam        (decacb6921ded1a38642642685d77dac) C:\windows\system32\DRIVERS\serscan.sys
00:23:03.0061 1064        StillCam - ok
00:23:03.0107 1064        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
00:23:03.0154 1064        stisvc - ok
00:23:03.0170 1064        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys
00:23:03.0185 1064        swenum - ok
00:23:03.0232 1064        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
00:23:03.0279 1064        swprv - ok
00:23:03.0341 1064        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
00:23:03.0388 1064        SysMain - ok
00:23:03.0419 1064        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
00:23:03.0466 1064        TabletInputService - ok
00:23:03.0482 1064        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
00:23:03.0529 1064        TapiSrv - ok
00:23:03.0544 1064        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
00:23:03.0591 1064        TBS - ok
00:23:03.0685 1064        Tcpip          (fc62769e7bff2896035aeed399108162) C:\windows\system32\drivers\tcpip.sys
00:23:03.0731 1064        Tcpip - ok
00:23:03.0872 1064        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\windows\system32\DRIVERS\tcpip.sys
00:23:03.0919 1064        TCPIP6 - ok
00:23:03.0997 1064        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
00:23:04.0059 1064        tcpipreg - ok
00:23:04.0075 1064        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
00:23:04.0090 1064        TDPIPE - ok
00:23:04.0121 1064        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
00:23:04.0137 1064        TDTCP - ok
00:23:04.0153 1064        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
00:23:04.0199 1064        tdx - ok
00:23:04.0215 1064        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\DRIVERS\termdd.sys
00:23:04.0215 1064        TermDD - ok
00:23:04.0262 1064        TermService    (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
00:23:04.0355 1064        TermService - ok
00:23:04.0387 1064        TFsExDisk      (48d9d00c2e0e72c3d4f52772c80355f6) C:\windows\System32\Drivers\TFsExDisk.sys
00:23:04.0387 1064        TFsExDisk - ok
00:23:04.0418 1064        Themes          (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
00:23:04.0449 1064        Themes - ok
00:23:04.0480 1064        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
00:23:04.0511 1064        THREADORDER - ok
00:23:04.0543 1064        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
00:23:04.0605 1064        TrkWks - ok
00:23:04.0652 1064        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\windows\servicing\TrustedInstaller.exe
00:23:04.0714 1064        TrustedInstaller - ok
00:23:04.0745 1064        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
00:23:04.0808 1064        tssecsrv - ok
00:23:04.0823 1064        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
00:23:04.0839 1064        TsUsbFlt - ok
00:23:04.0839 1064        TsUsbGD        (9cc2ccae8a84820eaecb886d477cbcb8) C:\windows\system32\drivers\TsUsbGD.sys
00:23:04.0855 1064        TsUsbGD - ok
00:23:04.0886 1064        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
00:23:04.0917 1064        tunnel - ok
00:23:04.0948 1064        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\drivers\uagp35.sys
00:23:04.0948 1064        uagp35 - ok
00:23:04.0979 1064        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
00:23:05.0042 1064        udfs - ok
00:23:05.0057 1064        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\windows\system32\UI0Detect.exe
00:23:05.0073 1064        UI0Detect - ok
00:23:05.0104 1064        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
00:23:05.0104 1064        uliagpkx - ok
00:23:05.0120 1064        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\DRIVERS\umbus.sys
00:23:05.0135 1064        umbus - ok
00:23:05.0167 1064        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\drivers\umpass.sys
00:23:05.0198 1064        UmPass - ok
00:23:05.0338 1064        UNS            (7e5e1603d0ff2d240ae70295c5c3fefc) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
00:23:05.0385 1064        UNS - ok
00:23:05.0479 1064        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\windows\System32\upnphost.dll
00:23:05.0525 1064        upnphost - ok
00:23:05.0557 1064        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
00:23:05.0588 1064        usbccgp - ok
00:23:05.0635 1064        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
00:23:05.0681 1064        usbcir - ok
00:23:05.0713 1064        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\drivers\usbehci.sys
00:23:05.0728 1064        usbehci - ok
00:23:05.0775 1064        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\DRIVERS\usbhub.sys
00:23:05.0806 1064        usbhub - ok
00:23:05.0837 1064        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
00:23:05.0884 1064        usbohci - ok
00:23:05.0915 1064        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys
00:23:05.0947 1064        usbprint - ok
00:23:05.0978 1064        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys
00:23:05.0993 1064        usbscan - ok
00:23:06.0009 1064        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
00:23:06.0040 1064        USBSTOR - ok
00:23:06.0071 1064        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
00:23:06.0103 1064        usbuhci - ok
00:23:06.0149 1064        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\windows\system32\Drivers\usbvideo.sys
00:23:06.0181 1064        usbvideo - ok
00:23:06.0212 1064        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\windows\System32\uxsms.dll
00:23:06.0274 1064        UxSms - ok
00:23:06.0305 1064        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
00:23:06.0337 1064        VaultSvc - ok
00:23:06.0399 1064        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
00:23:06.0430 1064        vdrvroot - ok
00:23:06.0461 1064        vds            (8d6b481601d01a456e75c3210f1830be) C:\windows\System32\vds.exe
00:23:06.0508 1064        vds - ok
00:23:06.0524 1064        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
00:23:06.0539 1064        vga - ok
00:23:06.0571 1064        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
00:23:06.0617 1064        VgaSave - ok
00:23:06.0649 1064        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
00:23:06.0649 1064        vhdmp - ok
00:23:06.0680 1064        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
00:23:06.0680 1064        viaide - ok
00:23:06.0711 1064        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
00:23:06.0711 1064        volmgr - ok
00:23:06.0727 1064        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
00:23:06.0742 1064        volmgrx - ok
00:23:06.0773 1064        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\windows\system32\drivers\volsnap.sys
00:23:06.0789 1064        volsnap - ok
00:23:06.0805 1064        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\drivers\vsmraid.sys
00:23:06.0820 1064        vsmraid - ok
00:23:06.0883 1064        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\windows\system32\vssvc.exe
00:23:06.0961 1064        VSS - ok
00:23:07.0039 1064        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
00:23:07.0054 1064        vwifibus - ok
00:23:07.0101 1064        vwififlt        (13a0decd1794de60a8427862c8669d27) C:\windows\system32\DRIVERS\vwififlt.sys
00:23:07.0117 1064        vwififlt - ok
00:23:07.0179 1064        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\windows\system32\w32time.dll
00:23:07.0241 1064        W32Time - ok
00:23:07.0273 1064        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\drivers\wacompen.sys
00:23:07.0319 1064        WacomPen - ok
00:23:07.0351 1064        WANARP          (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
00:23:07.0397 1064        WANARP - ok
00:23:07.0397 1064        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
00:23:07.0444 1064        Wanarpv6 - ok
00:23:07.0507 1064        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\windows\system32\wbengine.exe
00:23:07.0553 1064        wbengine - ok
00:23:07.0569 1064        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\windows\System32\wbiosrvc.dll
00:23:07.0600 1064        WbioSrvc - ok
00:23:07.0616 1064        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\windows\System32\wcncsvc.dll
00:23:07.0663 1064        wcncsvc - ok
00:23:07.0694 1064        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\windows\System32\WcsPlugInService.dll
00:23:07.0709 1064        WcsPlugInService - ok
00:23:07.0756 1064        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\drivers\wd.sys
00:23:07.0772 1064        Wd - ok
00:23:07.0803 1064        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
00:23:07.0819 1064        Wdf01000 - ok
00:23:07.0850 1064        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
00:23:07.0897 1064        WdiServiceHost - ok
00:23:07.0897 1064        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
00:23:07.0912 1064        WdiSystemHost - ok
00:23:07.0959 1064        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\windows\System32\webclnt.dll
00:23:07.0975 1064        WebClient - ok
00:23:08.0021 1064        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\windows\system32\wecsvc.dll
00:23:08.0068 1064        Wecsvc - ok
00:23:08.0084 1064        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\windows\System32\wercplsupport.dll
00:23:08.0131 1064        wercplsupport - ok
00:23:08.0162 1064        WerSvc          (6d137963730144698cbd10f202e9f251) C:\windows\System32\WerSvc.dll
00:23:08.0193 1064        WerSvc - ok
00:23:08.0271 1064        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
00:23:08.0318 1064        WfpLwf - ok
00:23:08.0333 1064        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
00:23:08.0349 1064        WIMMount - ok
00:23:08.0396 1064        WinDefend - ok
00:23:08.0396 1064        WinHttpAutoProxySvc - ok
00:23:08.0458 1064        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\windows\system32\wbem\WMIsvc.dll
00:23:08.0536 1064        Winmgmt - ok
00:23:08.0630 1064        WinRM          (bcb1310604aa415c4508708975b3931e) C:\windows\system32\WsmSvc.dll
00:23:08.0708 1064        WinRM - ok
00:23:08.0833 1064        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\windows\system32\DRIVERS\WinUsb.sys
00:23:08.0879 1064        WinUsb - ok
00:23:08.0926 1064        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\windows\System32\wlansvc.dll
00:23:08.0973 1064        Wlansvc - ok
00:23:09.0035 1064        wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
00:23:09.0051 1064        wlcrasvc - ok
00:23:09.0191 1064        wlidsvc        (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
00:23:09.0238 1064        wlidsvc - ok
00:23:09.0332 1064        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\drivers\wmiacpi.sys
00:23:09.0379 1064        WmiAcpi - ok
00:23:09.0441 1064        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\windows\system32\wbem\WmiApSrv.exe
00:23:09.0472 1064        wmiApSrv - ok
00:23:09.0535 1064        WMPNetworkSvc - ok
00:23:09.0566 1064        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\windows\System32\wpcsvc.dll
00:23:09.0597 1064        WPCSvc - ok
00:23:09.0613 1064        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\windows\system32\wpdbusenum.dll
00:23:09.0644 1064        WPDBusEnum - ok
00:23:09.0691 1064        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
00:23:09.0753 1064        ws2ifsl - ok
00:23:09.0769 1064        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\windows\System32\wscsvc.dll
00:23:09.0815 1064        wscsvc - ok
00:23:09.0831 1064        WSearch - ok
00:23:09.0925 1064        wuauserv        (9df12edbc698b0bc353b3ef84861e430) C:\windows\system32\wuaueng.dll
00:23:10.0003 1064        wuauserv - ok
00:23:10.0112 1064        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
00:23:10.0159 1064        WudfPf - ok
00:23:10.0190 1064        WUDFRd          (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
00:23:10.0237 1064        WUDFRd - ok
00:23:10.0268 1064        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\windows\System32\WUDFSvc.dll
00:23:10.0299 1064        wudfsvc - ok
00:23:10.0315 1064        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\windows\System32\wwansvc.dll
00:23:10.0346 1064        WwanSvc - ok
00:23:10.0393 1064        MBR (0x1B8)    (2e5debb2116b3417023e0d6562d7ed07) \Device\Harddisk0\DR0
00:23:10.0705 1064        \Device\Harddisk0\DR0 - ok
00:23:10.0720 1064        Boot (0x1200)  (fd9f4ebd5e220402b70fee7fbd492011) \Device\Harddisk0\DR0\Partition0
00:23:10.0720 1064        \Device\Harddisk0\DR0\Partition0 - ok
00:23:10.0751 1064        Boot (0x1200)  (34ef4fa741fe4bb0370400145d255672) \Device\Harddisk0\DR0\Partition1
00:23:10.0751 1064        \Device\Harddisk0\DR0\Partition1 - ok
00:23:10.0783 1064        Boot (0x1200)  (ed83f6c2d02d088071f70cbba2525440) \Device\Harddisk0\DR0\Partition2
00:23:10.0783 1064        \Device\Harddisk0\DR0\Partition2 - ok
00:23:10.0783 1064        ============================================================
00:23:10.0783 1064        Scan finished
00:23:10.0783 1064        ============================================================
00:23:10.0798 0456        Detected object count: 0
00:23:10.0798 0456        Actual detected object count: 0
00:26:38.0805 3244        Deinitialize success


cosinus 09.04.2012 15:25

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Vintage 09.04.2012 16:00

Code:

ComboFix 12-04-09.04 - Melina 09.04.2012  16:47:46.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.6124.4460 [GMT 2:00]
ausgeführt von:: C:\Users\Melina\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Lavasoft Ad-Watch Live! Virenschutz *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


(((((((((((((((((((((((  Dateien erstellt von 2012-03-09 bis 2012-04-09  ))))))))))))))))))))))))))))))


2012-04-09 14:55:01 . 2012-04-09 14:55:01        --------        d-----w-        C:\Users\Default\AppData\Local\temp
2012-04-08 20:23:49 . 2012-04-08 20:23:49        --------        d-----w-        C:\_OTL
2012-04-08 16:21:03 . 2012-04-08 16:21:03        --------        d-----w-        C:\Program Files (x86)\ESET
2012-04-06 09:01:03 . 2012-03-14 03:27:40        8669240        ----a-w-        C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A17D29F2-0125-4BFE-BA7A-21F06E2D5F75}\mpengine.dll
2012-04-04 17:00:22 . 2012-04-04 17:00:22        --------        d-----w-        C:\Users\Melina\AppData\Roaming\Malwarebytes
2012-04-04 17:00:07 . 2012-04-04 17:00:07        --------        d-----w-        C:\ProgramData\Malwarebytes
2012-04-04 17:00:06 . 2012-04-04 17:00:10        --------        d-----w-        C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-04-04 17:00:06 . 2011-12-10 13:24:08        23152        ----a-w-        C:\windows\system32\drivers\mbam.sys
2012-04-01 21:17:58 . 2012-04-02 08:23:42        --------        d-----w-        C:\Users\Melina\AppData\Roaming\Dropbox
2012-03-30 12:30:22 . 2012-03-30 12:30:22        --------        d-----w-        C:\Program Files (x86)\MSXML 4.0
2012-03-29 13:08:14 . 2010-04-27 02:25:16        18944        ----a-w-        C:\windows\system32\drivers\ss_bmdfl.sys
2012-03-26 22:29:03 . 2012-03-26 22:29:03        --------        d-----w-        C:\Users\Melina\AppData\Local\Diagnostics
2012-03-16 17:12:44 . 2012-03-29 12:45:17        --------        d-----w-        C:\windows\SysWow64\Samsung_USB_Drivers
2012-03-14 22:29:53 . 2011-11-19 15:20:37        5559152        ----a-w-        C:\windows\system32\ntoskrnl.exe
2012-03-14 22:29:52 . 2011-11-19 14:50:02        3968368        ----a-w-        C:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 22:29:51 . 2011-11-19 14:50:02        3913584        ----a-w-        C:\windows\SysWow64\ntoskrnl.exe
2012-03-14 05:43:44 . 2012-02-03 04:34:34        3145728        ----a-w-        C:\windows\system32\win32k.sys
2012-03-14 05:43:43 . 2012-02-10 06:36:07        1544192        ----a-w-        C:\windows\system32\DWrite.dll
2012-03-14 05:43:43 . 2012-02-10 05:38:43        1077248        ----a-w-        C:\windows\SysWow64\DWrite.dll
2012-03-14 05:43:24 . 2012-01-25 06:38:39        77312        ----a-w-        C:\windows\system32\rdpwsx.dll
2012-03-14 05:43:24 . 2012-01-25 06:38:38        149504        ----a-w-        C:\windows\system32\rdpcorekmts.dll
2012-03-14 05:43:24 . 2012-01-25 06:33:30        9216        ----a-w-        C:\windows\system32\rdrmemptylst.exe
2012-03-14 05:43:17 . 2012-02-17 06:38:26        1031680        ----a-w-        C:\windows\system32\rdpcore.dll
2012-03-14 05:43:17 . 2012-02-17 05:34:22        826880        ----a-w-        C:\windows\SysWow64\rdpcore.dll
2012-03-14 05:43:17 . 2012-02-17 04:58:24        210944        ----a-w-        C:\windows\system32\drivers\rdpwd.sys
2012-03-14 05:43:17 . 2012-02-17 04:57:32        23552        ----a-w-        C:\windows\system32\drivers\tdtcp.sys
.


((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))

2012-02-23 08:18:36 . 2010-11-21 03:27:21        279656        ------w-        C:\windows\system32\MpSigStub.exe
2012-02-15 19:28:37 . 2011-10-28 18:36:50        132320        ----a-w-        C:\windows\system32\drivers\avipbb.sys


((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))


*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-29 07:47:08 95576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl10"="C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe" [2010-09-20 03:24:42 87336]
"CLMLServer"="C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-11-02 05:21:26 103720]
"Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 15:10:28 35696]
"avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-11 12:59:37 258512]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 12:06:06 254696]

C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 12:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 13:27:14 138576]
R3 BtFilter;BtFilter;C:\windows\system32\DRIVERS\btfilter.sys [x]
R3 Samsung UPD Service;Samsung UPD Service;C:\windows\System32\SUPDSvc.exe [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);C:\windows\system32\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);C:\windows\system32\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;C:\windows\system32\DRIVERS\ss_bmdm.sys [x]
R3 TFsExDisk;TFsExDisk;C:\windows\System32\Drivers\TFsExDisk.sys [2010-07-05 07:24:54 16448]
R3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 09:10:10 57184]
S0 Lbd;Lbd;C:\windows\system32\DRIVERS\Lbd.sys [x]
S1 avkmgr;avkmgr;C:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;C:\windows\system32\Drivers\SABI.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AntiVirSchedulerService;Avira Planer;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 12:59:49 86224]
S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 02:30:38 2656280]
S3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\system32\DRIVERS\clwvd.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;C:\windows\system32\DRIVERS\ETD.sys [x]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-10-28 18:35:26 2152152]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2011-11-01 08:50:55 17152]
S3 MEIx64;Intel(R) Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\windows\system32\drivers\nvhda64v.sys [x]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 19:34:24 4925184]
S3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys [x]



--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-25 02:13:26 11895400]
"Logitech Download Assistant"="C:\Windows\system32\rundll32.exe" [2009-07-14 01:39:31 45568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0

------- Zusätzlicher Suchlauf -------

uLocal Page = C:\windows\system32\blank.htm
uStart Page = hxxp://samsung.msn.com
mStart Page = hxxp://samsung.msn.com
mLocal Page = C:\Windows\SysWOW64\blank.htm
IE: An OneNote s&enden - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {{328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - C:\Users\Melina\AppData\Roaming\Mozilla\Firefox\Profiles\bm6l607p.default\

- - - - Entfernte verwaiste Registrierungseinträge - - - -

Wow6432Node-HKLM-Run-NPSStartup - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
HKLM-Run-ETDCtrl - C:\Program Files (x86)\Elantech\ETDCtrl.exe


cosinus 09.04.2012 17:28

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Vintage 09.04.2012 17:46

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-09 18:43:33
-----------------------------
18:43:33.074    OS Version: Windows x64 6.1.7601 Service Pack 1
18:43:33.074    Number of processors: 4 586 0x2A07
18:43:33.074    ComputerName: MELINA-PC  UserName: Melina
18:43:33.558    Initialize success
18:43:41.482    AVAST engine defs: 12040901
18:44:00.015    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:44:00.031    Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 610480MB BusType: 3
18:44:00.046    Disk 0 MBR read successfully
18:44:00.062    Disk 0 MBR scan
18:44:00.093    Disk 0 unknown MBR code
18:44:00.109    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
18:44:00.140    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      235520 MB offset 206848
18:44:00.202    Disk 0 Partition - 00    0F Extended LBA            350490 MB offset 482551808
18:44:00.249    Disk 0 Partition 3 00    27 Hidden NTFS WinRE NTFS        24367 MB offset 1200355328
18:44:00.717    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      350489 MB offset 482553856
18:44:00.780    Disk 0 scanning C:\windows\system32\drivers
18:44:16.348    Service scanning
18:44:39.873    Modules scanning
18:44:40.372    Disk 0 trace - called modules:
18:44:40.419    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
18:44:40.419    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007826060]
18:44:40.435    3 CLASSPNP.SYS[fffff88001ba543f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800592b050]
18:44:40.450    Scan finished successfully
18:45:23.663    Disk 0 MBR has been saved successfully to "C:\Users\Melina\Desktop\MBR.dat"
18:45:23.678    The log file has been saved successfully to "C:\Users\Melina\Desktop\aswMBR.txt"

Hey cosinus,
ist das Problem eigentlich behoben? Das Popup Fenster erscheint zumindest nicht mehr :)

cosinus 09.04.2012 18:04

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

Vintage 09.04.2012 18:25

Ich habe eben den MBRfix gemacht.
Danach habe ich meinen PC neugestartet und wollte nochmal einen Scan machen um das neue LOg zu posten. Dabei ist mein PC dreimal abgestürzt und wurde sehr langsam.
Ist mein PC denn jetzt eigentlich Viren-frei oder wofür sind jetzt noch die ganzen Scans?

cosinus 09.04.2012 18:34

Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Vintage 09.04.2012 18:38

Das hatte ich schon gemacht. Beim allerersten Mal ist mein PC nämlich auch schon abgestürzt.

cosinus 09.04.2012 18:53

Wo stürzt aswMBR denn jetzt ab? Kannst du noch erkennen wie es den MBR nun einstuft?

Vintage 09.04.2012 19:05

Das stürzt ab, wenn es die Festplatte C scannt. Ist dieser Scan denn wichtig?

cosinus 09.04.2012 19:12

Wieso scannt aswMBR bei dir C:? Du solltest doch mit AV-Scan none den Scan machen wenn aswMBR abstürzt :confused:

Vintage 09.04.2012 19:46

ich habe es nochmal probiert. jetzt hat es geklappt:

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-09 20:43:35
-----------------------------
20:43:35.986    OS Version: Windows x64 6.1.7601 Service Pack 1
20:43:35.986    Number of processors: 4 586 0x2A07
20:43:35.988    ComputerName: MELINA-PC  UserName: Melina
20:43:36.620    Initialize success
20:43:44.778    AVAST engine defs: 12040901
20:44:10.192    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:44:10.197    Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 610480MB BusType: 3
20:44:10.217    Disk 0 MBR read successfully
20:44:10.223    Disk 0 MBR scan
20:44:10.234    Disk 0 Windows 7 default MBR code
20:44:10.259    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
20:44:10.281    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS      235520 MB offset 206848
20:44:10.294    Disk 0 Partition - 00    0F Extended LBA            350490 MB offset 482551808
20:44:10.327    Disk 0 Partition 3 00    27 Hidden NTFS WinRE NTFS        24367 MB offset 1200355328
20:44:10.377    Disk 0 Partition 4 00    07    HPFS/NTFS NTFS      350489 MB offset 482553856
20:44:10.424    Disk 0 scanning C:\windows\system32\drivers
20:44:23.461    Service scanning
20:44:52.592    Modules scanning
20:44:52.612    Disk 0 trace - called modules:
20:44:52.653    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
20:44:52.665    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007828060]
20:44:52.678    3 CLASSPNP.SYS[fffff8800181743f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005bb7050]
20:44:52.690    Scan finished successfully
20:45:19.333    Disk 0 MBR has been saved successfully to "C:\Users\Melina\Desktop\MBR.dat"
20:45:19.344    The log file has been saved successfully to "C:\Users\Melina\Desktop\aswMBR.txt"
20:45:44.667    Disk 0 MBR has been saved successfully to "C:\Users\Melina\Desktop\MBR.dat"
20:45:44.676    The log file has been saved successfully to "C:\Users\Melina\Desktop\aswMBR.txt"


cosinus 09.04.2012 19:47

Zitat:

20:44:10.234 Disk 0 Windows 7 default MBR code
Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Vintage 09.04.2012 21:18

Hey cosinus, ich habe jetzt nur einen ein mit mwb gemacht.

Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.04.09.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Melina :: MELINA-PC [Administrator]

09.04.2012 21:11:51
mbam-log-2012-04-09 (21-11-51).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 321523
Laufzeit: 1 Stunde(n), 4 Minute(n), 21 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 09.04.2012 22:12

Ok, das andere Log fehlt noch

Vintage 10.04.2012 05:47

Hey!
Ja, das andere wollte ich nicht mehr runterladen. Hab jetzt schon so viel ^^
Ist jetzt alles ok? Ich glaube schon!! :) :)
Vielen, vielen Dank für die ganze Hilfe !!!

cosinus 10.04.2012 12:01

Zitat:

Ja, das andere wollte ich nicht mehr runterladen.
Warum fragst du dann hier nach Hilfe wenn du meine Schriite nicht vollständig umsetzen willst? :balla:

Zitat:

Ist jetzt alles ok? Ich glaube schon!!
Was meinst du wohl warum ich auch einen Kontrollscan mit SASW sehen will? :stirn:

Vintage 10.04.2012 17:09

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 04/10/2012 at 05:17 PM

Application Version : 5.0.1146

Core Rules Database Version : 8431
Trace Rules Database Version: 6243

Scan type      : Complete Scan
Total Scan Time : 00:41:08

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 549
Memory threats detected  : 0
Registry items scanned    : 66197
Registry threats detected : 0
File items scanned        : 44444
File threats detected    : 25

Adware.Tracking Cookie
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\ML91FURZ.txt [ /smartadserver.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\DA6LP1BR.txt [ /tradedoubler.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\W7XW22XP.txt [ /tracking.quisma.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\UIIQV41J.txt [ /invitemedia.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\PHSMLAN9.txt [ /atdmt.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\88UUXLJP.txt [ /doubleclick.net ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\WF3JR6VF.txt [ /statse.webtrendslive.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\EJW9F7MD.txt [ /mediaplex.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\8C810FMI.txt [ /fastclick.net ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\O3H4UIGP.txt [ /media6degrees.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\YGOS0HHK.txt [ /ad.ad-srv.net ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\20GQ3OB4.txt [ /lucidmedia.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\8O2WJDC9.txt [ /ru4.com ]
        C:\Users\Melina\AppData\Roaming\Microsoft\Windows\Cookies\9F2K09DT.txt [ /apmebf.com ]
        C:\USERS\MELINA\Cookies\ML91FURZ.txt [ Cookie:melina@smartadserver.com/ ]
        C:\USERS\MELINA\Cookies\DA6LP1BR.txt [ Cookie:melina@tradedoubler.com/ ]
        C:\USERS\MELINA\Cookies\W7XW22XP.txt [ Cookie:melina@tracking.quisma.com/ ]
        C:\USERS\MELINA\Cookies\UIIQV41J.txt [ Cookie:melina@invitemedia.com/ ]
        C:\USERS\MELINA\Cookies\PHSMLAN9.txt [ Cookie:melina@atdmt.com/ ]
        C:\USERS\MELINA\Cookies\88UUXLJP.txt [ Cookie:melina@doubleclick.net/ ]
        C:\USERS\MELINA\Cookies\WF3JR6VF.txt [ Cookie:melina@statse.webtrendslive.com/ ]
        C:\USERS\MELINA\Cookies\EJW9F7MD.txt [ Cookie:melina@mediaplex.com/ ]
        C:\USERS\MELINA\Cookies\20GQ3OB4.txt [ Cookie:melina@lucidmedia.com/ ]
        C:\USERS\MELINA\Cookies\8O2WJDC9.txt [ Cookie:melina@ru4.com/ ]
        C:\USERS\MELINA\Cookies\9F2K09DT.txt [ Cookie:melina@apmebf.com/ ]


cosinus 10.04.2012 18:57

So das ist doch schon mal was, wenn auch SASW nur noch Cookies findet :)

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Vintage 10.04.2012 19:16

Okay, dann ist mein PC ja jetzt wieder virenfrei. Danke nochmal.
Kannst du mir noch sagen, was genau mit meinem Laptop passiert ist und wie ich so etwas in Zukunft verhindern kann?

cosinus 11.04.2012 10:14

Halte Dich am besten grob an diese Regeln:
  1. Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
  2. Halte Windows und alle verwendeten Programme immer aktuell - unterstützen kann dich dabei Secunia PSI
  3. Führe regelmäßig Backups auf externe Medien durch
  4. Arbeite mit eingeschränkten Rechten
  5. Nutze sicherere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen
  6. automatische Wiedergabe von allen Laufwerken komplett deaktivieren, denn das ist ein unnötiges Sicherheitsrisiko
  7. Bei der Installation von Software möglichst darauf achten, dass die Setups aus offiziellen Quellen stammen und du bei der Installation nach Möglichkeit die benutzerdefinierte Methode wählst - dann hast du die Möglichkeit etwaigen Schrott (wie Toolbars oder sowas wie RegistryBooster) abzuwählen, welcher sonst einfach mitinstalliert wird.
  8. Bösartige bzw. ungewollte Sites von vornherein blockieren lassen mit Hilfe der MVPS Hosts File => Blocking Unwanted Parasites with a Hosts File
  9. Finger weg von: TuneUp, Registry-Cleanern aller Art, Softonic sowie illegalen Cracks/Keygens oder anderen "Tools" um ein kommerzielles Programm ohne Lizenz nutzen zu können
  10. dubiose Seiten bzw. Kinofilm-Streaming-Portale ebenfalls sein lassen, erstens handelt man sich dort schnell Malware ein oder kann in Abofallen geraten und zweitens bewegen sich diese Seiten in einer rechtlichen Grauzone.


Alles noch genauer erklärt steht hier => Kompromittierung unvermeidbar?



Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

Vintage 12.04.2012 15:59

Hab jetzt noch die letzten Schritte durchgeführt.

Nochmal, danke für die Hilfe. Echt nett!


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:37 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131