Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Mystart.incredibar entfernen (https://www.trojaner-board.de/118591-mystart-incredibar-entfernen.html)

mirhannah 05.07.2012 08:40

Mystart.incredibar entfernen
 
Hallo liebe Helfer,

ich habe , wie anscheinend einige andere User auch, bei einem Download einer Pdf-creator Freeware die Mystart.incredibar mit auf meinen Computer gezogen.
Da ich gelesen habe, dass es sich dabei um eine Art Spyware handelt, würde ich sie gerne so schnell wie möglich loswerden.

bisher bin ich wie folgt vorgegangen:
Ich habe mir auf den Rat meines Vaters hin Malwarebytes runtergeladen und einen schnellscan durchgeführt (das LOG hänge ich an)
Dann habe ich, weil ich euren Blog noch nicht gelesen hatte, versucht alle Datein zu löschen, die mir als infiziert angezeigt wurden.

Wenn ich jetzt einen Scan durchführe, sagt mit Malwarebytes, mein Computer wäre sauber. Das Problem ist aber nicht behoben. Jedes mal wenn ich einen neuen tab öffne, erscheint darin die vermeintliche Suchmaschine.

Was kann ich jetzt tun?

Vielen Dank im Voraus!

cosinus 05.07.2012 16:40

Führ bitte auch ESET aus, danach sehen wir weiter.

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.

ESET Online Scanner

Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button http://img695.imageshack.us/img695/1599/eset1l.jpg (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Haken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher das bei Remove Found Threats kein Hacken gesetzt ist.
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurde
  • Klicke Finish.
  • Browser schließen.
Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und kopiere folgenden Text in das Ausführen Fenster.
Code:

"%PROGRAMFILES%\Eset\Eset Online Scanner\log.txt"
Hinweis: Falls du ein 64-Bit-Windows einsetzt, lautet der Pfad so:

Code:

"%PROGRAMFILES(X86)%\Eset\Eset Online Scanner\log.txt"
Poste nun den Inhalt der log.txt.

mirhannah 05.07.2012 20:57

Vielen Dank für die schnelle Antwort. Führe gerade den Scan durch und werde dann die Log Datei posten.
gruß
Hannah

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=92fde0672fbf0d4b9084b537aaed7525
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-05 10:52:20
# local_time=2012-07-06 12:52:20 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=5892 16776574 100 100 14683491 179050755 0 0
# compatibility_mode=8192 67108863 100 0 133 133 0 0
# scanned=166082
# found=0
# cleaned=0
# scan_time=10712

So wie ich das sehe, hat dieser scanner auch nichts gefunden, oder?
Das Problem ist aber leider immer noch das gleiche

mirhannah 12.07.2012 09:18

Hallo liebe Helfer,

Ich habe leider noch immer das gleiche Problem und keine Lösung. Kann mir jemand helfen?

Danke

cosinus 12.07.2012 12:45

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

mirhannah 12.07.2012 13:12

Vielen Dank für die Antwort anbei das Ergebnis der Suche

cosinus 12.07.2012 14:55

Die Logs bitte direkt posten und nicht als Anhang!

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

mirhannah 12.07.2012 15:46

# AdwCleaner v1.701 - Logfile created 07/12/2012 at 16:37:47
# Updated 02/07/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : Hannah - HANNAH-PC
# Running from : C:\Users\Hannah\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Hannah\AppData\Local\Conduit
Folder Deleted : C:\Users\Hannah\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Hannah\AppData\Roaming\kikin
Folder Deleted : C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\x6b6u5gh.default\Conduit
Folder Deleted : C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\x6b6u5gh.default\ConduitEngine
Folder Deleted : C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\x6b6u5gh.default\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b}
Folder Deleted : C:\ProgramData\Iminent
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent
Folder Deleted : C:\Program Files\Conduit
Deleted on reboot : C:\Program Files\Iminent
Folder Deleted : C:\Program Files\kikin
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\webbooster@iminent.com
File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\all-iminent.js

***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2704262
Key Deleted : HKCU\Software\AppDataLow\AskBarDis
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\ASKInstaller
Key Deleted : HKLM\SOFTWARE\Canneverbe Limited\OpenCandy
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.ActiveContentHandle.1
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.ActiveContentHandler
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.TinyUrlHandler
Key Deleted : HKLM\SOFTWARE\Classes\IminentWebBooster.TinyUrlHandler.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Iminent
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Deleted : HKLM\SOFTWARE\Web Assistant
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{26C9BBE4-6D45-4AB6-A5B4-E068C9F5EF6D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8F01233-2DE6-4EE7-8988-37263F00651B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ACA608DB-A210-4253-B799-3FD24E9A7BF5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5812E8F-0E16-4C65-88F7-492D36174CB2}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32B29DF0-2237-4370-9A29-37CEBB730E9B}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{32B29DF0-2237-4370-9A29-37CEBB730E9B}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\x6b6u5gh.default\prefs.js

C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\x6b6u5gh.default\user.js ... Deleted !

Deleted : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2269050.CTID", "CT2269050");
Deleted : user_pref("CT2269050.CurrentServerDate", "27-5-2010");
Deleted : user_pref("CT2269050.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2269050.EMailNotifierPollDate", "Thu May 27 2010 19:02:02 GMT+0200");
Deleted : user_pref("CT2269050.FirstServerDate", "27-5-2010");
Deleted : user_pref("CT2269050.FirstTime", true);
Deleted : user_pref("CT2269050.FirstTimeFF3", true);
Deleted : user_pref("CT2269050.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2269050.Initialize", true);
Deleted : user_pref("CT2269050.InitializeCommonPrefs", true);
Deleted : user_pref("CT2269050.InstalledDate", "Thu May 27 2010 19:02:00 GMT+0200");
Deleted : user_pref("CT2269050.InvalidateCache", false);
Deleted : user_pref("CT2269050.IsGrouping", false);
Deleted : user_pref("CT2269050.IsMulticommunity", false);
Deleted : user_pref("CT2269050.IsOpenThankYouPage", false);
Deleted : user_pref("CT2269050.IsOpenUninstallPage", false);
Deleted : user_pref("CT2269050.LanguagePackLastCheckTime", "Thu May 27 2010 19:02:03 GMT+0200");
Deleted : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2269050.LastLogin_2.5.8.6", "Thu May 27 2010 19:02:01 GMT+0200");
Deleted : user_pref("CT2269050.LatestVersion", "2.1.0.18");
Deleted : user_pref("CT2269050.Locale", "en");
Deleted : user_pref("CT2269050.LoginCache", 4);
Deleted : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2269050.RadioIsPodcast", false);
Deleted : user_pref("CT2269050.RadioLastCheckTime", "Thu May 27 2010 19:02:02 GMT+0200");
Deleted : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Deleted : user_pref("CT2269050.RadioMediaID", "12473383");
Deleted : user_pref("CT2269050.RadioMediaType", "Media Player");
Deleted : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Deleted : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Deleted : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Deleted : user_pref("CT2269050.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2269050.SavedHomepage", "hxxp://www.spiegel.de/");
Deleted : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT226[...]
Deleted : user_pref("CT2269050.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Thu May 27 2010 19:02:01 GMT+0200");
Deleted : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2269050.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2269050.SettingsLastCheckTime", "Thu May 27 2010 19:01:59 GMT+0200");
Deleted : user_pref("CT2269050.SettingsLastUpdate", "1274889351");
Deleted : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Thu May 27 2010 19:01:58 GMT+0200");
Deleted : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1274889351");
Deleted : user_pref("CT2269050.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2269050.UserID", "UN79241075609966263");
Deleted : user_pref("CT2269050.ValidationData_Toolbar", 0);
Deleted : user_pref("CT2269050.WeatherNetwork", "");
Deleted : user_pref("CT2269050.WeatherPollDate", "Thu May 27 2010 19:02:02 GMT+0200");
Deleted : user_pref("CT2269050.WeatherUnit", "C");
Deleted : user_pref("CT2269050.alertChannelId", "666138");
Deleted : user_pref("CT2269050.clientLogIsEnabled", false);
Deleted : user_pref("CT2269050.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2269050.myStuffEnabled", true);
Deleted : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2269050.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2769726..clientLogIsEnabled", false);
Deleted : user_pref("CT2769726..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2769726..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2769726.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2769726.AppTrackingLastCheckTime", "Mon Mar 21 2011 21:07:08 GMT+0100");
Deleted : user_pref("CT2769726.CTID", "CT2769726");
Deleted : user_pref("CT2769726.CurrentServerDate", "21-3-2011");
Deleted : user_pref("CT2769726.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2769726.DialogsGetterLastCheckTime", "Mon Mar 21 2011 21:06:59 GMT+0100");
Deleted : user_pref("CT2769726.DownloadReferralCookieData", "{\"BannerName\":\"\",\"BannerTypeId\":\"\",\"Bann[...]
Deleted : user_pref("CT2769726.ExternalComponentPollDate129372280275656718", "Mon Mar 21 2011 21:06:58 GMT+010[...]
Deleted : user_pref("CT2769726.FirstServerDate", "23-12-2010");
Deleted : user_pref("CT2769726.FirstTime", true);
Deleted : user_pref("CT2769726.FirstTimeFF3", true);
Deleted : user_pref("CT2769726.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2769726.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2769726.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2769726.HasUserGlobalKeys", true);
Deleted : user_pref("CT2769726.Initialize", true);
Deleted : user_pref("CT2769726.InitializeCommonPrefs", true);
Deleted : user_pref("CT2769726.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2769726.InstalledDate", "Thu Dec 23 2010 11:52:28 GMT+0100");
Deleted : user_pref("CT2769726.InvalidateCache", false);
Deleted : user_pref("CT2769726.IsGrouping", false);
Deleted : user_pref("CT2769726.IsMulticommunity", false);
Deleted : user_pref("CT2769726.IsOpenThankYouPage", true);
Deleted : user_pref("CT2769726.IsOpenUninstallPage", true);
Deleted : user_pref("CT2769726.LanguagePackLastCheckTime", "Mon Mar 21 2011 21:06:59 GMT+0100");
Deleted : user_pref("CT2769726.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2769726.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2769726.LastLogin_3.2.5.2", "Sun Jan 02 2011 13:48:24 GMT+0100");
Deleted : user_pref("CT2769726.LastLogin_3.3.3.2", "Mon Mar 21 2011 21:06:59 GMT+0100");
Deleted : user_pref("CT2769726.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2769726.Locale", "en");
Deleted : user_pref("CT2769726.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2769726.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2769726.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2769726.RadioIsPodcast", false);
Deleted : user_pref("CT2769726.RadioLastCheckTime", "Mon Mar 21 2011 21:06:59 GMT+0100");
Deleted : user_pref("CT2769726.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2769726.RadioLastUpdateServer", "129362291739470000");
Deleted : user_pref("CT2769726.RadioMediaID", "21624141");
Deleted : user_pref("CT2769726.RadioMediaType", "Media Player");
Deleted : user_pref("CT2769726.RadioMenuSelectedID", "EBRadioMenu_CT276972621624141");
Deleted : user_pref("CT2769726.RadioStationName", "BBC%20World%20Today");
Deleted : user_pref("CT2769726.RadioStationURL", "hxxp://hxxp-ws.bbc.co.uk.edgesuite.net/asx.esi?worldservice/[...]
Deleted : user_pref("CT2769726.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2769726.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT276[...]
Deleted : user_pref("CT2769726.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2769726.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2769726.SearchInNewTabLastCheckTime", "Mon Mar 21 2011 21:06:59 GMT+0100");
Deleted : user_pref("CT2769726.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2769726.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2769726.ServiceMapLastCheckTime", "Mon Mar 21 2011 21:06:58 GMT+0100");
Deleted : user_pref("CT2769726.SettingsLastCheckTime", "Mon Mar 21 2011 21:06:58 GMT+0100");
Deleted : user_pref("CT2769726.SettingsLastUpdate", "1298387099");
Deleted : user_pref("CT2769726.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2769726.ThirdPartyComponentsLastCheck", "Mon Mar 21 2011 21:06:58 GMT+0100");
Deleted : user_pref("CT2769726.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2769726.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2769726");
Deleted : user_pref("CT2769726.Uninstall", true);
Deleted : user_pref("CT2769726.UserID", "UN14120799854197208");
Deleted : user_pref("CT2769726.WeatherNetwork", "");
Deleted : user_pref("CT2769726.WeatherPollDate", "Mon Mar 21 2011 21:06:58 GMT+0100");
Deleted : user_pref("CT2769726.WeatherUnit", "C");
Deleted : user_pref("CT2769726.alertChannelId", "1161838");
Deleted : user_pref("CT2769726.backendstorage.amazonnew_all", "3931393639312C3937333339312C3939303439312C39393[...]
Deleted : user_pref("CT2769726.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2769726.globalFirstTimeInfoLastCheckTime", "Mon Mar 21 2011 21:06:59 GMT+0100");
Deleted : user_pref("CT2769726.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2769726.myStuffEnabled", true);
Deleted : user_pref("CT2769726.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2769726.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2769726.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2769726.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2769726.oldAppsList", "129282571754500061,129282571754968814,129372280275656718,1000082[...]
Deleted : user_pref("CT2769726.testingCtid", "");
Deleted : user_pref("CT2769726.toolbarAppMetaDataLastCheckTime", "Mon Mar 21 2011 21:06:59 GMT+0100");
Deleted : user_pref("CT2769726.toolbarContextMenuLastCheckTime", "Thu Dec 23 2010 11:52:28 GMT+0100");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1161838/1157525/DE", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/DE", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2769726", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2769726",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63428984078257[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/21/2[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/30/2[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2769726/CT2769726[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634[...]
Deleted : user_pref("CommunityToolbar.EngineOwner", "CT2769726");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{f4e6547e-325b-403c-a3bb-ad29ed37a92f}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "searchelf_1.2");
Deleted : user_pref("CommunityToolbar.IsEngineShown", false);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2769726");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{f4e6547e-325b-403c-a3bb-ad29ed37a92f}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "searchelf_1.2");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2269050,ConduitEngine,CT2769726");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2269050,CT2769726");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Mar 21 2011 21:06:37 GMT+01[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Jul 06 2011 09:08:30 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true);
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Tue Jul 05 2011 21:39:58 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "{24d4b275-545f-4e00-a797-4e3cbf261b79}");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu May 27 2010 19:02:02 GMT+0200");
Deleted : user_pref("CommunityToolbar.globalUserId", "fef11e63-fc19-4839-ad05-6561095ef584");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2269050");
Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Wed May 18 2011 08:16:20 GMT+0200");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Mon Mar 21 2011 21:06:34 GMT+0100");
Deleted : user_pref("ConduitEngine.FirstServerDate", "12/23/2010 13");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstalledDate", "Thu Dec 23 2010 11:52:27 GMT+0100");
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Mar 21 2011 21:06:34 GMT+0100");
Deleted : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Sun Jan 02 2011 13:48:28 GMT+0100");
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Mon Mar 21 2011 21:06:36 GMT+0100");
Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Mar 21 2011 21:06:34 GMT+0100");
Deleted : user_pref("ConduitEngine.UserID", "UN74661491810536643");
Deleted : user_pref("ConduitEngine.approveUntrustedApps", false);
Deleted : user_pref("ConduitEngine.engineLocale", "de");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Mar 21 2011 21:06:34 GMT+0100");
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Mon Mar 21 2011 21:06:35 GMT+0100");
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Deleted : user_pref("browser.bdtoolbar.orig_keyword_url", "hxxp://mystart.incredibar.com/mb139/?loc=IB_DS&a=6P[...]
Deleted : user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/mb139?a=6PQCfK2kzZ&loc=FF_NT");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&Sea[...]
Deleted : user_pref("extensions.4ff1b783c58f2.scode", "(function(){var bdomains={\"premiumreports.info\":1,\"d[...]
Deleted : user_pref("extensions.incredibar.admin", false);
Deleted : user_pref("extensions.incredibar.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar.cntry", "DE");
Deleted : user_pref("extensions.incredibar.dfltLng", "");
Deleted : user_pref("extensions.incredibar.dfltSrch", false);
Deleted : user_pref("extensions.incredibar.did", "10669");
Deleted : user_pref("extensions.incredibar.excTlbr", false);
Deleted : user_pref("extensions.incredibar.hdrMd5", "0BE9D29A08051BDEE6C785E75DD9B082");
Deleted : user_pref("extensions.incredibar.hmpg", false);
Deleted : user_pref("extensions.incredibar.id", "16c9c051000000000000001b9e59093e");
Deleted : user_pref("extensions.incredibar.installerproductid", "26");
Deleted : user_pref("extensions.incredibar.instlDay", "15523");
Deleted : user_pref("extensions.incredibar.instlRef", "");
Deleted : user_pref("extensions.incredibar.isDcmntCmplt", true);
Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1417:01:16");
Deleted : user_pref("extensions.incredibar.newTab", false);
Deleted : user_pref("extensions.incredibar.noFFXTlbr", false);
Deleted : user_pref("extensions.incredibar.ppd", "123%5F1");
Deleted : user_pref("extensions.incredibar.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar.productid", "26");
Deleted : user_pref("extensions.incredibar.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar.sg", "none");
Deleted : user_pref("extensions.incredibar.smplGrp", "none");
Deleted : user_pref("extensions.incredibar.tlbrId", "base");
Deleted : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQCfK2kzZ&loc=IB_T[...]
Deleted : user_pref("extensions.incredibar.upn2", "6PQCfK2kzZ");
Deleted : user_pref("extensions.incredibar.upn2n", "92543161453145719");
Deleted : user_pref("extensions.incredibar.vrsn", "1.5.11.14");
Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1417:01:16");
Deleted : user_pref("extensions.incredibar.vrsni", "1.5.11.14");
Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar_i.dfltLng", "");
Deleted : user_pref("extensions.incredibar_i.did", "10669");
Deleted : user_pref("extensions.incredibar_i.excTlbr", false);
Deleted : user_pref("extensions.incredibar_i.id", "16c9c051000000000000001b9e59093e");
Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");
Deleted : user_pref("extensions.incredibar_i.instlDay", "15523");
Deleted : user_pref("extensions.incredibar_i.instlRef", "");
Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");
Deleted : user_pref("extensions.incredibar_i.newTab", false);
Deleted : user_pref("extensions.incredibar_i.ppd", "123%5F1");
Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar_i.productid", "26");
Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");
Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");
Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQCfK2kzZ&loc=IB[...]
Deleted : user_pref("extensions.incredibar_i.upn2", "6PQCfK2kzZ");
Deleted : user_pref("extensions.incredibar_i.upn2n", "92543161453145719");
Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1417:01:16");
Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
Deleted : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb139/?loc=IB_DS&a=6PQCfK2kzZ&&i=26&search="[...]
Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...]

*************************

AdwCleaner[R1].txt - [27625 octets] - [12/07/2012 14:03:39]
AdwCleaner[S1].txt - [28326 octets] - [12/07/2012 16:37:47]

########## EOF - C:\AdwCleaner[S1].txt - [28455 octets] ##########

cosinus 12.07.2012 16:06

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

mirhannah 12.07.2012 16:17

1) Die einzigen Einschränkungen, die ich bemerkt habe, war das erscheinen der incredibar beim Öffnen eines neuen tabs in den Internetbrowsern (IE und Firefox). Das hat aber jetzt, soweit ich das sehe, aufgehört. Sonst habe ich keine Einschränkungen gemerkt.

2)Mir sind beim durchsehen keine leeren Ordner aufgefallen und vermissen tue ich bisher auch nichts.

das einzige was mir gerade auffällt: das Symbol auf der Desktop-Leiste (oder wie man das nennt - sorry) zeigt an, das der Pc nicht mit dem INternet verbunden ist. Ist er aber.

cosinus 12.07.2012 18:52

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


mirhannah 12.07.2012 20:36

OTL Logfile:
Code:

OTL logfile created on: 12.07.2012 21:00:10 - Run 1
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Hannah\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,75 Gb Total Physical Memory | 1,08 Gb Available Physical Memory | 62,09% Memory free
3,74 Gb Paging File | 2,86 Gb Available in Paging File | 76,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,05 Gb Total Space | 22,53 Gb Free Space | 32,63% Space Free | Partition Type: NTFS
Drive D: | 70,00 Gb Total Space | 22,87 Gb Free Space | 32,67% Space Free | Partition Type: NTFS
 
Computer Name: HANNAH-PC | User Name: Hannah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.12 20:55:55 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 07:53:56 | 000,815,512 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012.03.26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2010.09.21 13:43:40 | 000,360,448 | ---- | M] () -- C:\Programme\Browser MOUSE\mouse32a.exe
PRC - [2009.04.11 00:28:04 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.01.19 00:33:40 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.19 00:33:40 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2007.06.29 01:15:06 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe
PRC - [2007.06.13 06:11:30 | 004,489,216 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.06.01 12:36:00 | 000,684,032 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2007.04.26 04:20:48 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
PRC - [2007.04.24 14:49:02 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2007.04.24 11:50:32 | 000,723,760 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2007.04.04 03:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Programme\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2006.10.05 05:10:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2003.06.20 00:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\VS7DEBUG\mdm.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.13 10:25:20 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012.06.13 10:23:18 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.13 10:23:06 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.05.11 13:43:43 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll
MOD - [2012.05.11 13:37:49 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.11 13:29:17 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012.05.11 13:26:42 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.11 13:25:58 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012.04.04 07:54:04 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\AcroTray.DEU
MOD - [2011.09.27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.09.27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010.09.21 13:43:40 | 000,360,448 | ---- | M] () -- C:\Programme\Browser MOUSE\mouse32a.exe
MOD - [2010.09.21 13:43:40 | 000,057,344 | ---- | M] () -- C:\Programme\Browser MOUSE\mouDL32A.dll
MOD - [2009.03.29 22:42:14 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009.03.29 22:42:14 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
MOD - [2009.03.29 22:42:14 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2009.03.29 22:42:12 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2008.09.16 20:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2007.07.14 16:08:41 | 001,675,264 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2728.28937__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,360,448 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.2728.29164__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,233,472 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2728.28895__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,184,320 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2728.28951__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2728.29157__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2728.29115__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2728.28930__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2728.28950__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2728.29051__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2728.28915__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:39 | 000,483,328 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2728.29192__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:01 | 000,135,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2728.29198__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:01 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2728.28909__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:00 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2728.29145__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:00 | 000,331,776 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2728.29124__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:00 | 000,090,112 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2728.29131__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:00 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2728.29123__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:00 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2728.29184__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,917,504 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.2728.29159__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,667,648 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2728.29061__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,585,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2728.28964__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,438,272 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2728.28916__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2728.28971__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2007.07.14 16:07:59 | 000,208,896 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2728.28957__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,118,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2728.29082__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2728.29059__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2728.28970__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2728.29081__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2728.29052__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:58 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2728.29102__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:58 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2728.29051__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2728.29059__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2728.29102__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2665.42157__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2665.42187__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2665.42196__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2665.42166__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2665.42196__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2007.07.14 16:07:57 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2665.42152__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2665.42162__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2007.07.14 16:07:57 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2665.42198__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2665.42149__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2665.42240__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2007.07.14 16:07:57 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2665.42151__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2665.42178__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2665.42166__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2665.42161__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2665.42156__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2665.42168__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2665.42177__90ba9c70f846762e\DEM.OS.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2665.42179__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2665.42164__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2665.42181__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2665.42180__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2007.07.14 16:07:56 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2665.42186__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2007.07.14 16:07:56 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2665.42197__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll
MOD - [2007.07.14 16:07:55 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2665.42184__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2665.42187__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll

und das war auch da:
Code:

OTL Extras logfile created on: 12.07.2012 21:00:10 - Run 1
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Hannah\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,75 Gb Total Physical Memory | 1,08 Gb Available Physical Memory | 62,09% Memory free
3,74 Gb Paging File | 2,86 Gb Available in Paging File | 76,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,05 Gb Total Space | 22,53 Gb Free Space | 32,63% Space Free | Partition Type: NTFS
Drive D: | 70,00 Gb Total Space | 22,87 Gb Free Space | 32,67% Space Free | Partition Type: NTFS
 
Computer Name: HANNAH-PC | User Name: Hannah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] -- C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{14505F2B-7E4F-4F7B-BD61-B5ACEE368CB6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{1C39C865-199C-4FAA-A7CC-1B2203ABB7C9}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{B84AB5C6-8495-496E-992C-A07F14B28041}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{CCB3DA2A-CC12-42AB-A6EF-48A6CF31EBA0}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{332F145D-AB22-42E5-BA32-A59B013578BF}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3D2D4345-C03F-4C18-BA04-F680F6143512}" = protocol=6 | dir=in | app=c:\program files\iminent\mmserver\iminent.mmserver.exe |
"{5380499A-38B2-4AA9-AAB3-865A89AEFCE8}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{55BFF6D1-5FCB-4484-864A-3EC70E6D78C7}" = protocol=6 | dir=out | app=c:\program files\iminent\imbooster\imbooster.exe |
"{5D0D3FFA-24D7-4DDA-B360-8E1B2DA405C1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{930381AD-4298-4431-806E-05D1BDAF749B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B169F0E5-2D51-4ABF-936D-932F340FD2EB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BDEAFD20-7009-4918-A21B-E72F13CE4DF4}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{E439DD2D-2B93-4C58-946B-74C2F881D617}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{EEE74455-F08E-48B1-9AA1-16A0FCC20E04}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{F8AA1B89-02B8-4FC7-A14F-6A8F4C78928A}" = protocol=6 | dir=out | app=c:\program files\iminent\mmserver\iminent.mmserver.exe |
"{FA1D283F-EEA3-4210-B065-566A82A3A417}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FF75F12A-65FE-47AA-A13F-528BF13F4A00}" = protocol=6 | dir=in | app=c:\program files\iminent\imbooster\imbooster.exe |
"TCP Query User{487E026E-9AD4-481E-BBBC-DDCF6E4E4038}C:\program files\sbs wohnraumplaner cad\dmc-temp\dmcserver.exe" = protocol=6 | dir=in | app=c:\program files\sbs wohnraumplaner cad\dmc-temp\dmcserver.exe |
"TCP Query User{73CEDB04-3086-438C-8234-5D328C6E7A6B}C:\program files\simplify media\simplifymedia.exe" = protocol=6 | dir=in | app=c:\program files\simplify media\simplifymedia.exe |
"TCP Query User{77AB5102-9AF0-4C61-A456-A7DF2CEC8FB6}C:\program files\simplify media\simplifymedia.exe" = protocol=6 | dir=in | app=c:\program files\simplify media\simplifymedia.exe |
"TCP Query User{83FE67AE-3CD7-43A5-8F81-4E9D48FCFFDE}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{8D75506D-277C-4CEB-8694-C29CA3F10075}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"TCP Query User{8F0288D6-6927-4ED8-806E-94007B6CBF56}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{A1467FE1-C905-435E-859A-CB87CE3FFD4F}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{BC48FAC9-6066-4027-80AC-C0FE453B6413}C:\users\hannah\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\hannah\appdata\local\akamai\netsession_win.exe |
"UDP Query User{176AE1A7-413E-4519-9576-C3AA6FD817A5}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{1F9AF7CE-6712-4AF9-82CD-FD37A4633F14}C:\users\hannah\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\hannah\appdata\local\akamai\netsession_win.exe |
"UDP Query User{500A63E3-3F75-4781-A362-503252A9E265}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{643B5497-79A5-4E4E-94FD-5766D9863E9D}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{65F1C573-E92E-4DC1-8679-5792FE4FBF63}C:\program files\sbs wohnraumplaner cad\dmc-temp\dmcserver.exe" = protocol=17 | dir=in | app=c:\program files\sbs wohnraumplaner cad\dmc-temp\dmcserver.exe |
"UDP Query User{88AFDB41-D9F8-4C79-933F-4ECAD28DE44C}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{8CEA3BAA-27F2-4E31-A48B-EAFD21DFC8A2}C:\program files\simplify media\simplifymedia.exe" = protocol=17 | dir=in | app=c:\program files\simplify media\simplifymedia.exe |
"UDP Query User{BFD557C7-A4C2-4F80-BC58-C5263562CA88}C:\program files\simplify media\simplifymedia.exe" = protocol=17 | dir=in | app=c:\program files\simplify media\simplifymedia.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5000
"{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{082DF5B7-6572-6B88-F9F3-E1A41707F4A7}" = CCC Help Czech
"{0EE315C8-0081-8B6B-12AF-D26BBF275A82}" = CCC Help Korean
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{10F29C04-6DFA-65AD-B5AA-744255B4D7C8}" = CCC Help Polish
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP3500_series" = Canon iP3500 series
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{136E842A-87AC-4CFA-99A0-4D5BF9114566}" = Iminent
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution II
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{1EBD2C18-069A-4582-BF40-2B506AF6CFAD}" = Envisioneer Express 3.0
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5
"{287A32EF-A420-6596-ADDA-A9DE9A897796}" = CCC Help Portuguese
"{2AE84E70-5E53-C8B0-F423-C6494B4FEBED}" = CCC Help German
"{2EB709B5-0355-B855-8CC0-00821C49DA8B}" = Catalyst Control Center Localization Dutch
"{2F00CF0D-C670-9BD6-51FD-8DD1A0A42E37}" = Catalyst Control Center Localization Czech
"{2F2BB2EC-8494-3C43-6ABF-FEF5C05F3DA6}" = Catalyst Control Center Localization Polish
"{313EAEC4-F4E1-31B9-4F38-107FF621B31F}" = CCC Help Turkish
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor
"{32E64DF2-8426-C9E0-2829-5485AB959225}" = Catalyst Control Center Core Implementation
"{3345B08C-5CAF-AF8C-301C-1B159BB51556}" = Catalyst Control Center Localization Japanese
"{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2
"{3C25440D-FBA4-A668-D088-26842B689ADB}" = CCC Help French
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DFAF6BC-4FE2-5B0D-1C9B-F2055968277B}" = Catalyst Control Center Localization German
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{3FFE6A7B-13B9-494C-29D7-EB46E9E6646C}" = Catalyst Control Center Localization Russian
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{436B50D2-4CA3-A53D-00CF-482A886A1524}" = CCC Help Finnish
"{46623DE3-FDA8-2141-C951-1A2DFA420D03}" = Skins
"{480F7F23-279B-96A4-FAD2-7014D36B79C4}" = Catalyst Control Center Localization Turkish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client DE-DE Language Pack
"{56682EAB-48F1-7187-4F48-1FF9645A1D07}" = Catalyst Control Center Localization Finnish
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5E031BFC-0827-26D4-FDD3-B8D68472DAE1}" = Catalyst Control Center Localization Portuguese
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F29B192-AE83-2636-747D-C5D83E79E8FE}" = Catalyst Control Center Localization Chinese Traditional
"{5FE21275-8D6C-CD0F-5B36-394636C0D264}" = CCC Help Thai
"{6001A55E-2A00-C407-67DB-DCFB3E0CD6F2}" = Catalyst Control Center Graphics Previews Vista
"{6290211A-CB26-FD7E-F214-21B15A5F7C87}" = Catalyst Control Center Localization Korean
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{681C334E-6E93-84BF-E371-26109B7BF8B8}" = Catalyst Control Center Localization Italian
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B32EF07-8A23-4824-91BD-B0F24E50E974}" = Install McAfee
"{6B898739-AE0B-574E-9E7F-DCC7907372A0}" = CCC Help English
"{6B991234-EB5B-4FB3-5873-3946854F0850}" = Catalyst Control Center Localization Hungarian
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79538CDE-83AC-0264-3125-145F33D63B88}" = Catalyst Control Center Graphics Light
"{7A00BF8A-A7E5-D3E0-B17F-06BC5AEC48F6}" = CCC Help Japanese
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7D97029D-B047-F3A1-D6C0-BFF3647AC943}" = Catalyst Control Center Localization French
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7FB12670-0F93-4E1E-B2F5-4F339199A03A}" = Microsoft SQL Server Native Client
"{849A32C3-E75A-4791-9B11-E568BA3525A4}" = Microsoft SQL Server VSS Writer
"{87009005-9492-1307-F01A-25C1554F4F32}" = ccc-core-static
"{87824C5E-2830-63FC-177E-05E16F55F596}" = CCC Help Swedish
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E8FFB67-9316-F95E-969F-402722568272}" = CCC Help Italian
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"{961DC9E8-DDAF-6271-AD0A-689909295476}" = CCC Help Chinese Standard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A413023B-583C-4BDD-A639-346B1579DC01}" = Catalyst Control Center Localization Thai
"{A54A1F3D-E2E0-C9F9-8112-8F0C5A6B06E0}" = Catalyst Control Center Localization Swedish
"{A5C67209-3FC7-A6FF-F7FB-079586F223CC}" = Catalyst Control Center Localization Danish
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A7A27439-E5CD-AF54-FD49-8A08354D5122}" = Catalyst Control Center Localization Chinese Standard
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.1 - Deutsch
"{AD92E291-E249-4AAD-C8FF-BAF0FC7AFE9C}" = CCC Help Greek
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B15C935A-8944-937D-6FA4-D69BEFFEA643}" = CCC Help Spanish
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B7263C56-AED3-3D55-918C-E0BAFCCBF0C7}" = CCC Help Russian
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BB219FC1-008E-7D0D-91A0-CAE6D03DAC8C}" = Catalyst Control Center Localization Norwegian
"{C06CE867-0019-4BDD-88C3-CD96F79FCDC7}" = Cortona3D Viewer
"{C550F812-14C4-23F5-F369-6761A9C0E864}" = CCC Help Dutch
"{CAED2BFB-E4D5-D367-7179-D09E73C85938}" = Catalyst Control Center Localization Greek
"{CAF81DB8-F5DC-DF09-18A6-DD61635305E8}" = CCC Help Chinese Traditional
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4186013-EE74-7570-17D3-38BC3632D51A}" = CCC Help Norwegian
"{D9CE4019-982E-BF95-18CE-5EBB5D75D939}" = Catalyst Control Center Graphics Full New
"{DDD45306-E4F0-D309-447F-7B1A0F6F9CAB}" = Catalyst Control Center Localization Spanish
"{E28201F3-2C09-FCD1-6934-84A3A9E4F0BF}" = CCC Help Danish
"{E7310F2E-C551-4FAB-BA07-EAC2E158B1BB}" = IKEA Home Planner
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4A7EE8F-94F0-374C-E4F2-B7CDDE56ECA8}" = Catalyst Control Center Graphics Full Existing
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F790AD19-127F-9BD7-2655-13E3DA0D7BC2}" = ccc-utility
"{FC20E3FB-60DB-8CFB-4649-CB2F2092F6B2}" = CCC Help Hungarian
"{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"AnotherUnzipper_is1" = AnotherUnzipper - Deinstallation
"AviSynth" = AviSynth 2.5
"Browser MOUSE" = Browser MOUSE
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon iP3500 series Benutzerregistrierung" = Canon iP3500 series Benutzerregistrierung
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Doxillion" = Doxillion Document Converter
"DPP" = Canon Utilities Digital Photo Professional 3.1
"DVD Decrypter" = DVD Decrypter (Remove Only)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ElsterFormular 12.4.0.7094p" = ElsterFormular
"EOS Utility" = Canon Utilities EOS Utility
"ESET Online Scanner" = ESET Online Scanner v3
"Free YouTube Download_is1" = Free YouTube Download version 3.0.19.1206
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.14.1206
"InstallShield_{1EBD2C18-069A-4582-BF40-2B506AF6CFAD}" = Envisioneer Express 3.0
"InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"InstallShield_{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now
"kikin Plugin (NO23 Edition)" = kikin Plugin (NO23 Edition) 1.11
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
"MixPad" = MixPad Audio Mixer
"Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de)
"Mozilla Thunderbird 13.0.1 (x86 de)" = Mozilla Thunderbird 13.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"ODSK" = Canon Utilities Original Data Security Tools
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"tewi Fahrschule_is1" = tewi Fahrschule 2004-2005
"Uninstall_is1" = Uninstall 1.0.0.1
"VideoPad" = VideoPad Video Editor
"VLC media player" = VLC media player 1.1.5
"WavePad" = WavePad Sound Editor
"WFTK" = Canon Utilities WFT-E1/E2/E3 Utility
"WinRAR archiver" = WinRAR
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Game Organizer" = EasyBits GO
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 04.07.2012 15:22:09 | Computer Name = Hannah-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
 
Error - 05.07.2012 11:48:23 | Computer Name = Hannah-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 05.07.2012 19:23:33 | Computer Name = Hannah-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 07.07.2012 14:56:42 | Computer Name = Hannah-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 08.07.2012 17:07:46 | Computer Name = Hannah-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 09.07.2012 16:21:58 | Computer Name = Hannah-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 10.07.2012 13:01:24 | Computer Name = Hannah-PC | Source = EventSystem | ID = 4621
Description =
 
Error - 11.07.2012 08:49:15 | Computer Name = Hannah-PC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 11.07.2012 08:49:15 | Computer Name = Hannah-PC | Source = Windows Search Service | ID = 3013
Description =
 
Error - 11.07.2012 09:08:29 | Computer Name = Hannah-PC | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung WINWORD.EXE, Version 10.0.6866.0, Zeitstempel
 0x4c6486a7, fehlerhaftes Modul ntdll.dll, Version 6.0.6002.18541, Zeitstempel 0x4ec3e3d5,
 Ausnahmecode 0xc0000374, Fehleroffset 0x000b06b7,  Prozess-ID 0x10ec, Anwendungsstartzeit
 01cd5f44e134c6f8.
 
[ System Events ]
Error - 12.07.2012 10:41:23 | Computer Name = Hannah-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 12.07.2012 10:41:23 | Computer Name = Hannah-PC | Source = Service Control Manager | ID = 7034
Description =
 
Error - 12.07.2012 10:41:33 | Computer Name = Hannah-PC | Source = DCOM | ID = 10016
Description =
 
Error - 12.07.2012 10:42:13 | Computer Name = Hannah-PC | Source = DCOM | ID = 10016
Description =
 
Error - 12.07.2012 12:43:04 | Computer Name = Hannah-PC | Source = DCOM | ID = 10010
Description =
 
Error - 12.07.2012 14:51:53 | Computer Name = Hannah-PC | Source = DCOM | ID = 10016
Description =
 
Error - 12.07.2012 14:52:04 | Computer Name = Hannah-PC | Source = DCOM | ID = 10016
Description =
 
Error - 12.07.2012 14:52:23 | Computer Name = Hannah-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 12.07.2012 14:52:23 | Computer Name = Hannah-PC | Source = Service Control Manager | ID = 7034
Description =
 
Error - 12.07.2012 14:53:24 | Computer Name = Hannah-PC | Source = DCOM | ID = 10010
Description =
 
 
< End of report >

--- --- ---
[/code]

im ersten hat noch was gefehlt. Hier noch mal komplett:
OTL Logfile:
Code:

OTL logfile created on: 12.07.2012 21:00:10 - Run 1
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Hannah\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,75 Gb Total Physical Memory | 1,08 Gb Available Physical Memory | 62,09% Memory free
3,74 Gb Paging File | 2,86 Gb Available in Paging File | 76,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,05 Gb Total Space | 22,53 Gb Free Space | 32,63% Space Free | Partition Type: NTFS
Drive D: | 70,00 Gb Total Space | 22,87 Gb Free Space | 32,67% Space Free | Partition Type: NTFS
 
Computer Name: HANNAH-PC | User Name: Hannah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.12 20:55:55 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 07:53:56 | 000,815,512 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012.03.26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2010.09.21 13:43:40 | 000,360,448 | ---- | M] () -- C:\Programme\Browser MOUSE\mouse32a.exe
PRC - [2009.04.11 00:28:04 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.01.19 00:33:40 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.19 00:33:40 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2007.06.29 01:15:06 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe
PRC - [2007.06.13 06:11:30 | 004,489,216 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.06.01 12:36:00 | 000,684,032 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2007.04.26 04:20:48 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
PRC - [2007.04.24 14:49:02 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2007.04.24 11:50:32 | 000,723,760 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2007.04.04 03:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Programme\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2006.10.05 05:10:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2003.06.20 00:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\VS7DEBUG\mdm.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.13 10:25:20 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012.06.13 10:23:18 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.13 10:23:06 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.05.11 13:43:43 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll
MOD - [2012.05.11 13:37:49 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.11 13:29:17 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012.05.11 13:26:42 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.11 13:25:58 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012.04.04 07:54:04 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\AcroTray.DEU
MOD - [2011.09.27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.09.27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010.09.21 13:43:40 | 000,360,448 | ---- | M] () -- C:\Programme\Browser MOUSE\mouse32a.exe
MOD - [2010.09.21 13:43:40 | 000,057,344 | ---- | M] () -- C:\Programme\Browser MOUSE\mouDL32A.dll
MOD - [2009.03.29 22:42:14 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009.03.29 22:42:14 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
MOD - [2009.03.29 22:42:14 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2009.03.29 22:42:12 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2008.09.16 20:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2007.07.14 16:08:41 | 001,675,264 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2728.28937__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,360,448 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.2728.29164__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,233,472 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2728.28895__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,184,320 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2728.28951__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2728.29157__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2728.29115__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2728.28930__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2728.28950__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2728.29051__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2728.28915__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:39 | 000,483,328 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2728.29192__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:01 | 000,135,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2728.29198__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:01 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2728.28909__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:00 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2728.29145__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:00 | 000,331,776 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2728.29124__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:00 | 000,090,112 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2728.29131__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:00 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2728.29123__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:00 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2728.29184__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,917,504 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.2728.29159__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,667,648 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2728.29061__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,585,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2728.28964__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,438,272 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2728.28916__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2728.28971__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2007.07.14 16:07:59 | 000,208,896 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2728.28957__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,118,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2728.29082__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2728.29059__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2728.28970__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2728.29081__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2728.29052__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:58 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2728.29102__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:58 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2728.29051__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2728.29059__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2728.29102__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2665.42157__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2665.42187__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2665.42196__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2665.42166__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2665.42196__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2007.07.14 16:07:57 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2665.42152__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2665.42162__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2007.07.14 16:07:57 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2665.42198__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2665.42149__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2665.42240__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2007.07.14 16:07:57 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2665.42151__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2665.42178__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2665.42166__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2665.42161__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2665.42156__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2665.42168__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2665.42177__90ba9c70f846762e\DEM.OS.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2665.42179__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2665.42164__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2665.42181__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2665.42180__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2007.07.14 16:07:56 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2665.42186__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2007.07.14 16:07:56 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2665.42197__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll
MOD - [2007.07.14 16:07:55 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2665.42184__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2665.42187__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shared\2.0.2665.42182__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2665.42184__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2665.42184__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2665.42186__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2665.42182__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2665.42167__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2665.42180__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2665.42185__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2665.42166__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2665.42187__90ba9c70f846762e\APM.Foundation.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2665.42150__90ba9c70f846762e\AEM.Foundation.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2665.42181__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2665.42160__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2007.07.14 16:07:47 | 000,013,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray.resources\2.0.2728.29169_de_90ba9c70f846762e\CLI.Component.Systemtray.resources.dll
MOD - [2007.07.14 16:07:46 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.2728.29220__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2007.07.14 16:07:46 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.2728.28892__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2007.07.14 16:07:45 | 001,503,232 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2728.28903__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2007.07.14 16:07:45 | 000,466,944 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2728.28924__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2007.07.14 16:07:45 | 000,397,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2728.29169__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2007.07.14 16:07:45 | 000,102,400 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2728.29178__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2007.07.14 16:07:45 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2728.28894__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2007.07.14 16:07:45 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2728.29176__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2007.07.14 16:07:45 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.2728.28894__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2007.07.14 16:07:45 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2665.42165__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2665.42160__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2665.42158__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2007.07.14 16:07:45 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.2728.29177__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2007.07.14 16:07:45 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2665.42196__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2665.42169__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2665.42154__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2665.42167__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2665.42188__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2007.07.14 16:07:44 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2007.07.14 16:07:42 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2728.28893__90ba9c70f846762e\AEM.Server.dll
MOD - [2007.06.13 17:11:36 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2007.04.24 11:32:56 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll
MOD - [2007.02.23 11:32:40 | 000,065,536 | ---- | M] () -- C:\Programme\Samsung\EBM\ChkSec.dll
MOD - [2006.09.19 02:52:46 | 000,028,672 | ---- | M] () -- C:\Programme\Samsung\Easy Display Manager\WinMove.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.07.12 09:18:38 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.19 13:22:59 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010.01.15 14:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008.01.19 00:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 00:33:40 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2007.06.28 11:54:42 | 000,073,728 | ---- | M] () [Auto | Stopped] -- C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus)
SRV - [2006.10.26 07:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006.10.05 05:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2003.06.20 00:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\VS7DEBUG\mdm.exe -- (MDM)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012.01.18 07:44:52 | 004,332,960 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 500(UVC)
DRV - [2012.01.18 07:44:28 | 000,312,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2009.12.17 17:02:20 | 001,203,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009.04.10 23:06:28 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan)
DRV - [2008.01.18 23:15:00 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007.07.11 00:37:16 | 000,013,312 | ---- | M] (SAMSUNG ELECTRONICS CO., LTD.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\KMDFMEMIO.sys -- (KMDFMEMIO)
DRV - [2007.06.13 17:21:28 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2007.06.13 17:21:28 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2007.04.26 03:15:26 | 000,007,680 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV - [2006.11.28 21:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.02 09:30:56 | 002,589,184 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw2v32.sys -- (NETw2v32) Intel(R)
DRV - [2006.11.02 09:30:56 | 000,047,104 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.zeit.de/"
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f}:2.5.8.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
FF - HKLM\Software\MozillaPlugins\@parallelgraphics.com/Cortona: C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll (ParallelGraphics)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.69: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012.07.12 09:24:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.19 13:23:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.07.12 09:24:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.06.21 17:23:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2011.03.02 22:51:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\mozilla\Extensions
[2011.03.02 22:51:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.07.12 16:37:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\mozilla\Firefox\Profiles\x6b6u5gh.default\extensions
[2011.12.09 16:39:33 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Hannah\AppData\Roaming\mozilla\Firefox\Profiles\x6b6u5gh.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.11.18 20:20:45 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Hannah\AppData\Roaming\mozilla\Firefox\Profiles\x6b6u5gh.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2012.07.12 16:38:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2008.10.11 17:03:21 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.04.28 12:20:06 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.07.12 09:24:26 | 000,000,000 | ---D | M] (Adobe Acrobat - Create PDF) -- C:\PROGRAM FILES\ADOBE\ACROBAT 10.0\ACROBAT\BROWSER\WCFIREFOXEXTN
[2009.09.16 09:42:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.06.19 13:23:01 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009.06.01 13:22:18 | 000,874,008 | ---- | M] (ParallelGraphics) -- C:\Program Files\mozilla firefox\plugins\npCortona.dll
[2012.06.19 13:22:56 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.19 13:22:56 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.19 13:22:56 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.19 13:22:56 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.19 13:22:56 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.19 13:22:56 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll File not found
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [FLMOFFICE4DMOUSE] C:\Programme\Browser MOUSE\mouse32a.exe ()
O4 - HKLM..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup File not found
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003..\Run: [Akamai NetSession Interface] "C:\Users\Hannah\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll ()
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3861AC4B-0AFF-4C4A-9D1C-DBA6CCCD3C16}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C498F9F-C012-4D4F-BD26-A969CE8C66CB}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Hannah\Pictures\sonkram\the brain.jpg
O24 - Desktop BackupWallPaper: C:\Users\Hannah\Pictures\sonkram\the brain.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{28a47d84-ecfe-11dc-b386-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\34542.exe
O33 - MountPoints2\{56a52bbf-115f-11e1-a5f0-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\copy.exe
O33 - MountPoints2\{8830768c-ed5a-11dc-b22f-0013775baaa5}\Shell\AutoRun\command - "" = WDSetup.exe
O33 - MountPoints2\{e9538169-f073-11dc-8ecb-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe
O33 - MountPoints2\{f23719ee-790d-11de-bb2c-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpReg: Adobe Photo Downloader - hkey= - key= -  File not found
MsConfig - StartUpReg: Windows Defender - hkey= - key= -  File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - c:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger -  File not found
SafeBootNet: MsMpSvc - c:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\SL_ANET.ACM (Sipro Lab Telecom Inc.)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.12 20:55:51 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Hannah\Desktop\OTL.exe
[2012.07.12 10:02:06 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Local\Macromedia
[2012.07.06 09:18:06 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Desktop\Virus
[2012.07.05 21:51:34 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.07.05 17:54:49 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2012.07.05 17:38:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
[2012.07.05 17:17:48 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Desktop\Adobe Acrobat X
[2012.07.04 21:18:24 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2012.07.04 21:13:56 | 000,203,088 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2012.07.04 21:13:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012.07.04 21:13:08 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012.07.04 21:13:05 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Roaming\TestApp
[2012.07.04 16:55:10 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Roaming\Malwarebytes
[2012.07.04 16:55:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.04 16:54:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.04 16:54:47 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.07.04 16:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.07.02 17:01:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Premium
[2012.07.02 17:00:19 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[2012.06.21 15:02:02 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Desktop\Only lovers
[2012.06.16 19:25:59 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.12 20:55:55 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\OTL.exe
[2012.07.12 20:55:02 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.12 20:51:09 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.12 20:50:54 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.12 20:50:54 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.12 20:50:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.12 20:50:38 | 1877,131,264 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.12 18:43:20 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.07.12 18:18:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.12 16:39:35 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2012.07.12 14:02:42 | 000,618,655 | ---- | M] () -- C:\Users\Hannah\Desktop\adwcleaner.exe
[2012.07.12 09:24:47 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012.07.12 09:12:34 | 000,379,952 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.07.04 21:16:16 | 002,282,331 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB
[2012.07.03 12:06:25 | 000,634,602 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.07.03 12:06:25 | 000,601,250 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.07.03 12:06:25 | 000,128,520 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.07.03 12:06:25 | 000,106,164 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.07.02 17:01:18 | 000,000,454 | ---- | M] () -- C:\user.js
[2012.06.21 10:09:08 | 000,332,314 | ---- | M] () -- C:\Users\Hannah\Documents\Urheberrecht.pdf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.12 14:02:24 | 000,618,655 | ---- | C] () -- C:\Users\Hannah\Desktop\adwcleaner.exe
[2012.07.12 09:14:27 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.05 17:38:20 | 000,002,449 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2012.07.05 17:38:20 | 000,002,437 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
[2012.07.05 17:38:20 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012.07.04 21:14:06 | 002,282,331 | ---- | C] () -- C:\Windows\System32\drivers\Cat.DB
[2012.07.02 17:01:17 | 000,000,454 | ---- | C] () -- C:\user.js
[2012.06.21 10:09:07 | 000,332,314 | ---- | C] () -- C:\Users\Hannah\Documents\Urheberrecht.pdf
[2012.01.18 07:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2012.01.18 07:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2012.01.18 07:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2012.01.17 23:33:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012.01.17 23:31:45 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012.01.17 23:31:45 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.12.07 13:10:17 | 000,001,470 | ---- | C] () -- C:\Users\Hannah\AppData\Local\RecConfig.xml
[2011.07.26 07:48:54 | 000,028,418 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2010.11.04 00:33:53 | 000,000,680 | ---- | C] () -- C:\Users\Hannah\AppData\Local\d3d9caps.dat
[2009.07.31 14:37:00 | 000,000,582 | ---- | C] () -- C:\Users\Hannah\AppData\Roaming\AutoGK.ini
[2009.07.06 11:06:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.06.12 07:41:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.03.23 20:34:35 | 000,000,379 | ---- | C] () -- C:\Users\Hannah\AppData\Roaming\burnaware.ini
[2007.12.02 19:41:40 | 000,237,568 | ---- | C] () -- C:\Users\Hannah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== LOP Check ==========
 
[2009.04.13 20:10:49 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AnotherUnzipper
[2009.06.11 17:46:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Installer
[2009.06.11 17:49:16 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Programme
[2008.12.17 12:03:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AvexLab
[2010.12.23 13:38:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canneverbe Limited
[2008.01.23 14:46:31 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canon
[2011.12.09 20:45:04 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoft
[2011.12.09 20:40:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.10.27 18:15:23 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\elsterformular
[2011.12.07 12:11:54 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Free Sound Recorder
[2011.06.18 06:14:08 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\go
[2008.10.11 17:15:47 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ICQ
[2009.11.07 17:53:57 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\IN-MEDIAKG
[2009.06.11 01:53:52 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\SmartDraw
[2011.08.04 19:41:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TeamViewer
[2012.07.04 21:13:05 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TestApp
[2011.03.02 22:51:38 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Thunderbird
[2010.07.28 15:21:13 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\uTorrent
[2012.07.12 18:43:23 | 000,032,510 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.07.05 18:00:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Adobe
[2008.02.18 13:08:59 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AdobeUM
[2009.04.13 20:10:49 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AnotherUnzipper
[2012.02.01 23:38:35 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Apple Computer
[2009.06.11 17:46:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Installer
[2009.06.11 17:49:16 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Programme
[2007.12.01 12:37:47 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ATI
[2008.12.17 12:03:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AvexLab
[2009.06.26 16:12:09 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AVS4YOU
[2010.12.23 13:38:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canneverbe Limited
[2008.01.23 14:46:31 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canon
[2007.12.12 01:05:17 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\CyberLink
[2008.08.20 10:48:07 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DivX
[2012.05.05 10:01:13 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\dvdcss
[2011.12.09 20:45:04 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoft
[2011.12.09 20:40:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.10.27 18:15:23 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\elsterformular
[2011.12.07 12:11:54 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Free Sound Recorder
[2011.06.18 06:14:08 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\go
[2009.07.25 20:02:36 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Google
[2008.10.11 17:15:47 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ICQ
[2007.12.01 12:36:39 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Identities
[2009.11.07 17:53:57 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\IN-MEDIAKG
[2007.12.31 16:37:14 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Macromedia
[2012.07.04 16:55:10 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Media Center Programs
[2012.07.12 10:02:06 | 000,000,000 | --SD | M] -- C:\Users\Hannah\AppData\Roaming\Microsoft
[2009.05.23 19:52:16 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Move Networks
[2008.08.27 11:15:39 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Mozilla
[2011.12.09 23:28:32 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\NCH Software
[2011.01.13 18:07:57 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\OpenOffice.org2
[2010.08.26 20:40:51 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Real
[2012.07.12 21:00:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Skype
[2011.06.14 07:21:43 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\skypePM
[2009.06.11 01:53:52 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\SmartDraw
[2008.09.15 18:54:39 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Sun
[2011.08.04 19:41:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TeamViewer
[2012.07.04 21:13:05 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TestApp
[2011.03.02 22:51:38 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Thunderbird
[2010.07.28 15:21:13 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\uTorrent
[2012.03.08 12:27:05 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\vlc
[2009.04.25 14:36:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\WinRAR
[2008.04.12 11:08:14 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ZoomBrowser EX
 
< %APPDATA%\*.exe /s >
[2007.05.10 10:05:12 | 000,057,344 | ---- | M] (SBS) -- C:\Users\Hannah\AppData\Roaming\ASCON Installer\ASUNINST.EXE
[2007.11.27 09:41:32 | 000,405,504 | ---- | M] () -- C:\Users\Hannah\AppData\Roaming\NCH Software\Components\mp3el2\lame.exe
[2010.08.26 20:40:55 | 000,456,200 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Hannah\AppData\Roaming\Real\Update\setup3.12\setup.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007.07.11 00:57:39 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=313FF294978EA6AF715722D708FB249F -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\AGP440.sys
[2007.07.11 00:58:01 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2007.07.11 00:58:01 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2007.07.11 00:58:01 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2007.07.11 00:57:39 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f2490cb0\AGP440.sys
[2007.07.11 00:57:39 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 00:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 00:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007.07.11 00:58:23 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2007.07.11 00:58:22 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2007.07.11 00:58:22 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.01.19 06:33:23 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 00:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 00:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 00:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 00:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 00:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 00:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.07.11 00:54:56 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2007.07.11 00:54:57 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2008.01.19 00:36:48 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2009.04.11 00:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 00:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 00:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.18 22:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.18 22:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2007.06.14 05:11:50 | 000,339,968 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\Windows\system32\ATIDEMGX.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:66B13F37
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:6152D44C
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:C980DA7D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

--- --- ---

mirhannah 12.07.2012 20:42

das erste war nicht komplett,hier noch mal als ganzes:

OTL Logfile:
Code:

OTL logfile created on: 12.07.2012 21:00:10 - Run 1
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Hannah\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
1,75 Gb Total Physical Memory | 1,08 Gb Available Physical Memory | 62,09% Memory free
3,74 Gb Paging File | 2,86 Gb Available in Paging File | 76,48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,05 Gb Total Space | 22,53 Gb Free Space | 32,63% Space Free | Partition Type: NTFS
Drive D: | 70,00 Gb Total Space | 22,87 Gb Free Space | 32,67% Space Free | Partition Type: NTFS
 
Computer Name: HANNAH-PC | User Name: Hannah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.07.12 20:55:55 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\OTL.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 07:53:56 | 000,815,512 | ---- | M] (Adobe Systems Inc.) -- C:\Programme\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012.03.26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Programme\Microsoft Security Client\msseces.exe
PRC - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Programme\Microsoft Security Client\MsMpEng.exe
PRC - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2010.09.21 13:43:40 | 000,360,448 | ---- | M] () -- C:\Programme\Browser MOUSE\mouse32a.exe
PRC - [2009.04.11 00:28:04 | 001,233,920 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Sidebar\sidebar.exe
PRC - [2009.04.11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.01.19 00:33:40 | 000,896,512 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2008.01.19 00:33:40 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnscfg.exe
PRC - [2007.06.29 01:15:06 | 000,352,256 | ---- | M] (SAMSUNG Electronics co., LTD.) -- C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe
PRC - [2007.06.13 06:11:30 | 004,489,216 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.06.01 12:36:00 | 000,684,032 | ---- | M] (SAMSUNG Electronics) -- C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2007.04.26 04:20:48 | 000,045,056 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
PRC - [2007.04.24 14:49:02 | 000,565,248 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2007.04.24 11:50:32 | 000,723,760 | ---- | M] (Broadcom Corporation.) -- C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2007.04.04 03:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Programme\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2006.10.05 05:10:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2003.06.20 00:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Programme\Common Files\microsoft shared\VS7DEBUG\mdm.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.13 10:25:20 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012.06.13 10:23:18 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.13 10:23:06 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.05.11 13:43:43 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll
MOD - [2012.05.11 13:37:49 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.11 13:29:17 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012.05.11 13:26:42 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.11 13:25:58 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012.04.04 07:54:04 | 000,019,968 | ---- | M] () -- C:\Programme\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\AcroTray.DEU
MOD - [2011.09.27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.09.27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010.09.21 13:43:40 | 000,360,448 | ---- | M] () -- C:\Programme\Browser MOUSE\mouse32a.exe
MOD - [2010.09.21 13:43:40 | 000,057,344 | ---- | M] () -- C:\Programme\Browser MOUSE\mouDL32A.dll
MOD - [2009.03.29 22:42:14 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009.03.29 22:42:14 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
MOD - [2009.03.29 22:42:14 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2009.03.29 22:42:12 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2008.09.16 20:18:06 | 000,132,608 | ---- | M] () -- C:\Programme\WinRAR\RarExt.dll
MOD - [2007.07.14 16:08:41 | 001,675,264 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2728.28937__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,360,448 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.2728.29164__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,233,472 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2728.28895__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,184,320 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2728.28951__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2728.29157__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,065,536 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2728.29115__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2728.28930__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:41 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2728.28950__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2728.29051__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:41 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2728.28915__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:39 | 000,483,328 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2728.29192__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:01 | 000,135,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2728.29198__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:01 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2728.28909__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:00 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2728.29145__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:00 | 000,331,776 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2728.29124__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2007.07.14 16:08:00 | 000,090,112 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2728.29131__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2007.07.14 16:08:00 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2728.29123__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2007.07.14 16:08:00 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2728.29184__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,917,504 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.2728.29159__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,667,648 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2728.29061__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,585,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2728.28964__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,438,272 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2728.28916__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2728.28971__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2007.07.14 16:07:59 | 000,208,896 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2728.28957__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,118,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2728.29082__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:59 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2728.29059__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2728.28970__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:59 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2728.29081__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2728.29052__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:58 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2728.29102__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2007.07.14 16:07:58 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2728.29051__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2728.29059__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2728.29102__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2007.07.14 16:07:58 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2665.42157__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2665.42187__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2665.42196__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2665.42166__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2665.42196__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2007.07.14 16:07:58 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2007.07.14 16:07:57 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2665.42152__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2665.42162__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2007.07.14 16:07:57 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2665.42198__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2665.42149__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2665.42240__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2007.07.14 16:07:57 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2665.42151__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2665.42178__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2665.42166__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2665.42161__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2665.42156__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2665.42168__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2665.42177__90ba9c70f846762e\DEM.OS.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2665.42179__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2665.42164__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2665.42181__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2007.07.14 16:07:57 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2665.42180__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2007.07.14 16:07:56 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2665.42186__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2007.07.14 16:07:56 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2665.42197__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll
MOD - [2007.07.14 16:07:55 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2665.42184__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2665.42187__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shared\2.0.2665.42182__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2665.42184__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2665.42184__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2665.42186__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2665.42182__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2665.42167__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2665.42180__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2665.42185__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2665.42166__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2665.42187__90ba9c70f846762e\APM.Foundation.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2665.42150__90ba9c70f846762e\AEM.Foundation.dll
MOD - [2007.07.14 16:07:54 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2665.42181__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2007.07.14 16:07:54 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2665.42160__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2007.07.14 16:07:47 | 000,013,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray.resources\2.0.2728.29169_de_90ba9c70f846762e\CLI.Component.Systemtray.resources.dll
MOD - [2007.07.14 16:07:46 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.2728.29220__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2007.07.14 16:07:46 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.2728.28892__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2007.07.14 16:07:45 | 001,503,232 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2728.28903__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2007.07.14 16:07:45 | 000,466,944 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2728.28924__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2007.07.14 16:07:45 | 000,397,312 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2728.29169__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2007.07.14 16:07:45 | 000,102,400 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2728.29178__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2007.07.14 16:07:45 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2728.28894__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2007.07.14 16:07:45 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2728.29176__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2007.07.14 16:07:45 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.2728.28894__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2007.07.14 16:07:45 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2665.42165__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2665.42160__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2665.42158__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2007.07.14 16:07:45 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.2728.29177__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2007.07.14 16:07:45 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2665.42196__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2665.42169__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2665.42154__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2665.42167__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2007.07.14 16:07:45 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2665.42188__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2007.07.14 16:07:44 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2007.07.14 16:07:42 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2728.28893__90ba9c70f846762e\AEM.Server.dll
MOD - [2007.06.13 17:11:36 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2007.04.24 11:32:56 | 000,389,120 | ---- | M] () -- C:\Windows\System32\btwhidcs.dll
MOD - [2007.02.23 11:32:40 | 000,065,536 | ---- | M] () -- C:\Programme\Samsung\EBM\ChkSec.dll
MOD - [2006.09.19 02:52:46 | 000,028,672 | ---- | M] () -- C:\Programme\Samsung\Easy Display Manager\WinMove.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll
MOD - [2006.08.12 05:48:40 | 000,049,152 | ---- | M] () -- C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2012.07.12 09:18:38 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.06.19 13:22:59 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programme\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012.03.26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.01.18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Programme\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010.01.15 14:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Programme\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008.01.19 00:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008.01.19 00:33:40 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2007.06.28 11:54:42 | 000,073,728 | ---- | M] () [Auto | Stopped] -- C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe -- (Samsung Update Plus)
SRV - [2006.10.26 07:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006.10.05 05:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2003.06.20 00:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\microsoft shared\VS7DEBUG\mdm.exe -- (MDM)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012.01.18 07:44:52 | 004,332,960 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 500(UVC)
DRV - [2012.01.18 07:44:28 | 000,312,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2009.12.17 17:02:20 | 001,203,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009.04.10 23:06:28 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan)
DRV - [2008.01.18 23:15:00 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007.07.11 00:37:16 | 000,013,312 | ---- | M] (SAMSUNG ELECTRONICS CO., LTD.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\KMDFMEMIO.sys -- (KMDFMEMIO)
DRV - [2007.06.13 17:21:28 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2007.06.13 17:21:28 | 002,600,960 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2007.04.26 03:15:26 | 000,007,680 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV - [2006.11.28 21:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.02 09:30:56 | 002,589,184 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw2v32.sys -- (NETw2v32) Intel(R)
DRV - [2006.11.02 09:30:56 | 000,047,104 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\..\URLSearchHook:  - No CLSID value found
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.zeit.de/"
FF - prefs.js..extensions.enabledItems: de-DE@dictionaries.addons.mozilla.org:2.0.2
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f}:2.5.8.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
FF - HKLM\Software\MozillaPlugins\@parallelgraphics.com/Cortona: C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll (ParallelGraphics)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.69: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player:  File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012.07.12 09:24:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.19 13:23:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.07.12 09:24:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.06.21 17:23:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2011.03.02 22:51:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\mozilla\Extensions
[2011.03.02 22:51:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.07.12 16:37:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\mozilla\Firefox\Profiles\x6b6u5gh.default\extensions
[2011.12.09 16:39:33 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Hannah\AppData\Roaming\mozilla\Firefox\Profiles\x6b6u5gh.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.11.18 20:20:45 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\Hannah\AppData\Roaming\mozilla\Firefox\Profiles\x6b6u5gh.default\extensions\de-DE@dictionaries.addons.mozilla.org
[2012.07.12 16:38:02 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2008.10.11 17:03:21 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.04.28 12:20:06 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.07.12 09:24:26 | 000,000,000 | ---D | M] (Adobe Acrobat - Create PDF) -- C:\PROGRAM FILES\ADOBE\ACROBAT 10.0\ACROBAT\BROWSER\WCFIREFOXEXTN
[2009.09.16 09:42:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.06.19 13:23:01 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009.06.01 13:22:18 | 000,874,008 | ---- | M] (ParallelGraphics) -- C:\Program Files\mozilla firefox\plugins\npCortona.dll
[2012.06.19 13:22:56 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.19 13:22:56 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.19 13:22:56 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.19 13:22:56 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.19 13:22:56 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.19 13:22:56 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll File not found
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [FLMOFFICE4DMOUSE] C:\Programme\Browser MOUSE\mouse32a.exe ()
O4 - HKLM..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup File not found
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003..\Run: [Akamai NetSession Interface] "C:\Users\Hannah\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll ()
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3861AC4B-0AFF-4C4A-9D1C-DBA6CCCD3C16}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C498F9F-C012-4D4F-BD26-A969CE8C66CB}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Programme\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Hannah\Pictures\sonkram\the brain.jpg
O24 - Desktop BackupWallPaper: C:\Users\Hannah\Pictures\sonkram\the brain.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{28a47d84-ecfe-11dc-b386-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\34542.exe
O33 - MountPoints2\{56a52bbf-115f-11e1-a5f0-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\copy.exe
O33 - MountPoints2\{8830768c-ed5a-11dc-b22f-0013775baaa5}\Shell\AutoRun\command - "" = WDSetup.exe
O33 - MountPoints2\{e9538169-f073-11dc-8ecb-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe
O33 - MountPoints2\{f23719ee-790d-11de-bb2c-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpReg: Adobe Photo Downloader - hkey= - key= -  File not found
MsConfig - StartUpReg: Windows Defender - hkey= - key= -  File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - c:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger -  File not found
SafeBootNet: MsMpSvc - c:\Programme\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\SL_ANET.ACM (Sipro Lab Telecom Inc.)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.12 20:55:51 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Hannah\Desktop\OTL.exe
[2012.07.12 10:02:06 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Local\Macromedia
[2012.07.06 09:18:06 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Desktop\Virus
[2012.07.05 21:51:34 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.07.05 17:54:49 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2012.07.05 17:38:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
[2012.07.05 17:17:48 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Desktop\Adobe Acrobat X
[2012.07.04 21:18:24 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2012.07.04 21:13:56 | 000,203,088 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2012.07.04 21:13:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012.07.04 21:13:08 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012.07.04 21:13:05 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Roaming\TestApp
[2012.07.04 16:55:10 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Roaming\Malwarebytes
[2012.07.04 16:55:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.04 16:54:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.04 16:54:47 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.07.04 16:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.07.02 17:01:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Premium
[2012.07.02 17:00:19 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[2012.06.21 15:02:02 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Desktop\Only lovers
[2012.06.16 19:25:59 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.12 20:55:55 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\OTL.exe
[2012.07.12 20:55:02 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.12 20:51:09 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.12 20:50:54 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.12 20:50:54 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.12 20:50:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.12 20:50:38 | 1877,131,264 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.12 18:43:20 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.07.12 18:18:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.12 16:39:35 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2012.07.12 14:02:42 | 000,618,655 | ---- | M] () -- C:\Users\Hannah\Desktop\adwcleaner.exe
[2012.07.12 09:24:47 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012.07.12 09:12:34 | 000,379,952 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.07.04 21:16:16 | 002,282,331 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB
[2012.07.03 12:06:25 | 000,634,602 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.07.03 12:06:25 | 000,601,250 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.07.03 12:06:25 | 000,128,520 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.07.03 12:06:25 | 000,106,164 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.07.02 17:01:18 | 000,000,454 | ---- | M] () -- C:\user.js
[2012.06.21 10:09:08 | 000,332,314 | ---- | M] () -- C:\Users\Hannah\Documents\Urheberrecht.pdf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.12 14:02:24 | 000,618,655 | ---- | C] () -- C:\Users\Hannah\Desktop\adwcleaner.exe
[2012.07.12 09:14:27 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.05 17:38:20 | 000,002,449 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2012.07.05 17:38:20 | 000,002,437 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
[2012.07.05 17:38:20 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012.07.04 21:14:06 | 002,282,331 | ---- | C] () -- C:\Windows\System32\drivers\Cat.DB
[2012.07.02 17:01:17 | 000,000,454 | ---- | C] () -- C:\user.js
[2012.06.21 10:09:07 | 000,332,314 | ---- | C] () -- C:\Users\Hannah\Documents\Urheberrecht.pdf
[2012.01.18 07:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2012.01.18 07:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2012.01.18 07:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2012.01.17 23:33:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012.01.17 23:31:45 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012.01.17 23:31:45 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.12.07 13:10:17 | 000,001,470 | ---- | C] () -- C:\Users\Hannah\AppData\Local\RecConfig.xml
[2011.07.26 07:48:54 | 000,028,418 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2010.11.04 00:33:53 | 000,000,680 | ---- | C] () -- C:\Users\Hannah\AppData\Local\d3d9caps.dat
[2009.07.31 14:37:00 | 000,000,582 | ---- | C] () -- C:\Users\Hannah\AppData\Roaming\AutoGK.ini
[2009.07.06 11:06:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.06.12 07:41:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.03.23 20:34:35 | 000,000,379 | ---- | C] () -- C:\Users\Hannah\AppData\Roaming\burnaware.ini
[2007.12.02 19:41:40 | 000,237,568 | ---- | C] () -- C:\Users\Hannah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== LOP Check ==========
 
[2009.04.13 20:10:49 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AnotherUnzipper
[2009.06.11 17:46:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Installer
[2009.06.11 17:49:16 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Programme
[2008.12.17 12:03:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AvexLab
[2010.12.23 13:38:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canneverbe Limited
[2008.01.23 14:46:31 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canon
[2011.12.09 20:45:04 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoft
[2011.12.09 20:40:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.10.27 18:15:23 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\elsterformular
[2011.12.07 12:11:54 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Free Sound Recorder
[2011.06.18 06:14:08 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\go
[2008.10.11 17:15:47 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ICQ
[2009.11.07 17:53:57 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\IN-MEDIAKG
[2009.06.11 01:53:52 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\SmartDraw
[2011.08.04 19:41:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TeamViewer
[2012.07.04 21:13:05 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TestApp
[2011.03.02 22:51:38 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Thunderbird
[2010.07.28 15:21:13 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\uTorrent
[2012.07.12 18:43:23 | 000,032,510 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2012.07.05 18:00:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Adobe
[2008.02.18 13:08:59 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AdobeUM
[2009.04.13 20:10:49 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AnotherUnzipper
[2012.02.01 23:38:35 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Apple Computer
[2009.06.11 17:46:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Installer
[2009.06.11 17:49:16 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ASCON Programme
[2007.12.01 12:37:47 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ATI
[2008.12.17 12:03:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AvexLab
[2009.06.26 16:12:09 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\AVS4YOU
[2010.12.23 13:38:15 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canneverbe Limited
[2008.01.23 14:46:31 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Canon
[2007.12.12 01:05:17 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\CyberLink
[2008.08.20 10:48:07 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DivX
[2012.05.05 10:01:13 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\dvdcss
[2011.12.09 20:45:04 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoft
[2011.12.09 20:40:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.10.27 18:15:23 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\elsterformular
[2011.12.07 12:11:54 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Free Sound Recorder
[2011.06.18 06:14:08 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\go
[2009.07.25 20:02:36 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Google
[2008.10.11 17:15:47 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ICQ
[2007.12.01 12:36:39 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Identities
[2009.11.07 17:53:57 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\IN-MEDIAKG
[2007.12.31 16:37:14 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Macromedia
[2012.07.04 16:55:10 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Media Center Programs
[2012.07.12 10:02:06 | 000,000,000 | --SD | M] -- C:\Users\Hannah\AppData\Roaming\Microsoft
[2009.05.23 19:52:16 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Move Networks
[2008.08.27 11:15:39 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Mozilla
[2011.12.09 23:28:32 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\NCH Software
[2011.01.13 18:07:57 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\OpenOffice.org2
[2010.08.26 20:40:51 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Real
[2012.07.12 21:00:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Skype
[2011.06.14 07:21:43 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\skypePM
[2009.06.11 01:53:52 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\SmartDraw
[2008.09.15 18:54:39 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Sun
[2011.08.04 19:41:29 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TeamViewer
[2012.07.04 21:13:05 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TestApp
[2011.03.02 22:51:38 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Thunderbird
[2010.07.28 15:21:13 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\uTorrent
[2012.03.08 12:27:05 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\vlc
[2009.04.25 14:36:01 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\WinRAR
[2008.04.12 11:08:14 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\ZoomBrowser EX
 
< %APPDATA%\*.exe /s >
[2007.05.10 10:05:12 | 000,057,344 | ---- | M] (SBS) -- C:\Users\Hannah\AppData\Roaming\ASCON Installer\ASUNINST.EXE
[2007.11.27 09:41:32 | 000,405,504 | ---- | M] () -- C:\Users\Hannah\AppData\Roaming\NCH Software\Components\mp3el2\lame.exe
[2010.08.26 20:40:55 | 000,456,200 | ---- | M] (RealNetworks, Inc.) -- C:\Users\Hannah\AppData\Roaming\Real\Update\setup3.12\setup.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 00:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007.07.11 00:57:39 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=313FF294978EA6AF715722D708FB249F -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\AGP440.sys
[2007.07.11 00:58:01 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2007.07.11 00:58:01 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2007.07.11 00:58:01 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2007.07.11 00:57:39 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f2490cb0\AGP440.sys
[2007.07.11 00:57:39 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 00:32:28 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 00:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 00:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007.07.11 00:58:23 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2007.07.11 00:58:22 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2007.07.11 00:58:22 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.01.19 06:33:23 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 00:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 00:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 00:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 00:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 00:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 00:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.07.11 00:54:56 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2007.07.11 00:54:57 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2008.01.19 00:36:48 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2006.11.02 11:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2009.04.11 00:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 00:28:26 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 00:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 10:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.18 22:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.18 22:56:50 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2007.06.14 05:11:50 | 000,339,968 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\Windows\system32\ATIDEMGX.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:66B13F37
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:6152D44C
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:C980DA7D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >

--- --- ---

mirhannah 12.07.2012 20:43

doppelt, entfernt //cosinus

cosinus 13.07.2012 10:38

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - user.js - File not found
[2008.10.11 17:03:21 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
O3 - HKU\S-1-5-21-4131452526-3298899096-3233267490-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll File not found
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{28a47d84-ecfe-11dc-b386-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\34542.exe
O33 - MountPoints2\{56a52bbf-115f-11e1-a5f0-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\copy.exe
O33 - MountPoints2\{8830768c-ed5a-11dc-b22f-0013775baaa5}\Shell\AutoRun\command - "" = WDSetup.exe
O33 - MountPoints2\{e9538169-f073-11dc-8ecb-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe
O33 - MountPoints2\{f23719ee-790d-11de-bb2c-0013775baaa5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:66B13F37
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:6152D44C
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:C980DA7D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2
:Files
C:\Program Files\kikin
C:\user.js
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

mirhannah 13.07.2012 17:30

tut mir leid, dass ich so doof fragen muss. Aber soll ich jetzt insgesamt 1 oder 2 fix machen?

cosinus 13.07.2012 21:28

Wieso kommst du denn auf zwei :confused:
Meinen Text aus der Box 1:1 kopieren, bei OTL unten einfügen und dann 1x auf Fix klicken

Ist doch klar so in der Anleitung auch beschrieben! :wtf:

mirhannah 13.07.2012 21:44

Ja, sorry :stirn:
Hab das vorhin bei der Arbeit gelesen und gedacht: 1.mache ein OTL-FIX
2. beende alle Programme (...) mache ein OTL-FIX. Dann wären es zwei. :balla:

Also ich lege jetzt los, und poste dir dann die Ergebnisse. Vielen Dank für die Geduld.

Hier die Ergebnisse. (Beim ersten Versuch ist der PC zwischendrin abgestürzt. Das sind jetzt die Ergebnisse vom zweiten Anlauf)

Code:

All processes killed
========== OTL ==========
Prefs.js: "MyStart Search" removed from browser.search.defaultenginename
Prefs.js: "Search" removed from browser.search.defaultthis.engineName
Folder C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\ not found.
Registry value HKEY_USERS\S-1-5-21-4131452526-3298899096-3233267490-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E601996F-E400-41CA-804B-CD6373A7EEE2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
File C:\autoexec.bat not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{28a47d84-ecfe-11dc-b386-0013775baaa5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28a47d84-ecfe-11dc-b386-0013775baaa5}\ not found.
File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\34542.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56a52bbf-115f-11e1-a5f0-0013775baaa5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56a52bbf-115f-11e1-a5f0-0013775baaa5}\ not found.
File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\copy.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8830768c-ed5a-11dc-b22f-0013775baaa5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8830768c-ed5a-11dc-b22f-0013775baaa5}\ not found.
File WDSetup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9538169-f073-11dc-8ecb-0013775baaa5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e9538169-f073-11dc-8ecb-0013775baaa5}\ not found.
File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f23719ee-790d-11de-bb2c-0013775baaa5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f23719ee-790d-11de-bb2c-0013775baaa5}\ not found.
File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\copy.exe not found.
Unable to delete ADS C:\ProgramData\TEMP:430C6D84 .
Unable to delete ADS C:\ProgramData\TEMP:66B13F37 .
Unable to delete ADS C:\ProgramData\TEMP:6152D44C .
Unable to delete ADS C:\ProgramData\TEMP:C980DA7D .
Unable to delete ADS C:\ProgramData\TEMP:DFC5A2B2 .
========== FILES ==========
File\Folder C:\Program Files\kikin not found.
File\Folder C:\user.js not found.
========== COMMANDS ==========
 
[EMPTYTEMP]


mirhannah 17.07.2012 11:27

Hallo Arne, vielen Dank für die Hilfe. Die Symptome sind jetzt verschwunden. heißt das, dass mein PC jetzt wieder sauber ist?
Gruß,
Hannah

cosinus 17.07.2012 15:25

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

mirhannah 17.07.2012 15:51

Code:

16:41:00.0093 3432        TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
16:41:00.0186 3432        ============================================================
16:41:00.0186 3432        Current date / time: 2012/07/17 16:41:00.0186
16:41:00.0186 3432        SystemInfo:
16:41:00.0186 3432       
16:41:00.0186 3432        OS Version: 6.0.6002 ServicePack: 2.0
16:41:00.0186 3432        Product type: Workstation
16:41:00.0186 3432        ComputerName: HANNAH-PC
16:41:00.0186 3432        UserName: Hannah
16:41:00.0186 3432        Windows directory: C:\Windows
16:41:00.0186 3432        System windows directory: C:\Windows
16:41:00.0186 3432        Processor architecture: Intel x86
16:41:00.0186 3432        Number of processors: 2
16:41:00.0186 3432        Page size: 0x1000
16:41:00.0186 3432        Boot type: Normal boot
16:41:00.0186 3432        ============================================================
16:41:01.0450 3432        Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:41:01.0450 3432        ============================================================
16:41:01.0450 3432        \Device\Harddisk0\DR0:
16:41:01.0450 3432        MBR partitions:
16:41:01.0450 3432        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1400800, BlocksNum 0x8A19000
16:41:01.0450 3432        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x9E19800, BlocksNum 0x8BFF800
16:41:01.0450 3432        ============================================================
16:41:01.0481 3432        C: <-> \Device\Harddisk0\DR0\Partition0
16:41:01.0544 3432        D: <-> \Device\Harddisk0\DR0\Partition1
16:41:01.0544 3432        ============================================================
16:41:01.0544 3432        Initialize success
16:41:01.0544 3432        ============================================================
16:43:19.0872 2676        ============================================================
16:43:19.0872 2676        Scan started
16:43:19.0872 2676        Mode: Manual; SigCheck; TDLFS;
16:43:19.0872 2676        ============================================================
16:43:21.0371 2676        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
16:43:21.0542 2676        ACPI - ok
16:43:21.0683 2676        AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
16:43:21.0698 2676        AdobeFlashPlayerUpdateSvc - ok
16:43:21.0776 2676        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
16:43:21.0840 2676        adp94xx - ok
16:43:21.0965 2676        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
16:43:21.0996 2676        adpahci - ok
16:43:22.0105 2676        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
16:43:22.0121 2676        adpu160m - ok
16:43:22.0199 2676        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
16:43:22.0230 2676        adpu320 - ok
16:43:22.0308 2676        AeLookupSvc    (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
16:43:22.0386 2676        AeLookupSvc - ok
16:43:22.0511 2676        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
16:43:22.0604 2676        AFD - ok
16:43:22.0635 2676        AgereModemAudio (39e435c90c9c4f780fa0ed05ca3c3a1b) C:\Windows\system32\agrsmsvc.exe
16:43:22.0698 2676        AgereModemAudio - ok
16:43:23.0058 2676        AgereSoftModem  (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys
16:43:23.0245 2676        AgereSoftModem - ok
16:43:23.0292 2676        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
16:43:23.0323 2676        agp440 - ok
16:43:23.0370 2676        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
16:43:23.0385 2676        aic78xx - ok
16:43:23.0604 2676        ALG            (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
16:43:23.0760 2676        ALG - ok
16:43:23.0995 2676        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
16:43:24.0057 2676        aliide - ok
16:43:24.0119 2676        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
16:43:24.0135 2676        amdagp - ok
16:43:24.0166 2676        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
16:43:24.0182 2676        amdide - ok
16:43:24.0229 2676        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
16:43:24.0447 2676        AmdK7 - ok
16:43:24.0885 2676        AmdK8          (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
16:43:24.0994 2676        AmdK8 - ok
16:43:25.0088 2676        Appinfo        (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
16:43:25.0134 2676        Appinfo - ok
16:43:25.0415 2676        Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:43:25.0431 2676        Apple Mobile Device - ok
16:43:25.0478 2676        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
16:43:25.0493 2676        arc - ok
16:43:25.0556 2676        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
16:43:25.0571 2676        arcsas - ok
16:43:25.0618 2676        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
16:43:25.0696 2676        AsyncMac - ok
16:43:25.0821 2676        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
16:43:25.0836 2676        atapi - ok
16:43:26.0212 2676        athr            (f32fee7cb2ee32c1f808409bc8019701) C:\Windows\system32\DRIVERS\athr.sys
16:43:26.0368 2676        athr - ok
16:43:26.0805 2676        Ati External Event Utility (d29cae8aa91e405a569892fa3d97aa64) C:\Windows\system32\Ati2evxx.exe
16:43:26.0899 2676        Ati External Event Utility - ok
16:43:27.0914 2676        atikmdag        (e46f2fb11cfe13187a4e3ef512c0d226) C:\Windows\system32\DRIVERS\atikmdag.sys
16:43:28.0164 2676        atikmdag - ok
16:43:29.0054 2676        AtiPcie        (4aa1eb65481c392955939e735d27118b) C:\Windows\system32\DRIVERS\AtiPcie.sys
16:43:29.0101 2676        AtiPcie - ok
16:43:29.0257 2676        AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
16:43:29.0335 2676        AudioEndpointBuilder - ok
16:43:29.0350 2676        Audiosrv        (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
16:43:29.0382 2676        Audiosrv - ok
16:43:29.0413 2676        avkmgr - ok
16:43:29.0475 2676        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
16:43:29.0538 2676        Beep - ok
16:43:29.0709 2676        BFE            (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll
16:43:29.0787 2676        BFE - ok
16:43:29.0944 2676        BITS            (93952506c6d67330367f7e7934b6a02f) C:\Windows\System32\qmgr.dll
16:43:30.0038 2676        BITS - ok
16:43:30.0038 2676        blbdrive - ok
16:43:30.0303 2676        Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
16:43:30.0350 2676        Bonjour Service - ok
16:43:30.0631 2676        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
16:43:30.0693 2676        bowser - ok
16:43:30.0740 2676        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
16:43:30.0802 2676        BrFiltLo - ok
16:43:30.0818 2676        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
16:43:30.0896 2676        BrFiltUp - ok
16:43:31.0084 2676        Browser        (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
16:43:31.0162 2676        Browser - ok
16:43:31.0224 2676        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
16:43:31.0318 2676        Brserid - ok
16:43:31.0334 2676        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
16:43:31.0396 2676        BrSerWdm - ok
16:43:31.0427 2676        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
16:43:31.0490 2676        BrUsbMdm - ok
16:43:31.0536 2676        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
16:43:31.0614 2676        BrUsbSer - ok
16:43:31.0677 2676        BthEnum        (064fbc56921051de1075495d628b815f) C:\Windows\system32\DRIVERS\BthEnum.sys
16:43:31.0724 2676        BthEnum - ok
16:43:31.0755 2676        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
16:43:31.0833 2676        BTHMODEM - ok
16:43:31.0942 2676        BthPan          (b8c3d9ddf85fd197c3e5f849fef71144) C:\Windows\system32\DRIVERS\bthpan.sys
16:43:32.0021 2676        BthPan - ok
16:43:32.0099 2676        BTHPORT        (b24757d9154cca035e1bbd3db92966d7) C:\Windows\system32\Drivers\BTHport.sys
16:43:32.0146 2676        BTHPORT - ok
16:43:32.0224 2676        BthServ        (a4c8377fa4a994e07075107dbe2e3dce) C:\Windows\System32\bthserv.dll
16:43:32.0271 2676        BthServ - ok
16:43:32.0302 2676        BTHUSB          (d42cf5f0c7635b3f1578810fe34d9e41) C:\Windows\system32\Drivers\BTHUSB.sys
16:43:32.0333 2676        BTHUSB - ok
16:43:32.0395 2676        btwaudio        (636f45a8500c1438cfa7dee15fc5c184) C:\Windows\system32\drivers\btwaudio.sys
16:43:32.0427 2676        btwaudio - ok
16:43:32.0489 2676        btwavdt        (bf9256ff01b093a5d90bb7a35ec90410) C:\Windows\system32\drivers\btwavdt.sys
16:43:32.0505 2676        btwavdt - ok
16:43:32.0551 2676        btwrchid        (0ab8c1ac177afb27309e1072faf34a37) C:\Windows\system32\DRIVERS\btwrchid.sys
16:43:32.0567 2676        btwrchid - ok
16:43:32.0692 2676        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
16:43:32.0770 2676        cdfs - ok
16:43:32.0863 2676        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
16:43:32.0926 2676        cdrom - ok
16:43:33.0051 2676        CertPropSvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
16:43:33.0144 2676        CertPropSvc - ok
16:43:33.0222 2676        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
16:43:33.0331 2676        circlass - ok
16:43:33.0456 2676        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
16:43:33.0487 2676        CLFS - ok
16:43:33.0581 2676        clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:43:33.0597 2676        clr_optimization_v2.0.50727_32 - ok
16:43:33.0753 2676        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:43:33.0784 2676        clr_optimization_v4.0.30319_32 - ok
16:43:33.0862 2676        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
16:43:33.0924 2676        CmBatt - ok
16:43:33.0987 2676        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
16:43:34.0002 2676        cmdide - ok
16:43:34.0080 2676        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
16:43:34.0096 2676        Compbatt - ok
16:43:34.0111 2676        COMSysApp - ok
16:43:34.0111 2676        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
16:43:34.0143 2676        crcdisk - ok
16:43:34.0158 2676        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
16:43:34.0236 2676        Crusoe - ok
16:43:34.0283 2676        CryptSvc        (75c6a297e364014840b48eccd7525e30) C:\Windows\system32\cryptsvc.dll
16:43:34.0314 2676        CryptSvc - ok
16:43:34.0470 2676        DcomLaunch      (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
16:43:34.0564 2676        DcomLaunch - ok
16:43:34.0704 2676        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
16:43:34.0798 2676        DfsC - ok
16:43:35.0391 2676        DFSR            (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe
16:43:35.0640 2676        DFSR - ok
16:43:36.0046 2676        Dhcp            (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll
16:43:36.0124 2676        Dhcp - ok
16:43:36.0217 2676        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
16:43:36.0249 2676        disk - ok
16:43:36.0311 2676        Dnscache        (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll
16:43:36.0373 2676        Dnscache - ok
16:43:36.0436 2676        dot3svc        (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll
16:43:36.0467 2676        dot3svc - ok
16:43:36.0545 2676        DPS            (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
16:43:36.0607 2676        DPS - ok
16:43:36.0670 2676        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
16:43:36.0701 2676        drmkaud - ok
16:43:36.0810 2676        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
16:43:36.0841 2676        DXGKrnl - ok
16:43:36.0888 2676        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
16:43:36.0997 2676        E1G60 - ok
16:43:37.0060 2676        EapHost        (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
16:43:37.0091 2676        EapHost - ok
16:43:37.0185 2676        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
16:43:37.0200 2676        Ecache - ok
16:43:37.0263 2676        ehRecvr        (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
16:43:37.0325 2676        ehRecvr - ok
16:43:37.0403 2676        ehSched        (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
16:43:37.0450 2676        ehSched - ok
16:43:37.0481 2676        ehstart        (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
16:43:37.0512 2676        ehstart - ok
16:43:37.0590 2676        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
16:43:37.0637 2676        elxstor - ok
16:43:37.0746 2676        EMDMgmt        (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll
16:43:37.0840 2676        EMDMgmt - ok
16:43:37.0887 2676        EventSystem    (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll
16:43:37.0949 2676        EventSystem - ok
16:43:38.0011 2676        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
16:43:38.0089 2676        exfat - ok
16:43:38.0136 2676        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
16:43:38.0167 2676        fastfat - ok
16:43:38.0230 2676        fdc            (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
16:43:38.0323 2676        fdc - ok
16:43:38.0355 2676        fdPHost        (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
16:43:38.0386 2676        fdPHost - ok
16:43:38.0401 2676        FDResPub        (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
16:43:38.0479 2676        FDResPub - ok
16:43:38.0526 2676        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
16:43:38.0542 2676        FileInfo - ok
16:43:38.0557 2676        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
16:43:38.0604 2676        Filetrace - ok
16:43:38.0651 2676        flpydisk        (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
16:43:38.0729 2676        flpydisk - ok
16:43:38.0854 2676        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
16:43:38.0885 2676        FltMgr - ok
16:43:39.0088 2676        FontCache      (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll
16:43:39.0197 2676        FontCache - ok
16:43:39.0306 2676        FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
16:43:39.0337 2676        FontCache3.0.0.0 - ok
16:43:39.0369 2676        Fs_Rec          (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys
16:43:39.0431 2676        Fs_Rec - ok
16:43:39.0493 2676        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
16:43:39.0525 2676        gagp30kx - ok
16:43:39.0587 2676        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
16:43:39.0603 2676        GEARAspiWDM - ok
16:43:39.0743 2676        gpsvc          (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll
16:43:39.0868 2676        gpsvc - ok
16:43:40.0133 2676        gupdate        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
16:43:40.0149 2676        gupdate - ok
16:43:40.0149 2676        gupdatem        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
16:43:40.0180 2676        gupdatem - ok
16:43:40.0242 2676        HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
16:43:40.0351 2676        HdAudAddService - ok
16:43:40.0523 2676        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:43:40.0648 2676        HDAudBus - ok
16:43:40.0663 2676        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
16:43:40.0788 2676        HidBth - ok
16:43:40.0897 2676        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
16:43:41.0007 2676        HidIr - ok
16:43:41.0100 2676        hidserv        (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll
16:43:41.0163 2676        hidserv - ok
16:43:41.0303 2676        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
16:43:41.0365 2676        HidUsb - ok
16:43:41.0443 2676        hkmsvc          (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
16:43:41.0521 2676        hkmsvc - ok
16:43:41.0755 2676        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
16:43:41.0771 2676        HpCISSs - ok
16:43:41.0896 2676        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
16:43:42.0005 2676        HTTP - ok
16:43:42.0145 2676        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
16:43:42.0161 2676        i2omp - ok
16:43:42.0255 2676        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
16:43:42.0301 2676        i8042prt - ok
16:43:42.0411 2676        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
16:43:42.0442 2676        iaStorV - ok
16:43:42.0660 2676        IDriverT        (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
16:43:42.0691 2676        IDriverT ( UnsignedFile.Multi.Generic ) - warning
16:43:42.0691 2676        IDriverT - detected UnsignedFile.Multi.Generic (1)
16:43:42.0910 2676        idsvc          (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
16:43:43.0035 2676        idsvc - ok
16:43:43.0471 2676        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
16:43:43.0487 2676        iirsp - ok
16:43:43.0705 2676        IKEEXT          (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll
16:43:43.0783 2676        IKEEXT - ok
16:43:44.0423 2676        IntcAzAudAddService (7bd4e0428776d11c8e8e26f9f5508690) C:\Windows\system32\drivers\RTKVHDA.sys
16:43:44.0595 2676        IntcAzAudAddService - ok
16:43:45.0577 2676        intelide        (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
16:43:45.0593 2676        intelide - ok
16:43:45.0671 2676        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
16:43:45.0733 2676        intelppm - ok
16:43:45.0796 2676        IPBusEnum      (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
16:43:45.0843 2676        IPBusEnum - ok
16:43:45.0874 2676        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:43:45.0921 2676        IpFilterDriver - ok
16:43:46.0201 2676        iphlpsvc        (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll
16:43:46.0264 2676        iphlpsvc - ok
16:43:46.0264 2676        IpInIp - ok
16:43:46.0420 2676        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
16:43:46.0513 2676        IPMIDRV - ok
16:43:46.0591 2676        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
16:43:46.0654 2676        IPNAT - ok
16:43:47.0075 2676        iPod Service    (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe
16:43:47.0184 2676        iPod Service - ok
16:43:47.0293 2676        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
16:43:47.0340 2676        IRENUM - ok
16:43:47.0512 2676        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
16:43:47.0543 2676        isapnp - ok
16:43:47.0652 2676        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
16:43:47.0683 2676        iScsiPrt - ok
16:43:47.0777 2676        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
16:43:47.0808 2676        iteatapi - ok
16:43:47.0980 2676        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
16:43:48.0027 2676        iteraid - ok
16:43:48.0167 2676        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
16:43:48.0183 2676        kbdclass - ok
16:43:48.0261 2676        kbdhid          (d2600cb17b7408b4a83f231dc9a11ac3) C:\Windows\system32\DRIVERS\kbdhid.sys
16:43:48.0370 2676        kbdhid - ok
16:43:48.0573 2676        KeyIso          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:43:48.0666 2676        KeyIso - ok
16:43:48.0729 2676        KMDFMEMIO      (ebc507f129df8f0e0ca270dcfc0cf87f) C:\Windows\system32\DRIVERS\kmdfmemio.sys
16:43:48.0775 2676        KMDFMEMIO - ok
16:43:49.0056 2676        KSecDD          (4a1445efa932a3baf5bdb02d7131ee20) C:\Windows\system32\Drivers\ksecdd.sys
16:43:49.0119 2676        KSecDD - ok
16:43:49.0197 2676        KtmRm          (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
16:43:49.0337 2676        KtmRm - ok
16:43:49.0555 2676        LanmanServer    (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll
16:43:49.0649 2676        LanmanServer - ok
16:43:49.0836 2676        LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll
16:43:49.0914 2676        LanmanWorkstation - ok
16:43:50.0226 2676        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
16:43:50.0273 2676        lltdio - ok
16:43:50.0507 2676        lltdsvc        (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
16:43:50.0585 2676        lltdsvc - ok
16:43:50.0741 2676        lmhosts        (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
16:43:50.0819 2676        lmhosts - ok
16:43:50.0897 2676        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
16:43:50.0928 2676        LSI_FC - ok
16:43:51.0053 2676        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
16:43:51.0069 2676        LSI_SAS - ok
16:43:51.0178 2676        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
16:43:51.0209 2676        LSI_SCSI - ok
16:43:51.0334 2676        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
16:43:51.0396 2676        luafv - ok
16:43:51.0474 2676        LVRS            (ed643e777ba3f7151ef3f0fb6be4f7f0) C:\Windows\system32\DRIVERS\lvrs.sys
16:43:51.0521 2676        LVRS - ok
16:43:52.0535 2676        LVUVC          (5bc80451109a8dd7f2ddd35bce2929a3) C:\Windows\system32\DRIVERS\lvuvc.sys
16:43:52.0878 2676        LVUVC - ok
16:43:53.0299 2676        MBAMProtector  (6dfe7f2e8e8a337263aa5c92a215f161) C:\Windows\system32\drivers\mbam.sys
16:43:53.0315 2676        MBAMProtector - ok
16:43:53.0518 2676        MBAMService    (43683e970f008c93c9429ef428147a54) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
16:43:53.0627 2676        MBAMService - ok
16:43:53.0845 2676        McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
16:43:53.0877 2676        McComponentHostService - ok
16:43:54.0001 2676        Mcx2Svc        (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
16:43:54.0048 2676        Mcx2Svc - ok
16:43:54.0282 2676        MDM            (11f714f85530a2bd134074dc30e99fca) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
16:43:54.0313 2676        MDM - ok
16:43:54.0501 2676        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
16:43:54.0532 2676        megasas - ok
16:43:54.0641 2676        MMCSS          (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
16:43:54.0688 2676        MMCSS - ok
16:43:54.0766 2676        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
16:43:54.0813 2676        Modem - ok
16:43:54.0875 2676        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
16:43:54.0906 2676        monitor - ok
16:43:55.0031 2676        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
16:43:55.0047 2676        mouclass - ok
16:43:55.0062 2676        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
16:43:55.0109 2676        mouhid - ok
16:43:55.0203 2676        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
16:43:55.0218 2676        MountMgr - ok
16:43:55.0281 2676        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
16:43:55.0296 2676        MozillaMaintenance - ok
16:43:55.0343 2676        MpFilter        (d993bea500e7382dc4e760bf4f35efcb) C:\Windows\system32\DRIVERS\MpFilter.sys
16:43:55.0359 2676        MpFilter - ok
16:43:55.0405 2676        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
16:43:55.0421 2676        mpio - ok
16:43:55.0546 2676        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
16:43:55.0593 2676        mpsdrv - ok
16:43:55.0671 2676        MpsSvc          (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll
16:43:55.0749 2676        MpsSvc - ok
16:43:55.0795 2676        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
16:43:55.0811 2676        Mraid35x - ok
16:43:55.0858 2676        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
16:43:55.0889 2676        MRxDAV - ok
16:43:55.0983 2676        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:43:56.0045 2676        mrxsmb - ok
16:43:56.0170 2676        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:43:56.0217 2676        mrxsmb10 - ok
16:43:56.0248 2676        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:43:56.0295 2676        mrxsmb20 - ok
16:43:56.0419 2676        msahci          (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
16:43:56.0451 2676        msahci - ok
16:43:56.0591 2676        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
16:43:56.0607 2676        msdsm - ok
16:43:56.0747 2676        MSDTC          (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
16:43:56.0825 2676        MSDTC - ok
16:43:56.0887 2676        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
16:43:56.0934 2676        Msfs - ok
16:43:57.0012 2676        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
16:43:57.0028 2676        msisadrv - ok
16:43:57.0168 2676        MSiSCSI        (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
16:43:57.0246 2676        MSiSCSI - ok
16:43:57.0246 2676        msiserver - ok
16:43:57.0324 2676        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
16:43:57.0387 2676        MSKSSRV - ok
16:43:57.0558 2676        MsMpSvc        (24516bf4e12a46cb67302e2cdcb8cddf) c:\Program Files\Microsoft Security Client\MsMpEng.exe
16:43:57.0574 2676        MsMpSvc - ok
16:43:57.0652 2676        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
16:43:57.0745 2676        MSPCLOCK - ok
16:43:57.0792 2676        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
16:43:57.0855 2676        MSPQM - ok
16:43:57.0964 2676        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
16:43:57.0995 2676        MsRPC - ok
16:43:58.0120 2676        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
16:43:58.0151 2676        mssmbios - ok
16:43:58.0198 2676        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
16:43:58.0291 2676        MSTEE - ok
16:43:58.0338 2676        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
16:43:58.0354 2676        Mup - ok
16:43:58.0510 2676        napagent        (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll
16:43:58.0603 2676        napagent - ok
16:43:58.0744 2676        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
16:43:58.0806 2676        NativeWifiP - ok
16:43:59.0071 2676        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
16:43:59.0149 2676        NDIS - ok
16:43:59.0243 2676        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
16:43:59.0290 2676        NdisTapi - ok
16:43:59.0337 2676        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
16:43:59.0383 2676        Ndisuio - ok
16:43:59.0524 2676        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
16:43:59.0602 2676        NdisWan - ok
16:43:59.0649 2676        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
16:43:59.0680 2676        NDProxy - ok
16:43:59.0773 2676        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
16:43:59.0836 2676        NetBIOS - ok
16:43:59.0914 2676        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
16:43:59.0976 2676        netbt - ok
16:44:00.0117 2676        Netlogon        (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:44:00.0132 2676        Netlogon - ok
16:44:00.0226 2676        Netman          (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
16:44:00.0304 2676        Netman - ok
16:44:00.0366 2676        netprofm        (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
16:44:00.0429 2676        netprofm - ok
16:44:00.0569 2676        NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:44:00.0585 2676        NetTcpPortSharing - ok
16:44:01.0006 2676        NETw2v32        (6e9edc1020b319e7676387b8cdf2398c) C:\Windows\system32\DRIVERS\NETw2v32.sys
16:44:01.0365 2676        NETw2v32 - ok
16:44:01.0692 2676        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
16:44:01.0708 2676        nfrd960 - ok
16:44:01.0755 2676        NisDrv          (b52f26bade7d7e4a79706e3fd91834cd) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
16:44:01.0770 2676        NisDrv - ok
16:44:01.0942 2676        NisSrv          (290c0d4c4889398797f8df3be00b9698) c:\Program Files\Microsoft Security Client\NisSrv.exe
16:44:01.0957 2676        NisSrv - ok
16:44:02.0051 2676        NlaSvc          (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
16:44:02.0145 2676        NlaSvc - ok
16:44:02.0207 2676        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
16:44:02.0238 2676        Npfs - ok
16:44:02.0316 2676        nsi            (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
16:44:02.0363 2676        nsi - ok
16:44:02.0394 2676        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
16:44:02.0457 2676        nsiproxy - ok
16:44:02.0628 2676        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
16:44:02.0691 2676        Ntfs - ok
16:44:02.0753 2676        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
16:44:02.0831 2676        ntrigdigi - ok
16:44:02.0847 2676        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
16:44:02.0878 2676        Null - ok
16:44:02.0940 2676        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
16:44:02.0956 2676        nvraid - ok
16:44:03.0034 2676        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
16:44:03.0049 2676        nvstor - ok
16:44:03.0112 2676        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
16:44:03.0127 2676        nv_agp - ok
16:44:03.0127 2676        NwlnkFlt - ok
16:44:03.0143 2676        NwlnkFwd - ok
16:44:03.0174 2676        ohci1394        (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys
16:44:03.0237 2676        ohci1394 - ok
16:44:03.0330 2676        ose            (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:44:03.0346 2676        ose - ok
16:44:03.0486 2676        p2pimsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:03.0595 2676        p2pimsvc - ok
16:44:03.0611 2676        p2psvc          (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:03.0658 2676        p2psvc - ok
16:44:03.0720 2676        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
16:44:03.0798 2676        Parport - ok
16:44:03.0845 2676        partmgr        (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys
16:44:03.0861 2676        partmgr - ok
16:44:03.0892 2676        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
16:44:03.0985 2676        Parvdm - ok
16:44:04.0110 2676        PcaSvc          (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
16:44:04.0204 2676        PcaSvc - ok
16:44:04.0235 2676        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
16:44:04.0266 2676        pci - ok
16:44:04.0313 2676        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
16:44:04.0344 2676        pciide - ok
16:44:04.0391 2676        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\DRIVERS\pcmcia.sys
16:44:04.0407 2676        pcmcia - ok
16:44:04.0563 2676        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
16:44:04.0672 2676        PEAUTH - ok
16:44:04.0999 2676        pla            (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
16:44:05.0124 2676        pla - ok
16:44:05.0452 2676        PlugPlay        (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll
16:44:05.0499 2676        PlugPlay - ok
16:44:05.0701 2676        PNRPAutoReg    (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:05.0764 2676        PNRPAutoReg - ok
16:44:05.0779 2676        PNRPsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:05.0826 2676        PNRPsvc - ok
16:44:05.0920 2676        PolicyAgent    (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll
16:44:06.0013 2676        PolicyAgent - ok
16:44:06.0123 2676        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
16:44:06.0169 2676        PptpMiniport - ok
16:44:06.0216 2676        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
16:44:06.0325 2676        Processor - ok
16:44:06.0419 2676        ProfSvc        (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll
16:44:06.0450 2676        ProfSvc - ok
16:44:06.0497 2676        ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:44:06.0528 2676        ProtectedStorage - ok
16:44:06.0575 2676        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
16:44:06.0653 2676        PSched - ok
16:44:06.0700 2676        PxHelp20        (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys
16:44:06.0715 2676        PxHelp20 - ok
16:44:06.0856 2676        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
16:44:06.0965 2676        ql2300 - ok
16:44:07.0027 2676        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
16:44:07.0043 2676        ql40xx - ok
16:44:07.0105 2676        QWAVE          (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
16:44:07.0137 2676        QWAVE - ok
16:44:07.0183 2676        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
16:44:07.0215 2676        QWAVEdrv - ok
16:44:07.0542 2676        R300            (e46f2fb11cfe13187a4e3ef512c0d226) C:\Windows\system32\DRIVERS\atikmdag.sys
16:44:07.0683 2676        R300 - ok
16:44:07.0948 2676        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
16:44:08.0010 2676        RasAcd - ok
16:44:08.0057 2676        RasAuto        (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
16:44:08.0135 2676        RasAuto - ok
16:44:08.0166 2676        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:44:08.0213 2676        Rasl2tp - ok
16:44:08.0291 2676        RasMan          (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll
16:44:08.0369 2676        RasMan - ok
16:44:08.0447 2676        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
16:44:08.0494 2676        RasPppoe - ok
16:44:08.0556 2676        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
16:44:08.0587 2676        RasSstp - ok
16:44:08.0650 2676        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
16:44:08.0697 2676        rdbss - ok
16:44:08.0728 2676        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:44:08.0790 2676        RDPCDD - ok
16:44:08.0868 2676        rdpdr          (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
16:44:08.0977 2676        rdpdr - ok
16:44:08.0977 2676        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
16:44:09.0024 2676        RDPENCDD - ok
16:44:09.0102 2676        RDPWD          (c127ebd5afab31524662c48dfceb773a) C:\Windows\system32\drivers\RDPWD.sys
16:44:09.0149 2676        RDPWD - ok
16:44:09.0243 2676        RemoteAccess    (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
16:44:09.0289 2676        RemoteAccess - ok
16:44:09.0352 2676        RemoteRegistry  (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll
16:44:09.0414 2676        RemoteRegistry - ok
16:44:09.0461 2676        RFCOMM          (7ec90c316177ba3f1bce92005264b447) C:\Windows\system32\DRIVERS\rfcomm.sys
16:44:09.0523 2676        RFCOMM - ok
16:44:09.0679 2676        RichVideo      (2af094b1ce4725e4551f38fda2348637) C:\Program Files\CyberLink\Shared Files\RichVideo.exe
16:44:09.0726 2676        RichVideo ( UnsignedFile.Multi.Generic ) - warning
16:44:09.0726 2676        RichVideo - detected UnsignedFile.Multi.Generic (1)
16:44:09.0742 2676        RpcLocator      (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
16:44:09.0804 2676        RpcLocator - ok
16:44:09.0929 2676        RpcSs          (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
16:44:09.0991 2676        RpcSs - ok
16:44:10.0054 2676        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
16:44:10.0101 2676        rspndr - ok
16:44:10.0147 2676        RTL8023xp      (959ef612d2ccfdb6d9e443f8e3655013) C:\Windows\system32\DRIVERS\Rtnicxp.sys
16:44:10.0210 2676        RTL8023xp - ok
16:44:10.0257 2676        SamSs          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:44:10.0272 2676        SamSs - ok
16:44:10.0397 2676        Samsung Update Plus (4bfb51cdb25d4d4b9e8fccab635f262e) C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
16:44:10.0444 2676        Samsung Update Plus ( UnsignedFile.Multi.Generic ) - warning
16:44:10.0444 2676        Samsung Update Plus - detected UnsignedFile.Multi.Generic (1)
16:44:10.0475 2676        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
16:44:10.0491 2676        sbp2port - ok
16:44:10.0553 2676        SCardSvr        (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll
16:44:10.0631 2676        SCardSvr - ok
16:44:10.0740 2676        Schedule        (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll
16:44:10.0881 2676        Schedule - ok
16:44:10.0927 2676        SCPolicySvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
16:44:10.0959 2676        SCPolicySvc - ok
16:44:11.0068 2676        sdbus          (4339a2585708c7d9b0c0ce5aad3dd6ff) C:\Windows\system32\DRIVERS\sdbus.sys
16:44:11.0161 2676        sdbus - ok
16:44:11.0224 2676        SDRSVC          (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
16:44:11.0286 2676        SDRSVC - ok
16:44:11.0317 2676        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
16:44:11.0411 2676        secdrv - ok
16:44:11.0427 2676        seclogon        (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
16:44:11.0473 2676        seclogon - ok
16:44:11.0567 2676        SENS            (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
16:44:11.0614 2676        SENS - ok
16:44:11.0676 2676        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
16:44:11.0754 2676        Serenum - ok
16:44:11.0817 2676        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
16:44:11.0895 2676        Serial - ok
16:44:11.0988 2676        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
16:44:12.0019 2676        sermouse - ok
16:44:12.0191 2676        SessionEnv      (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
16:44:12.0238 2676        SessionEnv - ok
16:44:12.0363 2676        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
16:44:12.0456 2676        sffdisk - ok
16:44:12.0565 2676        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
16:44:12.0643 2676        sffp_mmc - ok
16:44:12.0721 2676        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
16:44:12.0799 2676        sffp_sd - ok
16:44:12.0831 2676        sfloppy        (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys
16:44:12.0877 2676        sfloppy - ok
16:44:12.0971 2676        SharedAccess    (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
16:44:13.0018 2676        SharedAccess - ok
16:44:13.0111 2676        ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll
16:44:13.0174 2676        ShellHWDetection - ok
16:44:13.0221 2676        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
16:44:13.0236 2676        sisagp - ok
16:44:13.0267 2676        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
16:44:13.0283 2676        SiSRaid2 - ok
16:44:13.0314 2676        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
16:44:13.0345 2676        SiSRaid4 - ok
16:44:13.0470 2676        SkypeUpdate    (ddaa5f4a6b958fc313ebd02dd925752f) C:\Program Files\Skype\Updater\Updater.exe
16:44:13.0486 2676        SkypeUpdate - ok
16:44:13.0938 2676        slsvc          (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe
16:44:14.0266 2676        slsvc - ok
16:44:14.0500 2676        SLUINotify      (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll
16:44:14.0578 2676        SLUINotify - ok
16:44:14.0656 2676        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
16:44:14.0749 2676        Smb - ok
16:44:14.0796 2676        SNMPTRAP        (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
16:44:14.0827 2676        SNMPTRAP - ok
16:44:14.0905 2676        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
16:44:14.0921 2676        spldr - ok
16:44:14.0999 2676        Spooler        (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe
16:44:15.0061 2676        Spooler - ok
16:44:15.0186 2676        SQLWriter      (d2f4f32b59440011174b4f8137af4e0c) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
16:44:15.0202 2676        SQLWriter - ok
16:44:15.0327 2676        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
16:44:15.0405 2676        srv - ok
16:44:15.0451 2676        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
16:44:15.0514 2676        srv2 - ok
16:44:15.0545 2676        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
16:44:15.0576 2676        srvnet - ok
16:44:15.0654 2676        SSDPSRV        (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
16:44:15.0701 2676        SSDPSRV - ok
16:44:15.0748 2676        SstpSvc        (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
16:44:15.0795 2676        SstpSvc - ok
16:44:15.0888 2676        stisvc          (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll
16:44:15.0982 2676        stisvc - ok
16:44:16.0044 2676        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
16:44:16.0060 2676        swenum - ok
16:44:16.0153 2676        swprv          (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll
16:44:16.0231 2676        swprv - ok
16:44:16.0309 2676        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
16:44:16.0341 2676        Symc8xx - ok
16:44:16.0356 2676        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
16:44:16.0387 2676        Sym_hi - ok
16:44:16.0419 2676        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
16:44:16.0450 2676        Sym_u3 - ok
16:44:16.0528 2676        SynTP          (c1777074592bbb55b1f1a2fbc7a60498) C:\Windows\system32\DRIVERS\SynTP.sys
16:44:16.0543 2676        SynTP - ok
16:44:16.0621 2676        SysMain        (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll
16:44:16.0684 2676        SysMain - ok
16:44:16.0731 2676        TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
16:44:16.0793 2676        TabletInputService - ok
16:44:16.0902 2676        TapiSrv        (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll
16:44:16.0980 2676        TapiSrv - ok
16:44:17.0043 2676        TBS            (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
16:44:17.0105 2676        TBS - ok
16:44:17.0245 2676        Tcpip          (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys
16:44:17.0355 2676        Tcpip - ok
16:44:17.0370 2676        Tcpip6          (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys
16:44:17.0417 2676        Tcpip6 - ok
16:44:17.0464 2676        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
16:44:17.0495 2676        tcpipreg - ok
16:44:17.0557 2676        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
16:44:17.0589 2676        TDPIPE - ok
16:44:17.0651 2676        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
16:44:17.0698 2676        TDTCP - ok
16:44:17.0760 2676        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
16:44:17.0823 2676        tdx - ok
16:44:17.0947 2676        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
16:44:17.0963 2676        TermDD - ok
16:44:18.0072 2676        TermService    (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll
16:44:18.0166 2676        TermService - ok
16:44:18.0228 2676        Themes          (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll
16:44:18.0259 2676        Themes - ok
16:44:18.0291 2676        THREADORDER    (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
16:44:18.0322 2676        THREADORDER - ok
16:44:18.0369 2676        TrkWks          (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
16:44:18.0415 2676        TrkWks - ok
16:44:18.0540 2676        TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe
16:44:18.0571 2676        TrustedInstaller - ok
16:44:18.0603 2676        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:44:18.0665 2676        tssecsrv - ok
16:44:18.0696 2676        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
16:44:18.0727 2676        tunmp - ok
16:44:18.0743 2676        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
16:44:18.0774 2676        tunnel - ok
16:44:18.0805 2676        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
16:44:18.0821 2676        uagp35 - ok
16:44:18.0883 2676        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
16:44:18.0930 2676        udfs - ok
16:44:19.0039 2676        UI0Detect      (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
16:44:19.0086 2676        UI0Detect - ok
16:44:19.0117 2676        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
16:44:19.0133 2676        uliagpkx - ok
16:44:19.0195 2676        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
16:44:19.0227 2676        uliahci - ok
16:44:19.0305 2676        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
16:44:19.0336 2676        UlSata - ok
16:44:19.0398 2676        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
16:44:19.0414 2676        ulsata2 - ok
16:44:19.0476 2676        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
16:44:19.0523 2676        umbus - ok
16:44:19.0663 2676        UMVPFSrv        (67a95b9d129ed5399e7965cd09cf30e7) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
16:44:19.0710 2676        UMVPFSrv - ok
16:44:19.0866 2676        upnphost        (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
16:44:19.0975 2676        upnphost - ok
16:44:20.0022 2676        USBAAPL        (eafe1e00739afe6c51487a050e772e17) C:\Windows\system32\Drivers\usbaapl.sys
16:44:20.0069 2676        USBAAPL - ok
16:44:20.0163 2676        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
16:44:20.0225 2676        usbaudio - ok
16:44:20.0287 2676        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
16:44:20.0350 2676        usbccgp - ok
16:44:20.0397 2676        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
16:44:20.0475 2676        usbcir - ok
16:44:20.0506 2676        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
16:44:20.0553 2676        usbehci - ok
16:44:20.0584 2676        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
16:44:20.0646 2676        usbhub - ok
16:44:20.0693 2676        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
16:44:20.0740 2676        usbohci - ok
16:44:20.0818 2676        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
16:44:20.0865 2676        usbprint - ok
16:44:20.0974 2676        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:44:21.0005 2676        USBSTOR - ok
16:44:21.0052 2676        usbuhci        (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
16:44:21.0130 2676        usbuhci - ok
16:44:21.0208 2676        usbvideo        (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
16:44:21.0286 2676        usbvideo - ok
16:44:21.0379 2676        UxSms          (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll
16:44:21.0442 2676        UxSms - ok
16:44:21.0535 2676        vds            (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe
16:44:21.0645 2676        vds - ok
16:44:21.0707 2676        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
16:44:21.0754 2676        vga - ok
16:44:21.0832 2676        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
16:44:21.0879 2676        VgaSave - ok
16:44:21.0910 2676        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
16:44:21.0941 2676        viaagp - ok
16:44:21.0957 2676        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
16:44:22.0081 2676        ViaC7 - ok
16:44:22.0097 2676        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
16:44:22.0113 2676        viaide - ok
16:44:22.0175 2676        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
16:44:22.0191 2676        volmgr - ok
16:44:22.0300 2676        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
16:44:22.0331 2676        volmgrx - ok
16:44:22.0378 2676        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
16:44:22.0409 2676        volsnap - ok
16:44:22.0440 2676        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
16:44:22.0456 2676        vsmraid - ok
16:44:22.0627 2676        VSS            (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe
16:44:22.0768 2676        VSS - ok
16:44:23.0002 2676        W32Time        (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll
16:44:23.0080 2676        W32Time - ok
16:44:23.0173 2676        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
16:44:23.0236 2676        WacomPen - ok
16:44:23.0298 2676        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:44:23.0345 2676        Wanarp - ok
16:44:23.0345 2676        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:44:23.0376 2676        Wanarpv6 - ok
16:44:23.0470 2676        wcncsvc        (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll
16:44:23.0501 2676        wcncsvc - ok
16:44:23.0563 2676        WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
16:44:23.0595 2676        WcsPlugInService - ok
16:44:23.0626 2676        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
16:44:23.0641 2676        Wd - ok
16:44:23.0797 2676        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
16:44:23.0829 2676        Wdf01000 - ok
16:44:23.0922 2676        WdiServiceHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
16:44:24.0000 2676        WdiServiceHost - ok
16:44:24.0016 2676        WdiSystemHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
16:44:24.0063 2676        WdiSystemHost - ok
16:44:24.0125 2676        WebClient      (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll
16:44:24.0187 2676        WebClient - ok
16:44:24.0250 2676        Wecsvc          (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
16:44:24.0297 2676        Wecsvc - ok
16:44:24.0375 2676        wercplsupport  (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
16:44:24.0437 2676        wercplsupport - ok
16:44:24.0499 2676        WerSvc          (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll
16:44:24.0546 2676        WerSvc - ok
16:44:24.0702 2676        WinDefend      (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
16:44:24.0733 2676        WinDefend - ok
16:44:24.0733 2676        WinHttpAutoProxySvc - ok
16:44:24.0843 2676        Winmgmt        (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll
16:44:24.0874 2676        Winmgmt - ok
16:44:25.0123 2676        WinRM          (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
16:44:25.0233 2676        WinRM - ok
16:44:25.0326 2676        Wlansvc        (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll
16:44:25.0404 2676        Wlansvc - ok
16:44:25.0529 2676        WmiAcpi        (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
16:44:25.0623 2676        WmiAcpi - ok
16:44:25.0763 2676        wmiApSrv        (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe
16:44:25.0810 2676        wmiApSrv - ok
16:44:26.0013 2676        WMPNetworkSvc  (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
16:44:26.0106 2676        WMPNetworkSvc - ok
16:44:26.0184 2676        WPCSvc          (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll
16:44:26.0247 2676        WPCSvc - ok
16:44:26.0293 2676        WPDBusEnum      (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll
16:44:26.0340 2676        WPDBusEnum - ok
16:44:26.0465 2676        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
16:44:26.0481 2676        WpdUsb - ok
16:44:26.0824 2676        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
16:44:26.0886 2676        WPFFontCache_v0400 - ok
16:44:26.0933 2676        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
16:44:26.0980 2676        ws2ifsl - ok
16:44:27.0042 2676        wscsvc          (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\System32\wscsvc.dll
16:44:27.0073 2676        wscsvc - ok
16:44:27.0120 2676        WSDPrintDevice  (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys
16:44:27.0151 2676        WSDPrintDevice - ok
16:44:27.0214 2676        WSDScan        (65d1ff8aaff4a7d8f787a290e5087816) C:\Windows\system32\DRIVERS\WSDScan.sys
16:44:27.0261 2676        WSDScan - ok
16:44:27.0261 2676        WSearch - ok
16:44:27.0666 2676        wuauserv        (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll
16:44:27.0822 2676        wuauserv - ok
16:44:28.0197 2676        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:44:28.0275 2676        WUDFRd - ok
16:44:28.0321 2676        wudfsvc        (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
16:44:28.0384 2676        wudfsvc - ok
16:44:28.0462 2676        yukonwlh        (04e268adfc81964c49dc0c082d520f7e) C:\Windows\system32\DRIVERS\yk60x86.sys
16:44:28.0509 2676        yukonwlh - ok
16:44:28.0540 2676        MBR (0x1B8)    (61a349592c4728853f4a90ff78f7628e) \Device\Harddisk0\DR0
16:44:29.0367 2676        \Device\Harddisk0\DR0 - ok
16:44:29.0398 2676        Boot (0x1200)  (2d3c8d6b7dd7b6f8b97b0afa65d62e88) \Device\Harddisk0\DR0\Partition0
16:44:29.0476 2676        \Device\Harddisk0\DR0\Partition0 - ok
16:44:29.0507 2676        Boot (0x1200)  (c9074faa7fa3743eae28f3b181586712) \Device\Harddisk0\DR0\Partition1
16:44:29.0507 2676        \Device\Harddisk0\DR0\Partition1 - ok
16:44:29.0507 2676        ============================================================
16:44:29.0507 2676        Scan finished
16:44:29.0507 2676        ============================================================
16:44:29.0523 5184        Detected object count: 3
16:44:29.0523 5184        Actual detected object count: 3


cosinus 18.07.2012 15:22

Log ist unvollständig!! Die untere Zusammenfassung fehlt!

mirhannah 18.07.2012 15:24

so besser?

Code:

16:41:00.0093 3432        TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
16:41:00.0186 3432        ============================================================
16:41:00.0186 3432        Current date / time: 2012/07/17 16:41:00.0186
16:41:00.0186 3432        SystemInfo:
16:41:00.0186 3432       
16:41:00.0186 3432        OS Version: 6.0.6002 ServicePack: 2.0
16:41:00.0186 3432        Product type: Workstation
16:41:00.0186 3432        ComputerName: HANNAH-PC
16:41:00.0186 3432        UserName: Hannah
16:41:00.0186 3432        Windows directory: C:\Windows
16:41:00.0186 3432        System windows directory: C:\Windows
16:41:00.0186 3432        Processor architecture: Intel x86
16:41:00.0186 3432        Number of processors: 2
16:41:00.0186 3432        Page size: 0x1000
16:41:00.0186 3432        Boot type: Normal boot
16:41:00.0186 3432        ============================================================
16:41:01.0450 3432        Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:41:01.0450 3432        ============================================================
16:41:01.0450 3432        \Device\Harddisk0\DR0:
16:41:01.0450 3432        MBR partitions:
16:41:01.0450 3432        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1400800, BlocksNum 0x8A19000
16:41:01.0450 3432        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x9E19800, BlocksNum 0x8BFF800
16:41:01.0450 3432        ============================================================
16:41:01.0481 3432        C: <-> \Device\Harddisk0\DR0\Partition0
16:41:01.0544 3432        D: <-> \Device\Harddisk0\DR0\Partition1
16:41:01.0544 3432        ============================================================
16:41:01.0544 3432        Initialize success
16:41:01.0544 3432        ============================================================
16:43:19.0872 2676        ============================================================
16:43:19.0872 2676        Scan started
16:43:19.0872 2676        Mode: Manual; SigCheck; TDLFS;
16:43:19.0872 2676        ============================================================
16:43:21.0371 2676        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
16:43:21.0542 2676        ACPI - ok
16:43:21.0683 2676        AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
16:43:21.0698 2676        AdobeFlashPlayerUpdateSvc - ok
16:43:21.0776 2676        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
16:43:21.0840 2676        adp94xx - ok
16:43:21.0965 2676        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
16:43:21.0996 2676        adpahci - ok
16:43:22.0105 2676        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
16:43:22.0121 2676        adpu160m - ok
16:43:22.0199 2676        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
16:43:22.0230 2676        adpu320 - ok
16:43:22.0308 2676        AeLookupSvc    (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
16:43:22.0386 2676        AeLookupSvc - ok
16:43:22.0511 2676        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
16:43:22.0604 2676        AFD - ok
16:43:22.0635 2676        AgereModemAudio (39e435c90c9c4f780fa0ed05ca3c3a1b) C:\Windows\system32\agrsmsvc.exe
16:43:22.0698 2676        AgereModemAudio - ok
16:43:23.0058 2676        AgereSoftModem  (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys
16:43:23.0245 2676        AgereSoftModem - ok
16:43:23.0292 2676        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
16:43:23.0323 2676        agp440 - ok
16:43:23.0370 2676        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
16:43:23.0385 2676        aic78xx - ok
16:43:23.0604 2676        ALG            (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
16:43:23.0760 2676        ALG - ok
16:43:23.0995 2676        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
16:43:24.0057 2676        aliide - ok
16:43:24.0119 2676        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
16:43:24.0135 2676        amdagp - ok
16:43:24.0166 2676        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
16:43:24.0182 2676        amdide - ok
16:43:24.0229 2676        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
16:43:24.0447 2676        AmdK7 - ok
16:43:24.0885 2676        AmdK8          (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
16:43:24.0994 2676        AmdK8 - ok
16:43:25.0088 2676        Appinfo        (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
16:43:25.0134 2676        Appinfo - ok
16:43:25.0415 2676        Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:43:25.0431 2676        Apple Mobile Device - ok
16:43:25.0478 2676        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
16:43:25.0493 2676        arc - ok
16:43:25.0556 2676        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
16:43:25.0571 2676        arcsas - ok
16:43:25.0618 2676        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
16:43:25.0696 2676        AsyncMac - ok
16:43:25.0821 2676        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
16:43:25.0836 2676        atapi - ok
16:43:26.0212 2676        athr            (f32fee7cb2ee32c1f808409bc8019701) C:\Windows\system32\DRIVERS\athr.sys
16:43:26.0368 2676        athr - ok
16:43:26.0805 2676        Ati External Event Utility (d29cae8aa91e405a569892fa3d97aa64) C:\Windows\system32\Ati2evxx.exe
16:43:26.0899 2676        Ati External Event Utility - ok
16:43:27.0914 2676        atikmdag        (e46f2fb11cfe13187a4e3ef512c0d226) C:\Windows\system32\DRIVERS\atikmdag.sys
16:43:28.0164 2676        atikmdag - ok
16:43:29.0054 2676        AtiPcie        (4aa1eb65481c392955939e735d27118b) C:\Windows\system32\DRIVERS\AtiPcie.sys
16:43:29.0101 2676        AtiPcie - ok
16:43:29.0257 2676        AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
16:43:29.0335 2676        AudioEndpointBuilder - ok
16:43:29.0350 2676        Audiosrv        (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
16:43:29.0382 2676        Audiosrv - ok
16:43:29.0413 2676        avkmgr - ok
16:43:29.0475 2676        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
16:43:29.0538 2676        Beep - ok
16:43:29.0709 2676        BFE            (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll
16:43:29.0787 2676        BFE - ok
16:43:29.0944 2676        BITS            (93952506c6d67330367f7e7934b6a02f) C:\Windows\System32\qmgr.dll
16:43:30.0038 2676        BITS - ok
16:43:30.0038 2676        blbdrive - ok
16:43:30.0303 2676        Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
16:43:30.0350 2676        Bonjour Service - ok
16:43:30.0631 2676        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
16:43:30.0693 2676        bowser - ok
16:43:30.0740 2676        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
16:43:30.0802 2676        BrFiltLo - ok
16:43:30.0818 2676        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
16:43:30.0896 2676        BrFiltUp - ok
16:43:31.0084 2676        Browser        (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
16:43:31.0162 2676        Browser - ok
16:43:31.0224 2676        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
16:43:31.0318 2676        Brserid - ok
16:43:31.0334 2676        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
16:43:31.0396 2676        BrSerWdm - ok
16:43:31.0427 2676        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
16:43:31.0490 2676        BrUsbMdm - ok
16:43:31.0536 2676        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
16:43:31.0614 2676        BrUsbSer - ok
16:43:31.0677 2676        BthEnum        (064fbc56921051de1075495d628b815f) C:\Windows\system32\DRIVERS\BthEnum.sys
16:43:31.0724 2676        BthEnum - ok
16:43:31.0755 2676        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
16:43:31.0833 2676        BTHMODEM - ok
16:43:31.0942 2676        BthPan          (b8c3d9ddf85fd197c3e5f849fef71144) C:\Windows\system32\DRIVERS\bthpan.sys
16:43:32.0021 2676        BthPan - ok
16:43:32.0099 2676        BTHPORT        (b24757d9154cca035e1bbd3db92966d7) C:\Windows\system32\Drivers\BTHport.sys
16:43:32.0146 2676        BTHPORT - ok
16:43:32.0224 2676        BthServ        (a4c8377fa4a994e07075107dbe2e3dce) C:\Windows\System32\bthserv.dll
16:43:32.0271 2676        BthServ - ok
16:43:32.0302 2676        BTHUSB          (d42cf5f0c7635b3f1578810fe34d9e41) C:\Windows\system32\Drivers\BTHUSB.sys
16:43:32.0333 2676        BTHUSB - ok
16:43:32.0395 2676        btwaudio        (636f45a8500c1438cfa7dee15fc5c184) C:\Windows\system32\drivers\btwaudio.sys
16:43:32.0427 2676        btwaudio - ok
16:43:32.0489 2676        btwavdt        (bf9256ff01b093a5d90bb7a35ec90410) C:\Windows\system32\drivers\btwavdt.sys
16:43:32.0505 2676        btwavdt - ok
16:43:32.0551 2676        btwrchid        (0ab8c1ac177afb27309e1072faf34a37) C:\Windows\system32\DRIVERS\btwrchid.sys
16:43:32.0567 2676        btwrchid - ok
16:43:32.0692 2676        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
16:43:32.0770 2676        cdfs - ok
16:43:32.0863 2676        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
16:43:32.0926 2676        cdrom - ok
16:43:33.0051 2676        CertPropSvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
16:43:33.0144 2676        CertPropSvc - ok
16:43:33.0222 2676        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
16:43:33.0331 2676        circlass - ok
16:43:33.0456 2676        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
16:43:33.0487 2676        CLFS - ok
16:43:33.0581 2676        clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:43:33.0597 2676        clr_optimization_v2.0.50727_32 - ok
16:43:33.0753 2676        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:43:33.0784 2676        clr_optimization_v4.0.30319_32 - ok
16:43:33.0862 2676        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
16:43:33.0924 2676        CmBatt - ok
16:43:33.0987 2676        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
16:43:34.0002 2676        cmdide - ok
16:43:34.0080 2676        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
16:43:34.0096 2676        Compbatt - ok
16:43:34.0111 2676        COMSysApp - ok
16:43:34.0111 2676        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
16:43:34.0143 2676        crcdisk - ok
16:43:34.0158 2676        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
16:43:34.0236 2676        Crusoe - ok
16:43:34.0283 2676        CryptSvc        (75c6a297e364014840b48eccd7525e30) C:\Windows\system32\cryptsvc.dll
16:43:34.0314 2676        CryptSvc - ok
16:43:34.0470 2676        DcomLaunch      (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
16:43:34.0564 2676        DcomLaunch - ok
16:43:34.0704 2676        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
16:43:34.0798 2676        DfsC - ok
16:43:35.0391 2676        DFSR            (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe
16:43:35.0640 2676        DFSR - ok
16:43:36.0046 2676        Dhcp            (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll
16:43:36.0124 2676        Dhcp - ok
16:43:36.0217 2676        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
16:43:36.0249 2676        disk - ok
16:43:36.0311 2676        Dnscache        (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll
16:43:36.0373 2676        Dnscache - ok
16:43:36.0436 2676        dot3svc        (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll
16:43:36.0467 2676        dot3svc - ok
16:43:36.0545 2676        DPS            (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
16:43:36.0607 2676        DPS - ok
16:43:36.0670 2676        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
16:43:36.0701 2676        drmkaud - ok
16:43:36.0810 2676        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
16:43:36.0841 2676        DXGKrnl - ok
16:43:36.0888 2676        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
16:43:36.0997 2676        E1G60 - ok
16:43:37.0060 2676        EapHost        (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
16:43:37.0091 2676        EapHost - ok
16:43:37.0185 2676        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
16:43:37.0200 2676        Ecache - ok
16:43:37.0263 2676        ehRecvr        (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
16:43:37.0325 2676        ehRecvr - ok
16:43:37.0403 2676        ehSched        (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
16:43:37.0450 2676        ehSched - ok
16:43:37.0481 2676        ehstart        (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
16:43:37.0512 2676        ehstart - ok
16:43:37.0590 2676        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
16:43:37.0637 2676        elxstor - ok
16:43:37.0746 2676        EMDMgmt        (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll
16:43:37.0840 2676        EMDMgmt - ok
16:43:37.0887 2676        EventSystem    (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll
16:43:37.0949 2676        EventSystem - ok
16:43:38.0011 2676        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
16:43:38.0089 2676        exfat - ok
16:43:38.0136 2676        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
16:43:38.0167 2676        fastfat - ok
16:43:38.0230 2676        fdc            (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
16:43:38.0323 2676        fdc - ok
16:43:38.0355 2676        fdPHost        (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
16:43:38.0386 2676        fdPHost - ok
16:43:38.0401 2676        FDResPub        (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
16:43:38.0479 2676        FDResPub - ok
16:43:38.0526 2676        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
16:43:38.0542 2676        FileInfo - ok
16:43:38.0557 2676        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
16:43:38.0604 2676        Filetrace - ok
16:43:38.0651 2676        flpydisk        (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
16:43:38.0729 2676        flpydisk - ok
16:43:38.0854 2676        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
16:43:38.0885 2676        FltMgr - ok
16:43:39.0088 2676        FontCache      (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll
16:43:39.0197 2676        FontCache - ok
16:43:39.0306 2676        FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
16:43:39.0337 2676        FontCache3.0.0.0 - ok
16:43:39.0369 2676        Fs_Rec          (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys
16:43:39.0431 2676        Fs_Rec - ok
16:43:39.0493 2676        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
16:43:39.0525 2676        gagp30kx - ok
16:43:39.0587 2676        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
16:43:39.0603 2676        GEARAspiWDM - ok
16:43:39.0743 2676        gpsvc          (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll
16:43:39.0868 2676        gpsvc - ok
16:43:40.0133 2676        gupdate        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
16:43:40.0149 2676        gupdate - ok
16:43:40.0149 2676        gupdatem        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
16:43:40.0180 2676        gupdatem - ok
16:43:40.0242 2676        HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
16:43:40.0351 2676        HdAudAddService - ok
16:43:40.0523 2676        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:43:40.0648 2676        HDAudBus - ok
16:43:40.0663 2676        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
16:43:40.0788 2676        HidBth - ok
16:43:40.0897 2676        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
16:43:41.0007 2676        HidIr - ok
16:43:41.0100 2676        hidserv        (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll
16:43:41.0163 2676        hidserv - ok
16:43:41.0303 2676        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
16:43:41.0365 2676        HidUsb - ok
16:43:41.0443 2676        hkmsvc          (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
16:43:41.0521 2676        hkmsvc - ok
16:43:41.0755 2676        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
16:43:41.0771 2676        HpCISSs - ok
16:43:41.0896 2676        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
16:43:42.0005 2676        HTTP - ok
16:43:42.0145 2676        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
16:43:42.0161 2676        i2omp - ok
16:43:42.0255 2676        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
16:43:42.0301 2676        i8042prt - ok
16:43:42.0411 2676        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
16:43:42.0442 2676        iaStorV - ok
16:43:42.0660 2676        IDriverT        (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
16:43:42.0691 2676        IDriverT ( UnsignedFile.Multi.Generic ) - warning
16:43:42.0691 2676        IDriverT - detected UnsignedFile.Multi.Generic (1)
16:43:42.0910 2676        idsvc          (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
16:43:43.0035 2676        idsvc - ok
16:43:43.0471 2676        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
16:43:43.0487 2676        iirsp - ok
16:43:43.0705 2676        IKEEXT          (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll
16:43:43.0783 2676        IKEEXT - ok
16:43:44.0423 2676        IntcAzAudAddService (7bd4e0428776d11c8e8e26f9f5508690) C:\Windows\system32\drivers\RTKVHDA.sys
16:43:44.0595 2676        IntcAzAudAddService - ok
16:43:45.0577 2676        intelide        (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
16:43:45.0593 2676        intelide - ok
16:43:45.0671 2676        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
16:43:45.0733 2676        intelppm - ok
16:43:45.0796 2676        IPBusEnum      (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
16:43:45.0843 2676        IPBusEnum - ok
16:43:45.0874 2676        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:43:45.0921 2676        IpFilterDriver - ok
16:43:46.0201 2676        iphlpsvc        (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll
16:43:46.0264 2676        iphlpsvc - ok
16:43:46.0264 2676        IpInIp - ok
16:43:46.0420 2676        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
16:43:46.0513 2676        IPMIDRV - ok
16:43:46.0591 2676        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
16:43:46.0654 2676        IPNAT - ok
16:43:47.0075 2676        iPod Service    (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe
16:43:47.0184 2676        iPod Service - ok
16:43:47.0293 2676        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
16:43:47.0340 2676        IRENUM - ok
16:43:47.0512 2676        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
16:43:47.0543 2676        isapnp - ok
16:43:47.0652 2676        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
16:43:47.0683 2676        iScsiPrt - ok
16:43:47.0777 2676        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
16:43:47.0808 2676        iteatapi - ok
16:43:47.0980 2676        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
16:43:48.0027 2676        iteraid - ok
16:43:48.0167 2676        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
16:43:48.0183 2676        kbdclass - ok
16:43:48.0261 2676        kbdhid          (d2600cb17b7408b4a83f231dc9a11ac3) C:\Windows\system32\DRIVERS\kbdhid.sys
16:43:48.0370 2676        kbdhid - ok
16:43:48.0573 2676        KeyIso          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:43:48.0666 2676        KeyIso - ok
16:43:48.0729 2676        KMDFMEMIO      (ebc507f129df8f0e0ca270dcfc0cf87f) C:\Windows\system32\DRIVERS\kmdfmemio.sys
16:43:48.0775 2676        KMDFMEMIO - ok
16:43:49.0056 2676        KSecDD          (4a1445efa932a3baf5bdb02d7131ee20) C:\Windows\system32\Drivers\ksecdd.sys
16:43:49.0119 2676        KSecDD - ok
16:43:49.0197 2676        KtmRm          (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
16:43:49.0337 2676        KtmRm - ok
16:43:49.0555 2676        LanmanServer    (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll
16:43:49.0649 2676        LanmanServer - ok
16:43:49.0836 2676        LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll
16:43:49.0914 2676        LanmanWorkstation - ok
16:43:50.0226 2676        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
16:43:50.0273 2676        lltdio - ok
16:43:50.0507 2676        lltdsvc        (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
16:43:50.0585 2676        lltdsvc - ok
16:43:50.0741 2676        lmhosts        (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
16:43:50.0819 2676        lmhosts - ok
16:43:50.0897 2676        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
16:43:50.0928 2676        LSI_FC - ok
16:43:51.0053 2676        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
16:43:51.0069 2676        LSI_SAS - ok
16:43:51.0178 2676        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
16:43:51.0209 2676        LSI_SCSI - ok
16:43:51.0334 2676        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
16:43:51.0396 2676        luafv - ok
16:43:51.0474 2676        LVRS            (ed643e777ba3f7151ef3f0fb6be4f7f0) C:\Windows\system32\DRIVERS\lvrs.sys
16:43:51.0521 2676        LVRS - ok
16:43:52.0535 2676        LVUVC          (5bc80451109a8dd7f2ddd35bce2929a3) C:\Windows\system32\DRIVERS\lvuvc.sys
16:43:52.0878 2676        LVUVC - ok
16:43:53.0299 2676        MBAMProtector  (6dfe7f2e8e8a337263aa5c92a215f161) C:\Windows\system32\drivers\mbam.sys
16:43:53.0315 2676        MBAMProtector - ok
16:43:53.0518 2676        MBAMService    (43683e970f008c93c9429ef428147a54) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
16:43:53.0627 2676        MBAMService - ok
16:43:53.0845 2676        McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
16:43:53.0877 2676        McComponentHostService - ok
16:43:54.0001 2676        Mcx2Svc        (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
16:43:54.0048 2676        Mcx2Svc - ok
16:43:54.0282 2676        MDM            (11f714f85530a2bd134074dc30e99fca) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
16:43:54.0313 2676        MDM - ok
16:43:54.0501 2676        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
16:43:54.0532 2676        megasas - ok
16:43:54.0641 2676        MMCSS          (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
16:43:54.0688 2676        MMCSS - ok
16:43:54.0766 2676        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
16:43:54.0813 2676        Modem - ok
16:43:54.0875 2676        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
16:43:54.0906 2676        monitor - ok
16:43:55.0031 2676        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
16:43:55.0047 2676        mouclass - ok
16:43:55.0062 2676        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
16:43:55.0109 2676        mouhid - ok
16:43:55.0203 2676        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
16:43:55.0218 2676        MountMgr - ok
16:43:55.0281 2676        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
16:43:55.0296 2676        MozillaMaintenance - ok
16:43:55.0343 2676        MpFilter        (d993bea500e7382dc4e760bf4f35efcb) C:\Windows\system32\DRIVERS\MpFilter.sys
16:43:55.0359 2676        MpFilter - ok
16:43:55.0405 2676        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
16:43:55.0421 2676        mpio - ok
16:43:55.0546 2676        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
16:43:55.0593 2676        mpsdrv - ok
16:43:55.0671 2676        MpsSvc          (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll
16:43:55.0749 2676        MpsSvc - ok
16:43:55.0795 2676        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
16:43:55.0811 2676        Mraid35x - ok
16:43:55.0858 2676        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
16:43:55.0889 2676        MRxDAV - ok
16:43:55.0983 2676        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:43:56.0045 2676        mrxsmb - ok
16:43:56.0170 2676        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:43:56.0217 2676        mrxsmb10 - ok
16:43:56.0248 2676        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:43:56.0295 2676        mrxsmb20 - ok
16:43:56.0419 2676        msahci          (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
16:43:56.0451 2676        msahci - ok
16:43:56.0591 2676        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
16:43:56.0607 2676        msdsm - ok
16:43:56.0747 2676        MSDTC          (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
16:43:56.0825 2676        MSDTC - ok
16:43:56.0887 2676        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
16:43:56.0934 2676        Msfs - ok
16:43:57.0012 2676        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
16:43:57.0028 2676        msisadrv - ok
16:43:57.0168 2676        MSiSCSI        (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
16:43:57.0246 2676        MSiSCSI - ok
16:43:57.0246 2676        msiserver - ok
16:43:57.0324 2676        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
16:43:57.0387 2676        MSKSSRV - ok
16:43:57.0558 2676        MsMpSvc        (24516bf4e12a46cb67302e2cdcb8cddf) c:\Program Files\Microsoft Security Client\MsMpEng.exe
16:43:57.0574 2676        MsMpSvc - ok
16:43:57.0652 2676        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
16:43:57.0745 2676        MSPCLOCK - ok
16:43:57.0792 2676        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
16:43:57.0855 2676        MSPQM - ok
16:43:57.0964 2676        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
16:43:57.0995 2676        MsRPC - ok
16:43:58.0120 2676        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
16:43:58.0151 2676        mssmbios - ok
16:43:58.0198 2676        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
16:43:58.0291 2676        MSTEE - ok
16:43:58.0338 2676        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
16:43:58.0354 2676        Mup - ok
16:43:58.0510 2676        napagent        (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll
16:43:58.0603 2676        napagent - ok
16:43:58.0744 2676        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
16:43:58.0806 2676        NativeWifiP - ok
16:43:59.0071 2676        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
16:43:59.0149 2676        NDIS - ok
16:43:59.0243 2676        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
16:43:59.0290 2676        NdisTapi - ok
16:43:59.0337 2676        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
16:43:59.0383 2676        Ndisuio - ok
16:43:59.0524 2676        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
16:43:59.0602 2676        NdisWan - ok
16:43:59.0649 2676        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
16:43:59.0680 2676        NDProxy - ok
16:43:59.0773 2676        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
16:43:59.0836 2676        NetBIOS - ok
16:43:59.0914 2676        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
16:43:59.0976 2676        netbt - ok
16:44:00.0117 2676        Netlogon        (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:44:00.0132 2676        Netlogon - ok
16:44:00.0226 2676        Netman          (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
16:44:00.0304 2676        Netman - ok
16:44:00.0366 2676        netprofm        (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
16:44:00.0429 2676        netprofm - ok
16:44:00.0569 2676        NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:44:00.0585 2676        NetTcpPortSharing - ok
16:44:01.0006 2676        NETw2v32        (6e9edc1020b319e7676387b8cdf2398c) C:\Windows\system32\DRIVERS\NETw2v32.sys
16:44:01.0365 2676        NETw2v32 - ok
16:44:01.0692 2676        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
16:44:01.0708 2676        nfrd960 - ok
16:44:01.0755 2676        NisDrv          (b52f26bade7d7e4a79706e3fd91834cd) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
16:44:01.0770 2676        NisDrv - ok
16:44:01.0942 2676        NisSrv          (290c0d4c4889398797f8df3be00b9698) c:\Program Files\Microsoft Security Client\NisSrv.exe
16:44:01.0957 2676        NisSrv - ok
16:44:02.0051 2676        NlaSvc          (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
16:44:02.0145 2676        NlaSvc - ok
16:44:02.0207 2676        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
16:44:02.0238 2676        Npfs - ok
16:44:02.0316 2676        nsi            (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
16:44:02.0363 2676        nsi - ok
16:44:02.0394 2676        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
16:44:02.0457 2676        nsiproxy - ok
16:44:02.0628 2676        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
16:44:02.0691 2676        Ntfs - ok
16:44:02.0753 2676        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
16:44:02.0831 2676        ntrigdigi - ok
16:44:02.0847 2676        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
16:44:02.0878 2676        Null - ok
16:44:02.0940 2676        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
16:44:02.0956 2676        nvraid - ok
16:44:03.0034 2676        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
16:44:03.0049 2676        nvstor - ok
16:44:03.0112 2676        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
16:44:03.0127 2676        nv_agp - ok
16:44:03.0127 2676        NwlnkFlt - ok
16:44:03.0143 2676        NwlnkFwd - ok
16:44:03.0174 2676        ohci1394        (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys
16:44:03.0237 2676        ohci1394 - ok
16:44:03.0330 2676        ose            (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:44:03.0346 2676        ose - ok
16:44:03.0486 2676        p2pimsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:03.0595 2676        p2pimsvc - ok
16:44:03.0611 2676        p2psvc          (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:03.0658 2676        p2psvc - ok
16:44:03.0720 2676        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
16:44:03.0798 2676        Parport - ok
16:44:03.0845 2676        partmgr        (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys
16:44:03.0861 2676        partmgr - ok
16:44:03.0892 2676        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
16:44:03.0985 2676        Parvdm - ok
16:44:04.0110 2676        PcaSvc          (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
16:44:04.0204 2676        PcaSvc - ok
16:44:04.0235 2676        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
16:44:04.0266 2676        pci - ok
16:44:04.0313 2676        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
16:44:04.0344 2676        pciide - ok
16:44:04.0391 2676        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\DRIVERS\pcmcia.sys
16:44:04.0407 2676        pcmcia - ok
16:44:04.0563 2676        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
16:44:04.0672 2676        PEAUTH - ok
16:44:04.0999 2676        pla            (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
16:44:05.0124 2676        pla - ok
16:44:05.0452 2676        PlugPlay        (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll
16:44:05.0499 2676        PlugPlay - ok
16:44:05.0701 2676        PNRPAutoReg    (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:05.0764 2676        PNRPAutoReg - ok
16:44:05.0779 2676        PNRPsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
16:44:05.0826 2676        PNRPsvc - ok
16:44:05.0920 2676        PolicyAgent    (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll
16:44:06.0013 2676        PolicyAgent - ok
16:44:06.0123 2676        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
16:44:06.0169 2676        PptpMiniport - ok
16:44:06.0216 2676        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
16:44:06.0325 2676        Processor - ok
16:44:06.0419 2676        ProfSvc        (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll
16:44:06.0450 2676        ProfSvc - ok
16:44:06.0497 2676        ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:44:06.0528 2676        ProtectedStorage - ok
16:44:06.0575 2676        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
16:44:06.0653 2676        PSched - ok
16:44:06.0700 2676        PxHelp20        (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys
16:44:06.0715 2676        PxHelp20 - ok
16:44:06.0856 2676        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
16:44:06.0965 2676        ql2300 - ok
16:44:07.0027 2676        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
16:44:07.0043 2676        ql40xx - ok
16:44:07.0105 2676        QWAVE          (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
16:44:07.0137 2676        QWAVE - ok
16:44:07.0183 2676        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
16:44:07.0215 2676        QWAVEdrv - ok
16:44:07.0542 2676        R300            (e46f2fb11cfe13187a4e3ef512c0d226) C:\Windows\system32\DRIVERS\atikmdag.sys
16:44:07.0683 2676        R300 - ok
16:44:07.0948 2676        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
16:44:08.0010 2676        RasAcd - ok
16:44:08.0057 2676        RasAuto        (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
16:44:08.0135 2676        RasAuto - ok
16:44:08.0166 2676        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:44:08.0213 2676        Rasl2tp - ok
16:44:08.0291 2676        RasMan          (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll
16:44:08.0369 2676        RasMan - ok
16:44:08.0447 2676        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
16:44:08.0494 2676        RasPppoe - ok
16:44:08.0556 2676        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
16:44:08.0587 2676        RasSstp - ok
16:44:08.0650 2676        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
16:44:08.0697 2676        rdbss - ok
16:44:08.0728 2676        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:44:08.0790 2676        RDPCDD - ok
16:44:08.0868 2676        rdpdr          (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
16:44:08.0977 2676        rdpdr - ok
16:44:08.0977 2676        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
16:44:09.0024 2676        RDPENCDD - ok
16:44:09.0102 2676        RDPWD          (c127ebd5afab31524662c48dfceb773a) C:\Windows\system32\drivers\RDPWD.sys
16:44:09.0149 2676        RDPWD - ok
16:44:09.0243 2676        RemoteAccess    (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
16:44:09.0289 2676        RemoteAccess - ok
16:44:09.0352 2676        RemoteRegistry  (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll
16:44:09.0414 2676        RemoteRegistry - ok
16:44:09.0461 2676        RFCOMM          (7ec90c316177ba3f1bce92005264b447) C:\Windows\system32\DRIVERS\rfcomm.sys
16:44:09.0523 2676        RFCOMM - ok
16:44:09.0679 2676        RichVideo      (2af094b1ce4725e4551f38fda2348637) C:\Program Files\CyberLink\Shared Files\RichVideo.exe
16:44:09.0726 2676        RichVideo ( UnsignedFile.Multi.Generic ) - warning
16:44:09.0726 2676        RichVideo - detected UnsignedFile.Multi.Generic (1)
16:44:09.0742 2676        RpcLocator      (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
16:44:09.0804 2676        RpcLocator - ok
16:44:09.0929 2676        RpcSs          (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
16:44:09.0991 2676        RpcSs - ok
16:44:10.0054 2676        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
16:44:10.0101 2676        rspndr - ok
16:44:10.0147 2676        RTL8023xp      (959ef612d2ccfdb6d9e443f8e3655013) C:\Windows\system32\DRIVERS\Rtnicxp.sys
16:44:10.0210 2676        RTL8023xp - ok
16:44:10.0257 2676        SamSs          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
16:44:10.0272 2676        SamSs - ok
16:44:10.0397 2676        Samsung Update Plus (4bfb51cdb25d4d4b9e8fccab635f262e) C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
16:44:10.0444 2676        Samsung Update Plus ( UnsignedFile.Multi.Generic ) - warning
16:44:10.0444 2676        Samsung Update Plus - detected UnsignedFile.Multi.Generic (1)
16:44:10.0475 2676        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
16:44:10.0491 2676        sbp2port - ok
16:44:10.0553 2676        SCardSvr        (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll
16:44:10.0631 2676        SCardSvr - ok
16:44:10.0740 2676        Schedule        (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll
16:44:10.0881 2676        Schedule - ok
16:44:10.0927 2676        SCPolicySvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
16:44:10.0959 2676        SCPolicySvc - ok
16:44:11.0068 2676        sdbus          (4339a2585708c7d9b0c0ce5aad3dd6ff) C:\Windows\system32\DRIVERS\sdbus.sys
16:44:11.0161 2676        sdbus - ok
16:44:11.0224 2676        SDRSVC          (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
16:44:11.0286 2676        SDRSVC - ok
16:44:11.0317 2676        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
16:44:11.0411 2676        secdrv - ok
16:44:11.0427 2676        seclogon        (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
16:44:11.0473 2676        seclogon - ok
16:44:11.0567 2676        SENS            (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
16:44:11.0614 2676        SENS - ok
16:44:11.0676 2676        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
16:44:11.0754 2676        Serenum - ok
16:44:11.0817 2676        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
16:44:11.0895 2676        Serial - ok
16:44:11.0988 2676        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
16:44:12.0019 2676        sermouse - ok
16:44:12.0191 2676        SessionEnv      (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
16:44:12.0238 2676        SessionEnv - ok
16:44:12.0363 2676        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
16:44:12.0456 2676        sffdisk - ok
16:44:12.0565 2676        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
16:44:12.0643 2676        sffp_mmc - ok
16:44:12.0721 2676        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
16:44:12.0799 2676        sffp_sd - ok
16:44:12.0831 2676        sfloppy        (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys
16:44:12.0877 2676        sfloppy - ok
16:44:12.0971 2676        SharedAccess    (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
16:44:13.0018 2676        SharedAccess - ok
16:44:13.0111 2676        ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll
16:44:13.0174 2676        ShellHWDetection - ok
16:44:13.0221 2676        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
16:44:13.0236 2676        sisagp - ok
16:44:13.0267 2676        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
16:44:13.0283 2676        SiSRaid2 - ok
16:44:13.0314 2676        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
16:44:13.0345 2676        SiSRaid4 - ok
16:44:13.0470 2676        SkypeUpdate    (ddaa5f4a6b958fc313ebd02dd925752f) C:\Program Files\Skype\Updater\Updater.exe
16:44:13.0486 2676        SkypeUpdate - ok
16:44:13.0938 2676        slsvc          (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe
16:44:14.0266 2676        slsvc - ok
16:44:14.0500 2676        SLUINotify      (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll
16:44:14.0578 2676        SLUINotify - ok
16:44:14.0656 2676        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
16:44:14.0749 2676        Smb - ok
16:44:14.0796 2676        SNMPTRAP        (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
16:44:14.0827 2676        SNMPTRAP - ok
16:44:14.0905 2676        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
16:44:14.0921 2676        spldr - ok
16:44:14.0999 2676        Spooler        (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe
16:44:15.0061 2676        Spooler - ok
16:44:15.0186 2676        SQLWriter      (d2f4f32b59440011174b4f8137af4e0c) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
16:44:15.0202 2676        SQLWriter - ok
16:44:15.0327 2676        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
16:44:15.0405 2676        srv - ok
16:44:15.0451 2676        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
16:44:15.0514 2676        srv2 - ok
16:44:15.0545 2676        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
16:44:15.0576 2676        srvnet - ok
16:44:15.0654 2676        SSDPSRV        (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
16:44:15.0701 2676        SSDPSRV - ok
16:44:15.0748 2676        SstpSvc        (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
16:44:15.0795 2676        SstpSvc - ok
16:44:15.0888 2676        stisvc          (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll
16:44:15.0982 2676        stisvc - ok
16:44:16.0044 2676        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
16:44:16.0060 2676        swenum - ok
16:44:16.0153 2676        swprv          (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll
16:44:16.0231 2676        swprv - ok
16:44:16.0309 2676        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
16:44:16.0341 2676        Symc8xx - ok
16:44:16.0356 2676        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
16:44:16.0387 2676        Sym_hi - ok
16:44:16.0419 2676        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
16:44:16.0450 2676        Sym_u3 - ok
16:44:16.0528 2676        SynTP          (c1777074592bbb55b1f1a2fbc7a60498) C:\Windows\system32\DRIVERS\SynTP.sys
16:44:16.0543 2676        SynTP - ok
16:44:16.0621 2676        SysMain        (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll
16:44:16.0684 2676        SysMain - ok
16:44:16.0731 2676        TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
16:44:16.0793 2676        TabletInputService - ok
16:44:16.0902 2676        TapiSrv        (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll
16:44:16.0980 2676        TapiSrv - ok
16:44:17.0043 2676        TBS            (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
16:44:17.0105 2676        TBS - ok
16:44:17.0245 2676        Tcpip          (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys
16:44:17.0355 2676        Tcpip - ok
16:44:17.0370 2676        Tcpip6          (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys
16:44:17.0417 2676        Tcpip6 - ok
16:44:17.0464 2676        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
16:44:17.0495 2676        tcpipreg - ok
16:44:17.0557 2676        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
16:44:17.0589 2676        TDPIPE - ok
16:44:17.0651 2676        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
16:44:17.0698 2676        TDTCP - ok
16:44:17.0760 2676        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
16:44:17.0823 2676        tdx - ok
16:44:17.0947 2676        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
16:44:17.0963 2676        TermDD - ok
16:44:18.0072 2676        TermService    (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll
16:44:18.0166 2676        TermService - ok
16:44:18.0228 2676        Themes          (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll
16:44:18.0259 2676        Themes - ok
16:44:18.0291 2676        THREADORDER    (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
16:44:18.0322 2676        THREADORDER - ok
16:44:18.0369 2676        TrkWks          (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
16:44:18.0415 2676        TrkWks - ok
16:44:18.0540 2676        TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe
16:44:18.0571 2676        TrustedInstaller - ok
16:44:18.0603 2676        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:44:18.0665 2676        tssecsrv - ok
16:44:18.0696 2676        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
16:44:18.0727 2676        tunmp - ok
16:44:18.0743 2676        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
16:44:18.0774 2676        tunnel - ok
16:44:18.0805 2676        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
16:44:18.0821 2676        uagp35 - ok
16:44:18.0883 2676        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
16:44:18.0930 2676        udfs - ok
16:44:19.0039 2676        UI0Detect      (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
16:44:19.0086 2676        UI0Detect - ok
16:44:19.0117 2676        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
16:44:19.0133 2676        uliagpkx - ok
16:44:19.0195 2676        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
16:44:19.0227 2676        uliahci - ok
16:44:19.0305 2676        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
16:44:19.0336 2676        UlSata - ok
16:44:19.0398 2676        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
16:44:19.0414 2676        ulsata2 - ok
16:44:19.0476 2676        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
16:44:19.0523 2676        umbus - ok
16:44:19.0663 2676        UMVPFSrv        (67a95b9d129ed5399e7965cd09cf30e7) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
16:44:19.0710 2676        UMVPFSrv - ok
16:44:19.0866 2676        upnphost        (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
16:44:19.0975 2676        upnphost - ok
16:44:20.0022 2676        USBAAPL        (eafe1e00739afe6c51487a050e772e17) C:\Windows\system32\Drivers\usbaapl.sys
16:44:20.0069 2676        USBAAPL - ok
16:44:20.0163 2676        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
16:44:20.0225 2676        usbaudio - ok
16:44:20.0287 2676        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
16:44:20.0350 2676        usbccgp - ok
16:44:20.0397 2676        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
16:44:20.0475 2676        usbcir - ok
16:44:20.0506 2676        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
16:44:20.0553 2676        usbehci - ok
16:44:20.0584 2676        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
16:44:20.0646 2676        usbhub - ok
16:44:20.0693 2676        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
16:44:20.0740 2676        usbohci - ok
16:44:20.0818 2676        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
16:44:20.0865 2676        usbprint - ok
16:44:20.0974 2676        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:44:21.0005 2676        USBSTOR - ok
16:44:21.0052 2676        usbuhci        (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
16:44:21.0130 2676        usbuhci - ok
16:44:21.0208 2676        usbvideo        (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
16:44:21.0286 2676        usbvideo - ok
16:44:21.0379 2676        UxSms          (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll
16:44:21.0442 2676        UxSms - ok
16:44:21.0535 2676        vds            (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe
16:44:21.0645 2676        vds - ok
16:44:21.0707 2676        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
16:44:21.0754 2676        vga - ok
16:44:21.0832 2676        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
16:44:21.0879 2676        VgaSave - ok
16:44:21.0910 2676        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
16:44:21.0941 2676        viaagp - ok
16:44:21.0957 2676        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
16:44:22.0081 2676        ViaC7 - ok
16:44:22.0097 2676        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
16:44:22.0113 2676        viaide - ok
16:44:22.0175 2676        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
16:44:22.0191 2676        volmgr - ok
16:44:22.0300 2676        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
16:44:22.0331 2676        volmgrx - ok
16:44:22.0378 2676        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
16:44:22.0409 2676        volsnap - ok
16:44:22.0440 2676        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
16:44:22.0456 2676        vsmraid - ok
16:44:22.0627 2676        VSS            (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe
16:44:22.0768 2676        VSS - ok
16:44:23.0002 2676        W32Time        (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll
16:44:23.0080 2676        W32Time - ok
16:44:23.0173 2676        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
16:44:23.0236 2676        WacomPen - ok
16:44:23.0298 2676        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:44:23.0345 2676        Wanarp - ok
16:44:23.0345 2676        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
16:44:23.0376 2676        Wanarpv6 - ok
16:44:23.0470 2676        wcncsvc        (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll
16:44:23.0501 2676        wcncsvc - ok
16:44:23.0563 2676        WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
16:44:23.0595 2676        WcsPlugInService - ok
16:44:23.0626 2676        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
16:44:23.0641 2676        Wd - ok
16:44:23.0797 2676        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
16:44:23.0829 2676        Wdf01000 - ok
16:44:23.0922 2676        WdiServiceHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
16:44:24.0000 2676        WdiServiceHost - ok
16:44:24.0016 2676        WdiSystemHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
16:44:24.0063 2676        WdiSystemHost - ok
16:44:24.0125 2676        WebClient      (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll
16:44:24.0187 2676        WebClient - ok
16:44:24.0250 2676        Wecsvc          (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
16:44:24.0297 2676        Wecsvc - ok
16:44:24.0375 2676        wercplsupport  (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
16:44:24.0437 2676        wercplsupport - ok
16:44:24.0499 2676        WerSvc          (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll
16:44:24.0546 2676        WerSvc - ok
16:44:24.0702 2676        WinDefend      (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
16:44:24.0733 2676        WinDefend - ok
16:44:24.0733 2676        WinHttpAutoProxySvc - ok
16:44:24.0843 2676        Winmgmt        (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll
16:44:24.0874 2676        Winmgmt - ok
16:44:25.0123 2676        WinRM          (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
16:44:25.0233 2676        WinRM - ok
16:44:25.0326 2676        Wlansvc        (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll
16:44:25.0404 2676        Wlansvc - ok
16:44:25.0529 2676        WmiAcpi        (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
16:44:25.0623 2676        WmiAcpi - ok
16:44:25.0763 2676        wmiApSrv        (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe
16:44:25.0810 2676        wmiApSrv - ok
16:44:26.0013 2676        WMPNetworkSvc  (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
16:44:26.0106 2676        WMPNetworkSvc - ok
16:44:26.0184 2676        WPCSvc          (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll
16:44:26.0247 2676        WPCSvc - ok
16:44:26.0293 2676        WPDBusEnum      (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll
16:44:26.0340 2676        WPDBusEnum - ok
16:44:26.0465 2676        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
16:44:26.0481 2676        WpdUsb - ok
16:44:26.0824 2676        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
16:44:26.0886 2676        WPFFontCache_v0400 - ok
16:44:26.0933 2676        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
16:44:26.0980 2676        ws2ifsl - ok
16:44:27.0042 2676        wscsvc          (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\System32\wscsvc.dll
16:44:27.0073 2676        wscsvc - ok
16:44:27.0120 2676        WSDPrintDevice  (4422ac5ed8d4c2f0db63e71d4c069dd7) C:\Windows\system32\DRIVERS\WSDPrint.sys
16:44:27.0151 2676        WSDPrintDevice - ok
16:44:27.0214 2676        WSDScan        (65d1ff8aaff4a7d8f787a290e5087816) C:\Windows\system32\DRIVERS\WSDScan.sys
16:44:27.0261 2676        WSDScan - ok
16:44:27.0261 2676        WSearch - ok
16:44:27.0666 2676        wuauserv        (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll
16:44:27.0822 2676        wuauserv - ok
16:44:28.0197 2676        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:44:28.0275 2676        WUDFRd - ok
16:44:28.0321 2676        wudfsvc        (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
16:44:28.0384 2676        wudfsvc - ok
16:44:28.0462 2676        yukonwlh        (04e268adfc81964c49dc0c082d520f7e) C:\Windows\system32\DRIVERS\yk60x86.sys
16:44:28.0509 2676        yukonwlh - ok
16:44:28.0540 2676        MBR (0x1B8)    (61a349592c4728853f4a90ff78f7628e) \Device\Harddisk0\DR0
16:44:29.0367 2676        \Device\Harddisk0\DR0 - ok
16:44:29.0398 2676        Boot (0x1200)  (2d3c8d6b7dd7b6f8b97b0afa65d62e88) \Device\Harddisk0\DR0\Partition0
16:44:29.0476 2676        \Device\Harddisk0\DR0\Partition0 - ok
16:44:29.0507 2676        Boot (0x1200)  (c9074faa7fa3743eae28f3b181586712) \Device\Harddisk0\DR0\Partition1
16:44:29.0507 2676        \Device\Harddisk0\DR0\Partition1 - ok
16:44:29.0507 2676        ============================================================
16:44:29.0507 2676        Scan finished
16:44:29.0507 2676        ============================================================
16:44:29.0523 5184        Detected object count: 3
16:44:29.0523 5184        Actual detected object count: 3
16:54:22.0115 5184        IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
16:54:22.0115 5184        IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:54:22.0130 5184        RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
16:54:22.0130 5184        RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:54:22.0130 5184        Samsung Update Plus ( UnsignedFile.Multi.Generic ) - skipped by user
16:54:22.0130 5184        Samsung Update Plus ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:54:24.0580 5604        Deinitialize success


cosinus 18.07.2012 20:21

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

mirhannah 18.07.2012 21:08

[code] Combofix Logfile:
Code:

ComboFix 12-07-18.04 - Hannah 18.07.2012  21:42:41.1.2 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.1789.1044 [GMT 2:00]
ausgeführt von:: c:\users\Hannah\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-06-18 bis 2012-07-18  ))))))))))))))))))))))))))))))
.
.
2012-07-18 19:50 . 2012-07-18 19:50        --------        d-----w-        c:\users\Hannah\AppData\Local\temp
2012-07-18 19:50 . 2012-07-18 19:50        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-07-18 19:21 . 2012-07-18 19:21        29904        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A8B69E6-D14B-4251-86AD-81D2D8D607EE}\MpKsl73129b21.sys
2012-07-18 19:21 . 2012-07-18 19:21        56200        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A8B69E6-D14B-4251-86AD-81D2D8D607EE}\offreg.dll
2012-07-18 18:54 . 2012-06-29 08:44        6891424        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A8B69E6-D14B-4251-86AD-81D2D8D607EE}\mpengine.dll
2012-07-17 14:45 . 2012-06-29 08:44        6891424        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-17 14:30 . 2012-07-17 14:36        --------        d-----w-        c:\programdata\Avira
2012-07-13 20:49 . 2012-07-13 20:49        --------        d-----w-        C:\_OTL
2012-07-12 08:02 . 2012-07-12 08:02        --------        d-----w-        c:\users\Hannah\AppData\Local\Macromedia
2012-07-12 07:14 . 2012-07-12 07:18        426184        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-07-11 17:29 . 2012-06-13 13:40        2047488        ----a-w-        c:\windows\system32\win32k.sys
2012-07-11 07:08 . 2012-04-23 16:00        984064        ----a-w-        c:\windows\system32\crypt32.dll
2012-07-11 07:08 . 2012-04-23 16:00        133120        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-07-11 07:08 . 2012-04-23 16:00        98304        ----a-w-        c:\windows\system32\cryptnet.dll
2012-07-11 07:07 . 2012-06-05 16:47        708608        ----a-w-        c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 07:07 . 2012-06-05 16:47        1401856        ----a-w-        c:\windows\system32\msxml6.dll
2012-07-11 07:07 . 2012-06-05 16:47        1248768        ----a-w-        c:\windows\system32\msxml3.dll
2012-07-11 07:07 . 2012-06-04 15:26        440704        ----a-w-        c:\windows\system32\drivers\ksecdd.sys
2012-07-11 07:07 . 2012-06-02 00:04        278528        ----a-w-        c:\windows\system32\schannel.dll
2012-07-11 07:07 . 2012-06-02 00:03        204288        ----a-w-        c:\windows\system32\ncrypt.dll
2012-07-05 19:51 . 2012-07-05 19:51        --------        d-----w-        c:\program files\ESET
2012-07-05 15:54 . 2012-07-05 15:54        --------        d-----w-        c:\programdata\regid.1986-12.com.adobe
2012-07-04 19:18 . 2012-07-05 15:49        --------        d-----w-        c:\program files\PC Tools
2012-07-04 19:13 . 2012-05-11 09:14        203088        ----a-w-        c:\windows\system32\drivers\PCTSD.sys
2012-07-04 19:13 . 2012-07-05 15:49        --------        d-----w-        c:\program files\Common Files\PC Tools
2012-07-04 19:13 . 2012-07-05 15:46        --------        d-----w-        c:\programdata\PC Tools
2012-07-04 19:13 . 2012-07-04 19:13        --------        d-----w-        c:\users\Hannah\AppData\Roaming\TestApp
2012-07-04 14:55 . 2012-07-04 14:55        --------        d-----w-        c:\users\Hannah\AppData\Roaming\Malwarebytes
2012-07-04 14:54 . 2012-07-04 14:54        --------        d-----w-        c:\programdata\Malwarebytes
2012-07-04 14:54 . 2012-07-03 11:46        22344        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-07-04 14:54 . 2012-07-13 18:11        --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
2012-07-04 11:35 . 2012-05-03 06:37        713784        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5E001C7F-B8AB-40BD-A366-5A2C054C0228}\gapaengine.dll
2012-07-02 15:01 . 2012-07-02 15:01        --------        d-----w-        c:\programdata\Premium
2012-07-02 15:00 . 2012-07-02 15:01        --------        d-----w-        c:\programdata\InstallMate
2012-06-22 07:24 . 2012-06-02 22:19        53784        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-22 07:24 . 2012-06-02 22:19        45080        ----a-w-        c:\windows\system32\wups2.dll
2012-06-22 07:24 . 2012-06-02 22:19        1933848        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-22 07:24 . 2012-06-02 22:12        2422272        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-22 07:24 . 2012-06-02 22:19        35864        ----a-w-        c:\windows\system32\wups.dll
2012-06-22 07:24 . 2012-06-02 22:12        88576        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-22 07:24 . 2012-06-02 22:19        577048        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-22 07:24 . 2012-06-02 13:19        171904        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-22 07:24 . 2012-06-02 13:12        33792        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-19 11:22 . 2012-06-19 11:22        421200        ----a-w-        c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-19 11:22 . 2012-06-19 11:22        770384        ----a-w-        c:\program files\Mozilla Firefox\msvcr100.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 07:18 . 2011-06-14 05:25        70344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-04 17:29 . 2012-06-16 17:25        772504        ----a-w-        c:\windows\system32\npDeployJava1.dll
2012-05-04 17:29 . 2010-06-18 18:38        687504        ----a-w-        c:\windows\system32\deployJava1.dll
2012-05-03 06:37 . 2012-05-03 06:41        713784        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-05-01 14:03 . 2012-06-13 06:12        180736        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-06-19 11:23 . 2011-05-10 20:45        85472        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-13 4489216]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-23 857648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 68640]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"FLMOFFICE4DMOUSE"="c:\program files\Browser MOUSE\mouse32a.exe" [2010-09-21 360448]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-04-04 36760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-04-04 815512]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-24 723760]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"NoHotStart"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-18 22:38        1008184        ----a-w-        c:\program files\Windows Defender\MSASCui.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MPKSL73129B21
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs        REG_MULTI_SZ          BthServ
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-07-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-12 07:18]
.
2012-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-23 13:39]
.
2012-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-23 13:39]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local;<local>
IE: Free YouTube Download - c:\users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Hannah\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\x6b6u5gh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.zeit.de/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKCU-Run-Akamai NetSession Interface - c:\users\Hannah\AppData\Local\Akamai\netsession_win.exe
HKLM-Run-IMBooster - c:\program files\Iminent\IMBooster\imbooster.exe
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe
AddRemove-kikin Plugin (NO23 Edition) - c:\program files\kikin\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-07-18 21:50
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(4400)
c:\windows\system32\btmmhook.dll
c:\program files\Browser MOUSE\MOUDL32A.DLL
.
Zeit der Fertigstellung: 2012-07-18  21:55:54
ComboFix-quarantined-files.txt  2012-07-18 19:55
.
Vor Suchlauf: 10 Verzeichnis(se), 23.656.595.456 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 23.610.908.672 Bytes frei
.
- - End Of File - - ADF26F2117576DF4918142E5DAB90DE7

--- --- ---

cosinus 19.07.2012 16:28

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

mirhannah 19.07.2012 18:10

habe weder winrar noch 7zip, geht auch was anderes?

cosinus 19.07.2012 20:06

Nein geht nicht. Was hindert dich daran 7zip zu installieren :confused:

mirhannah 19.07.2012 21:49

GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-19 22:46:24
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS542516K9A300 rev.BBCOC32P
Running: gmer.exe; Driver: C:\Users\Hannah\AppData\Local\Temp\uwdirpog.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\kbdclass \Device\KeyboardClass0                                                          Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice  \Driver\kbdclass \Device\KeyboardClass1                                                          Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027875488f                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00027875585f                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000278755861                     
Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000278755ef5                     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00027875488f (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00027875585f (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000278755861 (not active ControlSet) 
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000278755ef5 (not active ControlSet) 

---- EOF - GMER 1.0.15 ----

--- --- ---


OSAM Logfile:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 23:10:20 on 19.07.2012

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 14.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"catchme" (catchme) - ? - C:\Users\Hannah\AppData\Local\Temp\catchme.sys  (File not found)
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"MpKslcb5983fd" (MpKslcb5983fd) - "Microsoft Corporation" - c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{81679C99-B663-4D0E-AD63-48A8CD7A770C}\MpKslcb5983fd.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"uwdirpog" (uwdirpog) - ? - C:\Users\Hannah\AppData\Local\Temp\uwdirpog.sys  (Hidden registry entry, rootkit activity | File not found)

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
{91774881-D725-4E58-B298-07617B9B86A8} "Skype IE add-on Pluggable Protocol" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} "Acrobat Elements Context Menu" - "Adobe Systems Inc." - C:\Program Files\Adobe\Acrobat 10.0\Acrobat Elements\ContextMenu.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{09A47860-11B0-4DA5-AFA5-26D86198A780} "EPP" - "Microsoft Corporation" - c:\PROGRA~1\MI239C~1\shellext.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{7842554E-6BED-11D2-8CDB-B05550C10000} "Monitor Class" - "Broadcom Corporation." - C:\Windows\system32\btncopy.dll
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" - "RealNetworks, Inc." - C:\Program Files\Real\RealPlayer\rpshell.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - ? -  (File not found | COM-object registry key not found)
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - ? - C:\Program Files\WinRAR\rarext.dll

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} "Java Plug-in 1.6.0_03" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} "Java Plug-in 1.6.0_05" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 10.5.1" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 10.5.1" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -  (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
"@btrez.dll,-4015" - ? - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} "ClsidExtension" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2iexp.dll
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Click to Call" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar )-----
<binary data> "Adobe PDF" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{AE7CD045-E861-484f-8273-0445EE161910} "Adobe PDF Conversion Toolbar Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Oracle Corporation" - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} "Skype Browser Helper" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{F4971EE7-DAA0-4053-9964-665D8EE6A077} "SmartSelect Class" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\OSA.EXE  (Shortcut exists | File exists)
"BTTray.lnk" - "Broadcom Corporation." - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Skype" - "Skype Technologies S.A." - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Acrobat Assistant 8.0" - "Adobe Systems Inc." - "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
"Adobe Acrobat Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher" - "Adobe Systems Incorporated" - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AppleSyncNotifier" - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"CanonMyPrinter" - "CANON INC." - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
"CanonSolutionMenu" - "CANON INC." - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"FLMOFFICE4DMOUSE" - ? - C:\Program Files\Browser MOUSE\mouse32a.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"LanguageShortcut" - ? - "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"MSC" - "Microsoft Corporation" - "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"RemoteControl" - "Cyberlink Corp." - "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"StartCCC" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe  (File found, but it contains no detailed information)
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Adobe PDF Port Monitor" - "Adobe Systems Inc" - C:\Windows\system32\AdobePDF.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243" (NisSrv) - "Microsoft Corporation" - c:\Program Files\Microsoft Security Client\NisSrv.exe
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"Machine Debug Manager" (MDM) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Microsoft Antimalware Service" (MsMpSvc) - "Microsoft Corporation" - c:\Program Files\Microsoft Security Client\MsMpEng.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"Samsung Update Plus" (Samsung Update Plus) - ? - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe  (File found, but it contains no detailed information)
"Skype Updater" (SkypeUpdate) - "Skype Technologies" - C:\Program Files\Skype\Updater\Updater.exe
"SQL Server VSS Writer" (SQLWriter) - "Microsoft Corporation" - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===

--- --- ---
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru
[/code]

cosinus 20.07.2012 08:46

Was ist mit aswMBR?

mirhannah 20.07.2012 08:53

Hab ich gestern abend nicht mehr geschafft. Es hat zwischendrin immer abgebrochen. Aber ohne Fehlermeldung. Kümmere mich heute Abend drum. Danke

das program hat sich schon wieder aufgehängt. hier der log von dem was es bis dahin geschaft hat. danach hat sich nichts mehr getan.
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-20 23:00:02
-----------------------------
23:00:02.473    OS Version: Windows 6.0.6002 Service Pack 2
23:00:02.473    Number of processors: 2 586 0xF0D
23:00:02.473    ComputerName: HANNAH-PC  UserName: Hannah
23:00:49.912    Initialize success
23:01:01.659    AVAST engine defs: 12071902
23:05:29.090    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:05:29.090    Disk 0 Vendor: Hitachi_HTS542516K9A300 BBCOC32P Size: 152627MB BusType: 3
23:05:29.121    Disk 0 MBR read successfully
23:05:29.121    Disk 0 MBR scan
23:05:29.184    Disk 0 unknown MBR code
23:05:29.199    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
23:05:29.230    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        70706 MB offset 20973568
23:05:29.262    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        71679 MB offset 165779456
23:05:29.262    Disk 0 scanning sectors +312578048
23:05:29.355    Disk 0 scanning C:\Windows\system32\drivers
23:05:43.239    Service scanning
23:06:17.544    Modules scanning
23:06:25.281    Disk 0 trace - called modules:
23:06:25.328    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
23:06:25.328    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x856eaac8]
23:06:25.328    3 CLASSPNP.SYS[87dab8b3] -> nt!IofCallDriver -> [0x851c9918]
23:06:25.344    5 acpi.sys[8324d6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85165030]
23:06:25.921    AVAST engine scan C:\Windows
23:06:29.696    AVAST engine scan C:\Windows\system32
23:10:54.477    AVAST engine scan C:\Windows\system32\drivers
23:11:10.763    AVAST engine scan C:\Users\Hannah
23:19:12.242    Disk 0 MBR has been saved successfully to "C:\Users\Hannah\Desktop\MBR.dat"
23:19:12.257    The log file has been saved successfully to "C:\Users\Hannah\Desktop\aswMBR1.txt"

und so sieht es aus wenn ich AV scan "none" wähle
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-20 23:30:13
-----------------------------
23:30:13.320    OS Version: Windows 6.0.6002 Service Pack 2
23:30:13.320    Number of processors: 2 586 0xF0D
23:30:13.320    ComputerName: HANNAH-PC  UserName: Hannah
23:30:14.459    Initialize success
23:30:23.772    AVAST engine defs: 12071902
23:30:30.106    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:30:30.106    Disk 0 Vendor: Hitachi_HTS542516K9A300 BBCOC32P Size: 152627MB BusType: 3
23:30:30.215    Disk 0 MBR read successfully
23:30:30.215    Disk 0 MBR scan
23:30:30.262    Disk 0 unknown MBR code
23:30:30.293    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
23:30:30.324    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        70706 MB offset 20973568
23:30:30.355    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        71679 MB offset 165779456
23:30:30.418    Disk 0 scanning sectors +312578048
23:30:30.558    Disk 0 scanning C:\Windows\system32\drivers
23:30:54.973    Service scanning
23:31:27.842    Modules scanning
23:31:51.601    Disk 0 trace - called modules:
23:31:51.664    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys atikmdag.sys watchdog.sys ndis.sys athr.sys usbhub.sys USBPORT.SYS usbohci.sys tcpip.sys NETIO.SYS
23:31:51.679    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x856eaac8]
23:31:51.679    3 CLASSPNP.SYS[87dab8b3] -> nt!IofCallDriver -> [0x851c9918]
23:31:51.695    5 acpi.sys[8324d6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85165030]
23:31:51.695    Scan finished successfully
23:32:17.669    Disk 0 MBR has been saved successfully to "C:\Users\Hannah\Desktop\MBR.dat"
23:32:17.684    The log file has been saved successfully to "C:\Users\Hannah\Desktop\aswMBR2.txt"


mirhannah 28.07.2012 12:35

Hallo Arne,
Vielen Dank für deine Hilfe.
Ist denn mein Pc jetzt wieder sauber?
Lieber Gruß
Hannah

cosinus 29.07.2012 00:23

sry hab deinen Strang übersehen, hier ist gerade einfach zuviel los :headbang:

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

mirhannah 30.07.2012 22:12

bei den ersten malen hat es sich wieder aufgehängt. Das ist dabei rausgekommen:
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-30 22:54:55
-----------------------------
22:54:55.683    OS Version: Windows 6.0.6002 Service Pack 2
22:54:55.683    Number of processors: 2 586 0xF0D
22:54:55.683    ComputerName: HANNAH-PC  UserName: Hannah
22:55:46.041    Initialize success
22:55:58.923    AVAST engine defs: 12073000
22:56:20.716    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:56:20.716    Disk 0 Vendor: Hitachi_HTS542516K9A300 BBCOC32P Size: 152627MB BusType: 3
22:56:20.732    Disk 0 MBR read successfully
22:56:20.747    Disk 0 MBR scan
22:56:20.763    Disk 0 Windows VISTA default MBR code
22:56:20.794    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
22:56:20.810    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        70706 MB offset 20973568
22:56:20.857    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        71679 MB offset 165779456
22:56:20.888    Disk 0 scanning sectors +312578048
22:56:20.997    Disk 0 scanning C:\Windows\system32\drivers
22:56:38.609    Service scanning
22:57:14.006    Modules scanning
22:57:26.564    Disk 0 trace - called modules:
22:57:27.110    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
22:57:27.125    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8517a8b0]
22:57:27.141    3 CLASSPNP.SYS[87c948b3] -> nt!IofCallDriver -> [0x85149938]
22:57:27.141    5 acpi.sys[832426bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x851565e0]
22:57:27.812    AVAST engine scan C:\Windows
22:57:31.603    AVAST engine scan C:\Windows\system32
23:02:03.045    AVAST engine scan C:\Windows\system32\drivers
23:02:19.113    AVAST engine scan C:\Users\Hannah
23:03:43.571    Disk 0 MBR has been saved successfully to "C:\Users\Hannah\Desktop\MBR.dat"
23:03:43.587    The log file has been saved successfully to "C:\Users\Hannah\Desktop\aswMBR4.txt"

dann hab ichs wieder mit "none" gemacht. dabei kam das raus:
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-30 23:04:09
-----------------------------
23:04:09.053    OS Version: Windows 6.0.6002 Service Pack 2
23:04:09.053    Number of processors: 2 586 0xF0D
23:04:09.053    ComputerName: HANNAH-PC  UserName: Hannah
23:04:09.677    Initialize success
23:04:17.258    AVAST engine defs: 12073000
23:04:30.841    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:04:30.841    Disk 0 Vendor: Hitachi_HTS542516K9A300 BBCOC32P Size: 152627MB BusType: 3
23:04:30.873    Disk 0 MBR read successfully
23:04:30.888    Disk 0 MBR scan
23:04:30.935    Disk 0 Windows VISTA default MBR code
23:04:30.951    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
23:04:30.982    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        70706 MB offset 20973568
23:04:31.013    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS        71679 MB offset 165779456
23:04:31.029    Disk 0 scanning sectors +312578048
23:04:31.122    Disk 0 scanning C:\Windows\system32\drivers
23:04:51.574    Service scanning
23:05:24.739    Modules scanning
23:05:44.927    Disk 0 trace - called modules:
23:05:44.958    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys tcpip.sys NETIO.SYS
23:05:44.974    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8517a8b0]
23:05:44.974    3 CLASSPNP.SYS[87c948b3] -> nt!IofCallDriver -> [0x85149938]
23:05:44.989    5 acpi.sys[832426bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x851565e0]
23:05:44.989    Scan finished successfully
23:06:17.921    Disk 0 MBR has been saved successfully to "C:\Users\Hannah\Desktop\MBR.dat"
23:06:17.936    The log file has been saved successfully to "C:\Users\Hannah\Desktop\aswMBR5.txt"


cosinus 31.07.2012 09:51

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

mirhannah 31.07.2012 09:52

ok, vielen Dank.
Mach ich heute nach der Arbeit.

hier der superantispyware bericht:
Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 08/01/2012 at 00:15 AM

Application Version : 5.5.1012

Core Rules Database Version : 8987
Trace Rules Database Version: 6799

Scan type      : Complete Scan
Total Scan Time : 02:49:47

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 799
Memory threats detected  : 0
Registry items scanned    : 35227
Registry threats detected : 0
File items scanned        : 167830
File threats detected    : 303

Adware.Tracking Cookie
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@ad3.adfarm1.adition[1].txt [ /ad3.adfarm1.adition ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@adbrite[2].txt [ /adbrite ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@adopt.euroclick[2].txt [ /adopt.euroclick ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@ads.adbrite[1].txt [ /ads.adbrite ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@adserver.71i[1].txt [ /adserver.71i ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@adtech[2].txt [ /adtech ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@advertising[2].txt [ /advertising ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@atwola[2].txt [ /atwola ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@cdn.at.atwola[1].txt [ /cdn.at.atwola ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@divx.112.2o7[1].txt [ /divx.112.2o7 ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@doubleclick[2].txt [ /doubleclick ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@im.banner.t-online[1].txt [ /im.banner.t-online ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@imrworldwide[2].txt [ /imrworldwide ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@mediacenter.sf[2].txt [ /mediacenter.sf ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@questionmarket[2].txt [ /questionmarket ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@sevenoneintermedia.112.2o7[1].txt [ /sevenoneintermedia.112.2o7 ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@statse.webtrendslive[2].txt [ /statse.webtrendslive ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@webmasterplan[2].txt [ /webmasterplan ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\hannah@windowsmedia[2].txt [ /windowsmedia ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\46OY2XZ1.txt [ /c.atdmt.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\APQ47S0Z.txt [ /adfarm1.adition.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\PVNJ6YYY.txt [ /apmebf.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\IBPO4LLI.txt [ /mediaplex.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\135IKOIN.txt [ /serving-sys.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\FI91L2FD.txt [ /fastclick.net ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\9UGF093O.txt [ /track.adform.net ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\YYTHEHHI.txt [ /ad.yieldmanager.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\N2D5HYDG.txt [ /adform.net ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\V8IALMGF.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\HU8KJUFL.txt [ /eas.apm.emediate.eu ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\3RDQC5MK.txt [ /invitemedia.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\2RFMZ2QR.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Hannah\AppData\Roaming\Microsoft\Windows\Cookies\BSN9X7AE.txt [ /bs.serving-sys.com ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@e-2dj6wjk4oldjgfp.stats.esomniture[2].txt [ Cookie:hannah@e-2dj6wjk4oldjgfp.stats.esomniture.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@studivz.adfarm1.adition[1].txt [ Cookie:hannah@studivz.adfarm1.adition.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@allesklarcomag.112.2o7[1].txt [ Cookie:hannah@allesklarcomag.112.2o7.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@content.yieldmanager[1].txt [ Cookie:hannah@content.yieldmanager.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\W24E1G7D.txt [ Cookie:hannah@doubleclick.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@atdmt[2].txt [ Cookie:hannah@atdmt.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@apmebf[2].txt [ Cookie:hannah@apmebf.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@de.sitestat[1].txt [ Cookie:hannah@de.sitestat.com/titus/de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@insightexpressai[2].txt [ Cookie:hannah@insightexpressai.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@adx.chip[2].txt [ Cookie:hannah@adx.chip.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@banner.herr-der-ringe-film[1].txt [ Cookie:hannah@banner.herr-der-ringe-film.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@serving-sys[1].txt [ Cookie:hannah@serving-sys.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@adserver.71i[1].txt [ Cookie:hannah@adserver.71i.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\S8W0DTIV.txt [ Cookie:hannah@fastclick.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@dyntracker[1].txt [ Cookie:hannah@dyntracker.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@revenue[2].txt [ Cookie:hannah@revenue.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@track.adform[2].txt [ Cookie:hannah@track.adform.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\QNRBR95C.txt [ Cookie:hannah@revsci.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@e-2dj6wbkygpc5ofo.stats.esomniture[2].txt [ Cookie:hannah@e-2dj6wbkygpc5ofo.stats.esomniture.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@webmasterplan[2].txt [ Cookie:hannah@webmasterplan.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@adbrite[1].txt [ Cookie:hannah@adbrite.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@e-2dj6wjkyqgczikp.stats.esomniture[1].txt [ Cookie:hannah@e-2dj6wjkyqgczikp.stats.esomniture.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@www.zanox-affiliate[1].txt [ Cookie:hannah@www.zanox-affiliate.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@komtrack[2].txt [ Cookie:hannah@komtrack.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@adviva[1].txt [ Cookie:hannah@adviva.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@e-2dj6wjkywpajeep.stats.esomniture[2].txt [ Cookie:hannah@e-2dj6wjkywpajeep.stats.esomniture.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@bfast[1].txt [ Cookie:hannah@bfast.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@unitymedia[2].txt [ Cookie:hannah@unitymedia.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@xiti[1].txt [ Cookie:hannah@xiti.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@adserver.adtechus[1].txt [ Cookie:hannah@adserver.adtechus.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@ad2.adfarm1.adition[1].txt [ Cookie:hannah@ad2.adfarm1.adition.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\9K2HAMGU.txt [ Cookie:hannah@eas.apm.emediate.eu/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@casalemedia[1].txt [ Cookie:hannah@casalemedia.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\PDMX5YSY.txt [ Cookie:hannah@ad.zanox.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@adecn[1].txt [ Cookie:hannah@adecn.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@paypal.112.2o7[1].txt [ Cookie:hannah@paypal.112.2o7.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@data.coremetrics[1].txt [ Cookie:hannah@data.coremetrics.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@specificclick[2].txt [ Cookie:hannah@specificclick.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@e-2dj6wnloaiczscq.stats.esomniture[1].txt [ Cookie:hannah@e-2dj6wnloaiczscq.stats.esomniture.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@msnportal.112.2o7[1].txt [ Cookie:hannah@msnportal.112.2o7.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@advertising[2].txt [ Cookie:hannah@advertising.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\TL1225QL.txt [ Cookie:hannah@adtech.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@imrworldwide[2].txt [ Cookie:hannah@imrworldwide.com/cgi-bin ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@tacoda[2].txt [ Cookie:hannah@tacoda.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\TGUEJ6CP.txt [ Cookie:hannah@im.banner.t-online.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@at.atwola[2].txt [ Cookie:hannah@at.atwola.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@statcounter[2].txt [ Cookie:hannah@statcounter.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@clickfuse[1].txt [ Cookie:hannah@clickfuse.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\E0NHKEF3.txt [ Cookie:hannah@tribalfusion.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@tracking.mindshare[1].txt [ Cookie:hannah@tracking.mindshare.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@c1.atdmt[1].txt [ Cookie:hannah@c1.atdmt.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@ad.dyntracker[1].txt [ Cookie:hannah@ad.dyntracker.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@invitemedia[1].txt [ Cookie:hannah@invitemedia.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@microsoftsto.112.2o7[1].txt [ Cookie:hannah@microsoftsto.112.2o7.net/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@ads1.moonchildmedia[1].txt [ Cookie:hannah@ads1.moonchildmedia.de/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@fl01.ct2.comclick[2].txt [ Cookie:hannah@fl01.ct2.comclick.com/ ]
        C:\USERS\HANNAH\AppData\Roaming\Microsoft\Windows\Cookies\Low\hannah@traffictrack[1].txt [ Cookie:hannah@traffictrack.de/ ]
        C:\USERS\HANNAH\Cookies\hannah@doubleclick[2].txt [ Cookie:hannah@doubleclick.net/ ]
        C:\USERS\HANNAH\Cookies\PVNJ6YYY.txt [ Cookie:hannah@apmebf.com/ ]
        C:\USERS\HANNAH\Cookies\135IKOIN.txt [ Cookie:hannah@serving-sys.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@questionmarket[2].txt [ Cookie:hannah@questionmarket.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@adserver.71i[1].txt [ Cookie:hannah@adserver.71i.de/ ]
        C:\USERS\HANNAH\Cookies\FI91L2FD.txt [ Cookie:hannah@fastclick.net/ ]
        C:\USERS\HANNAH\Cookies\9UGF093O.txt [ Cookie:hannah@track.adform.net/ ]
        C:\USERS\HANNAH\Cookies\hannah@ads.adbrite[1].txt [ Cookie:hannah@ads.adbrite.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@cdn.at.atwola[1].txt [ Cookie:hannah@cdn.at.atwola.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@webmasterplan[2].txt [ Cookie:hannah@webmasterplan.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@adbrite[2].txt [ Cookie:hannah@adbrite.com/ ]
        C:\USERS\HANNAH\Cookies\V8IALMGF.txt [ Cookie:hannah@ad2.adfarm1.adition.com/ ]
        C:\USERS\HANNAH\Cookies\HU8KJUFL.txt [ Cookie:hannah@eas.apm.emediate.eu/ ]
        C:\USERS\HANNAH\Cookies\3RDQC5MK.txt [ Cookie:hannah@invitemedia.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@adopt.euroclick[2].txt [ Cookie:hannah@adopt.euroclick.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@atwola[2].txt [ Cookie:hannah@atwola.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@windowsmedia[2].txt [ Cookie:hannah@windowsmedia.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@advertising[2].txt [ Cookie:hannah@advertising.com/ ]
        C:\USERS\HANNAH\Cookies\hannah@adtech[2].txt [ Cookie:hannah@adtech.de/ ]
        C:\USERS\HANNAH\Cookies\hannah@imrworldwide[2].txt [ Cookie:hannah@imrworldwide.com/cgi-bin ]
        C:\USERS\HANNAH\Cookies\hannah@im.banner.t-online[1].txt [ Cookie:hannah@im.banner.t-online.de/ ]
        ia.media-imdb.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UK7JDANQ ]
        www.royalmediamarketing.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UK7JDANQ ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@AXELSPRINGER.122.2O7[1].TXT [ /AXELSPRINGER.122.2O7 ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@AD.ADC-SERV[1].TXT [ /AD.ADC-SERV ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@AD4.ADFARM1.ADITION[2].TXT [ /AD4.ADFARM1.ADITION ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADFORM[1].TXT [ /ADFORM ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@MEDIAPLEX[1].TXT [ /MEDIAPLEX ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@DIVX.112.2O7[1].TXT [ /DIVX.112.2O7 ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADS.PUBMATIC[2].TXT [ /ADS.PUBMATIC ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@MEDIA6DEGREES[2].TXT [ /MEDIA6DEGREES ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@AD.ADNET[1].TXT [ /AD.ADNET ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADSERVER.KINO-ZEIT[1].TXT [ /ADSERVER.KINO-ZEIT ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@STATSE.WEBTRENDSLIVE[2].TXT [ /STATSE.WEBTRENDSLIVE ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@BS.SERVING-SYS[2].TXT [ /BS.SERVING-SYS ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@TRACKING.HANNOVERSCHE[2].TXT [ /TRACKING.HANNOVERSCHE ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADSERVER.W3ANYTHINK[1].TXT [ /ADSERVER.W3ANYTHINK ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@AD.AD-SRV[2].TXT [ /AD.AD-SRV ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADS.UNDERTONE[2].TXT [ /ADS.UNDERTONE ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@GUJ.122.2O7[1].TXT [ /GUJ.122.2O7 ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADS.MEDIENHAUS[1].TXT [ /ADS.MEDIENHAUS ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@TRACKING.QUISMA[2].TXT [ /TRACKING.QUISMA ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@TRADEDOUBLER[1].TXT [ /TRADEDOUBLER ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADS.HEIAS[1].TXT [ /ADS.HEIAS ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADS.CREATIVE-SERVING[2].TXT [ /ADS.CREATIVE-SERVING ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@SEVENONEINTERMEDIA.112.2O7[1].TXT [ /SEVENONEINTERMEDIA.112.2O7 ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@A.REVENUEMAX[1].TXT [ /A.REVENUEMAX ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@2O7[1].TXT [ /2O7 ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ZANOX-AFFILIATE[2].TXT [ /ZANOX-AFFILIATE ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADS.BESSERPLANEN[2].TXT [ /ADS.BESSERPLANEN ]
        C:\USERS\HANNAH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\HANNAH@ADS.ADK2[2].TXT [ /ADS.ADK2 ]
        .guj.122.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .122.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .122.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .webresint.122.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .getclicky.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .static.getclicky.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .opodo.122.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        tracking.sim-technik.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .tns-counter.ru [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        s03.flagcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .c.gigcount.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .cinemaviewfinder.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .turneruk.112.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.belstat.be [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .mediabiz.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .hearst.112.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .usatoday1.112.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .fisherbrothersmedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .countby.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .media.mtvnservices.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .media.mtvnservices.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .corbis.122.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .8tracks.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .estat.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .flagcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .stats.complex.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .stats.complex.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .123count.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .123count.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .123count.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .steelhousemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .steelhousemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .artmediaagency.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .artmediaagency.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.tracker.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.tracker.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .mediabiz.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .mediabiz.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .starmedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .starmedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .gambitstat.org [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .bestcontentfind.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .citygridmedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        nedstat.hostelbookers.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        nedstat.hostelbookers.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        stats.kultur-online.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .rcsmediagroup.it [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .rcsmediagroup.it [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .bravenet.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .pearson.122.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .countomat.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .germanwings.112.2o7.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        commons.wikimedia.org [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        sales.liveperson.net [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .fuckyeahexistentialism.tumblr.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .fuckyeahexistentialism.tumblr.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]
        goodcounter.org [ C:\USERS\HANNAH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\X6B6U5GH.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-FakeAV
        C:\PROGRAM FILES\WINRAR\DEFAULT.SFX

der andere folgt heute abend.

cosinus 01.08.2012 15:11

Kommt das andere Log noch?

mirhannah 01.08.2012 15:13

ja, kommt. bin noch auf der Arbeit und kann hier schlecht einen scan durchführen...

Code:

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.01.06

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Hannah :: HANNAH-PC [Administrator]

01.08.2012 21:50:17
mbam-log-2012-08-01 (21-50-17).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 365333
Laufzeit: 2 Stunde(n), 5 Minute(n), 56 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 02.08.2012 12:12

Sieht ok aus, da wurden nur Cookies gefunden.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

mirhannah 02.08.2012 12:20

Super. Vielen Dank für die Tipps. Ich denke ich werde dann das mit den Cookies direkt löschen einstellen. Lieber ein bisschen mehr arbeit beim anmelden als unsicher surfen. Ich hatte auch überlegt ob ich meinen Pc mal komplett neu mache, aber dazu hab ich momentan nicht die Zeit.

Probleme sehe ich eigentlich keine mehr. Nur gelegentlich öffnet sich unverhofft ein Hinweis, der besagt: Adobe Flash player update service 11.3 r300 funktioniert nicht mehr.
Vielen Lieben Dank,

Hannah

cosinus 03.08.2012 12:28

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 10:24 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19