Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojaner TR/ATRAPS.Gen2 (https://www.trojaner-board.de/125174-trojaner-tr-atraps-gen2.html)

schustan 04.10.2012 20:25

Trojaner TR/ATRAPS.Gen2
 
hallo

ich bin auch opfer des TR/ATRAPS.Gen2 geworden. ich hab mir in anderen forenbeiträgen schonmal grob durchgelesen, was zu tun ist.
und zwar hier

den Vollscan (alle lokalen laufwerke) mit Malwarebytes Anti-Malware habe ich bereits gemacht.
hier der log nach dem Scan

Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.04.06

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Andreas :: ANDREAS-PC [Administrator]

04.10.2012 17:28:18
mbam-log-2012-10-04 (20-57-46).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 465305
Laufzeit: 3 Stunde(n), 26 Minute(n), 4 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\Users\Andreas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JN6H3IZ9\WORLD_21_target_5830[1].exe (PUP.Adware.Agent) -> Keine Aktion durchgeführt.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Keine Aktion durchgeführt.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\000000cb.@ (Rootkit.0Access) -> Keine Aktion durchgeführt.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@ (Rootkit.0Access.64) -> Keine Aktion durchgeführt.

(Ende)

und hier der Log NACH dem Löschen der 4 infizierten Files.

Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.04.06

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Andreas :: ANDREAS-PC [Administrator]

04.10.2012 17:28:18
mbam-log-2012-10-04 (17-28-18).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 465305
Laufzeit: 3 Stunde(n), 26 Minute(n), 4 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 4
C:\Users\Andreas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JN6H3IZ9\WORLD_21_target_5830[1].exe (PUP.Adware.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\000000cb.@ (Rootkit.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@ (Rootkit.0Access.64) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Avira AntiVir hat nach dem "erfolgreichen Löschen" und dem neu booten allerdings die selbe Meldung angezeigt :-( also offenbar noch kein Erfolg!
(es steht in der avira-meldung, dass der zugriff auf die datei verweigert wurde.)

als kommendes habe ich den Systemscan mit OTL gemacht. hier das logfile.

Code:

OTL logfile created on: 04.10.2012 21:07:27 - Run 1
OTL by OldTimer - Version 3.2.70.2    Folder = C:\Users\Andreas\Dropbox
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,47 Gb Available Physical Memory | 61,76% Memory free
8,16 Gb Paging File | 6,43 Gb Available in Paging File | 78,70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453,74 Gb Total Space | 221,35 Gb Free Space | 48,78% Space Free | Partition Type: NTFS
Drive D: | 12,02 Gb Total Space | 1,93 Gb Free Space | 16,04% Space Free | Partition Type: NTFS
 
Computer Name: ANDREAS-PC | User Name: Andreas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Andreas\Dropbox\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
PRC - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe ()
PRC - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Windows\SysWOW64\WerFault.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files (x86)\AAVUpdateManager\aavus.exe ()
PRC - C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Programme\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Programme\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - C:\Programme\Microsoft Office\OFFICE11\OUTLCTL.DLL ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\Hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (Ati External Event Utility) -- C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (SearchAnonymizer) -- C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (DokanMounter) -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Recovery Service for Windows) -- C:\Program Files (x86)\SMINST\BLService.exe ()
SRV - (TVCapSvc) -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched) -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (AAV UpdateService) -- C:\Program Files (x86)\AAVUpdateManager\aavus.exe ()
SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (NEOFLTR_710_19243) -- C:\Windows\SysNative\Drivers\NEOFLTR_710_19243.SYS (Juniper Networks)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\DRIVERS\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\DRIVERS\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (Dokan) -- C:\Windows\SysNative\drivers\dokan.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (ctxusbm) -- C:\Windows\SysNative\DRIVERS\ctxusbm.sys (Citrix Systems, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (JMCR) -- C:\Windows\SysNative\DRIVERS\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys (Nokia)
DRV:64bit: - (nmwcdnsucx64) -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys (Nokia)
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys (Nokia)
DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (NETw5v64) -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (enecir) -- C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation                                            )
DRV:64bit: - (NETw3v64) -- C:\Windows\SysNative\DRIVERS\NETw3v64.sys (Intel Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr) -- C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (yukonx64) -- C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B4F381CE-68D8-4179-A60A-797EC0C34865}
IE:64bit: - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE:64bit: - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE:64bit: - HKLM\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\..\URLSearchHook: {b106b661-3e1b-4015-af5c-195e909f35c6} - C:\Program Files (x86)\NCH_DE\prxtbNCH_.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
IE - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}: "URL" = hxxp://search.qip.ru/?query={searchTerms}
IE - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKLM\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://search.qip.ru
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.qip.ru
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://webzugang.brnet.de/dana-na/auth/url_default/welcome.cgi
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
IE - HKCU\..\URLSearchHook: {b106b661-3e1b-4015-af5c-195e909f35c6} - C:\Program Files (x86)\NCH_DE\prxtbNCH_.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494538535243&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKCU\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net.anonymize-me.de/?anonymto=687474703A2F2F64652E6B656C6B6F6F706172746E6572732E6E65742F63746C2F646F2F7365617263683F7369746553656172636851756572793D7B7365617263685465726D737D2666726F6D666F726D3D7472756526783D7472756526793D7472756526706172746E65723D687026706172746E657249643D3936393133393333&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKCU\..\SearchScopes\{19EAF838-C817-489D-9164-4F9D7CDF11DE}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{58351DFF-916A-410C-B2B1-B5127B5EDC9C}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKCU\..\SearchScopes\{67E737C1-2EA9-4E09-9226-ED9F878CCED4}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{96E2641C-19A6-4E4D-B569-5295DCAF3EEA}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{A296D9B5-0565-4DC2-9F05-EC9F3C5EA171}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}: "URL" = hxxp://search.qip.ru.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E7169702E72752F3F71756572793D7B7365617263685465726D737D&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKCU\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com.anonymize-me.de/?anonymto=687474703A2F2F736C69727372656469726563742E7365617263682E616F6C2E636F6D2F736C6972735F687474702F7372656469723F7372656469723D313134352671756572793D7B7365617263685465726D737D26696E766F636174696F6E547970653D746235306870636E6E626965372D64652D6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKCU\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com.anonymize-me.de/?anonymto=687474703A2F2F64652E7365617263682E7961686F6F2E636F6D2F7365617263683F703D7B7365617263685465726D737D2665693D7B696E707574456E636F64696E677D2666723D63622D6870303626747970653D696532303038&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKCU\..\SearchScopes\{CE7156AD-F537-461D-8488-1997877AA4EA}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{F4435E4E-EB74-4D9A-B706-A9B71780D292}: "URL" = hxxp://www.google.de.anonymize-me.de/?anonymto=687474703A2F2F7777772E676F6F676C652E64652F7365617263683F713D7B7365617263685465726D737D&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "heute.de"
FF - prefs.js..extensions.enabledAddons: optout@google.com:1.5
FF - prefs.js..extensions.enabledAddons: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.2.1
FF - prefs.js..extensions.enabledAddons: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledAddons: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..extensions.enabledAddons: {b106b661-3e1b-4015-af5c-195e909f35c6}:10.10.27.6
FF - prefs.js..extensions.enabledAddons: firejump@firejump.net:1.0.2.5
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.6
FF - prefs.js..extensions.enabledItems: helperbar@helperbar.com:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.12
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q="
FF - prefs.js..network.proxy.http: "128.6.192.158"
FF - prefs.js..network.proxy.http_port: 3127
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.10.11 12:30:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.08 11:37:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.09.08 11:37:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.06.23 10:25:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\extension@preispilot.com: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\extension@preispilot.com
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\firejump@firejump.net [2012.08.21 16:22:46 | 000,000,000 | ---D | M]
 
[2011.06.19 19:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions
[2011.06.19 19:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009.11.08 15:16:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2012.09.26 15:45:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions
[2012.08.18 19:54:32 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010.04.30 11:50:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.05.23 16:06:37 | 000,000,000 | ---D | M] (QipAuthorizer) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
[2011.02.03 21:34:01 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010.08.23 20:56:39 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.09.18 19:23:51 | 000,000,000 | ---D | M] (NCH DE) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{b106b661-3e1b-4015-af5c-195e909f35c6}
[2012.08.21 16:22:46 | 000,000,000 | ---D | M] (FireJump) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\firejump@firejump.net
[2012.08.24 00:20:32 | 000,000,000 | ---D | M] ("Avira SearchFree Toolbar plus Web Protection") -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\toolbar@ask.com
[2012.08.26 13:07:59 | 000,008,363 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\optout@google.com.xpi
[2012.09.26 15:45:30 | 000,529,316 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012.08.18 19:54:32 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.11.12 13:10:02 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012.08.21 16:23:06 | 000,002,702 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\ecosia.xml
[2012.08.21 16:23:06 | 000,002,014 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\firefox-add-ons.xml
[2012.08.21 16:23:06 | 000,002,707 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icq-search.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-1.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-2.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-3.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin.xml
[2012.09.15 16:16:14 | 000,002,401 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\Web Search.xml
[2012.08.21 16:23:06 | 000,002,186 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{6E8BA072-B308-40CD-BE3C-ECF3C1030F06}.xml
[2012.08.21 16:23:06 | 000,002,075 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{6FFD10E3-90CF-4C13-8A9C-14588B33DDA3}.xml
[2012.08.21 16:23:06 | 000,001,868 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{AA1117CE-3DFB-43B9-B157-D1F3907A8B15}.xml
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.08 11:37:19 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.09.08 11:37:32 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009.09.12 23:05:42 | 000,124,240 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll
[2009.09.12 23:06:22 | 000,070,488 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll
[2009.09.12 23:06:32 | 000,091,480 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll
[2009.09.12 23:06:28 | 000,022,360 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll
[2009.09.12 23:08:36 | 000,406,864 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll
[2009.09.12 23:06:24 | 000,023,896 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll
[2012.08.21 18:28:02 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.31 18:14:13 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.21 18:28:02 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.21 18:28:02 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.21 18:28:02 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.21 18:28:02 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.05.11 18:39:40 | 000,000,935 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1 im.adtech.de
O1 - Hosts: 127.0.0.1 adserver.adtech.de
O1 - Hosts: 127.0.0.1 adtech.de
O1 - Hosts: 127.0.0.1 atwola.com
O1 - Hosts: 127.0.0.1 adserver.71i.de
O1 - Hosts: 127.0.0.1 adicqserver.71i.de
O1 - Hosts: 127.0.0.1 71i.de
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (NCH DE Toolbar) - {b106b661-3e1b-4015-af5c-195e909f35c6} - C:\Program Files (x86)\NCH_DE\prxtbNCH_.dll (Conduit Ltd.)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (NCH DE Toolbar) - {b106b661-3e1b-4015-af5c-195e909f35c6} - C:\Program Files (x86)\NCH_DE\prxtbNCH_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Infium] C:\Program Files (x86)\QIP 2010\qip.exe (QIP)
O4 - Startup: C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro3.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://webzugang.brnet.de/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{552B14CB-20AD-4649-BAFC-D79E76C6329F}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\cdo - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Andreas\Eigener Zwischenspeicher\Wallpaper\DSC07649.JPG
O24 - Desktop BackupWallPaper: C:\Users\Andreas\Eigener Zwischenspeicher\Wallpaper\DSC07649.JPG
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{de514ff2-b638-11de-80da-00238b965f48}\Shell\AutoRun\command - "" = F:\Launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.04 17:27:05 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Malwarebytes
[2012.10.04 17:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.04 17:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.04 17:26:49 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.04 17:26:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.10.03 12:46:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2012.10.03 12:46:38 | 000,000,000 | ---D | C] -- C:\rei
[2012.10.03 12:46:33 | 000,000,000 | ---D | C] -- C:\Program Files\Reimage
[2012.10.03 11:12:28 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Local\Macroplant_LLC
[2012.10.03 11:12:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dokan
[2012.10.03 11:12:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phone Disk
[2012.10.03 11:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Phone Disk
[2012.10.03 10:49:20 | 003,419,216 | ---- | C] (Macroplant LLC                                              ) -- C:\Users\Andreas\Desktop\Phone_Disk_Setup.exe
[2012.10.03 10:48:03 | 004,156,848 | ---- | C] (WindSolutions) -- C:\Users\Andreas\Desktop\Install_CopyTrans_Suite.exe
[2012.10.02 08:45:40 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\shortcut Fotos
[2012.09.30 08:46:39 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
[2012.09.30 08:46:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2012.09.30 08:46:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GMX SMS-Manager
[2012.09.26 21:51:55 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bigasoft Audio Converter
[2012.09.26 21:51:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bigasoft Audio Converter
[2012.09.26 21:47:02 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\hörbuch-temp
[2012.09.26 21:46:22 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU
[2012.09.26 21:46:18 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\AVS4YOU
[2012.09.26 21:45:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU
[2012.09.26 21:44:48 | 011,137,024 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\libmfxsw32.dll
[2012.09.26 21:44:48 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GdiPlus.dll
[2012.09.26 21:44:47 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3a.dll
[2012.09.26 21:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia
[2012.09.26 09:33:43 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\Wasser
[2012.09.26 09:33:33 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\temp
[2012.09.25 03:02:44 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.09.25 03:02:44 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.09.25 03:02:40 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.09.25 03:02:40 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.09.25 03:02:40 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012.09.25 03:02:40 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012.09.25 03:02:39 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.09.25 03:02:39 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.09.25 03:02:38 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012.09.25 03:02:38 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012.09.25 03:02:38 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012.09.25 03:02:38 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012.09.25 03:02:37 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012.09.25 03:02:37 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012.09.25 03:02:37 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012.09.18 20:56:46 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
[2012.09.18 20:56:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\No.23 Recorder
[2012.09.18 20:29:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lame For Audacity
[2012.09.18 20:15:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64
[2012.09.18 20:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack x64
[2012.09.18 20:12:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012.09.18 20:12:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012.09.18 19:24:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2012.09.18 19:24:00 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Local\Conduit
[2012.09.18 19:23:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NCH_DE
[2012.09.18 19:23:39 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\NCH Software
[2012.09.18 19:23:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
[2012.09.18 19:23:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audioverwandte Programme
[2012.09.18 19:21:07 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
[2012.09.17 13:01:19 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Local\{E8F2465D-AB5F-4AF0-85D0-71C9F53F9FCF}
[2012.09.17 12:44:42 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\HandBrake
[2012.09.17 12:40:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft Free Studio
[2012.09.15 17:24:34 | 000,000,000 | ---D | C] -- C:\ProgramData\VistaCodecs
[2012.09.15 16:17:07 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\TuneUp Software
[2012.09.15 16:16:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.09.15 16:16:50 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012.09.15 16:16:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012.09.15 16:16:27 | 000,719,872 | ---- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll
[2012.09.15 16:16:27 | 000,369,152 | ---- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll
[2012.09.15 16:16:27 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2012.09.15 16:16:27 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll
[2012.09.15 16:16:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2012.09.15 16:14:40 | 000,327,749 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\drvc.dll
[2012.09.15 16:14:40 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2012.09.15 16:13:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft
[2012.09.15 13:26:12 | 000,000,000 | ---D | C] -- C:\ProgramData\xml_param
[2012.09.15 13:22:53 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\iSkysoft Video Converter
[2012.09.15 13:22:18 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\Windows\SysWow64\iconv.dll
[2012.09.15 12:56:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ashampoo
[2012.09.08 11:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2007.08.13 17:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\Andreas\AppData\Local\CDRip.dll
[2007.01.18 21:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\Andreas\AppData\Local\No23 Recorder.exe
[2006.12.11 19:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\Andreas\AppData\Local\basscd.dll
[2006.12.11 19:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\Andreas\AppData\Local\bass.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.04 21:00:59 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.04 21:00:59 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.04 21:00:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.04 21:00:34 | 4292,026,368 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.04 17:26:51 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.04 16:29:31 | 000,674,446 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.04 16:29:31 | 000,634,540 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.04 16:29:31 | 000,119,106 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.04 16:29:30 | 000,145,100 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.04 16:29:29 | 001,566,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.03 12:47:53 | 000,000,286 | ---- | M] () -- C:\Windows\reimage.ini
[2012.10.03 12:11:31 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.10.03 12:11:31 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.10.03 11:12:07 | 000,000,825 | ---- | M] () -- C:\Users\Public\Desktop\Phone Disk.lnk
[2012.10.03 11:09:21 | 001,546,632 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.03 10:49:40 | 003,419,216 | ---- | M] (Macroplant LLC                                              ) -- C:\Users\Andreas\Desktop\Phone_Disk_Setup.exe
[2012.10.03 10:48:28 | 004,156,848 | ---- | M] (WindSolutions) -- C:\Users\Andreas\Desktop\Install_CopyTrans_Suite.exe
[2012.10.03 10:03:06 | 000,102,912 | ---- | M] () -- C:\Users\Andreas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.30 09:09:16 | 000,000,702 | ---- | M] () -- C:\Users\Andreas\Documents\Software-Liste.rtf
[2012.09.29 16:55:55 | 408,891,301 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.09.21 23:50:04 | 000,000,034 | ---- | M] () -- C:\Windows\cdplayer.ini
[2012.09.21 16:51:03 | 000,321,800 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.18 21:10:52 | 000,001,478 | ---- | M] () -- C:\Users\Andreas\AppData\Local\RecConfig.xml
[2012.09.18 19:24:10 | 000,000,009 | ---- | M] () -- C:\END
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2012.10.04 17:26:51 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.03 12:47:41 | 000,000,286 | ---- | C] () -- C:\Windows\reimage.ini
[2012.10.03 11:12:07 | 000,000,825 | ---- | C] () -- C:\Users\Public\Desktop\Phone Disk.lnk
[2012.09.30 09:09:15 | 000,000,702 | ---- | C] () -- C:\Users\Andreas\Documents\Software-Liste.rtf
[2012.09.30 08:46:33 | 000,000,968 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GMX-SMS-Manager.lnk
[2012.09.18 20:59:06 | 000,001,478 | ---- | C] () -- C:\Users\Andreas\AppData\Local\RecConfig.xml
[2012.09.18 20:15:43 | 000,206,336 | ---- | C] () -- C:\Windows\SysNative\unrar.dll
[2012.09.18 20:15:43 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll
[2012.09.18 20:15:41 | 000,127,488 | ---- | C] () -- C:\Windows\SysNative\ff_vfw.dll
[2012.09.18 20:12:22 | 000,000,977 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Videobearbeitungs-Software.lnk
[2012.09.18 19:24:10 | 000,000,009 | ---- | C] () -- C:\END
[2012.09.18 19:23:31 | 000,001,861 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Audiobearbeitungs-Software.lnk
[2012.09.15 16:16:27 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2012.09.15 13:22:18 | 000,675,840 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.ax
[2012.09.15 13:22:18 | 000,496,640 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012.08.21 16:22:44 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2012.08.18 20:12:37 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\Gif89.dll
[2011.03.30 17:53:19 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2010.04.19 20:37:22 | 000,004,096 | -H-- | C] () -- C:\Users\Andreas\AppData\Local\keyfile3.drm
[2009.09.13 14:09:06 | 000,000,182 | ---- | C] () -- C:\Users\Andreas\AppData\Roaming\default.rss
[2009.05.30 12:28:11 | 000,000,212 | ---- | C] () -- C:\Users\Andreas\AppData\Roaming\wklnhst.dat
[2009.05.17 20:55:29 | 000,102,912 | ---- | C] () -- C:\Users\Andreas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.08.13 17:46:00 | 000,155,136 | ---- | C] () -- C:\Users\Andreas\AppData\Local\lame_enc.dll
[2006.10.26 01:06:48 | 000,064,000 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbisenc.dll
[2006.10.26 01:06:48 | 000,019,456 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbisfile.dll
[2006.10.26 01:06:46 | 000,143,872 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbis.dll
[2006.10.26 01:06:36 | 000,015,872 | ---- | C] () -- C:\Users\Andreas\AppData\Local\ogg.dll
[2005.08.23 22:34:06 | 000,029,184 | ---- | C] () -- C:\Users\Andreas\AppData\Local\no23xwrapper.dll
 
========== ZeroAccess Check ==========
 
[2011.11.18 22:55:05 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
[2012.10.03 12:01:04 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L
[2012.10.04 21:04:40 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U
[2012.10.04 21:00:44 | 000,000,804 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\00000004.@
[2012.10.03 11:51:17 | 000,002,048 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000004.@
[2012.10.04 21:04:40 | 000,232,960 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@
[2012.10.04 21:04:33 | 000,001,632 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\000000cb.@
[2012.10.04 21:04:34 | 000,016,896 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@
[2012.10.04 21:04:37 | 000,087,040 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000032.@
[2012.10.04 04:32:55 | 000,072,704 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000064.@
[2006.11.02 17:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[2012.10.04 21:00:40 | 000,004,608 | -HS- | M] () -- C:\Windows\assembly\GAC_32\Desktop.ini
[2012.10.04 21:00:40 | 000,006,144 | -HS- | M] () -- C:\Windows\assembly\GAC_64\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 00:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.21 04:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >

die Datei Extras.Txt wurde ebenfalls erzeugt ...

Code:

OTL Extras logfile created on: 04.10.2012 21:07:27 - Run 1
OTL by OldTimer - Version 3.2.70.2    Folder = C:\Users\Andreas\Dropbox
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,47 Gb Available Physical Memory | 61,76% Memory free
8,16 Gb Paging File | 6,43 Gb Available in Paging File | 78,70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453,74 Gb Total Space | 221,35 Gb Free Space | 48,78% Space Free | Partition Type: NTFS
Drive D: | 12,02 Gb Total Space | 1,93 Gb Free Space | 16,04% Space Free | Partition Type: NTFS
 
Computer Name: ANDREAS-PC | User Name: Andreas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Unable to open value key
htmlfile [edit] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Unable to open value key
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Unable to open value key
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Programme\Winamp\winamp.exe" /BOOKMARK "%1"
Directory [Winamp.Enqueue] -- "C:\Programme\Winamp\winamp.exe" /ADD "%1"
Directory [Winamp.Play] -- "C:\Programme\Winamp\winamp.exe" "%1"
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Unable to open value key
htmlfile [edit] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Programme\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Unable to open value key
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Unable to open value key
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Programme\Winamp\winamp.exe" /BOOKMARK "%1"
Directory [Winamp.Enqueue] -- "C:\Programme\Winamp\winamp.exe" /ADD "%1"
Directory [Winamp.Play] -- "C:\Programme\Winamp\winamp.exe" "%1"
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01  [binary data]
"VistaSp2" = BE DD 17 36 47 DE C9 01  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1056953686-97644573-1457974269-1000]
"EnableNotificationsRef" = 3
"EnableNotifications" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
 
========== Firewall Settings ==========
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{191C1158-D287-4074-B749-D4CDD321E062}" = ProtectSmart Hard Drive Protection
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{33EB1061-ABF1-4470-A540-32E97A610536}" = Apple Mobile Device Support
"{3975CE71-3544-9FBA-56E5-2E9709E348C5}" = ATI Catalyst Install Manager
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{53529DAD-F7C9-476E-87CC-1547C4E3E821}" = iTunes
"{68660049-8D48-427C-9FF7-139D8340CDC0}" = MSVC80_x64
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7F67AF0E-DF48-0198-E0F3-F1C9F7A6FC22}" = ccc-utility64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B38BCB00-1C17-48F5-BB94-584BB89D34D0}" = Logitech Z-series Software 1.04
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{F1568AA6-5982-4AFB-A871-C68E4328BC3B}" = HP MediaSmart SmartMenu
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"07B260955637F1FF7587ED2AA87459040DD09BF7" = Windows-Treiberpaket - ENE (enecir) HIDClass  (09/04/2008 2.6.0.0)
"A6BCA7876CD547CFB5821019998F044515D81B74" = Windows-Treiberpaket - Hewlett-Packard Image  (04/27/2007 9.0.0.0)
"DesktopIconAmazon" = Desktop Icon für Amazon
"E8A6D621B6D3FC5D43C68C549D959DE76EEF5D84" = Windows-Treiberpaket - Nokia Modem  (06/01/2009 4.1)
"F779F5541ABD99C95C03B0FD5E3C058B22DA0FF7" = Windows-Treiberpaket - Nokia Modem  (06/01/2009 7.01.0.3)
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows-Treiberpaket - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"KLiteCodecPack64_is1" = K-Lite Codec Pack 9.2.0 (64-bit)
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Redirection Port Monitor" = RedMon - Redirection Port Monitor
"Reimage Repair" = Reimage Repair
"SearchAnonymizer" = SearchAnonymizer
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}" = Citrix Online Plug-in (Web)
"{0C7F8FBE-435C-34D2-6813-2A632AAC0C92}" = Catalyst Control Center Localization Greek
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{0D8E6567-7082-48DB-A305-293873AC8B39}_is1" = Preispilot für Firefox
"{0E1F58B6-39BF-23FC-B4E5-3A2B4A0FADEB}" = CCC Help Turkish
"{0EEF3E07-3971-5080-2A3F-910691DA1135}" = Catalyst Control Center Graphics Previews Vista
"{114C14EE-652A-5EF6-59B8-3E5B33D6A4DF}" = Catalyst Control Center Graphics Full New
"{116C3B09-ADE0-1B8B-2F9F-C8B09A89F9AA}" = CCC Help Thai
"{12C11B2C-00F3-AF06-94D4-1AAF70616507}" = Catalyst Control Center Graphics Light
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{187817E2-6407-461C-B59B-56CE73363D34}" = Catalyst Control Center - Branding
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D8635E1-46A9-1B10-6151-ED7169AB8C9A}" = GMX SMS-Manager
"{1EC09CDB-0674-B3D6-FCB1-7B3CE2BFF3E8}" = Catalyst Control Center Localization Danish
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20B1B020-DEAE-48D1-9960-D4C3185D758B}" = Phase 5 HTML-Editor
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{22B0E143-2B0B-435B-9F56-136A3D16065F}" = No23 Recorder
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{255C206B-4776-1D14-9EDD-2F9458847739}" = ccc-core-static
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216034FF}" = Java(TM) 6 Update 35
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34CFF761-7AD1-7C1A-4513-79B3E2F54290}" = CCC Help Greek
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 L1
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3A6F3C3C-A83C-34D5-F80A-4FDA2FBBFE2F}" = Catalyst Control Center Localization Chinese Standard
"{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite
"{3DFA31F1-4747-60E4-6CA9-0060CFB99E30}" = CCC Help Spanish
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4198AAE5-A938-B0A0-9AD2-95C2F23ED677}" = Catalyst Control Center Localization Italian
"{46345EA6-1608-2E99-B47F-D83725A5C4D9}" = CCC Help Hungarian
"{46ACB9C1-6109-088B-931F-B7A5CE735504}" = CCC Help Italian
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51B8CA01-3E68-9993-E6F3-7F8982A0F600}" = CCC Help Finnish
"{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver
"{55392E52-1AAD-44C4-BE49-258FFE72434F}" = Citrix Online Plug-in (USB)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{650A275F-75B8-B71E-4C9D-04E952A63E5F}" = Catalyst Control Center Graphics Previews Common
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6756A967-2904-DE46-3265-4BB80B934904}" = Catalyst Control Center Localization Chinese Traditional
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0E28-3A8E-4ADC-A050-784064B76236}" = HP User Guides 0134
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{732A3F80-008B-4350-BD58-EC5AE98707B8}" = HP Common Access Service Library
"{735DAC68-3FF4-2895-83A2-DBF135AB9F44}" = CCC Help German
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{812424AC-A8B5-44E6-8D48-07E939D1AD9A}" = Citrix Online Plug-in (HDX)
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 4.1.2
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8DAD42E6-BBE7-C12B-C78D-8AC8C87F4055}" = Catalyst Control Center Localization German
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{9017CEAF-BE5A-4F73-8A0E-C87E26971E55}" = TomTom HOME
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{90EF242A-A2ED-FBBD-2F1F-A159DB0DDAC3}" = CCC Help Chinese Traditional
"{9198CC8F-8B08-6F7B-BF7D-A6594526B5DF}" = Catalyst Control Center Localization Hungarian
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{93DD8BC9-ADD5-D20B-22B5-1526E45CB6C8}" = CCC Help French
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95A747E0-DF19-46CB-A622-20A0107201BD}" = HP Total Care Setup
"{99AF6670-F557-F4D3-3069-AE62DA675A70}" = Catalyst Control Center Localization French
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B88930B-A7E7-03E5-1313-BED90FCCF72C}" = CCC Help Swedish
"{9F19486B-B187-5A51-189F-FCCEBBB70E2E}" = Catalyst Control Center Localization Dutch
"{A019B329-BFA8-3F59-6F80-6A3714104CE9}" = CCC Help English
"{A107F928-EED3-28FC-857F-ED33FEDBA02A}" = Catalyst Control Center Localization Korean
"{A15B2786-6F7E-0B96-A222-141202F9CECC}" = CCC Help Japanese
"{A5D5CC36-6A42-6FB6-882F-90C6262C8DCA}" = CCC Help Korean
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9359BA2-B496-8E14-EDA9-923DBE8913CB}" = Catalyst Control Center Localization Thai
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B3D11644-94AB-17E7-D9CF-52EF943D9F52}" = Catalyst Control Center Localization Spanish
"{B4B199E3-4D33-4F08-688A-9BCE5920AAF6}" = Catalyst Control Center Localization Japanese
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BA5388B6-7107-4565-A438-E86933B74341}" = SimonT Hockey Simulator Support Files
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BDDB0932-2C7F-ABB3-ED54-6F045EEF14F7}" = Catalyst Control Center Localization Swedish
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C2E52B6F-E4F1-B9D6-D671-D7E2FC60C7C0}" = CCC Help Chinese Standard
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C58AED82-0DD9-DF4B-1CE7-F7EE9B1BBB83}" = CCC Help Danish
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C61D8EF2-D9BF-B36F-4887-ADE39C924F3F}" = Catalyst Control Center Localization Polish
"{C7D02E19-07F2-8EE5-7C18-1617A656AF74}" = Catalyst Control Center Localization Turkish
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{C91CC841-7B39-9454-4A16-91C7FF300EC8}" = CCC Help Portuguese
"{C9A87D86-FDFD-418B-BF96-EF09320973B3}" = PC Inspector smart recovery
"{C9F06F5D-D521-43D5-AEB7-79176DC6CCDE}_is1" = Phone Disk 1.2.1.1
"{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}" = CanoScan Toolbox Ver4.9
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE60D4C0-86A7-52C8-7C8A-AFD2E99A1790}" = Catalyst Control Center Graphics Full Existing
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF53CF7C-D996-43EB-9904-DBED57C25625}" = Citrix Online Plug-in (DV)
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6EA6018-0F5B-E4CC-C930-990412BED306}" = Catalyst Control Center Localization Czech
"{D80D6A7D-A6AA-019A-12D8-CA58F76FA313}" = Skins
"{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1" = FireJump
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DB7DE91F-AC23-7A23-B1A7-6FD3A05534E2}" = CCC Help Czech
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DF6FE172-006A-4324-AF7F-ACFE4BA290FE}" = AAVUpdateManager
"{DFC21203-E063-A351-8027-F5D43162539D}" = CCC Help Norwegian
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0FE7850-04F8-D01A-971F-C7B00F8D003A}" = Catalyst Control Center Localization Russian
"{E18407AE-614D-5B0B-9C38-5A1853E8AB5D}" = Catalyst Control Center Core Implementation
"{E1B2BA63-4023-B582-0D88-ABB528E281D9}" = Catalyst Control Center InstallProxy
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5E29403-3D25-40C6-892B-F9FEE2A95585}" = HP Wireless Assistant
"{E6333CE4-9DC0-455C-9D43-E011CE33F5FA}_is1" = Bigasoft Audio Converter 3.7.16.4643
"{E651B083-2904-8342-5C27-39800B39E03B}" = CCC Help Polish
"{E6695454-03CD-146E-4A10-75FCB5AFE3FB}" = Catalyst Control Center Localization Finnish
"{e6aeb291-6192-4832-a1cf-dcef433f0a73}" = Nero 9 Lite
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E7D293C9-732D-4E22-905D-2615FED321A4}" = BILD-Steuer 2010
"{E8020EC7-5DD8-80C9-7237-7B2E9BDA8CC6}" = muvee Reveal
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{E9D045D8-E31E-E3D6-004D-9AD4EE6C2747}" = CCC Help Russian
"{E9EEB277-B66C-9A72-9CF0-90AC7BFC2095}" = Catalyst Control Center Localization Norwegian
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}" = Nokia Software Updater
"{F98DF01D-F1C3-3878-FCE6-F749729A8949}" = CCC Help Dutch
"{FDBA2850-0054-7733-527B-A6286D639345}" = Catalyst Control Center Localization Portuguese
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Renamer_is1" = Advanced Renamer
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE v.6.81
"Audacity_is1" = Audacity 2.0
"Audiograbber" = Audiograbber 1.83 SE
"Audiograbber-Lame" = Audiograbber Lame-MP3-Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"CitrixOnlinePluginPackWeb" = Citrix Online Plug-in - Web
"com.unitedinternet.ums.sms-mms-manager" = GMX SMS-Manager
"DokanLibrary" = Dokan Library 0.5.3
"ElsterFormular 11.2.0.4074" = ElsterFormular
"ElsterFormular für Privatanwender 12.0.0.5880p" = ElsterFormular-Update
"FileZilla Client" = FileZilla Client 3.5.3
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Studio_is1" = Free Studio version 5.7.3.903
"Free WAV to MP3 Converter" = Free WAV to MP3 Converter
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.32.918
"Google Calendar Sync" = Google Calendar Sync
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"IrfanView" = IrfanView (remove only)
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"JuniperSetupClient Activex Control" = Juniper Networks Setup Client Activex Control
"LAME_is1" = LAME v3.99.3 (for Windows)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.0.1400
"McAfee Security Scan" = McAfee Security Scan Plus
"mIRC" = mIRC
"MixPad" = MixPad Audio Mixer
"Mozilla Firefox 15.0.1 (x86 de)" = Mozilla Firefox 15.0.1 (x86 de)
"Mozilla Thunderbird (3.1.11)" = Mozilla Thunderbird (3.1.11)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NCH_DE Toolbar" = NCH DE Toolbar
"Neoteris_Secure_Application_Manager" = Juniper Networks Secure Application Manager
"Nokia PC Suite" = Nokia PC Suite
"Pidgin" = Pidgin
"Siedler3Deinstall" = Siedler3
"Siedler3MissionUninstall" = DIE SIEDLER III MISSION CD
"SopCast" = SopCast 3.2.8
"ToolBox" = NCH Toolbox
"Uninstall_is1" = Uninstall 1.0.0.1
"VideoPad" = VideoPad Videobearbeitungs-Software
"WavePad" = WavePad Audiobearbeitungs-Software
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"xp-AntiSpy" = xp-AntiSpy 3.97-2
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Juniper_Setup_Client" = Juniper Networks, Inc. Setup Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"QIP 2010" = QIP 2010 3.1.6116
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 20.04.2011 22:19:13 | Computer Name = Andreas-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 20.04.2011 22:58:20 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 20.04.2011 22:58:20 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1076
 
Error - 20.04.2011 22:58:20 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1076
 
Error - 20.04.2011 23:11:00 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 20.04.2011 23:11:01 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 761378
 
Error - 20.04.2011 23:11:01 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 761378
 
Error - 20.04.2011 23:11:02 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 20.04.2011 23:11:02 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 762891
 
Error - 20.04.2011 23:11:02 | Computer Name = Andreas-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 762891
 
[ System Events ]
Error - 04.10.2012 10:25:15 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 04.10.2012 15:02:17 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7023
Description =
 
Error - 04.10.2012 15:02:17 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7003
Description =
 
Error - 04.10.2012 15:02:17 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 04.10.2012 15:02:17 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 04.10.2012 15:02:17 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7003
Description =
 
Error - 04.10.2012 15:02:53 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7026
Description =
 
Error - 04.10.2012 15:03:28 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7009
Description =
 
Error - 04.10.2012 15:03:28 | Computer Name = Andreas-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 04.10.2012 15:03:28 | Computer Name = Andreas-PC | Source = DCOM | ID = 10005
Description =
 
 
< End of report >

und das sagt der adw-cleaner:

Code:

# AdwCleaner v2.003 - Datei am 10/04/2012 um 21:27:03 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Benutzer : Andreas - ANDREAS-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Andreas\Dropbox\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gefunden : C:\Users\Andreas\AppData\Local\Temp\Uninstall.exe
Datei Gefunden : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\searchplugins\Web Search.xml
Datei Gefunden : C:\Windows\Tasks\Scheduled Update for Ask Toolbar.job
Ordner Gefunden : C:\Program Files (x86)\Ask.com
Ordner Gefunden : C:\Program Files (x86)\Conduit
Ordner Gefunden : C:\Program Files (x86)\NCH_DE
Ordner Gefunden : C:\Users\Andreas\AppData\Local\Conduit
Ordner Gefunden : C:\Users\Andreas\AppData\Local\Temp\AskSearch
Ordner Gefunden : C:\Users\Andreas\AppData\Local\Temp\CT2801937
Ordner Gefunden : C:\Users\Andreas\AppData\Local\Temp\TempDir
Ordner Gefunden : C:\Users\Andreas\AppData\LocalLow\AskToolbar
Ordner Gefunden : C:\Users\Andreas\AppData\LocalLow\NCH_DE
Ordner Gefunden : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
Ordner Gefunden : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{b106b661-3e1b-4015-af5c-195e909f35c6}
Ordner Gefunden : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\toolbar@ask.com
Ordner Gefunden : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registrierungsdatenbank] *****

Schlüssel Gefunden : HKCU\Software\APN
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\NCH_DE
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gefunden : HKCU\Software\Ask.com
Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\NCH_DE Toolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Schlüssel Gefunden : HKLM\Software\APN
Schlüssel Gefunden : HKLM\Software\AskToolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2801937
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8EEB1C24-43B2-4210-B48A-87FE0EAE6267}
Schlüssel Gefunden : HKLM\Software\NCH_DE
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8EEB1C24-43B2-4210-B48A-87FE0EAE6267}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E8F019F-7512-4EDB-88B1-33B161C029CF}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF2361CB-B994-4BE8-8398-C73FB143E7C9}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NCH_DE Toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gefunden : HKU\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : HKU\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Wert Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gefunden : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://search.qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
[HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}
[HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms}

-\\ Mozilla Firefox v15.0.1 (de)

Profilname : default
Datei : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\prefs.js

Gefunden : user_pref("CT2801937.FirstTime", "true");
Gefunden : user_pref("CT2801937.FirstTimeFF3", "true");
Gefunden : user_pref("CT2801937.UserID", "UN58287906994390367");
Gefunden : user_pref("CT2801937.autoDisableScopes", -1);
Gefunden : user_pref("CT2801937.defaultSearch", "false");
Gefunden : user_pref("CT2801937.enableAlerts", "true");
Gefunden : user_pref("CT2801937.enableSearchFromAddressBar", "true");
Gefunden : user_pref("CT2801937.fixPageNotFoundError", "true");
Gefunden : user_pref("CT2801937.fixUrls", true);
Gefunden : user_pref("CT2801937.installId", "ConduitInstaller.exe");
Gefunden : user_pref("CT2801937.installType", "ConduitNSISIntegration");
Gefunden : user_pref("CT2801937.isPerformedSmartBarTransition", "true");
Gefunden : user_pref("CT2801937.openThankYouPage", "false");
Gefunden : user_pref("CT2801937.openUninstallPage", "true");
Gefunden : user_pref("CT2801937.settingsINI", true);
Gefunden : user_pref("CT2801937.shouldFirstTimeDialog", "false");
Gefunden : user_pref("CT2801937.smartbar.CTID", "CT2801937");
Gefunden : user_pref("CT2801937.smartbar.Uninstall", "0");
Gefunden : user_pref("CT2801937.smartbar.isHidden", true);
Gefunden : user_pref("CT2801937.smartbar.toolbarName", "NCH DE ");
Gefunden : user_pref("CT2801937.startPage", "false");
Gefunden : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
Gefunden : user_pref("extensions.asktb.apn_dbr", "ff_9.0.1");
Gefunden : user_pref("extensions.asktb.cbid", "LL");
Gefunden : user_pref("extensions.asktb.config-updated", false);
Gefunden : user_pref("extensions.asktb.crumb", "2012.01.14+01.46.53-toolbar018iad-DE-TnVyZW1iZXJnLEdlcm1hbnk%3D[...]
Gefunden : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...]
Gefunden : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Gefunden : user_pref("extensions.asktb.fresh-install", false);
Gefunden : user_pref("extensions.asktb.guid", "1e3b3cf3-09b4-453e-968a-12968ff4e579");
Gefunden : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...]
Gefunden : user_pref("extensions.asktb.if", "first");
Gefunden : user_pref("extensions.asktb.l", "dis");
Gefunden : user_pref("extensions.asktb.last-config-req", "1339437446457");
Gefunden : user_pref("extensions.asktb.last-v", "3.14.1.100015");
Gefunden : user_pref("extensions.asktb.locale", "de_DE");
Gefunden : user_pref("extensions.asktb.location", "Nuremberg,Germany");
Gefunden : user_pref("extensions.asktb.notification-shown", true);
Gefunden : user_pref("extensions.asktb.o", "APN10023");
Gefunden : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Gefunden : user_pref("extensions.asktb.qsrc", "2871");
Gefunden : user_pref("extensions.asktb.r", "4");
Gefunden : user_pref("extensions.asktb.sa", "NO");
Gefunden : user_pref("extensions.asktb.search-suggestions-enabled", true);
Gefunden : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Gefunden : user_pref("extensions.asktb.themeid", "");
Gefunden : user_pref("extensions.asktb.timeinstalled", "14.01.2012 10:48:59");
Gefunden : user_pref("extensions.asktb.to", "");
Gefunden : user_pref("extensions.asktb.v", "3.14.1.100015");
Gefunden : user_pref("extensions.asktb.version", "5.14.1.20064");
Gefunden : user_pref("keyword.URL", "hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=D[...]

*************************

AdwCleaner[R1].txt - [13392 octets] - [04/10/2012 21:27:03]

########## EOF - C:\AdwCleaner[R1].txt - [13453 octets] ##########

kann mir bitte jemand helfen, wie's jetzt weitergeht?
im voraus schonmal DANKE! :)

cosinus 05.10.2012 08:43

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

schustan 05.10.2012 12:28

habe in der vergangenheit nicht mit alwarebytes gearbeitet.

fehlt bei den logfiles denn etwas? ich habe eines nach dem kompletten scan bekommen, und ein weiteres nachdem ich die 4 files gelöscht habe (vermeintlich gelöscht).

cosinus 05.10.2012 14:18


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset



Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

schustan 05.10.2012 22:52

alles gemacht wie beschrieben .. et voila ...

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=18327d442d39d84a99c5ec4e0f08cf98
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-10-05 09:29:14
# local_time=2012-10-05 11:29:14 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 22931805 22931805 0 0
# compatibility_mode=5892 16776574 66 56 304120 186986618 0 0
# compatibility_mode=8192 67108863 100 0 335 335 0 0
# compatibility_mode=9217 16777214 0 13 106879692 106879693 0 0
# scanned=280288
# found=17
# cleaned=0
# scan_time=9842
C:\Users\Andreas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JN6H3IZ9\bi_downloader[1].exe        a variant of Win32/Somoto.A application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\Local\Temp\nsw6BB1.tmp        a variant of Win32/Somoto.A application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\Local\Temp\NERO1005256\unit_app_75\Toolbar.exe        Win32/Toolbar.AskSBar application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\Local\Temp\plugtmp-7\plugin-other.swf        SWF.Injector.A trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\d9b7edf-72d2bc92        a variant of Java/Exploit.Agent.NBC trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\20ad3661-2f2fbe68        a variant of Java/Exploit.Blacole.AN trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2b4c09a1-6d91bc46        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\4f6eb3a6-78ac17a2        Java/Exploit.Agent.NBS trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\23656971-7aac1cc8        Java/Exploit.Agent.NBS trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\427ea4b4-29ebd6c3        Java/TrojanDownloader.Agent.NDR trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\611e0a7d-5685e3ae        multiple threats (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000004.@        Win64/Conedex.C trojan (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@        Win64/Agent.BA trojan (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\000000cb.@        Win64/Conedex.B trojan (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@        Win64/Sirefef.AP trojan (unable to clean)        00000000000000000000000000000000        I
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000032.@        probably a variant of Win32/Sirefef.FD trojan (unable to clean)        00000000000000000000000000000000        I
${Memory}        a variant of Win32/Sirefef.EZ trojan        00000000000000000000000000000000        I


cosinus 07.10.2012 05:27

adwCleaner - Toolbars und ungewollte Start-/Suchseiten entfernen
  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Löschen.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Sx].txt. (x=fortlaufende Nummer)

schustan 07.10.2012 08:51

alles gemacht. nach dem booten kam wieder die avira-meldung :-(

aber hier mal das logfile:

Code:

# AdwCleaner v2.003 - Datei am 10/07/2012 um 09:45:33 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Benutzer : Andreas - ANDREAS-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Andreas\Dropbox\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\Andreas\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Windows\Tasks\Scheduled Update for Ask Toolbar.job
Gelöscht mit Neustart : C:\Program Files (x86)\Ask.com
Gelöscht mit Neustart : C:\Program Files (x86)\Conduit
Gelöscht mit Neustart : C:\Program Files (x86)\NCH_DE
Gelöscht mit Neustart : C:\Users\Andreas\AppData\Local\Conduit
Gelöscht mit Neustart : C:\Users\Andreas\AppData\Local\Temp\AskSearch
Gelöscht mit Neustart : C:\Users\Andreas\AppData\Local\Temp\CT2801937
Gelöscht mit Neustart : C:\Users\Andreas\AppData\Local\Temp\TempDir
Gelöscht mit Neustart : C:\Users\Andreas\AppData\LocalLow\AskToolbar
Gelöscht mit Neustart : C:\Users\Andreas\AppData\LocalLow\NCH_DE
Gelöscht mit Neustart : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
Gelöscht mit Neustart : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{b106b661-3e1b-4015-af5c-195e909f35c6}
Gelöscht mit Neustart : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\toolbar@ask.com
Gelöscht mit Neustart : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\APN
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\NCH_DE
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\Ask.com
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\NCH_DE Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Schlüssel Gelöscht : HKLM\Software\APN
Schlüssel Gelöscht : HKLM\Software\AskToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2801937
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8EEB1C24-43B2-4210-B48A-87FE0EAE6267}
Schlüssel Gelöscht : HKLM\Software\NCH_DE
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8EEB1C24-43B2-4210-B48A-87FE0EAE6267}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E8F019F-7512-4EDB-88B1-33B161C029CF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF2361CB-B994-4BE8-8398-C73FB143E7C9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B106B661-3E1B-4015-AF5C-195E909F35C6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NCH_DE Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{B106B661-3E1B-4015-AF5C-195E909F35C6}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://search.qip.ru --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.qip.ru --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=DE&userid=e588f593-2b4b-4e79-9113-16f05fe0e7a5&searchtype=ds&q={searchTerms} --> hxxp://www.google.com

-\\ Mozilla Firefox v15.0.1 (de)

Profilname : default
Datei : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\prefs.js

Gelöscht : user_pref("CT2801937.FirstTime", "true");
Gelöscht : user_pref("CT2801937.FirstTimeFF3", "true");
Gelöscht : user_pref("CT2801937.UserID", "UN58287906994390367");
Gelöscht : user_pref("CT2801937.autoDisableScopes", -1);
Gelöscht : user_pref("CT2801937.defaultSearch", "false");
Gelöscht : user_pref("CT2801937.enableAlerts", "true");
Gelöscht : user_pref("CT2801937.enableSearchFromAddressBar", "true");
Gelöscht : user_pref("CT2801937.fixPageNotFoundError", "true");
Gelöscht : user_pref("CT2801937.fixUrls", true);
Gelöscht : user_pref("CT2801937.installId", "ConduitInstaller.exe");
Gelöscht : user_pref("CT2801937.installType", "ConduitNSISIntegration");
Gelöscht : user_pref("CT2801937.isPerformedSmartBarTransition", "true");
Gelöscht : user_pref("CT2801937.openThankYouPage", "false");
Gelöscht : user_pref("CT2801937.openUninstallPage", "true");
Gelöscht : user_pref("CT2801937.settingsINI", true);
Gelöscht : user_pref("CT2801937.shouldFirstTimeDialog", "false");
Gelöscht : user_pref("CT2801937.smartbar.CTID", "CT2801937");
Gelöscht : user_pref("CT2801937.smartbar.Uninstall", "0");
Gelöscht : user_pref("CT2801937.smartbar.isHidden", true);
Gelöscht : user_pref("CT2801937.smartbar.toolbarName", "NCH DE ");
Gelöscht : user_pref("CT2801937.startPage", "false");
Gelöscht : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
Gelöscht : user_pref("extensions.asktb.apn_dbr", "ff_9.0.1");
Gelöscht : user_pref("extensions.asktb.cbid", "LL");
Gelöscht : user_pref("extensions.asktb.config-updated", false);
Gelöscht : user_pref("extensions.asktb.crumb", "2012.01.14+01.46.53-toolbar018iad-DE-TnVyZW1iZXJnLEdlcm1hbnk%3D[...]
Gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...]
Gelöscht : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Gelöscht : user_pref("extensions.asktb.fresh-install", false);
Gelöscht : user_pref("extensions.asktb.guid", "1e3b3cf3-09b4-453e-968a-12968ff4e579");
Gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...]
Gelöscht : user_pref("extensions.asktb.if", "first");
Gelöscht : user_pref("extensions.asktb.l", "dis");
Gelöscht : user_pref("extensions.asktb.last-config-req", "1339437446457");
Gelöscht : user_pref("extensions.asktb.last-v", "3.14.1.100015");
Gelöscht : user_pref("extensions.asktb.locale", "de_DE");
Gelöscht : user_pref("extensions.asktb.location", "Nuremberg,Germany");
Gelöscht : user_pref("extensions.asktb.notification-shown", true);
Gelöscht : user_pref("extensions.asktb.o", "APN10023");
Gelöscht : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Gelöscht : user_pref("extensions.asktb.qsrc", "2871");
Gelöscht : user_pref("extensions.asktb.r", "4");
Gelöscht : user_pref("extensions.asktb.sa", "NO");
Gelöscht : user_pref("extensions.asktb.search-suggestions-enabled", true);
Gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Gelöscht : user_pref("extensions.asktb.themeid", "");
Gelöscht : user_pref("extensions.asktb.timeinstalled", "14.01.2012 10:48:59");
Gelöscht : user_pref("extensions.asktb.to", "");
Gelöscht : user_pref("extensions.asktb.v", "3.14.1.100015");
Gelöscht : user_pref("extensions.asktb.version", "5.14.1.20064");
Gelöscht : user_pref("keyword.URL", "hxxp://feed.snap.do/?publisher=SnapdoIMonetizer&dpid=SnapdoIMonetizer&co=D[...]

*************************

AdwCleaner[R1].txt - [13505 octets] - [04/10/2012 21:27:03]
AdwCleaner[R2].txt - [13566 octets] - [07/10/2012 09:44:32]
AdwCleaner[S1].txt - [13773 octets] - [07/10/2012 09:45:33]

########## EOF - C:\AdwCleaner[S1].txt - [13834 octets] ##########


cosinus 07.10.2012 09:18

Hätte da mal zwei Fragen bevor es weiter geht (wir sind noch nicht fertig!)

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

schustan 07.10.2012 12:02

1) Windows ging die ganze Zeit über uneingeschränkt. Wäre da nicht die Avira-Meldung, würde ich von der Sache garnichts merken. Außerdem kommt noch immer wieder die Meldung, dass der "Hostprozess für Windows-Dienste" nicht mehr funktioniert. ich kann dann wählen, ob ich online nach einer lösung suchen, oder schließen will. wenn ich schließe, kommt die meldung trotzdem in 5 oder 10min wieder ...

2) nein, im Startmenü scheint alles normal ..

cosinus 07.10.2012 19:10

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


schustan 07.10.2012 19:49

et voila ...

sind wir auf nem guten weg?

Code:

OTL logfile created on: 07.10.2012 20:25:36 - Run 2
OTL by OldTimer - Version 3.2.70.2    Folder = C:\Users\Andreas\Dropbox
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,71 Gb Available Physical Memory | 67,79% Memory free
8,16 Gb Paging File | 6,60 Gb Available in Paging File | 80,82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453,74 Gb Total Space | 220,80 Gb Free Space | 48,66% Space Free | Partition Type: NTFS
Drive D: | 12,02 Gb Total Space | 1,93 Gb Free Space | 16,04% Space Free | Partition Type: NTFS
 
Computer Name: ANDREAS-PC | User Name: Andreas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Andreas\Dropbox\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe ()
PRC - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files (x86)\AAVUpdateManager\aavus.exe ()
PRC - C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe (Logitech Inc.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\Hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (Ati External Event Utility) -- C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (SearchAnonymizer) -- C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (DokanMounter) -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Recovery Service for Windows) -- C:\Program Files (x86)\SMINST\BLService.exe ()
SRV - (TVCapSvc) -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched) -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (AAV UpdateService) -- C:\Program Files (x86)\AAVUpdateManager\aavus.exe ()
SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (NEOFLTR_710_19243) -- C:\Windows\SysNative\Drivers\NEOFLTR_710_19243.SYS (Juniper Networks)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\DRIVERS\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\DRIVERS\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (Dokan) -- C:\Windows\SysNative\drivers\dokan.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (ctxusbm) -- C:\Windows\SysNative\DRIVERS\ctxusbm.sys (Citrix Systems, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (JMCR) -- C:\Windows\SysNative\DRIVERS\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys (Nokia)
DRV:64bit: - (nmwcdnsucx64) -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys (Nokia)
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys (Nokia)
DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (NETw5v64) -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (enecir) -- C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation                                            )
DRV:64bit: - (NETw3v64) -- C:\Windows\SysNative\DRIVERS\NETw3v64.sys (Intel Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr) -- C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (yukonx64) -- C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE:64bit: - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE:64bit: - HKLM\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKLM\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://webzugang.brnet.de/dana-na/auth/url_default/welcome.cgi
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494538535243&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net.anonymize-me.de/?anonymto=687474703A2F2F64652E6B656C6B6F6F706172746E6572732E6E65742F63746C2F646F2F7365617263683F7369746553656172636851756572793D7B7365617263685465726D737D2666726F6D666F726D3D7472756526783D7472756526793D7472756526706172746E65723D687026706172746E657249643D3936393133393333&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{19EAF838-C817-489D-9164-4F9D7CDF11DE}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{58351DFF-916A-410C-B2B1-B5127B5EDC9C}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{67E737C1-2EA9-4E09-9226-ED9F878CCED4}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{96E2641C-19A6-4E4D-B569-5295DCAF3EEA}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{A296D9B5-0565-4DC2-9F05-EC9F3C5EA171}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com.anonymize-me.de/?anonymto=687474703A2F2F736C69727372656469726563742E7365617263682E616F6C2E636F6D2F736C6972735F687474702F7372656469723F7372656469723D313134352671756572793D7B7365617263685465726D737D26696E766F636174696F6E547970653D746235306870636E6E626965372D64652D6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com.anonymize-me.de/?anonymto=687474703A2F2F64652E7365617263682E7961686F6F2E636F6D2F7365617263683F703D7B7365617263685465726D737D2665693D7B696E707574456E636F64696E677D2666723D63622D6870303626747970653D696532303038&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{CE7156AD-F537-461D-8488-1997877AA4EA}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{F4435E4E-EB74-4D9A-B706-A9B71780D292}: "URL" = hxxp://www.google.de.anonymize-me.de/?anonymto=687474703A2F2F7777772E676F6F676C652E64652F7365617263683F713D7B7365617263685465726D737D&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "heute.de"
FF - prefs.js..extensions.enabledAddons: optout@google.com:1.5
FF - prefs.js..extensions.enabledAddons: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.2.1
FF - prefs.js..extensions.enabledAddons: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledAddons: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..extensions.enabledAddons: firejump@firejump.net:1.0.2.5
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.6
FF - prefs.js..extensions.enabledItems: helperbar@helperbar.com:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.12
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..network.proxy.http: "128.6.192.158"
FF - prefs.js..network.proxy.http_port: 3127
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.10.11 12:30:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.08 11:37:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.09.08 11:37:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.06.23 10:25:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\extension@preispilot.com: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\extension@preispilot.com
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\firejump@firejump.net [2012.08.21 16:22:46 | 000,000,000 | ---D | M]
 
[2011.06.19 19:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions
[2011.06.19 19:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009.11.08 15:16:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2012.10.07 09:47:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions
[2012.08.18 19:54:32 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010.04.30 11:50:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.02.03 21:34:01 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010.08.23 20:56:39 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.08.21 16:22:46 | 000,000,000 | ---D | M] (FireJump) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\firejump@firejump.net
[2012.08.26 13:07:59 | 000,008,363 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\optout@google.com.xpi
[2012.09.26 15:45:30 | 000,529,316 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012.08.18 19:54:32 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.11.12 13:10:02 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012.08.21 16:23:06 | 000,002,702 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\ecosia.xml
[2012.08.21 16:23:06 | 000,002,014 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\firefox-add-ons.xml
[2012.08.21 16:23:06 | 000,002,707 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icq-search.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-1.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-2.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-3.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin.xml
[2012.08.21 16:23:06 | 000,002,186 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{6E8BA072-B308-40CD-BE3C-ECF3C1030F06}.xml
[2012.08.21 16:23:06 | 000,002,075 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{6FFD10E3-90CF-4C13-8A9C-14588B33DDA3}.xml
[2012.08.21 16:23:06 | 000,001,868 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{AA1117CE-3DFB-43B9-B157-D1F3907A8B15}.xml
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.08 11:37:19 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.09.08 11:37:32 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009.09.12 23:05:42 | 000,124,240 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll
[2009.09.12 23:06:22 | 000,070,488 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll
[2009.09.12 23:06:32 | 000,091,480 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll
[2009.09.12 23:06:28 | 000,022,360 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll
[2009.09.12 23:08:36 | 000,406,864 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll
[2009.09.12 23:06:24 | 000,023,896 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll
[2012.08.21 18:28:02 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.31 18:14:13 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.21 18:28:02 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.21 18:28:02 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.21 18:28:02 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.21 18:28:02 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.05.11 18:39:40 | 000,000,935 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1 im.adtech.de
O1 - Hosts: 127.0.0.1 adserver.adtech.de
O1 - Hosts: 127.0.0.1 adtech.de
O1 - Hosts: 127.0.0.1 atwola.com
O1 - Hosts: 127.0.0.1 adserver.71i.de
O1 - Hosts: 127.0.0.1 adicqserver.71i.de
O1 - Hosts: 127.0.0.1 71i.de
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1056953686-97644573-1457974269-1000..\Run: [Infium] C:\Program Files (x86)\QIP 2010\qip.exe (QIP)
O4 - Startup: C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro3.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://webzugang.brnet.de/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{552B14CB-20AD-4649-BAFC-D79E76C6329F}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\cdo - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Andreas\Eigener Zwischenspeicher\Wallpaper\DSC07649.JPG
O24 - Desktop BackupWallPaper: C:\Users\Andreas\Eigener Zwischenspeicher\Wallpaper\DSC07649.JPG
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{de514ff2-b638-11de-80da-00238b965f48}\Shell\AutoRun\command - "" = F:\Launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: ezSharedSvc - C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe - (Adobe Systems, Inc.)
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: CLMLServer for HP TouchSmart - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
MsConfig:64bit - StartUpReg: DVDAgent - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: HP Health Check Scheduler - hkey= - key= - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
MsConfig:64bit - StartUpReg: Launch LCDMon - hkey= - key= - C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe (Logitech Inc.)
MsConfig:64bit - StartUpReg: PC Suite Tray - hkey= - key= - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
MsConfig:64bit - StartUpReg: PDFPrint - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: TomTomHOME.exe - hkey= - key= - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
MsConfig:64bit - StartUpReg: TSMAgent - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: TVAgent - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UCam_Menu - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdateLBPShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdateP2GoShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdatePDIRShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdatePSTShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - State: "startup" - Reg Error: Unable to open variant key
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: WinDefend - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: BFE - Service
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: MPSSvc - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WinDefend - Service
SafeBootNet:64bit: WudfPf - Driver
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: BFE - Service
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MPSSvc - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - Service
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5463F8EC-1E20-408B-43E9-16B20888C113} - .NET Framework
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32:64bit: VIDC.LAGS - lagarith.dll ( )
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.07 20:22:34 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Andreas\Desktop\OTL.exe
[2012.10.05 20:39:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.05 20:39:13 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012.10.05 20:38:41 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Andreas\Desktop\esetsmartinstaller_enu.exe
[2012.10.04 17:27:05 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Malwarebytes
[2012.10.04 17:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.04 17:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.04 17:26:49 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.04 17:26:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.10.03 12:46:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2012.10.03 12:46:38 | 000,000,000 | ---D | C] -- C:\rei
[2012.10.03 12:46:33 | 000,000,000 | ---D | C] -- C:\Program Files\Reimage
[2012.10.03 11:12:28 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Local\Macroplant_LLC
[2012.10.03 11:12:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dokan
[2012.10.03 11:12:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phone Disk
[2012.10.03 11:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Phone Disk
[2012.10.03 10:49:20 | 003,419,216 | ---- | C] (Macroplant LLC                                              ) -- C:\Users\Andreas\Desktop\Phone_Disk_Setup.exe
[2012.10.03 10:48:03 | 004,156,848 | ---- | C] (WindSolutions) -- C:\Users\Andreas\Desktop\Install_CopyTrans_Suite.exe
[2012.10.02 08:45:40 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\shortcut Fotos
[2012.09.30 08:46:39 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
[2012.09.30 08:46:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2012.09.30 08:46:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GMX SMS-Manager
[2012.09.26 21:51:55 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bigasoft Audio Converter
[2012.09.26 21:51:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bigasoft Audio Converter
[2012.09.26 21:47:02 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\hörbuch-temp
[2012.09.26 21:46:22 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU
[2012.09.26 21:46:18 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\AVS4YOU
[2012.09.26 21:45:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU
[2012.09.26 21:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia
[2012.09.26 09:33:43 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\Wasser
[2012.09.26 09:33:33 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\temp
[2012.09.18 20:56:46 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
[2012.09.18 20:56:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\No.23 Recorder
[2012.09.18 20:29:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lame For Audacity
[2012.09.18 20:15:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64
[2012.09.18 20:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack x64
[2012.09.18 20:12:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012.09.18 20:12:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012.09.18 19:23:39 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\NCH Software
[2012.09.18 19:23:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
[2012.09.18 19:23:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audioverwandte Programme
[2012.09.18 19:21:07 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
[2012.09.17 13:01:19 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Local\{E8F2465D-AB5F-4AF0-85D0-71C9F53F9FCF}
[2012.09.17 12:44:42 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\HandBrake
[2012.09.17 12:40:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft Free Studio
[2012.09.15 17:24:34 | 000,000,000 | ---D | C] -- C:\ProgramData\VistaCodecs
[2012.09.15 16:17:07 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\TuneUp Software
[2012.09.15 16:16:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.09.15 16:16:50 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012.09.15 16:16:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012.09.15 16:16:27 | 000,719,872 | ---- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll
[2012.09.15 16:16:27 | 000,369,152 | ---- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll
[2012.09.15 16:16:27 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2012.09.15 16:16:27 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll
[2012.09.15 16:16:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2012.09.15 16:14:40 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2012.09.15 16:13:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft
[2012.09.15 13:26:12 | 000,000,000 | ---D | C] -- C:\ProgramData\xml_param
[2012.09.15 13:22:53 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\iSkysoft Video Converter
[2012.09.15 13:22:18 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\Windows\SysWow64\iconv.dll
[2012.09.15 12:56:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ashampoo
[2012.09.08 11:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2007.08.13 17:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\Andreas\AppData\Local\CDRip.dll
[2007.01.18 21:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\Andreas\AppData\Local\No23 Recorder.exe
[2006.12.11 19:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\Andreas\AppData\Local\basscd.dll
[2006.12.11 19:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\Andreas\AppData\Local\bass.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.07 20:22:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Andreas\Desktop\OTL.exe
[2012.10.07 20:20:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.07 18:43:10 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 18:43:10 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 18:42:48 | 4292,026,368 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.05 20:38:48 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Andreas\Desktop\esetsmartinstaller_enu.exe
[2012.10.04 17:26:51 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.04 16:29:31 | 000,674,446 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.04 16:29:31 | 000,634,540 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.04 16:29:31 | 000,119,106 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.04 16:29:30 | 000,145,100 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.04 16:29:29 | 001,566,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.03 12:47:53 | 000,000,286 | ---- | M] () -- C:\Windows\reimage.ini
[2012.10.03 11:12:07 | 000,000,825 | ---- | M] () -- C:\Users\Public\Desktop\Phone Disk.lnk
[2012.10.03 11:09:21 | 001,546,632 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.03 10:49:40 | 003,419,216 | ---- | M] (Macroplant LLC                                              ) -- C:\Users\Andreas\Desktop\Phone_Disk_Setup.exe
[2012.10.03 10:48:28 | 004,156,848 | ---- | M] (WindSolutions) -- C:\Users\Andreas\Desktop\Install_CopyTrans_Suite.exe
[2012.10.03 10:03:06 | 000,102,912 | ---- | M] () -- C:\Users\Andreas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.30 09:09:16 | 000,000,702 | ---- | M] () -- C:\Users\Andreas\Documents\Software-Liste.rtf
[2012.09.29 16:55:55 | 408,891,301 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.09.21 23:50:04 | 000,000,034 | ---- | M] () -- C:\Windows\cdplayer.ini
[2012.09.21 16:51:03 | 000,321,800 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.18 21:10:52 | 000,001,478 | ---- | M] () -- C:\Users\Andreas\AppData\Local\RecConfig.xml
[2012.09.18 19:24:10 | 000,000,009 | ---- | M] () -- C:\END
 
========== Files Created - No Company Name ==========
 
[2012.10.04 17:26:51 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.03 12:47:41 | 000,000,286 | ---- | C] () -- C:\Windows\reimage.ini
[2012.10.03 11:12:07 | 000,000,825 | ---- | C] () -- C:\Users\Public\Desktop\Phone Disk.lnk
[2012.09.30 09:09:15 | 000,000,702 | ---- | C] () -- C:\Users\Andreas\Documents\Software-Liste.rtf
[2012.09.30 08:46:33 | 000,000,968 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GMX-SMS-Manager.lnk
[2012.09.18 20:59:06 | 000,001,478 | ---- | C] () -- C:\Users\Andreas\AppData\Local\RecConfig.xml
[2012.09.18 20:15:43 | 000,206,336 | ---- | C] () -- C:\Windows\SysNative\unrar.dll
[2012.09.18 20:15:43 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll
[2012.09.18 20:15:41 | 000,127,488 | ---- | C] () -- C:\Windows\SysNative\ff_vfw.dll
[2012.09.18 20:12:22 | 000,000,977 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Videobearbeitungs-Software.lnk
[2012.09.18 19:24:10 | 000,000,009 | ---- | C] () -- C:\END
[2012.09.18 19:23:31 | 000,001,861 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Audiobearbeitungs-Software.lnk
[2012.09.15 16:16:27 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2012.09.15 13:22:18 | 000,675,840 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.ax
[2012.09.15 13:22:18 | 000,496,640 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012.08.21 16:22:44 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2012.08.18 20:12:37 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\Gif89.dll
[2011.03.30 17:53:19 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2010.04.19 20:37:22 | 000,004,096 | -H-- | C] () -- C:\Users\Andreas\AppData\Local\keyfile3.drm
[2009.09.13 14:09:06 | 000,000,182 | ---- | C] () -- C:\Users\Andreas\AppData\Roaming\default.rss
[2009.05.30 12:28:11 | 000,000,212 | ---- | C] () -- C:\Users\Andreas\AppData\Roaming\wklnhst.dat
[2009.05.17 20:55:29 | 000,102,912 | ---- | C] () -- C:\Users\Andreas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.08.13 17:46:00 | 000,155,136 | ---- | C] () -- C:\Users\Andreas\AppData\Local\lame_enc.dll
[2006.10.26 01:06:48 | 000,064,000 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbisenc.dll
[2006.10.26 01:06:48 | 000,019,456 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbisfile.dll
[2006.10.26 01:06:46 | 000,143,872 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbis.dll
[2006.10.26 01:06:36 | 000,015,872 | ---- | C] () -- C:\Users\Andreas\AppData\Local\ogg.dll
[2005.08.23 22:34:06 | 000,029,184 | ---- | C] () -- C:\Users\Andreas\AppData\Local\no23xwrapper.dll
 
========== ZeroAccess Check ==========
 
[2011.11.18 22:55:05 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
[2012.10.03 12:01:04 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L
[2012.10.04 21:04:40 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U
[2012.10.07 18:43:01 | 000,000,804 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\00000004.@
[2012.10.03 11:51:17 | 000,002,048 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000004.@
[2012.10.04 21:04:40 | 000,232,960 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@
[2012.10.04 21:04:33 | 000,001,632 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\000000cb.@
[2012.10.04 21:04:34 | 000,016,896 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@
[2012.10.04 21:04:37 | 000,087,040 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000032.@
[2012.10.04 04:32:55 | 000,072,704 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000064.@
[2006.11.02 17:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[2012.10.07 18:42:54 | 000,004,608 | -HS- | M] () -- C:\Windows\assembly\GAC_32\Desktop.ini
[2012.10.07 18:42:54 | 000,006,144 | -HS- | M] () -- C:\Windows\assembly\GAC_64\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 00:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.21 04:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2011.05.31 22:12:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\.purple
[2010.01.17 11:18:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Ashampoo
[2012.09.28 21:50:13 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audacity
[2011.04.14 20:28:33 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audio Recorder for Free
[2012.09.15 12:40:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\avidemux
[2009.10.23 15:45:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Canon
[2012.09.30 08:46:39 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
[2012.08.21 16:22:44 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DesktopIconForAmazon
[2012.10.07 18:44:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Dropbox
[2012.10.03 10:23:17 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoft
[2012.09.17 12:42:40 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.02 22:52:05 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\elsterformular
[2012.08.28 18:27:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\FileZilla
[2012.09.17 12:44:42 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\HandBrake
[2012.08.22 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Hulubulu
[2011.01.12 17:52:08 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICAClient
[2011.05.11 18:46:57 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICQ
[2012.09.15 13:22:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\iSkysoft Video Converter
[2011.01.13 21:56:16 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Juniper Networks
[2011.06.20 19:44:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\KompoZer
[2012.09.18 19:22:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\NCH Swift Sound
[2009.10.11 12:53:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Nokia
[2012.08.21 16:22:38 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\OCS
[2012.08.21 16:23:06 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Opera
[2009.10.11 12:33:14 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\PC Suite
[2010.10.12 20:17:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\QIP
[2009.05.30 12:28:12 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Template
[2011.06.19 19:20:31 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Thunderbird
[2009.11.08 15:16:56 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TomTom
[2012.09.15 16:17:07 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TuneUp Software
[2012.08.21 16:39:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\XMedia Recode
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.05.31 22:12:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\.purple
[2012.10.03 11:09:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Adobe
[2010.10.21 11:26:12 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Apple Computer
[2010.01.17 11:18:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Ashampoo
[2009.05.17 18:52:18 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ATI
[2012.09.28 21:50:13 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audacity
[2011.04.14 20:28:33 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audio Recorder for Free
[2012.09.15 12:40:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\avidemux
[2012.01.14 11:54:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Avira
[2012.09.26 21:46:18 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\AVS4YOU
[2009.10.23 15:45:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Canon
[2012.09.30 08:46:39 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
[2009.09.09 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\CyberLink
[2012.08.21 16:22:44 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DesktopIconForAmazon
[2009.09.13 14:08:43 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DivX
[2012.10.07 18:44:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Dropbox
[2012.10.03 10:23:17 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoft
[2012.09.17 12:42:40 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.02 22:52:05 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\elsterformular
[2012.08.28 18:27:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\FileZilla
[2012.09.17 12:44:42 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\HandBrake
[2009.05.17 18:52:55 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Hewlett-Packard
[2009.05.17 18:46:50 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\HP TCS
[2012.08.22 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Hulubulu
[2011.01.12 17:52:08 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICAClient
[2011.05.11 18:46:57 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICQ
[2009.05.17 18:51:55 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Identities
[2012.09.15 13:22:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\iSkysoft Video Converter
[2011.01.13 21:56:16 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Juniper Networks
[2011.06.20 19:44:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\KompoZer
[2009.05.17 19:37:54 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Macromedia
[2012.10.04 17:27:05 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Malwarebytes
[2006.11.02 17:07:25 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Media Center Programs
[2011.03.22 21:59:14 | 000,000,000 | --SD | M] -- C:\Users\Andreas\AppData\Roaming\Microsoft
[2012.10.07 13:00:26 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\mIRC
[2009.05.17 19:30:14 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Mozilla
[2012.09.18 20:12:19 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\NCH Software
[2012.09.18 19:22:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\NCH Swift Sound
[2009.09.09 20:29:13 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Nero
[2009.10.11 12:53:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Nokia
[2012.08.21 16:22:38 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\OCS
[2012.08.21 16:23:06 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Opera
[2009.10.11 12:33:14 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\PC Suite
[2010.10.12 20:17:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\QIP
[2012.08.30 17:34:45 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Skype
[2012.03.15 21:49:42 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\skypePM
[2009.05.30 12:28:12 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Template
[2011.06.19 19:20:31 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Thunderbird
[2009.11.08 15:16:56 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TomTom
[2012.09.15 16:17:07 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TuneUp Software
[2009.11.14 11:28:25 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Winamp
[2009.09.19 10:32:07 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\WinRAR
[2012.08.21 16:39:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\XMedia Recode
 
< %APPDATA%\*.exe /s >
[2012.08.21 16:22:38 | 000,753,664 | ---- | M] (Microsoft) -- C:\Users\Andreas\AppData\Roaming\DesktopIconForAmazon\IconForAmazon.exe
[2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2012.05.24 20:39:24 | 000,872,144 | ---- | M] (Dropbox, Inc.) -- C:\Users\Andreas\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2012.05.24 20:39:56 | 000,177,280 | ---- | M] (Dropbox, Inc.) -- C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2012.05.13 17:45:35 | 005,421,896 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\install_lstb12.exe
[2012.03.20 11:28:13 | 005,457,544 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_09_8086_8479.exe
[2012.04.03 15:52:39 | 004,061,352 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_09_8479_8531.exe
[2012.05.13 17:45:44 | 004,577,536 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_09_8531_8623.exe
[2012.03.20 11:28:28 | 005,646,912 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_10_8086_8479.exe
[2012.04.03 15:52:51 | 004,199,808 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_10_8479_8531.exe
[2012.05.13 17:46:00 | 005,759,728 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_10_8531_8623.exe
[2012.03.20 11:28:44 | 006,912,752 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_11_8086_8479.exe
[2012.04.03 15:53:02 | 004,180,528 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_11_8479_8531.exe
[2012.05.13 17:46:15 | 005,933,016 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_11_8531_8623.exe
[2012.03.20 11:27:42 | 007,446,584 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_pica_0_8086_8479.exe
[2012.05.13 17:45:06 | 005,576,392 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_pica_0_8479_8623.exe
[2009.12.02 09:22:52 | 000,292,136 | ---- | M] (Juniper Networks") -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Host Checker\dsHostChecker.exe
[2009.12.02 09:22:52 | 000,230,696 | ---- | M] (Juniper Networks) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Host Checker\dsHostCheckerProxy.exe
[2009.12.02 09:23:04 | 000,055,248 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Host Checker\uninstall.exe
[2011.09.08 03:29:12 | 000,149,368 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\dsmmf.exe
[2011.09.08 03:29:32 | 000,282,576 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperCompMgrInstaller.exe
[2011.09.08 03:29:10 | 000,571,256 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClient.exe
[2011.09.08 03:28:46 | 000,348,256 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClientOCX.exe
[2011.09.08 03:22:28 | 000,236,504 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupXP.exe
[2011.09.08 03:29:34 | 000,056,952 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\uninstall.exe
[2012.09.30 08:45:53 | 000,053,664 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Andreas\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2012.09.30 08:45:50 | 015,428,440 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Andreas\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airinstaller3x0\airinstaller3x0.exe
[2010.08.23 22:35:57 | 000,010,134 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{20B1B020-DEAE-48D1-9960-D4C3185D758B}\Foren.exe
[2010.08.23 22:35:57 | 000,000,766 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{20B1B020-DEAE-48D1-9960-D4C3185D758B}\htmledit.exe
[2012.09.18 20:56:48 | 000,003,262 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{22B0E143-2B0B-435B-9F56-136A3D16065F}\controlPanelIcon.exe
[2012.09.18 20:56:48 | 000,010,134 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{22B0E143-2B0B-435B-9F56-136A3D16065F}\SystemFolder_msiexec.exe
[2010.02.12 17:36:07 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{DF6FE172-006A-4324-AF7F-ACFE4BA290FE}\ARPPRODUCTICON.exe
[2012.08.21 16:22:38 | 000,106,496 | ---- | M] (OCS) -- C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
[2012.08.21 16:22:38 | 000,040,960 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.21 04:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009.01.22 07:30:59 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=35137384FFB6FB4B4C3063CEB5DB34BE -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_37d5e5fef5f86cf7\atapi.sys
[2009.01.22 07:30:59 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=B388797CAAB36D523840347CC6A39B96 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_398211faf34b271a\atapi.sys
[2009.04.11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.05.17 22:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.21 04:51:03 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 00:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 00:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.21 04:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008.01.21 04:49:49 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 04:48:29 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.21 04:49:14 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2009.04.10 23:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.10 23:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2009.04.11 00:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 00:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.21 04:49:47 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:50:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
[2006.11.02 17:42:03 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006.11.02 17:42:03 | 000,008,000 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.05.18 19:14:25 | 000,000,206 | ---- | C] () -- C:\Windows\Tasks\{B9B31758-9ABD-4FBC-875D-D4AA867B25D5}.job
[2010.07.06 16:01:23 | 000,000,198 | ---- | C] () -- C:\Windows\Tasks\{5B63F7D2-B10D-4B25-BCB3-4D2BBBDB9ABC}.job
[2010.07.06 16:01:30 | 000,000,544 | ---- | C] () -- C:\Windows\Tasks\{05622D7C-E102-421F-B9BD-F587BF569F37}.job
[2010.07.06 16:13:01 | 000,000,206 | ---- | C] () -- C:\Windows\Tasks\{26D45942-2C27-4338-93C2-049F1A435729}.job
[2010.07.06 16:19:33 | 000,000,546 | ---- | C] () -- C:\Windows\Tasks\{6E02B945-C0CE-453A-9BA6-230DC76E1BAC}.job
[2011.04.01 16:12:04 | 000,000,562 | ---- | C] () -- C:\Windows\Tasks\{83EBD7E3-5521-4D5A-897A-E105084669EA}.job

< End of report >


cosinus 07.10.2012 20:29

Hast du OTL wirklich neu runtergeladen vorher?

schustan 07.10.2012 21:17

ich hab's runtergeladen, und dann gesehen dass die datei (v.3.2.69.0) vermeintlich älter ist als die, die ich bereits auf dem rechner hatte (nämlich 3.2.70.2) ...

wie dem auch sei. hier nochmal der scan mit der gerade eben runtergeladenen version ..

hinweis: avira lässt sich nicht schließen (es hieß ja ich solle alle laufenden programme beenden ...)

Code:

OTL logfile created on: 07.10.2012 21:58:12 - Run 3
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Andreas\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,46 Gb Available Physical Memory | 61,62% Memory free
8,21 Gb Paging File | 6,44 Gb Available in Paging File | 78,40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453,74 Gb Total Space | 220,77 Gb Free Space | 48,65% Space Free | Partition Type: NTFS
Drive D: | 12,02 Gb Total Space | 1,93 Gb Free Space | 16,04% Space Free | Partition Type: NTFS
 
Computer Name: ANDREAS-PC | User Name: Andreas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Andreas\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe ()
PRC - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files (x86)\AAVUpdateManager\aavus.exe ()
PRC - C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe (Logitech Inc.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (hpsrv) -- C:\Windows\SysNative\Hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (Ati External Event Utility) -- C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (TomTomHOMEService) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (SearchAnonymizer) -- C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (DokanMounter) -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Recovery Service for Windows) -- C:\Program Files (x86)\SMINST\BLService.exe ()
SRV - (TVCapSvc) -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched) -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (AAV UpdateService) -- C:\Program Files (x86)\AAVUpdateManager\aavus.exe ()
SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (NEOFLTR_710_19243) -- C:\Windows\SysNative\Drivers\NEOFLTR_710_19243.SYS (Juniper Networks)
DRV:64bit: - (hpdskflt) -- C:\Windows\SysNative\DRIVERS\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) -- C:\Windows\SysNative\DRIVERS\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (Dokan) -- C:\Windows\SysNative\drivers\dokan.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (ctxusbm) -- C:\Windows\SysNative\DRIVERS\ctxusbm.sys (Citrix Systems, Inc.)
DRV:64bit: - (STHDA) -- C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (JMCR) -- C:\Windows\SysNative\DRIVERS\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (nmwcdnsux64) -- C:\Windows\SysNative\drivers\nmwcdnsux64.sys (Nokia)
DRV:64bit: - (nmwcdnsucx64) -- C:\Windows\SysNative\drivers\nmwcdnsucx64.sys (Nokia)
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64j.sys (Nokia)
DRV:64bit: - (nmwcdx64) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\DRIVERS\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdcx64) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (NETw5v64) -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (enecir) -- C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation                                            )
DRV:64bit: - (NETw3v64) -- C:\Windows\SysNative\DRIVERS\NETw3v64.sys (Intel Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr) -- C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (yukonx64) -- C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE:64bit: - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE:64bit: - HKLM\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKLM\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://webzugang.brnet.de/dana-na/auth/url_default/welcome.cgi
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com.anonymize-me.de/?anonymto=687474703A2F2F7777772E62696E672E636F6D2F7365617263683F713D7B7365617263685465726D737D267372633D49452D536561726368426F7826464F524D3D494538535243&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = hxxp://de.kelkoopartners.net.anonymize-me.de/?anonymto=687474703A2F2F64652E6B656C6B6F6F706172746E6572732E6E65742F63746C2F646F2F7365617263683F7369746553656172636851756572793D7B7365617263685465726D737D2666726F6D666F726D3D7472756526783D7472756526793D7472756526706172746E65723D687026706172746E657249643D3936393133393333&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{19EAF838-C817-489D-9164-4F9D7CDF11DE}: "URL" = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{58351DFF-916A-410C-B2B1-B5127B5EDC9C}: "URL" = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{67E737C1-2EA9-4E09-9226-ED9F878CCED4}: "URL" = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{96E2641C-19A6-4E4D-B569-5295DCAF3EEA}: "URL" = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{A296D9B5-0565-4DC2-9F05-EC9F3C5EA171}: "URL" = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = hxxp://slirsredirect.search.aol.com.anonymize-me.de/?anonymto=687474703A2F2F736C69727372656469726563742E7365617263682E616F6C2E636F6D2F736C6972735F687474702F7372656469723F7372656469723D313134352671756572793D7B7365617263685465726D737D26696E766F636174696F6E547970653D746235306870636E6E626965372D64652D6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = hxxp://de.search.yahoo.com.anonymize-me.de/?anonymto=687474703A2F2F64652E7365617263682E7961686F6F2E636F6D2F7365617263683F703D7B7365617263685465726D737D2665693D7B696E707574456E636F64696E677D2666723D63622D6870303626747970653D696532303038&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{CE7156AD-F537-461D-8488-1997877AA4EA}: "URL" = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{F4435E4E-EB74-4D9A-B706-A9B71780D292}: "URL" = hxxp://www.google.de.anonymize-me.de/?anonymto=687474703A2F2F7777772E676F6F676C652E64652F7365617263683F713D7B7365617263685465726D737D&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "heute.de"
FF - prefs.js..extensions.enabledAddons: optout@google.com:1.5
FF - prefs.js..extensions.enabledAddons: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.2.1
FF - prefs.js..extensions.enabledAddons: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledAddons: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..extensions.enabledAddons: firejump@firejump.net:1.0.2.5
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.6
FF - prefs.js..extensions.enabledItems: helperbar@helperbar.com:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.12
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..network.proxy.http: "128.6.192.158"
FF - prefs.js..network.proxy.http_port: 3127
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.10.11 12:30:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.09.08 11:37:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.09.08 11:37:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.06.23 10:25:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\extension@preispilot.com: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\extension@preispilot.com
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\extensions\firejump@firejump.net [2012.08.21 16:22:46 | 000,000,000 | ---D | M]
 
[2011.06.19 19:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions
[2011.06.19 19:20:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009.11.08 15:16:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2012.10.07 09:47:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions
[2012.08.18 19:54:32 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010.04.30 11:50:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.02.03 21:34:01 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010.08.23 20:56:39 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.08.21 16:22:46 | 000,000,000 | ---D | M] (FireJump) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\firejump@firejump.net
[2012.08.26 13:07:59 | 000,008,363 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\optout@google.com.xpi
[2012.09.26 15:45:30 | 000,529,316 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012.08.18 19:54:32 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.11.12 13:10:02 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012.08.21 16:23:06 | 000,002,702 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\ecosia.xml
[2012.08.21 16:23:06 | 000,002,014 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\firefox-add-ons.xml
[2012.08.21 16:23:06 | 000,002,707 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icq-search.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-1.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-2.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-3.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin.xml
[2012.08.21 16:23:06 | 000,002,186 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{6E8BA072-B308-40CD-BE3C-ECF3C1030F06}.xml
[2012.08.21 16:23:06 | 000,002,075 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{6FFD10E3-90CF-4C13-8A9C-14588B33DDA3}.xml
[2012.08.21 16:23:06 | 000,001,868 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\{AA1117CE-3DFB-43B9-B157-D1F3907A8B15}.xml
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012.09.08 11:37:19 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
[2012.09.08 11:37:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012.09.08 11:37:32 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009.09.12 23:05:42 | 000,124,240 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll
[2009.09.12 23:06:22 | 000,070,488 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll
[2009.09.12 23:06:32 | 000,091,480 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll
[2009.09.12 23:06:28 | 000,022,360 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll
[2009.09.12 23:08:36 | 000,406,864 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll
[2009.09.12 23:06:24 | 000,023,896 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll
[2012.08.21 18:28:02 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.31 18:14:13 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.08.21 18:28:02 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.21 18:28:02 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.21 18:28:02 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.21 18:28:02 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.05.11 18:39:40 | 000,000,935 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1 im.adtech.de
O1 - Hosts: 127.0.0.1 adserver.adtech.de
O1 - Hosts: 127.0.0.1 adtech.de
O1 - Hosts: 127.0.0.1 atwola.com
O1 - Hosts: 127.0.0.1 adserver.71i.de
O1 - Hosts: 127.0.0.1 adicqserver.71i.de
O1 - Hosts: 127.0.0.1 71i.de
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1056953686-97644573-1457974269-1000..\Run: [Infium] C:\Program Files (x86)\QIP 2010\qip.exe (QIP)
O4 - Startup: C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro3.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://webzugang.brnet.de/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{552B14CB-20AD-4649-BAFC-D79E76C6329F}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\cdo - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Andreas\Eigener Zwischenspeicher\Wallpaper\DSC07649.JPG
O24 - Desktop BackupWallPaper: C:\Users\Andreas\Eigener Zwischenspeicher\Wallpaper\DSC07649.JPG
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{de514ff2-b638-11de-80da-00238b965f48}\Shell\AutoRun\command - "" = F:\Launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: ezSharedSvc - C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe - (Adobe Systems, Inc.)
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: CLMLServer for HP TouchSmart - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
MsConfig:64bit - StartUpReg: DVDAgent - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: HP Health Check Scheduler - hkey= - key= - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
MsConfig:64bit - StartUpReg: Launch LCDMon - hkey= - key= - C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe (Logitech Inc.)
MsConfig:64bit - StartUpReg: PC Suite Tray - hkey= - key= - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
MsConfig:64bit - StartUpReg: PDFPrint - hkey= - key= -  File not found
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: TomTomHOME.exe - hkey= - key= - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
MsConfig:64bit - StartUpReg: TSMAgent - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: TVAgent - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UCam_Menu - hkey= - key= - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdateLBPShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdateP2GoShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdatePDIRShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: UpdatePSTShortCut - hkey= - key= - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
MsConfig:64bit - State: "startup" - Reg Error: Key error.
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: WinDefend - Service
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: BFE - Service
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: MPSSvc - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WinDefend - Service
SafeBootNet:64bit: WudfPf - Driver
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: BFE - Service
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MPSSvc - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - Service
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5463F8EC-1E20-408B-43E9-16B20888C113} - .NET Framework
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32:64bit: VIDC.LAGS - lagarith.dll ( )
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.07 20:22:34 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Andreas\Desktop\OTL.exe
[2012.10.05 20:39:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.05 20:39:13 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012.10.05 20:38:41 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Andreas\Desktop\esetsmartinstaller_enu.exe
[2012.10.04 17:27:05 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Malwarebytes
[2012.10.04 17:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.04 17:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.04 17:26:49 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.04 17:26:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.10.03 12:46:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2012.10.03 12:46:38 | 000,000,000 | ---D | C] -- C:\rei
[2012.10.03 12:46:33 | 000,000,000 | ---D | C] -- C:\Program Files\Reimage
[2012.10.03 11:12:28 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Local\Macroplant_LLC
[2012.10.03 11:12:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dokan
[2012.10.03 11:12:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phone Disk
[2012.10.03 11:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Phone Disk
[2012.10.03 10:49:20 | 003,419,216 | ---- | C] (Macroplant LLC                                              ) -- C:\Users\Andreas\Desktop\Phone_Disk_Setup.exe
[2012.10.03 10:48:03 | 004,156,848 | ---- | C] (WindSolutions) -- C:\Users\Andreas\Desktop\Install_CopyTrans_Suite.exe
[2012.10.02 08:45:40 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\shortcut Fotos
[2012.09.30 08:46:39 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
[2012.09.30 08:46:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2012.09.30 08:46:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GMX SMS-Manager
[2012.09.26 21:51:55 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bigasoft Audio Converter
[2012.09.26 21:51:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bigasoft Audio Converter
[2012.09.26 21:47:02 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\hörbuch-temp
[2012.09.26 21:46:22 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU
[2012.09.26 21:46:18 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\AVS4YOU
[2012.09.26 21:45:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU
[2012.09.26 21:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia
[2012.09.26 09:33:43 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\Wasser
[2012.09.26 09:33:33 | 000,000,000 | ---D | C] -- C:\Users\Andreas\Desktop\temp
[2012.09.18 20:56:46 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
[2012.09.18 20:56:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\No.23 Recorder
[2012.09.18 20:29:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lame For Audacity
[2012.09.18 20:15:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64
[2012.09.18 20:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack x64
[2012.09.18 20:12:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012.09.18 20:12:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012.09.18 19:23:39 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\NCH Software
[2012.09.18 19:23:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Produktpalette
[2012.09.18 19:23:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audioverwandte Programme
[2012.09.18 19:21:07 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
[2012.09.17 13:01:19 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Local\{E8F2465D-AB5F-4AF0-85D0-71C9F53F9FCF}
[2012.09.17 12:44:42 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\HandBrake
[2012.09.17 12:40:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft Free Studio
[2012.09.15 17:24:34 | 000,000,000 | ---D | C] -- C:\ProgramData\VistaCodecs
[2012.09.15 16:17:07 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\TuneUp Software
[2012.09.15 16:16:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012.09.15 16:16:50 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012.09.15 16:16:50 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012.09.15 16:16:27 | 000,719,872 | ---- | C] (Abysmal Software) -- C:\Windows\SysWow64\devil.dll
[2012.09.15 16:16:27 | 000,369,152 | ---- | C] (The Public) -- C:\Windows\SysWow64\avisynth.dll
[2012.09.15 16:16:27 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
[2012.09.15 16:16:27 | 000,070,656 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\i420vfw.dll
[2012.09.15 16:16:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2012.09.15 16:14:40 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2012.09.15 16:13:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eRightSoft
[2012.09.15 13:26:12 | 000,000,000 | ---D | C] -- C:\ProgramData\xml_param
[2012.09.15 13:22:53 | 000,000,000 | ---D | C] -- C:\Users\Andreas\AppData\Roaming\iSkysoft Video Converter
[2012.09.15 13:22:18 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\Windows\SysWow64\iconv.dll
[2012.09.15 12:56:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ashampoo
[2012.09.08 11:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2007.08.13 17:46:00 | 000,102,912 | ---- | C] (Albert L Faber) -- C:\Users\Andreas\AppData\Local\CDRip.dll
[2007.01.18 21:09:54 | 000,623,616 | ---- | C] (Ivan Bischof ©2003 - 2005) -- C:\Users\Andreas\AppData\Local\No23 Recorder.exe
[2006.12.11 19:13:14 | 000,013,872 | ---- | C] (Un4seen Developments) -- C:\Users\Andreas\AppData\Local\basscd.dll
[2006.12.11 19:13:12 | 000,097,336 | ---- | C] (Un4seen Developments) -- C:\Users\Andreas\AppData\Local\bass.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.07 21:53:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.07 20:43:06 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 20:43:06 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 20:22:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Andreas\Desktop\OTL.exe
[2012.10.07 18:42:48 | 4292,026,368 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.05 20:38:48 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Andreas\Desktop\esetsmartinstaller_enu.exe
[2012.10.04 17:26:51 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.04 16:29:31 | 000,674,446 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.10.04 16:29:31 | 000,634,540 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.10.04 16:29:31 | 000,119,106 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.10.04 16:29:30 | 000,145,100 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.10.04 16:29:29 | 001,566,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.10.03 12:47:53 | 000,000,286 | ---- | M] () -- C:\Windows\reimage.ini
[2012.10.03 11:12:07 | 000,000,825 | ---- | M] () -- C:\Users\Public\Desktop\Phone Disk.lnk
[2012.10.03 11:09:21 | 001,546,632 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.03 10:49:40 | 003,419,216 | ---- | M] (Macroplant LLC                                              ) -- C:\Users\Andreas\Desktop\Phone_Disk_Setup.exe
[2012.10.03 10:48:28 | 004,156,848 | ---- | M] (WindSolutions) -- C:\Users\Andreas\Desktop\Install_CopyTrans_Suite.exe
[2012.10.03 10:03:06 | 000,102,912 | ---- | M] () -- C:\Users\Andreas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.09.30 09:09:16 | 000,000,702 | ---- | M] () -- C:\Users\Andreas\Documents\Software-Liste.rtf
[2012.09.29 16:55:55 | 408,891,301 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.09.21 23:50:04 | 000,000,034 | ---- | M] () -- C:\Windows\cdplayer.ini
[2012.09.21 16:51:03 | 000,321,800 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.18 21:10:52 | 000,001,478 | ---- | M] () -- C:\Users\Andreas\AppData\Local\RecConfig.xml
[2012.09.18 19:24:10 | 000,000,009 | ---- | M] () -- C:\END
 
========== Files Created - No Company Name ==========
 
[2012.10.04 17:26:51 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.03 12:47:41 | 000,000,286 | ---- | C] () -- C:\Windows\reimage.ini
[2012.10.03 11:12:07 | 000,000,825 | ---- | C] () -- C:\Users\Public\Desktop\Phone Disk.lnk
[2012.09.30 09:09:15 | 000,000,702 | ---- | C] () -- C:\Users\Andreas\Documents\Software-Liste.rtf
[2012.09.30 08:46:33 | 000,000,968 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GMX-SMS-Manager.lnk
[2012.09.18 20:59:06 | 000,001,478 | ---- | C] () -- C:\Users\Andreas\AppData\Local\RecConfig.xml
[2012.09.18 20:15:43 | 000,206,336 | ---- | C] () -- C:\Windows\SysNative\unrar.dll
[2012.09.18 20:15:43 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll
[2012.09.18 20:15:41 | 000,127,488 | ---- | C] () -- C:\Windows\SysNative\ff_vfw.dll
[2012.09.18 20:12:22 | 000,000,977 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Videobearbeitungs-Software.lnk
[2012.09.18 19:24:10 | 000,000,009 | ---- | C] () -- C:\END
[2012.09.18 19:23:31 | 000,001,861 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Audiobearbeitungs-Software.lnk
[2012.09.15 16:16:27 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2012.09.15 13:22:18 | 000,675,840 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.ax
[2012.09.15 13:22:18 | 000,496,640 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012.08.21 16:22:44 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2012.08.18 20:12:37 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\Gif89.dll
[2011.03.30 17:53:19 | 000,000,510 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2010.04.19 20:37:22 | 000,004,096 | -H-- | C] () -- C:\Users\Andreas\AppData\Local\keyfile3.drm
[2009.09.13 14:09:06 | 000,000,182 | ---- | C] () -- C:\Users\Andreas\AppData\Roaming\default.rss
[2009.05.30 12:28:11 | 000,000,212 | ---- | C] () -- C:\Users\Andreas\AppData\Roaming\wklnhst.dat
[2009.05.17 20:55:29 | 000,102,912 | ---- | C] () -- C:\Users\Andreas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.08.13 17:46:00 | 000,155,136 | ---- | C] () -- C:\Users\Andreas\AppData\Local\lame_enc.dll
[2006.10.26 01:06:48 | 000,064,000 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbisenc.dll
[2006.10.26 01:06:48 | 000,019,456 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbisfile.dll
[2006.10.26 01:06:46 | 000,143,872 | ---- | C] () -- C:\Users\Andreas\AppData\Local\vorbis.dll
[2006.10.26 01:06:36 | 000,015,872 | ---- | C] () -- C:\Users\Andreas\AppData\Local\ogg.dll
[2005.08.23 22:34:06 | 000,029,184 | ---- | C] () -- C:\Users\Andreas\AppData\Local\no23xwrapper.dll
 
========== ZeroAccess Check ==========
 
[2011.11.18 22:55:05 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
[2012.10.03 12:01:04 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L
[2012.10.04 21:04:40 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U
[2012.10.07 18:43:01 | 000,000,804 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L\00000004.@
[2012.10.03 11:51:17 | 000,002,048 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000004.@
[2012.10.04 21:04:40 | 000,232,960 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@
[2012.10.04 21:04:33 | 000,001,632 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\000000cb.@
[2012.10.04 21:04:34 | 000,016,896 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@
[2012.10.04 21:04:37 | 000,087,040 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000032.@
[2012.10.04 04:32:55 | 000,072,704 | ---- | M] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000064.@
[2006.11.02 17:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[2012.10.07 18:42:54 | 000,004,608 | -HS- | M] () -- C:\Windows\assembly\GAC_32\Desktop.ini
[2012.10.07 18:42:54 | 000,006,144 | -HS- | M] () -- C:\Windows\assembly\GAC_64\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 00:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.21 04:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2011.05.31 22:12:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\.purple
[2010.01.17 11:18:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Ashampoo
[2012.09.28 21:50:13 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audacity
[2011.04.14 20:28:33 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audio Recorder for Free
[2012.09.15 12:40:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\avidemux
[2009.10.23 15:45:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Canon
[2012.09.30 08:46:39 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
[2012.08.21 16:22:44 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DesktopIconForAmazon
[2012.10.07 18:44:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Dropbox
[2012.10.03 10:23:17 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoft
[2012.09.17 12:42:40 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.02 22:52:05 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\elsterformular
[2012.08.28 18:27:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\FileZilla
[2012.09.17 12:44:42 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\HandBrake
[2012.08.22 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Hulubulu
[2011.01.12 17:52:08 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICAClient
[2011.05.11 18:46:57 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICQ
[2012.09.15 13:22:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\iSkysoft Video Converter
[2011.01.13 21:56:16 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Juniper Networks
[2011.06.20 19:44:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\KompoZer
[2012.09.18 19:22:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\NCH Swift Sound
[2009.10.11 12:53:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Nokia
[2012.08.21 16:22:38 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\OCS
[2012.08.21 16:23:06 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Opera
[2009.10.11 12:33:14 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\PC Suite
[2010.10.12 20:17:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\QIP
[2009.05.30 12:28:12 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Template
[2011.06.19 19:20:31 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Thunderbird
[2009.11.08 15:16:56 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TomTom
[2012.09.15 16:17:07 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TuneUp Software
[2012.08.21 16:39:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\XMedia Recode
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.05.31 22:12:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\.purple
[2012.10.03 11:09:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Adobe
[2010.10.21 11:26:12 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Apple Computer
[2010.01.17 11:18:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Ashampoo
[2009.05.17 18:52:18 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ATI
[2012.09.28 21:50:13 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audacity
[2011.04.14 20:28:33 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Audio Recorder for Free
[2012.09.15 12:40:46 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\avidemux
[2012.01.14 11:54:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Avira
[2012.09.26 21:46:18 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\AVS4YOU
[2009.10.23 15:45:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Canon
[2012.09.30 08:46:39 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
[2009.09.09 20:51:55 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\CyberLink
[2012.08.21 16:22:44 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DesktopIconForAmazon
[2009.09.13 14:08:43 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DivX
[2012.10.07 18:44:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Dropbox
[2012.10.03 10:23:17 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoft
[2012.09.17 12:42:40 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.02.02 22:52:05 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\elsterformular
[2012.08.28 18:27:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\FileZilla
[2012.09.17 12:44:42 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\HandBrake
[2009.05.17 18:52:55 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Hewlett-Packard
[2009.05.17 18:46:50 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\HP TCS
[2012.08.22 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Hulubulu
[2011.01.12 17:52:08 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICAClient
[2011.05.11 18:46:57 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\ICQ
[2009.05.17 18:51:55 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Identities
[2012.09.15 13:22:53 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\iSkysoft Video Converter
[2011.01.13 21:56:16 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Juniper Networks
[2011.06.20 19:44:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\KompoZer
[2009.05.17 19:37:54 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Macromedia
[2012.10.04 17:27:05 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Malwarebytes
[2006.11.02 17:07:25 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Media Center Programs
[2011.03.22 21:59:14 | 000,000,000 | --SD | M] -- C:\Users\Andreas\AppData\Roaming\Microsoft
[2012.10.07 13:00:26 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\mIRC
[2009.05.17 19:30:14 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Mozilla
[2012.09.18 20:12:19 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\NCH Software
[2012.09.18 19:22:32 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\NCH Swift Sound
[2009.09.09 20:29:13 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Nero
[2009.10.11 12:53:51 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Nokia
[2012.08.21 16:22:38 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\OCS
[2012.08.21 16:23:06 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Opera
[2009.10.11 12:33:14 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\PC Suite
[2010.10.12 20:17:04 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\QIP
[2012.08.30 17:34:45 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Skype
[2012.03.15 21:49:42 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\skypePM
[2009.05.30 12:28:12 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Template
[2011.06.19 19:20:31 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Thunderbird
[2009.11.08 15:16:56 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TomTom
[2012.09.15 16:17:07 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\TuneUp Software
[2009.11.14 11:28:25 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\Winamp
[2009.09.19 10:32:07 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\WinRAR
[2012.08.21 16:39:41 | 000,000,000 | ---D | M] -- C:\Users\Andreas\AppData\Roaming\XMedia Recode
 
< %APPDATA%\*.exe /s >
[2012.08.21 16:22:38 | 000,753,664 | ---- | M] (Microsoft) -- C:\Users\Andreas\AppData\Roaming\DesktopIconForAmazon\IconForAmazon.exe
[2012.05.24 20:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2012.05.24 20:39:24 | 000,872,144 | ---- | M] (Dropbox, Inc.) -- C:\Users\Andreas\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2012.05.24 20:39:56 | 000,177,280 | ---- | M] (Dropbox, Inc.) -- C:\Users\Andreas\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2012.05.13 17:45:35 | 005,421,896 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\install_lstb12.exe
[2012.03.20 11:28:13 | 005,457,544 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_09_8086_8479.exe
[2012.04.03 15:52:39 | 004,061,352 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_09_8479_8531.exe
[2012.05.13 17:45:44 | 004,577,536 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_09_8531_8623.exe
[2012.03.20 11:28:28 | 005,646,912 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_10_8086_8479.exe
[2012.04.03 15:52:51 | 004,199,808 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_10_8479_8531.exe
[2012.05.13 17:46:00 | 005,759,728 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_10_8531_8623.exe
[2012.03.20 11:28:44 | 006,912,752 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_11_8086_8479.exe
[2012.04.03 15:53:02 | 004,180,528 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_11_8479_8531.exe
[2012.05.13 17:46:15 | 005,933,016 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_est_11_8531_8623.exe
[2012.03.20 11:27:42 | 007,446,584 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_pica_0_8086_8479.exe
[2012.05.13 17:45:06 | 005,576,392 | ---- | M] (Landesfinanzdirektion Thueringen) -- C:\Users\Andreas\AppData\Roaming\elsterformular\pluginmanager\tmp\update_pica_0_8479_8623.exe
[2009.12.02 09:22:52 | 000,292,136 | ---- | M] (Juniper Networks") -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Host Checker\dsHostChecker.exe
[2009.12.02 09:22:52 | 000,230,696 | ---- | M] (Juniper Networks) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Host Checker\dsHostCheckerProxy.exe
[2009.12.02 09:23:04 | 000,055,248 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Host Checker\uninstall.exe
[2011.09.08 03:29:12 | 000,149,368 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\dsmmf.exe
[2011.09.08 03:29:32 | 000,282,576 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperCompMgrInstaller.exe
[2011.09.08 03:29:10 | 000,571,256 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClient.exe
[2011.09.08 03:28:46 | 000,348,256 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClientOCX.exe
[2011.09.08 03:22:28 | 000,236,504 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupXP.exe
[2011.09.08 03:29:34 | 000,056,952 | ---- | M] (Juniper Networks, Inc.) -- C:\Users\Andreas\AppData\Roaming\Juniper Networks\Setup Client\uninstall.exe
[2012.09.30 08:45:53 | 000,053,664 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Andreas\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2012.09.30 08:45:50 | 015,428,440 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Andreas\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airinstaller3x0\airinstaller3x0.exe
[2010.08.23 22:35:57 | 000,010,134 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{20B1B020-DEAE-48D1-9960-D4C3185D758B}\Foren.exe
[2010.08.23 22:35:57 | 000,000,766 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{20B1B020-DEAE-48D1-9960-D4C3185D758B}\htmledit.exe
[2012.09.18 20:56:48 | 000,003,262 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{22B0E143-2B0B-435B-9F56-136A3D16065F}\controlPanelIcon.exe
[2012.09.18 20:56:48 | 000,010,134 | R--- | M] () -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{22B0E143-2B0B-435B-9F56-136A3D16065F}\SystemFolder_msiexec.exe
[2010.02.12 17:36:07 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Andreas\AppData\Roaming\Microsoft\Installer\{DF6FE172-006A-4324-AF7F-ACFE4BA290FE}\ARPPRODUCTICON.exe
[2012.08.21 16:22:38 | 000,106,496 | ---- | M] (OCS) -- C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
[2012.08.21 16:22:38 | 000,040,960 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.21 04:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.21 04:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009.01.22 07:30:59 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=35137384FFB6FB4B4C3063CEB5DB34BE -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_37d5e5fef5f86cf7\atapi.sys
[2009.01.22 07:30:59 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=B388797CAAB36D523840347CC6A39B96 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_398211faf34b271a\atapi.sys
[2009.04.11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 00:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.05.17 22:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2008.01.21 04:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.21 04:51:03 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.10 23:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 00:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 00:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.21 04:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.21 04:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008.01.21 04:49:49 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.10 23:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 00:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2008.01.21 04:48:29 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.21 04:49:14 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2009.04.10 23:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.10 23:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2009.04.11 00:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 00:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.21 04:50:36 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.21 04:49:46 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.21 04:48:04 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.21 04:50:23 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 00:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.21 04:49:47 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.10 23:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:50:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.21 04:49:42 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >


cosinus 07.10.2012 21:24

Ja das ist richtig, es gibt leider ein paar Fehler in den 70er Versionen deswegen ist wieder 69.0 online


Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)


Code:

:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE:64bit: - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcnnbie7-de-de
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}: "URL" = http://de.kelkoopartners.net.anonymize-me.de/?anonymto=687474703A2F2F64652E6B656C6B6F6F706172746E6572732E6E65742F63746C2F646F2F7365617263683F7369746553656172636851756572793D7B7365617263685465726D737D2666726F6D666F726D3D7472756526783D7472756526793D7472756526706172746E65723D687026706172746E657249643D3936393133393333&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{19EAF838-C817-489D-9164-4F9D7CDF11DE}: "URL" = http://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E6963712E636F6D2F7365617263682F726573756C74732E7068703F713D7B7365617263685465726D737D2663685F69643D6F7364&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{67E737C1-2EA9-4E09-9226-ED9F878CCED4}: "URL" = http://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{96E2641C-19A6-4E4D-B569-5295DCAF3EEA}: "URL" = http://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{A296D9B5-0565-4DC2-9F05-EC9F3C5EA171}: "URL" = http://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}: "URL" = http://slirsredirect.search.aol.com.anonymize-me.de/?anonymto=687474703A2F2F736C69727372656469726563742E7365617263682E616F6C2E636F6D2F736C6972735F687474702F7372656469723F7372656469723D313134352671756572793D7B7365617263685465726D737D26696E766F636174696F6E547970653D746235306870636E6E626965372D64652D6465&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}: "URL" = http://de.search.yahoo.com.anonymize-me.de/?anonymto=687474703A2F2F64652E7365617263682E7961686F6F2E636F6D2F7365617263683F703D7B7365617263685465726D737D2665693D7B696E707574456E636F64696E677D2666723D63622D6870303626747970653D696532303038&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&k=0
IE - HKU\S-1-5-21-1056953686-97644573-1457974269-1000\..\SearchScopes\{CE7156AD-F537-461D-8488-1997877AA4EA}: "URL" = http://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=0541e5dc-00c1-4d6b-bca9-c675e1f8026c&pid=netzwelt&mode=bounce&k=0
FF - prefs.js..extensions.enabledItems: helperbar@helperbar.com:1.0
FF - prefs.js..network.proxy.http: "128.6.192.158"
FF - prefs.js..network.proxy.http_port: 3127
FF - user.js - File not found
[2010.04.30 11:50:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.08.21 16:23:06 | 000,002,014 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\firefox-add-ons.xml
[2012.08.21 16:23:06 | 000,002,707 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icq-search.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-1.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-2.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-3.xml
[2012.08.21 16:23:06 | 000,001,101 | ---- | M] () -- C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin.xml
O4 - HKLM..\Run: []  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{de514ff2-b638-11de-80da-00238b965f48}\Shell\AutoRun\command - "" = F:\Launcher.exe
[2012.10.03 12:46:38 | 000,000,000 | ---D | C] -- C:\rei
[2012.09.18 19:24:10 | 000,000,009 | ---- | M] () -- C:\END
:Files
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}
C:\Windows\assembly\GAC_32\Desktop.ini
C:\Windows\assembly\GAC_64\Desktop.ini
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

schustan 08.10.2012 03:34

und bitteschön :-)

(es hat zwar 5min gedauert, aber die avira-meldung ist immer noch mein stetiger begleiter ...)

Code:

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F381CE-68D8-4179-A60A-797EC0C34865}\ not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F381CE-68D8-4179-A60A-797EC0C34865}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11FFFB92-94CE-4A86-B80B-8783E57FF2B3}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{19EAF838-C817-489D-9164-4F9D7CDF11DE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19EAF838-C817-489D-9164-4F9D7CDF11DE}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{67E737C1-2EA9-4E09-9226-ED9F878CCED4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67E737C1-2EA9-4E09-9226-ED9F878CCED4}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{96E2641C-19A6-4E4D-B569-5295DCAF3EEA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{96E2641C-19A6-4E4D-B569-5295DCAF3EEA}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A296D9B5-0565-4DC2-9F05-EC9F3C5EA171}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A296D9B5-0565-4DC2-9F05-EC9F3C5EA171}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B4F381CE-68D8-4179-A60A-797EC0C34865}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F381CE-68D8-4179-A60A-797EC0C34865}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFF76C5E-CBC4-495C-B661-5C006E231FBD}\ not found.
Registry key HKEY_USERS\S-1-5-21-1056953686-97644573-1457974269-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CE7156AD-F537-461D-8488-1997877AA4EA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE7156AD-F537-461D-8488-1997877AA4EA}\ not found.
Prefs.js: helperbar@helperbar.com:1.0 removed from extensions.enabledItems
Prefs.js: "128.6.192.158" removed from network.proxy.http
Prefs.js: 3127 removed from network.proxy.http_port
C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences folder moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults folder moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome folder moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\Firefox\Profiles\pn21nwmv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} folder moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\firefox-add-ons.xml moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icq-search.xml moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-1.xml moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-2.xml moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin-3.xml moved successfully.
C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\pn21nwmv.default\searchplugins\icqplugin.xml moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{de514ff2-b638-11de-80da-00238b965f48}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{de514ff2-b638-11de-80da-00238b965f48}\ not found.
File F:\Launcher.exe not found.
C:\rei\Temp\20121003_1247\DownloaderTemp folder moved successfully.
C:\rei\Temp\20121003_1247 folder moved successfully.
C:\rei\Temp folder moved successfully.
C:\rei\Results\EXE1.6.2.7\RUN20121003_1247 folder moved successfully.
C:\rei\Results\EXE1.6.2.7 folder moved successfully.
C:\rei\Results folder moved successfully.
C:\rei\AV\Microsoft.VC90.CRT folder moved successfully.
C:\rei\AV folder moved successfully.
C:\rei folder moved successfully.
C:\END moved successfully.
========== FILES ==========
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U folder moved successfully.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L folder moved successfully.
C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888} folder moved successfully.
C:\Windows\assembly\GAC_32\Desktop.ini moved successfully.
C:\Windows\assembly\GAC_64\Desktop.ini moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Andreas\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Andreas\Desktop\cmd.bat deleted successfully.
C:\Users\Andreas\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Andreas
->Temp folder emptied: 3358290914 bytes
->Temporary Internet Files folder emptied: 297676983 bytes
->FireFox cache emptied: 510902381 bytes
->Flash cache emptied: 15672611 bytes
 
User: AppData
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56504 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34009262 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes
RecycleBin emptied: 181119797 bytes
 
Total Files Cleaned = 4.194,00 mb
 
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.69.0 log created on 10072012_222944

Files\Folders moved on Reboot...
C:\Users\Andreas\AppData\Local\Temp\ehmsas.txt moved successfully.
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 08.10.2012 11:25

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

schustan 08.10.2012 12:22

und das nächste log-file ..

Code:

13:13:02.0989 5032  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
13:13:03.0145 5032  ============================================================
13:13:03.0145 5032  Current date / time: 2012/10/08 13:13:03.0145
13:13:03.0145 5032  SystemInfo:
13:13:03.0145 5032 
13:13:03.0145 5032  OS Version: 6.0.6002 ServicePack: 2.0
13:13:03.0145 5032  Product type: Workstation
13:13:03.0145 5032  ComputerName: ANDREAS-PC
13:13:03.0145 5032  UserName: Andreas
13:13:03.0145 5032  Windows directory: C:\Windows
13:13:03.0145 5032  System windows directory: C:\Windows
13:13:03.0145 5032  Running under WOW64
13:13:03.0145 5032  Processor architecture: Intel x64
13:13:03.0145 5032  Number of processors: 2
13:13:03.0145 5032  Page size: 0x1000
13:13:03.0145 5032  Boot type: Normal boot
13:13:03.0145 5032  ============================================================
13:13:04.0939 5032  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:13:04.0954 5032  ============================================================
13:13:04.0954 5032  \Device\Harddisk0\DR0:
13:13:04.0954 5032  MBR partitions:
13:13:04.0954 5032  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x38B7A000
13:13:04.0954 5032  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38B7A800, BlocksNum 0x180A000
13:13:04.0954 5032  ============================================================
13:13:04.0986 5032  C: <-> \Device\Harddisk0\DR0\Partition1
13:13:05.0095 5032  D: <-> \Device\Harddisk0\DR0\Partition2
13:13:05.0095 5032  ============================================================
13:13:05.0095 5032  Initialize success
13:13:05.0095 5032  ============================================================
13:13:33.0393 3324  ============================================================
13:13:33.0393 3324  Scan started
13:13:33.0393 3324  Mode: Manual; SigCheck; TDLFS;
13:13:33.0393 3324  ============================================================
13:13:35.0952 3324  ================ Scan system memory ========================
13:13:35.0952 3324  System memory - ok
13:13:35.0952 3324  ================ Scan services =============================
13:13:36.0264 3324  [ 7EEB488346FBFA3731276C3EE8A8FD9E ] AAV UpdateService C:\Program Files (x86)\AAVUpdateManager\aavus.exe
13:13:36.0388 3324  AAV UpdateService - ok
13:13:36.0669 3324  [ 5C368F4B04ED2A923E6AFCA2D37BAFF5 ] Accelerometer  C:\Windows\system32\DRIVERS\Accelerometer.sys
13:13:37.0137 3324  Accelerometer - ok
13:13:37.0246 3324  [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI            C:\Windows\system32\drivers\acpi.sys
13:13:37.0278 3324  ACPI - ok
13:13:37.0387 3324  [ F84C9DEE4698DF3C1D76801B7B1B55D7 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
13:13:37.0512 3324  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
13:13:37.0512 3324  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
13:13:37.0730 3324  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:13:37.0761 3324  AdobeARMservice - ok
13:13:38.0042 3324  [ F14215E37CF124104575073F782111D2 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
13:13:38.0182 3324  adp94xx - ok
13:13:38.0245 3324  [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci        C:\Windows\system32\drivers\adpahci.sys
13:13:38.0307 3324  adpahci - ok
13:13:38.0338 3324  [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
13:13:38.0385 3324  adpu160m - ok
13:13:38.0416 3324  [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
13:13:38.0448 3324  adpu320 - ok
13:13:38.0510 3324  [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
13:13:38.0666 3324  AeLookupSvc - ok
13:13:39.0150 3324  [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe
13:13:39.0259 3324  AESTFilters - ok
13:13:39.0337 3324  [ C4F6CE6087760AD70960C9EB130E7943 ] AFD            C:\Windows\system32\drivers\afd.sys
13:13:39.0430 3324  AFD - ok
13:13:39.0493 3324  [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440          C:\Windows\system32\drivers\agp440.sys
13:13:39.0540 3324  agp440 - ok
13:13:39.0586 3324  [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
13:13:39.0633 3324  aic78xx - ok
13:13:39.0649 3324  [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG            C:\Windows\System32\alg.exe
13:13:40.0148 3324  ALG - ok
13:13:40.0226 3324  [ E0CA5BB8E6C79533DC6B1DA7361A201E ] aliide          C:\Windows\system32\drivers\aliide.sys
13:13:40.0242 3324  aliide - ok
13:13:40.0242 3324  [ 7034F8D1B9703D711D3F92C95DEB377D ] amdide          C:\Windows\system32\drivers\amdide.sys
13:13:40.0257 3324  amdide - ok
13:13:40.0304 3324  [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
13:13:40.0366 3324  AmdK8 - ok
13:13:40.0710 3324  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
13:13:40.0834 3324  AntiVirSchedulerService - ok
13:13:41.0006 3324  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
13:13:41.0037 3324  AntiVirService - ok
13:13:41.0100 3324  [ 676894FA57B671FEC5C3F05F8929E03B ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
13:13:41.0178 3324  AntiVirWebService - ok
13:13:41.0240 3324  [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo        C:\Windows\System32\appinfo.dll
13:13:41.0318 3324  Appinfo - ok
13:13:41.0614 3324  [ 70D7BE78061126DD0C3ACCDB7E129017 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:13:41.0646 3324  Apple Mobile Device - ok
13:13:41.0724 3324  [ BA8417D4765F3988FF921F30F630E303 ] arc            C:\Windows\system32\drivers\arc.sys
13:13:41.0770 3324  arc - ok
13:13:41.0802 3324  [ 9D41C435619733B34CC16A511E644B11 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
13:13:41.0817 3324  arcsas - ok
13:13:42.0394 3324  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:13:42.0457 3324  aspnet_state - ok
13:13:42.0519 3324  [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
13:13:42.0613 3324  AsyncMac - ok
13:13:42.0660 3324  [ E68D9B3A3905619732F7FE039466A623 ] atapi          C:\Windows\system32\drivers\atapi.sys
13:13:42.0675 3324  atapi - ok
13:13:42.0769 3324  [ 54CA8AAC988B441A692311E3B584D944 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
13:13:42.0878 3324  Ati External Event Utility - ok
13:13:43.0252 3324  [ 4B42547AE95A31D0E1E200B68A6C7647 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
13:13:43.0627 3324  atikmdag - ok
13:13:43.0705 3324  [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:13:43.0798 3324  AudioEndpointBuilder - ok
13:13:43.0798 3324  [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
13:13:43.0845 3324  AudioSrv - ok
13:13:43.0986 3324  [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
13:13:44.0001 3324  avgntflt - ok
13:13:44.0095 3324  [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
13:13:44.0110 3324  avipbb - ok
13:13:44.0142 3324  [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
13:13:44.0157 3324  avkmgr - ok
13:13:44.0204 3324  [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
13:13:44.0266 3324  blbdrive - ok
13:13:44.0422 3324  [ 673CF4F6BB1FBE09331B526802FBB892 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
13:13:44.0485 3324  Bonjour Service - ok
13:13:44.0532 3324  [ 2348447A80920B2493A9B582A23E81E1 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
13:13:44.0625 3324  bowser - ok
13:13:44.0688 3324  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
13:13:44.0766 3324  BrFiltLo - ok
13:13:44.0797 3324  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
13:13:44.0859 3324  BrFiltUp - ok
13:13:44.0906 3324  [ A1B39DE453433B115B4EA69EE0343816 ] Browser        C:\Windows\System32\browser.dll
13:13:44.0984 3324  Browser - ok
13:13:45.0062 3324  [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid        C:\Windows\system32\drivers\brserid.sys
13:13:45.0405 3324  Brserid - ok
13:13:45.0452 3324  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
13:13:45.0577 3324  BrSerWdm - ok
13:13:45.0624 3324  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
13:13:45.0717 3324  BrUsbMdm - ok
13:13:45.0764 3324  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
13:13:45.0858 3324  BrUsbSer - ok
13:13:45.0936 3324  [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
13:13:46.0029 3324  BTHMODEM - ok
13:13:46.0154 3324  [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
13:13:46.0310 3324  cdfs - ok
13:13:46.0497 3324  [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
13:13:46.0591 3324  cdrom - ok
13:13:46.0638 3324  [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc    C:\Windows\System32\certprop.dll
13:13:46.0716 3324  CertPropSvc - ok
13:13:46.0794 3324  [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
13:13:46.0918 3324  circlass - ok
13:13:47.0043 3324  [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS            C:\Windows\system32\CLFS.sys
13:13:47.0152 3324  CLFS - ok
13:13:47.0324 3324  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:13:47.0386 3324  clr_optimization_v2.0.50727_32 - ok
13:13:47.0433 3324  [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:13:47.0464 3324  clr_optimization_v2.0.50727_64 - ok
13:13:47.0901 3324  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:13:47.0995 3324  clr_optimization_v4.0.30319_32 - ok
13:13:48.0026 3324  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:13:48.0104 3324  clr_optimization_v4.0.30319_64 - ok
13:13:48.0151 3324  [ B52D9A14CE4101577900A364BA86F3DF ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
13:13:48.0260 3324  CmBatt - ok
13:13:48.0322 3324  [ 8C6AA24C1D7273A02284588426AB8CE3 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
13:13:48.0369 3324  cmdide - ok
13:13:48.0447 3324  [ 12E94E225BD7B05A2BCCD5C0B841E921 ] Com4QLBEx      C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
13:13:48.0494 3324  Com4QLBEx - ok
13:13:48.0572 3324  [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
13:13:48.0603 3324  Compbatt - ok
13:13:48.0634 3324  COMSysApp - ok
13:13:49.0102 3324  cpuz134 - ok
13:13:49.0134 3324  [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
13:13:49.0180 3324  crcdisk - ok
13:13:49.0274 3324  [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
13:13:49.0399 3324  CryptSvc - ok
13:13:49.0492 3324  [ BA8E5B2291C01EF71CA80E25F0C79D55 ] ctxusbm        C:\Windows\system32\DRIVERS\ctxusbm.sys
13:13:49.0539 3324  ctxusbm - ok
13:13:49.0633 3324  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch      C:\Windows\system32\rpcss.dll
13:13:49.0789 3324  DcomLaunch - ok
13:13:49.0882 3324  [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
13:13:50.0007 3324  DfsC - ok
13:13:50.0397 3324  [ C647F468F7DE343DF8C143655C5557D4 ] DFSR            C:\Windows\system32\DFSR.exe
13:13:50.0678 3324  DFSR - ok
13:13:50.0756 3324  [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
13:13:50.0803 3324  Dhcp - ok
13:13:50.0850 3324  [ B0107E40ECDB5FA692EBF832F295D905 ] disk            C:\Windows\system32\drivers\disk.sys
13:13:50.0881 3324  disk - ok
13:13:50.0928 3324  [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
13:13:50.0990 3324  Dnscache - ok
13:13:51.0068 3324  [ 57AE249F2C6A90476E8E400F0EEC3C56 ] Dokan          C:\Windows\system32\drivers\dokan.sys
13:13:51.0099 3324  Dokan - ok
13:13:51.0146 3324  [ F4FEAE56DA1B5B7DC78D5F9214CDEF5E ] DokanMounter    C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
13:13:51.0177 3324  DokanMounter ( UnsignedFile.Multi.Generic ) - warning
13:13:51.0177 3324  DokanMounter - detected UnsignedFile.Multi.Generic (1)
13:13:51.0255 3324  [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc        C:\Windows\System32\dot3svc.dll
13:13:51.0302 3324  dot3svc - ok
13:13:51.0349 3324  [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS            C:\Windows\system32\dps.dll
13:13:51.0411 3324  DPS - ok
13:13:51.0567 3324  [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
13:13:51.0708 3324  drmkaud - ok
13:13:51.0801 3324  [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
13:13:51.0910 3324  DXGKrnl - ok
13:13:51.0973 3324  [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60          C:\Windows\system32\DRIVERS\E1G6032E.sys
13:13:52.0051 3324  E1G60 - ok
13:13:52.0129 3324  [ C2303883FD9BE49DC36A6400643002EA ] EapHost        C:\Windows\System32\eapsvc.dll
13:13:52.0191 3324  EapHost - ok
13:13:52.0269 3324  [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache          C:\Windows\system32\drivers\ecache.sys
13:13:52.0300 3324  Ecache - ok
13:13:52.0378 3324  [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
13:13:52.0456 3324  ehRecvr - ok
13:13:52.0488 3324  [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched        C:\Windows\ehome\ehsched.exe
13:13:52.0534 3324  ehSched - ok
13:13:52.0581 3324  [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart        C:\Windows\ehome\ehstart.dll
13:13:52.0644 3324  ehstart - ok
13:13:52.0690 3324  [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
13:13:52.0722 3324  elxstor - ok
13:13:52.0784 3324  [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
13:13:52.0924 3324  EMDMgmt - ok
13:13:52.0987 3324  [ F218A3A27ED6592C0E22EC3595554447 ] enecir          C:\Windows\system32\DRIVERS\enecir.sys
13:13:53.0080 3324  enecir - ok
13:13:53.0112 3324  [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev          C:\Windows\system32\drivers\errdev.sys
13:13:53.0236 3324  ErrDev - ok
13:13:53.0361 3324  [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem    C:\Windows\system32\es.dll
13:13:53.0470 3324  EventSystem - ok
13:13:53.0502 3324  [ 486844F47B6636044A42454614ED4523 ] exfat          C:\Windows\system32\drivers\exfat.sys
13:13:53.0611 3324  exfat - ok
13:13:53.0611 3324  ezSharedSvc - ok
13:13:53.0673 3324  [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
13:13:53.0736 3324  fastfat - ok
13:13:53.0782 3324  [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
13:13:53.0845 3324  fdc - ok
13:13:53.0907 3324  [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost        C:\Windows\system32\fdPHost.dll
13:13:53.0970 3324  fdPHost - ok
13:13:54.0016 3324  [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub        C:\Windows\system32\fdrespub.dll
13:13:54.0110 3324  FDResPub - ok
13:13:54.0157 3324  Fildro - ok
13:13:54.0204 3324  [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
13:13:54.0235 3324  FileInfo - ok
13:13:54.0235 3324  [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
13:13:54.0313 3324  Filetrace - ok
13:13:54.0360 3324  [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
13:13:54.0453 3324  flpydisk - ok
13:13:54.0547 3324  [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
13:13:54.0578 3324  FltMgr - ok
13:13:54.0781 3324  [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache      C:\Windows\system32\FntCache.dll
13:13:54.0906 3324  FontCache - ok
13:13:55.0077 3324  [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:13:55.0140 3324  FontCache3.0.0.0 - ok
13:13:55.0171 3324  [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
13:13:55.0233 3324  Fs_Rec - ok
13:13:55.0280 3324  [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
13:13:55.0296 3324  gagp30kx - ok
13:13:55.0405 3324  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:13:55.0420 3324  GEARAspiWDM - ok
13:13:55.0576 3324  [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc          C:\Windows\System32\gpsvc.dll
13:13:55.0654 3324  gpsvc - ok
13:13:55.0732 3324  [ 68E732382B32417FF61FD663259B4B09 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:13:55.0842 3324  HdAudAddService - ok
13:13:55.0935 3324  [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
13:13:56.0044 3324  HDAudBus - ok
13:13:56.0107 3324  [ B4881C84A180E75B8C25DC1D726C375F ] HidBth          C:\Windows\system32\drivers\hidbth.sys
13:13:56.0200 3324  HidBth - ok
13:13:56.0247 3324  [ 5F47839455D01FF6403B008D481A6F5B ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
13:13:56.0341 3324  HidIr - ok
13:13:56.0403 3324  [ 59361D38A297755D46A540E450202B2A ] hidserv        C:\Windows\system32\hidserv.dll
13:13:56.0481 3324  hidserv - ok
13:13:56.0606 3324  [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
13:13:56.0684 3324  HidUsb - ok
13:13:56.0778 3324  [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc          C:\Windows\system32\kmsvc.dll
13:13:56.0840 3324  hkmsvc - ok
13:13:56.0949 3324  [ A19B0BB5A7EB6DF2DD4A0711D36955EE ] HP Health Check Service c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
13:13:56.0965 3324  HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
13:13:56.0965 3324  HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
13:13:57.0058 3324  [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
13:13:57.0074 3324  HpCISSs - ok
13:13:57.0136 3324  [ 4E0BEC0F78096FFD6D3314B497FC49D3 ] hpdskflt        C:\Windows\system32\DRIVERS\hpdskflt.sys
13:13:57.0168 3324  hpdskflt - ok
13:13:57.0230 3324  [ 0ECC54FD34D6A089C300846B011E81D6 ] HpqKbFiltr      C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
13:13:57.0308 3324  HpqKbFiltr - ok
13:13:57.0417 3324  [ 188FF0ADF66768D53AD94F43972E1E9A ] hpqwmiex        C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
13:13:57.0464 3324  hpqwmiex ( UnsignedFile.Multi.Generic ) - warning
13:13:57.0464 3324  hpqwmiex - detected UnsignedFile.Multi.Generic (1)
13:13:57.0526 3324  [ FC7C13B5A9E9BE23B7AE72BBC7FDB278 ] hpsrv          C:\Windows\system32\Hpservice.exe
13:13:57.0558 3324  hpsrv - ok
13:13:57.0651 3324  [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
13:13:57.0870 3324  HTTP - ok
13:13:57.0979 3324  [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
13:13:58.0026 3324  i2omp - ok
13:13:58.0104 3324  [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
13:13:58.0166 3324  i8042prt - ok
13:13:58.0197 3324  [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
13:13:58.0213 3324  iaStorV - ok
13:13:58.0322 3324  [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:13:58.0369 3324  idsvc - ok
13:13:58.0431 3324  [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
13:13:58.0447 3324  iirsp - ok
13:13:58.0572 3324  [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT          C:\Windows\System32\ikeext.dll
13:13:58.0665 3324  IKEEXT - ok
13:13:58.0743 3324  [ 475490CAF376E55E6E8B37BBDFEB2E81 ] intelide        C:\Windows\system32\drivers\intelide.sys
13:13:58.0759 3324  intelide - ok
13:13:58.0790 3324  [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
13:13:58.0837 3324  intelppm - ok
13:13:58.0899 3324  [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
13:13:58.0962 3324  IPBusEnum - ok
13:13:59.0024 3324  [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:13:59.0118 3324  IpFilterDriver - ok
13:13:59.0118 3324  IpInIp - ok
13:13:59.0180 3324  [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
13:13:59.0258 3324  IPMIDRV - ok
13:13:59.0289 3324  [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
13:13:59.0352 3324  IPNAT - ok
13:13:59.0476 3324  [ 24595EC9236D7E421661A2D4FFBD901A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
13:13:59.0523 3324  iPod Service - ok
13:13:59.0617 3324  [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
13:13:59.0695 3324  IRENUM - ok
13:13:59.0757 3324  [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
13:13:59.0773 3324  isapnp - ok
13:13:59.0851 3324  [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
13:13:59.0866 3324  iScsiPrt - ok
13:13:59.0898 3324  [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
13:13:59.0913 3324  iteatapi - ok
13:13:59.0960 3324  [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid        C:\Windows\system32\drivers\iteraid.sys
13:14:00.0022 3324  iteraid - ok
13:14:00.0054 3324  [ BB86B1C3489463BBA1FD04C876DBE414 ] JMCR            C:\Windows\system32\DRIVERS\jmcr.sys
13:14:00.0147 3324  JMCR - ok
13:14:00.0178 3324  [ 423696F3BA6472DD17699209B933BC26 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
13:14:00.0194 3324  kbdclass - ok
13:14:00.0210 3324  [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
13:14:00.0288 3324  kbdhid - ok
13:14:00.0319 3324  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso          C:\Windows\system32\lsass.exe
13:14:00.0381 3324  KeyIso - ok
13:14:00.0444 3324  [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
13:14:00.0506 3324  KSecDD - ok
13:14:00.0600 3324  [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
13:14:00.0693 3324  ksthunk - ok
13:14:00.0756 3324  [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm          C:\Windows\system32\msdtckrm.dll
13:14:00.0865 3324  KtmRm - ok
13:14:00.0943 3324  [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer    C:\Windows\system32\srvsvc.dll
13:14:01.0052 3324  LanmanServer - ok
13:14:01.0083 3324  [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:14:01.0161 3324  LanmanWorkstation - ok
13:14:01.0270 3324  [ 83D8BE94E1CBCBE2EA8372DB1A95A159 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
13:14:01.0302 3324  LightScribeService ( UnsignedFile.Multi.Generic ) - warning
13:14:01.0302 3324  LightScribeService - detected UnsignedFile.Multi.Generic (1)
13:14:01.0333 3324  [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
13:14:01.0380 3324  lltdio - ok
13:14:01.0520 3324  [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
13:14:01.0598 3324  lltdsvc - ok
13:14:01.0660 3324  [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts        C:\Windows\System32\lmhsvc.dll
13:14:01.0738 3324  lmhosts - ok
13:14:01.0801 3324  [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
13:14:01.0816 3324  LSI_FC - ok
13:14:01.0848 3324  [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
13:14:01.0863 3324  LSI_SAS - ok
13:14:01.0894 3324  [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
13:14:01.0910 3324  LSI_SCSI - ok
13:14:02.0019 3324  [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv          C:\Windows\system32\drivers\luafv.sys
13:14:02.0097 3324  luafv - ok
13:14:02.0331 3324  [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
13:14:02.0425 3324  McComponentHostService - ok
13:14:02.0503 3324  [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
13:14:02.0534 3324  Mcx2Svc - ok
13:14:02.0596 3324  [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas        C:\Windows\system32\drivers\megasas.sys
13:14:02.0643 3324  megasas - ok
13:14:02.0721 3324  [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
13:14:02.0815 3324  MegaSR - ok
13:14:02.0862 3324  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS          C:\Windows\system32\mmcss.dll
13:14:02.0908 3324  MMCSS - ok
13:14:02.0955 3324  [ 59848D5CC74606F0EE7557983BB73C2E ] Modem          C:\Windows\system32\drivers\modem.sys
13:14:03.0033 3324  Modem - ok
13:14:03.0080 3324  [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
13:14:03.0158 3324  monitor - ok
13:14:03.0174 3324  [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
13:14:03.0189 3324  mouclass - ok
13:14:03.0252 3324  [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
13:14:03.0345 3324  mouhid - ok
13:14:03.0361 3324  [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
13:14:03.0392 3324  MountMgr - ok
13:14:03.0486 3324  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:14:03.0501 3324  MozillaMaintenance - ok
13:14:03.0532 3324  [ F8276EB8698142884498A528DFEA8478 ] mpio            C:\Windows\system32\drivers\mpio.sys
13:14:03.0548 3324  mpio - ok
13:14:03.0579 3324  [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
13:14:03.0642 3324  mpsdrv - ok
13:14:03.0657 3324  [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
13:14:03.0673 3324  Mraid35x - ok
13:14:03.0720 3324  [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
13:14:03.0751 3324  MRxDAV - ok
13:14:03.0813 3324  [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
13:14:03.0876 3324  mrxsmb - ok
13:14:03.0922 3324  [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:14:03.0969 3324  mrxsmb10 - ok
13:14:04.0000 3324  [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:14:04.0032 3324  mrxsmb20 - ok
13:14:04.0094 3324  [ AA459F2AB3AB603C357FF117CAE3D818 ] msahci          C:\Windows\system32\drivers\msahci.sys
13:14:04.0110 3324  msahci - ok
13:14:04.0156 3324  [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
13:14:04.0188 3324  msdsm - ok
13:14:04.0219 3324  [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC          C:\Windows\System32\msdtc.exe
13:14:04.0281 3324  MSDTC - ok
13:14:04.0344 3324  [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs            C:\Windows\system32\drivers\Msfs.sys
13:14:04.0422 3324  Msfs - ok
13:14:04.0500 3324  [ 00EBC952961664780D43DCA157E79B27 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
13:14:04.0531 3324  msisadrv - ok
13:14:04.0562 3324  [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
13:14:04.0656 3324  MSiSCSI - ok
13:14:04.0656 3324  msiserver - ok
13:14:04.0687 3324  [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
13:14:04.0734 3324  MSKSSRV - ok
13:14:04.0780 3324  [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
13:14:04.0858 3324  MSPCLOCK - ok
13:14:04.0905 3324  [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
13:14:04.0952 3324  MSPQM - ok
13:14:04.0999 3324  [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
13:14:05.0030 3324  MsRPC - ok
13:14:05.0077 3324  [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
13:14:05.0092 3324  mssmbios - ok
13:14:05.0155 3324  [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
13:14:05.0217 3324  MSTEE - ok
13:14:05.0295 3324  [ 0CC49F78D8ACA0877D885F149084E543 ] Mup            C:\Windows\system32\Drivers\mup.sys
13:14:05.0311 3324  Mup - ok
13:14:05.0373 3324  [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent        C:\Windows\system32\qagentRT.dll
13:14:05.0514 3324  napagent - ok
13:14:05.0592 3324  [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
13:14:05.0638 3324  NativeWifiP - ok
13:14:05.0763 3324  NAVENG - ok
13:14:05.0763 3324  NAVEX15 - ok
13:14:05.0919 3324  [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS            C:\Windows\system32\drivers\ndis.sys
13:14:06.0013 3324  NDIS - ok
13:14:06.0060 3324  [ 64DF698A425478E321981431AC171334 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
13:14:06.0153 3324  NdisTapi - ok
13:14:06.0200 3324  [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
13:14:06.0278 3324  Ndisuio - ok
13:14:06.0340 3324  [ F8158771905260982CE724076419EF19 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
13:14:06.0387 3324  NdisWan - ok
13:14:06.0434 3324  [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
13:14:06.0496 3324  NDProxy - ok
13:14:06.0574 3324  [ 89FD76A90CBE63F03A70C2D1B85E802C ] NEOFLTR_710_19243 C:\Windows\system32\Drivers\NEOFLTR_710_19243.SYS
13:14:06.0590 3324  NEOFLTR_710_19243 - ok
13:14:06.0652 3324  Nero BackItUp Scheduler 4.0 - ok
13:14:06.0668 3324  [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
13:14:06.0762 3324  NetBIOS - ok
13:14:06.0840 3324  [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
13:14:06.0933 3324  netbt - ok
13:14:06.0964 3324  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon        C:\Windows\system32\lsass.exe
13:14:06.0980 3324  Netlogon - ok
13:14:07.0011 3324  [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman          C:\Windows\System32\netman.dll
13:14:07.0167 3324  Netman - ok
13:14:07.0230 3324  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:14:07.0308 3324  NetMsmqActivator - ok
13:14:07.0323 3324  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:14:07.0339 3324  NetPipeActivator - ok
13:14:07.0432 3324  [ 7846D0136CC2B264926A73047BA7688A ] netprofm        C:\Windows\System32\netprofm.dll
13:14:07.0510 3324  netprofm - ok
13:14:07.0542 3324  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:14:07.0557 3324  NetTcpActivator - ok
13:14:07.0573 3324  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:14:07.0588 3324  NetTcpPortSharing - ok
13:14:07.0791 3324  [ C86984AEE87900C1EEB6942EDE3BF4B6 ] NETw3v64        C:\Windows\system32\DRIVERS\NETw3v64.sys
13:14:08.0056 3324  NETw3v64 - ok
13:14:08.0649 3324  [ 2BDCB7B7917380794C9D87AC2153CE33 ] NETw5v64        C:\Windows\system32\DRIVERS\NETw5v64.sys
13:14:09.0195 3324  NETw5v64 - ok
13:14:09.0226 3324  [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
13:14:09.0258 3324  nfrd960 - ok
13:14:09.0320 3324  [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc          C:\Windows\System32\nlasvc.dll
13:14:09.0382 3324  NlaSvc - ok
13:14:09.0445 3324  [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64      C:\Windows\system32\drivers\ccdcmbox64.sys
13:14:09.0554 3324  nmwcdcx64 - ok
13:14:09.0616 3324  [ 76292103C5149EB140419F36DCF26C1B ] nmwcdnsucx64    C:\Windows\system32\drivers\nmwcdnsucx64.sys
13:14:09.0694 3324  nmwcdnsucx64 - ok
13:14:09.0741 3324  [ 2974296DA6296B4FEA3E313BF98C693D ] nmwcdnsux64    C:\Windows\system32\drivers\nmwcdnsux64.sys
13:14:09.0804 3324  nmwcdnsux64 - ok
13:14:09.0850 3324  [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64        C:\Windows\system32\drivers\ccdcmbx64.sys
13:14:09.0913 3324  nmwcdx64 - ok
13:14:09.0928 3324  Norton Internet Security - ok
13:14:09.0975 3324  [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
13:14:10.0006 3324  Npfs - ok
13:14:10.0053 3324  [ ACB62BAA1C319B17752553DF3026EEEB ] nsi            C:\Windows\system32\nsisvc.dll
13:14:10.0131 3324  nsi - ok
13:14:10.0225 3324  [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
13:14:10.0318 3324  nsiproxy - ok
13:14:10.0490 3324  [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
13:14:10.0646 3324  Ntfs - ok
13:14:10.0708 3324  [ DD5D684975352B85B52E3FD5347C20CB ] Null            C:\Windows\system32\drivers\Null.sys
13:14:10.0786 3324  Null - ok
13:14:10.0818 3324  [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
13:14:10.0833 3324  nvraid - ok
13:14:10.0864 3324  [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor          C:\Windows\system32\drivers\nvstor.sys
13:14:10.0880 3324  nvstor - ok
13:14:10.0927 3324  [ 19067CA93075EF4823E3938A686F532F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
13:14:10.0942 3324  nv_agp - ok
13:14:10.0958 3324  NwlnkFlt - ok
13:14:10.0958 3324  NwlnkFwd - ok
13:14:11.0020 3324  [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
13:14:11.0067 3324  ohci1394 - ok
13:14:11.0130 3324  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:14:11.0192 3324  ose - ok
13:14:11.0301 3324  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc        C:\Windows\system32\p2psvc.dll
13:14:11.0442 3324  p2pimsvc - ok
13:14:11.0488 3324  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc          C:\Windows\system32\p2psvc.dll
13:14:11.0566 3324  p2psvc - ok
13:14:11.0613 3324  [ AECD57F94C887F58919F307C35498EA0 ] Parport        C:\Windows\system32\drivers\parport.sys
13:14:11.0691 3324  Parport - ok
13:14:11.0785 3324  [ B43751085E2ABE389DA466BC62A4B987 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
13:14:11.0800 3324  partmgr - ok
13:14:11.0847 3324  [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc          C:\Windows\System32\pcasvc.dll
13:14:11.0910 3324  PcaSvc - ok
13:14:11.0988 3324  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
13:14:12.0050 3324  pccsmcfd - ok
13:14:12.0097 3324  [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci            C:\Windows\system32\drivers\pci.sys
13:14:12.0112 3324  pci - ok
13:14:12.0159 3324  [ 15E5C3F89A3452EFBDA3B39816DBC4EE ] pciide          C:\Windows\system32\drivers\pciide.sys
13:14:12.0175 3324  pciide - ok
13:14:12.0206 3324  [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
13:14:12.0237 3324  pcmcia - ok
13:14:12.0253 3324  [ 58865916F53592A61549B04941BFD80D ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
13:14:12.0393 3324  PEAUTH - ok
13:14:12.0487 3324  [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
13:14:12.0565 3324  PerfHost - ok
13:14:12.0658 3324  [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla            C:\Windows\system32\pla.dll
13:14:12.0721 3324  pla - ok
13:14:12.0861 3324  [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
13:14:12.0892 3324  PlugPlay - ok
13:14:12.0924 3324  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
13:14:12.0955 3324  PNRPAutoReg - ok
13:14:12.0955 3324  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc        C:\Windows\system32\p2psvc.dll
13:14:13.0002 3324  PNRPsvc - ok
13:14:13.0126 3324  [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
13:14:13.0158 3324  PolicyAgent - ok
13:14:13.0251 3324  [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
13:14:13.0314 3324  PptpMiniport - ok
13:14:13.0360 3324  [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor      C:\Windows\system32\drivers\processr.sys
13:14:13.0423 3324  Processor - ok
13:14:13.0516 3324  [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc        C:\Windows\system32\profsvc.dll
13:14:13.0548 3324  ProfSvc - ok
13:14:13.0563 3324  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
13:14:13.0594 3324  ProtectedStorage - ok
13:14:13.0657 3324  [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
13:14:13.0688 3324  PSched - ok
13:14:13.0813 3324  [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300          C:\Windows\system32\drivers\ql2300.sys
13:14:13.0922 3324  ql2300 - ok
13:14:14.0000 3324  [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
13:14:14.0047 3324  ql40xx - ok
13:14:14.0125 3324  [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE          C:\Windows\system32\qwave.dll
13:14:14.0187 3324  QWAVE - ok
13:14:14.0218 3324  [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
13:14:14.0281 3324  QWAVEdrv - ok
13:14:14.0328 3324  [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
13:14:14.0374 3324  RasAcd - ok
13:14:14.0421 3324  [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto        C:\Windows\System32\rasauto.dll
13:14:14.0499 3324  RasAuto - ok
13:14:14.0546 3324  [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
13:14:14.0593 3324  Rasl2tp - ok
13:14:14.0640 3324  [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan          C:\Windows\System32\rasmans.dll
13:14:14.0671 3324  RasMan - ok
13:14:14.0702 3324  [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
13:14:14.0796 3324  RasPppoe - ok
13:14:14.0811 3324  [ C6A593B51F34C33E5474539544072527 ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
13:14:14.0827 3324  RasSstp - ok
13:14:14.0874 3324  [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
13:14:14.0967 3324  rdbss - ok
13:14:14.0998 3324  [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
13:14:15.0030 3324  RDPCDD - ok
13:14:15.0045 3324  [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
13:14:15.0092 3324  rdpdr - ok
13:14:15.0108 3324  [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
13:14:15.0170 3324  RDPENCDD - ok
13:14:15.0217 3324  [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
13:14:15.0310 3324  RDPWD - ok
13:14:15.0404 3324  [ BC0A4D47472B042537F4E57B950415FA ] Recovery Service for Windows C:\Program Files (x86)\SMINST\BLService.exe
13:14:15.0420 3324  Recovery Service for Windows - ok
13:14:15.0482 3324  [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess    C:\Windows\System32\mprdim.dll
13:14:15.0544 3324  RemoteAccess - ok
13:14:15.0607 3324  [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
13:14:15.0638 3324  RemoteRegistry - ok
13:14:15.0810 3324  [ 805AE1F90C64758D19AAA001CF8CBA12 ] RichVideo      C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
13:14:15.0856 3324  RichVideo ( UnsignedFile.Multi.Generic ) - warning
13:14:15.0856 3324  RichVideo - detected UnsignedFile.Multi.Generic (1)
13:14:15.0903 3324  [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator      C:\Windows\system32\locator.exe
13:14:15.0981 3324  RpcLocator - ok
13:14:16.0200 3324  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs          C:\Windows\system32\rpcss.dll
13:14:16.0309 3324  RpcSs - ok
13:14:16.0371 3324  [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
13:14:16.0449 3324  rspndr - ok
13:14:16.0512 3324  [ 8B91737DA75ADD21CB1554B38089196A ] RTL8169        C:\Windows\system32\DRIVERS\Rtlh64.sys
13:14:16.0605 3324  RTL8169 - ok
13:14:16.0621 3324  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs          C:\Windows\system32\lsass.exe
13:14:16.0636 3324  SamSs - ok
13:14:16.0683 3324  [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
13:14:16.0699 3324  sbp2port - ok
13:14:16.0792 3324  [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr        C:\Windows\System32\SCardSvr.dll
13:14:16.0870 3324  SCardSvr - ok
13:14:17.0042 3324  [ 0F838C811AD295D2A4489B9993096C63 ] Schedule        C:\Windows\system32\schedsvc.dll
13:14:17.0198 3324  Schedule - ok
13:14:17.0229 3324  [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc    C:\Windows\System32\certprop.dll
13:14:17.0260 3324  SCPolicySvc - ok
13:14:17.0354 3324  [ B42EE50F7D24F837F925332EB349ECA5 ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
13:14:17.0432 3324  sdbus - ok
13:14:17.0510 3324  [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
13:14:17.0572 3324  SDRSVC - ok
13:14:17.0947 3324  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
13:14:17.0962 3324  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
13:14:17.0962 3324  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
13:14:18.0009 3324  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
13:14:18.0150 3324  secdrv - ok
13:14:18.0181 3324  [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon        C:\Windows\system32\seclogon.dll
13:14:18.0243 3324  seclogon - ok
13:14:18.0259 3324  [ 90973A64B96CD647FF81C79443618EED ] SENS            C:\Windows\System32\sens.dll
13:14:18.0321 3324  SENS - ok
13:14:18.0352 3324  [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum        C:\Windows\system32\drivers\serenum.sys
13:14:18.0399 3324  Serenum - ok
13:14:18.0415 3324  [ E62FAC91EE288DB29A9696A9D279929C ] Serial          C:\Windows\system32\drivers\serial.sys
13:14:18.0462 3324  Serial - ok
13:14:18.0477 3324  [ A842F04833684BCEEA7336211BE478DF ] sermouse        C:\Windows\system32\drivers\sermouse.sys
13:14:18.0540 3324  sermouse - ok
13:14:18.0711 3324  [ 58D5BFDF3ADF49FE9CABD78CC61D92F6 ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
13:14:18.0836 3324  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
13:14:18.0836 3324  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
13:14:18.0883 3324  [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv      C:\Windows\system32\sessenv.dll
13:14:18.0976 3324  SessionEnv - ok
13:14:19.0054 3324  [ 14D4B4465193A87C127933978E8C4106 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
13:14:19.0101 3324  sffdisk - ok
13:14:19.0132 3324  [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
13:14:19.0242 3324  sffp_mmc - ok
13:14:19.0288 3324  [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
13:14:19.0366 3324  sffp_sd - ok
13:14:19.0398 3324  [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
13:14:19.0476 3324  sfloppy - ok
13:14:19.0538 3324  [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:14:19.0647 3324  ShellHWDetection - ok
13:14:19.0694 3324  [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
13:14:19.0741 3324  SiSRaid2 - ok
13:14:19.0756 3324  [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
13:14:19.0788 3324  SiSRaid4 - ok
13:14:19.0881 3324  [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
13:14:19.0897 3324  SkypeUpdate - ok
13:14:20.0178 3324  [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc          C:\Windows\system32\SLsvc.exe
13:14:20.0349 3324  slsvc - ok
13:14:20.0505 3324  [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify      C:\Windows\system32\SLUINotify.dll
13:14:20.0568 3324  SLUINotify - ok
13:14:20.0646 3324  [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
13:14:20.0708 3324  Smb - ok
13:14:20.0770 3324  [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
13:14:20.0817 3324  SNMPTRAP - ok
13:14:20.0880 3324  [ 386C3C63F00A7040C7EC5E384217E89D ] spldr          C:\Windows\system32\drivers\spldr.sys
13:14:20.0911 3324  spldr - ok
13:14:20.0942 3324  [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler        C:\Windows\System32\spoolsv.exe
13:14:20.0973 3324  Spooler - ok
13:14:20.0989 3324  SRTSP - ok
13:14:20.0989 3324  SRTSPX - ok
13:14:21.0067 3324  [ 880A57FCCB571EBD063D4DD50E93E46D ] srv            C:\Windows\system32\DRIVERS\srv.sys
13:14:21.0176 3324  srv - ok
13:14:21.0223 3324  [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
13:14:21.0316 3324  srv2 - ok
13:14:21.0332 3324  [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
13:14:21.0441 3324  srvnet - ok
13:14:21.0472 3324  [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
13:14:21.0582 3324  SSDPSRV - ok
13:14:21.0722 3324  [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc        C:\Windows\system32\sstpsvc.dll
13:14:21.0816 3324  SstpSvc - ok
13:14:22.0034 3324  [ 72EB6157E892A674E47E08732BB5CCE3 ] STacSV          C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe
13:14:22.0081 3324  STacSV - ok
13:14:22.0174 3324  [ 0C7BDA7E9A329A071C080EB5210FE019 ] STHDA          C:\Windows\system32\DRIVERS\stwrt64.sys
13:14:22.0252 3324  STHDA - ok
13:14:22.0315 3324  [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc          C:\Windows\System32\wiaservc.dll
13:14:22.0408 3324  stisvc - ok
13:14:22.0455 3324  [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
13:14:22.0471 3324  swenum - ok
13:14:22.0611 3324  [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv          C:\Windows\System32\swprv.dll
13:14:22.0642 3324  swprv - ok
13:14:22.0674 3324  [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
13:14:22.0689 3324  Symc8xx - ok
13:14:22.0736 3324  [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
13:14:22.0767 3324  Sym_hi - ok
13:14:22.0767 3324  [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
13:14:22.0783 3324  Sym_u3 - ok
13:14:22.0876 3324  [ 3A706A967295E16511E40842B1A2761D ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
13:14:22.0908 3324  SynTP - ok
13:14:22.0970 3324  [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain        C:\Windows\system32\sysmain.dll
13:14:23.0079 3324  SysMain - ok
13:14:23.0204 3324  [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:14:23.0266 3324  TabletInputService - ok
13:14:23.0313 3324  [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv        C:\Windows\System32\tapisrv.dll
13:14:23.0407 3324  TapiSrv - ok
13:14:23.0469 3324  [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS            C:\Windows\System32\tbssvc.dll
13:14:23.0594 3324  TBS - ok
13:14:23.0828 3324  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
13:14:23.0984 3324  Tcpip - ok
13:14:24.0000 3324  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
13:14:24.0093 3324  Tcpip6 - ok
13:14:24.0202 3324  [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
13:14:24.0296 3324  tcpipreg - ok
13:14:24.0343 3324  [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
13:14:24.0436 3324  TDPIPE - ok
13:14:24.0468 3324  [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
13:14:24.0561 3324  TDTCP - ok
13:14:24.0608 3324  [ 458919C8C42E398DC4802178D5FFEE27 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
13:14:24.0655 3324  tdx - ok
13:14:24.0702 3324  [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
13:14:24.0733 3324  TermDD - ok
13:14:24.0795 3324  [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService    C:\Windows\System32\termsrv.dll
13:14:24.0920 3324  TermService - ok
13:14:24.0982 3324  [ 56793271ECDEDD350C5ADD305603E963 ] Themes          C:\Windows\system32\shsvcs.dll
13:14:25.0014 3324  Themes - ok
13:14:25.0092 3324  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER    C:\Windows\system32\mmcss.dll
13:14:25.0138 3324  THREADORDER - ok
13:14:25.0232 3324  [ 0407143F2BBC1A5DD5B518AC0704FCBF ] TomTomHOMEService C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
13:14:25.0248 3324  TomTomHOMEService - ok
13:14:25.0310 3324  [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks          C:\Windows\System32\trkwks.dll
13:14:25.0388 3324  TrkWks - ok
13:14:25.0560 3324  [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:14:25.0638 3324  TrustedInstaller - ok
13:14:25.0684 3324  [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
13:14:25.0794 3324  tssecsrv - ok
13:14:25.0887 3324  [ 89EC74A9E602D16A75A4170511029B3C ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
13:14:25.0965 3324  tunmp - ok
13:14:26.0012 3324  [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
13:14:26.0074 3324  tunnel - ok
13:14:26.0308 3324  [ 1C31169DDDC70C1605F703DA701EAEEA ] TVCapSvc        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
13:14:26.0308 3324  TVCapSvc - ok
13:14:26.0324 3324  [ 290B8C381DBC15D3DBCBD2BDB6B0BA12 ] TVSched        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
13:14:26.0324 3324  TVSched - ok
13:14:26.0371 3324  [ FEC266EF401966311744BD0F359F7F56 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
13:14:26.0386 3324  uagp35 - ok
13:14:26.0464 3324  [ FAF2640A2A76ED03D449E443194C4C34 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
13:14:26.0527 3324  udfs - ok
13:14:26.0574 3324  [ 060507C4113391394478F6953A79EEDC ] UI0Detect      C:\Windows\system32\UI0Detect.exe
13:14:26.0620 3324  UI0Detect - ok
13:14:26.0698 3324  [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
13:14:26.0792 3324  uliagpkx - ok
13:14:26.0823 3324  [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci        C:\Windows\system32\drivers\uliahci.sys
13:14:26.0886 3324  uliahci - ok
13:14:26.0901 3324  [ 31707F09846056651EA2C37858F5DDB0 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
13:14:26.0948 3324  UlSata - ok
13:14:26.0995 3324  [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
13:14:27.0010 3324  ulsata2 - ok
13:14:27.0042 3324  [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
13:14:27.0088 3324  umbus - ok
13:14:27.0135 3324  [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost        C:\Windows\System32\upnphost.dll
13:14:27.0198 3324  upnphost - ok
13:14:27.0244 3324  [ 9856C38AB8FAACCA4DD99DAC7B42F838 ] upperdev        C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
13:14:27.0307 3324  upperdev - ok
13:14:27.0385 3324  [ CD03479F2DA26500B203ED075C146A7A ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
13:14:27.0447 3324  USBAAPL64 - ok
13:14:27.0525 3324  [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
13:14:27.0588 3324  usbaudio - ok
13:14:27.0619 3324  [ 07E3498FC60834219D2356293DA0FECC ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
13:14:27.0666 3324  usbccgp - ok
13:14:27.0697 3324  [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
13:14:27.0744 3324  usbcir - ok
13:14:27.0806 3324  [ 827E44DE934A736EA31E91D353EB126F ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
13:14:27.0837 3324  usbehci - ok
13:14:27.0900 3324  [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
13:14:27.0978 3324  usbhub - ok
13:14:28.0009 3324  [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
13:14:28.0087 3324  usbohci - ok
13:14:28.0134 3324  [ ACFEE697AF477021BB3EC78C5431FED2 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
13:14:28.0227 3324  usbprint - ok
13:14:28.0321 3324  [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
13:14:28.0368 3324  usbscan - ok
13:14:28.0414 3324  [ F7386007FB19E7685FC7B298560AA81F ] usbser          C:\Windows\system32\drivers\usbser.sys
13:14:28.0477 3324  usbser - ok
13:14:28.0524 3324  [ 89123DC822AC7A708BD4C9E196A37610 ] UsbserFilt      C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys
13:14:28.0602 3324  UsbserFilt - ok
13:14:28.0680 3324  [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:14:28.0742 3324  USBSTOR - ok
13:14:28.0773 3324  [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
13:14:28.0820 3324  usbuhci - ok
13:14:28.0867 3324  [ FC33099877790D51B0927B7039059855 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
13:14:28.0914 3324  usbvideo - ok
13:14:28.0992 3324  [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms          C:\Windows\System32\uxsms.dll
13:14:29.0054 3324  UxSms - ok
13:14:29.0085 3324  [ 294945381DFA7CE58CECF0A9896AF327 ] vds            C:\Windows\System32\vds.exe
13:14:29.0194 3324  vds - ok
13:14:29.0272 3324  [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
13:14:29.0397 3324  vga - ok
13:14:29.0413 3324  [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave        C:\Windows\System32\drivers\vga.sys
13:14:29.0460 3324  VgaSave - ok
13:14:29.0506 3324  [ 4F964E6828156F0EF3FA8D3A9A7895DE ] viaide          C:\Windows\system32\drivers\viaide.sys
13:14:29.0522 3324  viaide - ok
13:14:29.0569 3324  [ 2B7E885ED951519A12C450D24535DFCA ] volmgr          C:\Windows\system32\drivers\volmgr.sys
13:14:29.0584 3324  volmgr - ok
13:14:29.0647 3324  [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
13:14:29.0709 3324  volmgrx - ok
13:14:29.0772 3324  [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap        C:\Windows\system32\drivers\volsnap.sys
13:14:29.0803 3324  volsnap - ok
13:14:29.0850 3324  [ A68F455ED2673835209318DD61BFBB0E ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
13:14:29.0896 3324  vsmraid - ok
13:14:30.0037 3324  [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS            C:\Windows\system32\vssvc.exe
13:14:30.0318 3324  VSS - ok
13:14:30.0427 3324  [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time        C:\Windows\system32\w32time.dll
13:14:30.0520 3324  W32Time - ok
13:14:30.0567 3324  [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
13:14:30.0661 3324  WacomPen - ok
13:14:30.0770 3324  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
13:14:30.0817 3324  Wanarp - ok
13:14:30.0817 3324  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
13:14:30.0848 3324  Wanarpv6 - ok
13:14:30.0973 3324  [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
13:14:31.0066 3324  wcncsvc - ok
13:14:31.0113 3324  [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:14:31.0160 3324  WcsPlugInService - ok
13:14:31.0191 3324  [ 0C17A0816F65B89E362E682AD5E7266E ] Wd              C:\Windows\system32\drivers\wd.sys
13:14:31.0363 3324  Wd - ok
13:14:31.0441 3324  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
13:14:31.0566 3324  Wdf01000 - ok
13:14:31.0597 3324  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost  C:\Windows\system32\wdi.dll
13:14:31.0675 3324  WdiServiceHost - ok
13:14:31.0690 3324  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost  C:\Windows\system32\wdi.dll
13:14:31.0753 3324  WdiSystemHost - ok
13:14:31.0784 3324  [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient      C:\Windows\System32\webclnt.dll
13:14:31.0831 3324  WebClient - ok
13:14:31.0893 3324  [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc          C:\Windows\system32\wecsvc.dll
13:14:31.0956 3324  Wecsvc - ok
13:14:31.0987 3324  [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
13:14:32.0065 3324  wercplsupport - ok
13:14:32.0112 3324  [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc          C:\Windows\System32\WerSvc.dll
13:14:32.0190 3324  WerSvc - ok
13:14:32.0205 3324  WinHttpAutoProxySvc - ok
13:14:32.0330 3324  [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
13:14:32.0392 3324  Winmgmt - ok
13:14:32.0689 3324  [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM          C:\Windows\system32\WsmSvc.dll
13:14:33.0126 3324  WinRM - ok
13:14:33.0313 3324  [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc        C:\Windows\System32\wlansvc.dll
13:14:33.0469 3324  Wlansvc - ok
13:14:33.0937 3324  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:14:34.0186 3324  wlidsvc - ok
13:14:34.0249 3324  [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
13:14:34.0311 3324  WmiAcpi - ok
13:14:34.0374 3324  [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
13:14:34.0436 3324  wmiApSrv - ok
13:14:34.0530 3324  WMPNetworkSvc - ok
13:14:34.0639 3324  [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
13:14:34.0748 3324  WPCSvc - ok
13:14:34.0826 3324  [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
13:14:34.0935 3324  WPDBusEnum - ok
13:14:34.0982 3324  [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
13:14:35.0060 3324  WpdUsb - ok
13:14:35.0856 3324  [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:14:36.0074 3324  WPFFontCache_v0400 - ok
13:14:36.0136 3324  [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
13:14:36.0246 3324  ws2ifsl - ok
13:14:36.0308 3324  WSearch - ok
13:14:36.0339 3324  [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
13:14:36.0370 3324  WUDFRd - ok
13:14:36.0402 3324  [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
13:14:36.0464 3324  wudfsvc - ok
13:14:36.0573 3324  [ 07F7285220307AAFB755D890295F0F9A ] yukonx64        C:\Windows\system32\DRIVERS\yk60x64.sys
13:14:36.0682 3324  yukonx64 - ok
13:14:36.0745 3324  [ 1CACFEF9E5DD866C5B79A135EE729E18 ] {55662437-DA8C-40c0-AADA-2C816A897A49} C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
13:14:36.0760 3324  {55662437-DA8C-40c0-AADA-2C816A897A49} - ok
13:14:36.0760 3324  ================ Scan global ===============================
13:14:36.0807 3324  [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
13:14:36.0901 3324  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
13:14:36.0901 3324  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
13:14:36.0963 3324  [ B8844F93D2C5F1DCDB179AAA9AF134B7 ] C:\Windows\system32\services.exe
13:14:36.0979 3324  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - infected
13:14:36.0979 3324  C:\Windows\system32\services.exe - detected Virus.Win64.ZAccess.a (0)
13:14:36.0979 3324  ================ Scan MBR ==================================
13:14:36.0994 3324  [ 5C86ADEC17B739C437E145E3B3FC2E6D ] \Device\Harddisk0\DR0
13:14:38.0664 3324  \Device\Harddisk0\DR0 - ok
13:14:38.0664 3324  ================ Scan VBR ==================================
13:14:38.0695 3324  [ 4F671ACB12D2B23C2A215D3B242A1E8F ] \Device\Harddisk0\DR0\Partition1
13:14:38.0695 3324  \Device\Harddisk0\DR0\Partition1 - ok
13:14:38.0742 3324  [ 7B194D67144E38317068B1DBCA999781 ] \Device\Harddisk0\DR0\Partition2
13:14:38.0742 3324  \Device\Harddisk0\DR0\Partition2 - ok
13:14:38.0742 3324  ============================================================
13:14:38.0742 3324  Scan finished
13:14:38.0742 3324  ============================================================
13:14:38.0757 4868  Detected object count: 9
13:14:38.0757 4868  Actual detected object count: 9
13:21:38.0710 4868  Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  DokanMounter ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  DokanMounter ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  hpqwmiex ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  hpqwmiex ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
13:21:38.0710 4868  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:21:38.0710 4868  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - skipped by user
13:21:38.0710 4868  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - User select action: Skip


cosinus 08.10.2012 13:14

Code:

C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - skipped by user
Diesen Eintrag bitte mit dem TDSS-Killer fixen. Aber bitte nur diesen Eintrag!

Um das zu tun musst du den TDSS-Killer neu starten und einen neuen Scan machen. Wenn du danach die Ergebnisse siehst, stellst du bitte diesen Eintrag auf CURE bzw. DELETE (je nachdem was dir angeboten wird, alle anderen bitte auf SKIP lassen! ) und klickst dann unten rechts auf continue

Starte Windows danach neu und mach wieder ein komplett neues Log mit dem TDSS-Killer. Wie immer wieder in CODE-Tags posten.

schustan 08.10.2012 15:26

alles gemacht wie beschrieben ..

Code:

16:23:28.0290 2292  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
16:23:28.0306 2292  ============================================================
16:23:28.0306 2292  Current date / time: 2012/10/08 16:23:28.0306
16:23:28.0306 2292  SystemInfo:
16:23:28.0306 2292 
16:23:28.0306 2292  OS Version: 6.0.6002 ServicePack: 2.0
16:23:28.0306 2292  Product type: Workstation
16:23:28.0306 2292  ComputerName: ANDREAS-PC
16:23:28.0306 2292  UserName: Andreas
16:23:28.0306 2292  Windows directory: C:\Windows
16:23:28.0306 2292  System windows directory: C:\Windows
16:23:28.0306 2292  Running under WOW64
16:23:28.0306 2292  Processor architecture: Intel x64
16:23:28.0306 2292  Number of processors: 2
16:23:28.0306 2292  Page size: 0x1000
16:23:28.0306 2292  Boot type: Normal boot
16:23:28.0306 2292  ============================================================
16:23:29.0804 2292  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:23:29.0804 2292  ============================================================
16:23:29.0804 2292  \Device\Harddisk0\DR0:
16:23:29.0804 2292  MBR partitions:
16:23:29.0804 2292  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x38B7A000
16:23:29.0804 2292  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38B7A800, BlocksNum 0x180A000
16:23:29.0804 2292  ============================================================
16:23:29.0835 2292  C: <-> \Device\Harddisk0\DR0\Partition1
16:23:29.0944 2292  D: <-> \Device\Harddisk0\DR0\Partition2
16:23:29.0944 2292  ============================================================
16:23:29.0944 2292  Initialize success
16:23:29.0944 2292  ============================================================
16:23:35.0295 3268  ============================================================
16:23:35.0310 3268  Scan started
16:23:35.0310 3268  Mode: Manual; SigCheck; TDLFS;
16:23:35.0310 3268  ============================================================
16:23:36.0418 3268  ================ Scan system memory ========================
16:23:36.0418 3268  System memory - ok
16:23:36.0418 3268  ================ Scan services =============================
16:23:36.0746 3268  [ 7EEB488346FBFA3731276C3EE8A8FD9E ] AAV UpdateService C:\Program Files (x86)\AAVUpdateManager\aavus.exe
16:23:36.0902 3268  AAV UpdateService - ok
16:23:37.0214 3268  [ 5C368F4B04ED2A923E6AFCA2D37BAFF5 ] Accelerometer  C:\Windows\system32\DRIVERS\Accelerometer.sys
16:23:37.0260 3268  Accelerometer - ok
16:23:37.0338 3268  [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI            C:\Windows\system32\drivers\acpi.sys
16:23:37.0354 3268  ACPI - ok
16:23:37.0572 3268  [ F84C9DEE4698DF3C1D76801B7B1B55D7 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
16:23:37.0650 3268  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
16:23:37.0650 3268  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
16:23:37.0806 3268  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
16:23:37.0822 3268  AdobeARMservice - ok
16:23:37.0900 3268  [ F14215E37CF124104575073F782111D2 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
16:23:37.0931 3268  adp94xx - ok
16:23:37.0962 3268  [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci        C:\Windows\system32\drivers\adpahci.sys
16:23:38.0009 3268  adpahci - ok
16:23:38.0056 3268  [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
16:23:38.0087 3268  adpu160m - ok
16:23:38.0118 3268  [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
16:23:38.0150 3268  adpu320 - ok
16:23:38.0259 3268  [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
16:23:38.0321 3268  AeLookupSvc - ok
16:23:38.0618 3268  [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe
16:23:38.0649 3268  AESTFilters - ok
16:23:38.0742 3268  [ C4F6CE6087760AD70960C9EB130E7943 ] AFD            C:\Windows\system32\drivers\afd.sys
16:23:38.0852 3268  AFD - ok
16:23:38.0914 3268  [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440          C:\Windows\system32\drivers\agp440.sys
16:23:38.0945 3268  agp440 - ok
16:23:38.0992 3268  [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
16:23:39.0023 3268  aic78xx - ok
16:23:39.0054 3268  [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG            C:\Windows\System32\alg.exe
16:23:39.0210 3268  ALG - ok
16:23:39.0273 3268  [ E0CA5BB8E6C79533DC6B1DA7361A201E ] aliide          C:\Windows\system32\drivers\aliide.sys
16:23:39.0304 3268  aliide - ok
16:23:39.0304 3268  [ 7034F8D1B9703D711D3F92C95DEB377D ] amdide          C:\Windows\system32\drivers\amdide.sys
16:23:39.0335 3268  amdide - ok
16:23:39.0398 3268  [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
16:23:39.0476 3268  AmdK8 - ok
16:23:39.0819 3268  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
16:23:39.0850 3268  AntiVirSchedulerService - ok
16:23:39.0944 3268  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
16:23:39.0959 3268  AntiVirService - ok
16:23:40.0068 3268  [ 676894FA57B671FEC5C3F05F8929E03B ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
16:23:40.0115 3268  AntiVirWebService - ok
16:23:40.0178 3268  [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo        C:\Windows\System32\appinfo.dll
16:23:40.0240 3268  Appinfo - ok
16:23:40.0599 3268  [ 70D7BE78061126DD0C3ACCDB7E129017 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:23:40.0677 3268  Apple Mobile Device - ok
16:23:40.0724 3268  [ BA8417D4765F3988FF921F30F630E303 ] arc            C:\Windows\system32\drivers\arc.sys
16:23:40.0755 3268  arc - ok
16:23:40.0786 3268  [ 9D41C435619733B34CC16A511E644B11 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
16:23:40.0833 3268  arcsas - ok
16:23:41.0379 3268  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
16:23:41.0441 3268  aspnet_state - ok
16:23:41.0488 3268  [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
16:23:41.0597 3268  AsyncMac - ok
16:23:41.0628 3268  [ E68D9B3A3905619732F7FE039466A623 ] atapi          C:\Windows\system32\drivers\atapi.sys
16:23:41.0660 3268  atapi - ok
16:23:41.0753 3268  [ 54CA8AAC988B441A692311E3B584D944 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
16:23:41.0800 3268  Ati External Event Utility - ok
16:23:42.0018 3268  [ 4B42547AE95A31D0E1E200B68A6C7647 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
16:23:42.0206 3268  atikmdag - ok
16:23:42.0377 3268  [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
16:23:42.0424 3268  AudioEndpointBuilder - ok
16:23:42.0440 3268  [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
16:23:42.0471 3268  AudioSrv - ok
16:23:42.0564 3268  [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
16:23:42.0580 3268  avgntflt - ok
16:23:42.0658 3268  [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
16:23:42.0689 3268  avipbb - ok
16:23:42.0767 3268  [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
16:23:42.0783 3268  avkmgr - ok
16:23:42.0861 3268  [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
16:23:42.0908 3268  blbdrive - ok
16:23:43.0095 3268  [ 673CF4F6BB1FBE09331B526802FBB892 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
16:23:43.0110 3268  Bonjour Service - ok
16:23:43.0188 3268  [ 2348447A80920B2493A9B582A23E81E1 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
16:23:43.0235 3268  bowser - ok
16:23:43.0313 3268  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
16:23:43.0376 3268  BrFiltLo - ok
16:23:43.0407 3268  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
16:23:43.0500 3268  BrFiltUp - ok
16:23:43.0532 3268  [ A1B39DE453433B115B4EA69EE0343816 ] Browser        C:\Windows\System32\browser.dll
16:23:43.0625 3268  Browser - ok
16:23:43.0688 3268  [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid        C:\Windows\system32\drivers\brserid.sys
16:23:43.0875 3268  Brserid - ok
16:23:43.0922 3268  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
16:23:44.0031 3268  BrSerWdm - ok
16:23:44.0093 3268  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
16:23:44.0202 3268  BrUsbMdm - ok
16:23:44.0249 3268  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
16:23:44.0312 3268  BrUsbSer - ok
16:23:44.0358 3268  [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
16:23:44.0436 3268  BTHMODEM - ok
16:23:44.0452 3268  [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
16:23:44.0499 3268  cdfs - ok
16:23:44.0561 3268  [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
16:23:44.0592 3268  cdrom - ok
16:23:44.0655 3268  [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc    C:\Windows\System32\certprop.dll
16:23:44.0686 3268  CertPropSvc - ok
16:23:44.0748 3268  [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
16:23:44.0826 3268  circlass - ok
16:23:44.0889 3268  [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS            C:\Windows\system32\CLFS.sys
16:23:44.0920 3268  CLFS - ok
16:23:45.0014 3268  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:23:45.0029 3268  clr_optimization_v2.0.50727_32 - ok
16:23:45.0060 3268  [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
16:23:45.0076 3268  clr_optimization_v2.0.50727_64 - ok
16:23:45.0606 3268  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:23:45.0918 3268  clr_optimization_v4.0.30319_32 - ok
16:23:45.0950 3268  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
16:23:46.0028 3268  clr_optimization_v4.0.30319_64 - ok
16:23:46.0074 3268  [ B52D9A14CE4101577900A364BA86F3DF ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
16:23:46.0152 3268  CmBatt - ok
16:23:46.0168 3268  [ 8C6AA24C1D7273A02284588426AB8CE3 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
16:23:46.0184 3268  cmdide - ok
16:23:46.0277 3268  [ 12E94E225BD7B05A2BCCD5C0B841E921 ] Com4QLBEx      C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
16:23:46.0293 3268  Com4QLBEx - ok
16:23:46.0371 3268  [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
16:23:46.0386 3268  Compbatt - ok
16:23:46.0418 3268  COMSysApp - ok
16:23:46.0901 3268  cpuz134 - ok
16:23:46.0964 3268  [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
16:23:46.0995 3268  crcdisk - ok
16:23:47.0088 3268  [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
16:23:47.0166 3268  CryptSvc - ok
16:23:47.0260 3268  [ BA8E5B2291C01EF71CA80E25F0C79D55 ] ctxusbm        C:\Windows\system32\DRIVERS\ctxusbm.sys
16:23:47.0291 3268  ctxusbm - ok
16:23:47.0478 3268  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch      C:\Windows\system32\rpcss.dll
16:23:47.0572 3268  DcomLaunch - ok
16:23:47.0650 3268  [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
16:23:47.0728 3268  DfsC - ok
16:23:48.0508 3268  [ C647F468F7DE343DF8C143655C5557D4 ] DFSR            C:\Windows\system32\DFSR.exe
16:23:48.0758 3268  DFSR - ok
16:23:48.0820 3268  [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
16:23:48.0914 3268  Dhcp - ok
16:23:48.0976 3268  [ B0107E40ECDB5FA692EBF832F295D905 ] disk            C:\Windows\system32\drivers\disk.sys
16:23:49.0023 3268  disk - ok
16:23:49.0085 3268  [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
16:23:49.0132 3268  Dnscache - ok
16:23:49.0350 3268  [ 57AE249F2C6A90476E8E400F0EEC3C56 ] Dokan          C:\Windows\system32\drivers\dokan.sys
16:23:49.0397 3268  Dokan - ok
16:23:49.0491 3268  [ F4FEAE56DA1B5B7DC78D5F9214CDEF5E ] DokanMounter    C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
16:23:49.0506 3268  DokanMounter ( UnsignedFile.Multi.Generic ) - warning
16:23:49.0506 3268  DokanMounter - detected UnsignedFile.Multi.Generic (1)
16:23:49.0631 3268  [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc        C:\Windows\System32\dot3svc.dll
16:23:49.0694 3268  dot3svc - ok
16:23:49.0740 3268  [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS            C:\Windows\system32\dps.dll
16:23:49.0787 3268  DPS - ok
16:23:49.0865 3268  [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
16:23:49.0896 3268  drmkaud - ok
16:23:49.0959 3268  [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
16:23:49.0990 3268  DXGKrnl - ok
16:23:50.0099 3268  [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60          C:\Windows\system32\DRIVERS\E1G6032E.sys
16:23:50.0146 3268  E1G60 - ok
16:23:50.0224 3268  [ C2303883FD9BE49DC36A6400643002EA ] EapHost        C:\Windows\System32\eapsvc.dll
16:23:50.0255 3268  EapHost - ok
16:23:50.0349 3268  [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache          C:\Windows\system32\drivers\ecache.sys
16:23:50.0364 3268  Ecache - ok
16:23:50.0458 3268  [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
16:23:50.0489 3268  ehRecvr - ok
16:23:50.0536 3268  [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched        C:\Windows\ehome\ehsched.exe
16:23:50.0552 3268  ehSched - ok
16:23:50.0583 3268  [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart        C:\Windows\ehome\ehstart.dll
16:23:50.0598 3268  ehstart - ok
16:23:50.0708 3268  [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
16:23:50.0723 3268  elxstor - ok
16:23:50.0832 3268  [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
16:23:50.0910 3268  EMDMgmt - ok
16:23:50.0973 3268  [ F218A3A27ED6592C0E22EC3595554447 ] enecir          C:\Windows\system32\DRIVERS\enecir.sys
16:23:51.0020 3268  enecir - ok
16:23:51.0066 3268  [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev          C:\Windows\system32\drivers\errdev.sys
16:23:51.0144 3268  ErrDev - ok
16:23:51.0285 3268  [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem    C:\Windows\system32\es.dll
16:23:51.0316 3268  EventSystem - ok
16:23:51.0363 3268  [ 486844F47B6636044A42454614ED4523 ] exfat          C:\Windows\system32\drivers\exfat.sys
16:23:51.0425 3268  exfat - ok
16:23:51.0425 3268  ezSharedSvc - ok
16:23:51.0456 3268  [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
16:23:51.0488 3268  fastfat - ok
16:23:51.0519 3268  [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
16:23:51.0534 3268  fdc - ok
16:23:51.0581 3268  [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost        C:\Windows\system32\fdPHost.dll
16:23:51.0612 3268  fdPHost - ok
16:23:51.0612 3268  [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub        C:\Windows\system32\fdrespub.dll
16:23:51.0659 3268  FDResPub - ok
16:23:51.0675 3268  Fildro - ok
16:23:51.0722 3268  [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
16:23:51.0737 3268  FileInfo - ok
16:23:51.0737 3268  [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
16:23:51.0768 3268  Filetrace - ok
16:23:51.0784 3268  [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
16:23:51.0815 3268  flpydisk - ok
16:23:51.0878 3268  [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
16:23:51.0893 3268  FltMgr - ok
16:23:52.0002 3268  [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache      C:\Windows\system32\FntCache.dll
16:23:52.0080 3268  FontCache - ok
16:23:52.0205 3268  [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:23:52.0268 3268  FontCache3.0.0.0 - ok
16:23:52.0299 3268  [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
16:23:52.0346 3268  Fs_Rec - ok
16:23:52.0392 3268  [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
16:23:52.0408 3268  gagp30kx - ok
16:23:52.0502 3268  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
16:23:52.0517 3268  GEARAspiWDM - ok
16:23:52.0673 3268  [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc          C:\Windows\System32\gpsvc.dll
16:23:52.0704 3268  gpsvc - ok
16:23:52.0798 3268  [ 68E732382B32417FF61FD663259B4B09 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
16:23:52.0876 3268  HdAudAddService - ok
16:23:53.0063 3268  [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
16:23:53.0172 3268  HDAudBus - ok
16:23:53.0219 3268  [ B4881C84A180E75B8C25DC1D726C375F ] HidBth          C:\Windows\system32\drivers\hidbth.sys
16:23:53.0282 3268  HidBth - ok
16:23:53.0344 3268  [ 5F47839455D01FF6403B008D481A6F5B ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
16:23:53.0375 3268  HidIr - ok
16:23:53.0406 3268  [ 59361D38A297755D46A540E450202B2A ] hidserv        C:\Windows\system32\hidserv.dll
16:23:53.0438 3268  hidserv - ok
16:23:53.0516 3268  [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
16:23:53.0547 3268  HidUsb - ok
16:23:53.0562 3268  [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc          C:\Windows\system32\kmsvc.dll
16:23:53.0609 3268  hkmsvc - ok
16:23:53.0765 3268  [ A19B0BB5A7EB6DF2DD4A0711D36955EE ] HP Health Check Service c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
16:23:53.0765 3268  HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
16:23:53.0765 3268  HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
16:23:53.0874 3268  [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
16:23:53.0890 3268  HpCISSs - ok
16:23:53.0937 3268  [ 4E0BEC0F78096FFD6D3314B497FC49D3 ] hpdskflt        C:\Windows\system32\DRIVERS\hpdskflt.sys
16:23:53.0968 3268  hpdskflt - ok
16:23:54.0093 3268  [ 0ECC54FD34D6A089C300846B011E81D6 ] HpqKbFiltr      C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
16:23:54.0155 3268  HpqKbFiltr - ok
16:23:54.0249 3268  [ 188FF0ADF66768D53AD94F43972E1E9A ] hpqwmiex        C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
16:23:54.0264 3268  hpqwmiex ( UnsignedFile.Multi.Generic ) - warning
16:23:54.0264 3268  hpqwmiex - detected UnsignedFile.Multi.Generic (1)
16:23:54.0358 3268  [ FC7C13B5A9E9BE23B7AE72BBC7FDB278 ] hpsrv          C:\Windows\system32\Hpservice.exe
16:23:54.0389 3268  hpsrv - ok
16:23:54.0498 3268  [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
16:23:54.0608 3268  HTTP - ok
16:23:54.0639 3268  [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
16:23:54.0670 3268  i2omp - ok
16:23:54.0732 3268  [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
16:23:54.0779 3268  i8042prt - ok
16:23:54.0810 3268  [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
16:23:54.0826 3268  iaStorV - ok
16:23:55.0169 3268  [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
16:23:55.0388 3268  idsvc - ok
16:23:55.0512 3268  [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
16:23:55.0528 3268  iirsp - ok
16:23:55.0606 3268  [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT          C:\Windows\System32\ikeext.dll
16:23:55.0653 3268  IKEEXT - ok
16:23:55.0700 3268  [ 475490CAF376E55E6E8B37BBDFEB2E81 ] intelide        C:\Windows\system32\drivers\intelide.sys
16:23:55.0715 3268  intelide - ok
16:23:55.0762 3268  [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
16:23:55.0809 3268  intelppm - ok
16:23:55.0824 3268  [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
16:23:55.0871 3268  IPBusEnum - ok
16:23:55.0934 3268  [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:23:55.0965 3268  IpFilterDriver - ok
16:23:55.0965 3268  IpInIp - ok
16:23:55.0996 3268  [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
16:23:56.0043 3268  IPMIDRV - ok
16:23:56.0090 3268  [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
16:23:56.0136 3268  IPNAT - ok
16:23:56.0277 3268  [ 24595EC9236D7E421661A2D4FFBD901A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
16:23:56.0308 3268  iPod Service - ok
16:23:56.0339 3268  [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
16:23:56.0417 3268  IRENUM - ok
16:23:56.0464 3268  [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
16:23:56.0480 3268  isapnp - ok
16:23:56.0542 3268  [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
16:23:56.0558 3268  iScsiPrt - ok
16:23:56.0589 3268  [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
16:23:56.0604 3268  iteatapi - ok
16:23:56.0667 3268  [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid        C:\Windows\system32\drivers\iteraid.sys
16:23:56.0682 3268  iteraid - ok
16:23:56.0714 3268  [ BB86B1C3489463BBA1FD04C876DBE414 ] JMCR            C:\Windows\system32\DRIVERS\jmcr.sys
16:23:56.0760 3268  JMCR - ok
16:23:56.0792 3268  [ 423696F3BA6472DD17699209B933BC26 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
16:23:56.0792 3268  kbdclass - ok
16:23:56.0854 3268  [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
16:23:56.0870 3268  kbdhid - ok
16:23:56.0916 3268  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso          C:\Windows\system32\lsass.exe
16:23:56.0948 3268  KeyIso - ok
16:23:57.0010 3268  [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
16:23:57.0041 3268  KSecDD - ok
16:23:57.0088 3268  [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
16:23:57.0119 3268  ksthunk - ok
16:23:57.0166 3268  [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm          C:\Windows\system32\msdtckrm.dll
16:23:57.0228 3268  KtmRm - ok
16:23:57.0306 3268  [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer    C:\Windows\system32\srvsvc.dll
16:23:57.0353 3268  LanmanServer - ok
16:23:57.0384 3268  [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
16:23:57.0416 3268  LanmanWorkstation - ok
16:23:57.0540 3268  [ 83D8BE94E1CBCBE2EA8372DB1A95A159 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
16:23:57.0540 3268  LightScribeService ( UnsignedFile.Multi.Generic ) - warning
16:23:57.0540 3268  LightScribeService - detected UnsignedFile.Multi.Generic (1)
16:23:57.0603 3268  [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
16:23:57.0681 3268  lltdio - ok
16:23:57.0806 3268  [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
16:23:57.0852 3268  lltdsvc - ok
16:23:57.0868 3268  [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts        C:\Windows\System32\lmhsvc.dll
16:23:57.0915 3268  lmhosts - ok
16:23:57.0946 3268  [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
16:23:57.0977 3268  LSI_FC - ok
16:23:57.0977 3268  [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
16:23:58.0008 3268  LSI_SAS - ok
16:23:58.0008 3268  [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
16:23:58.0040 3268  LSI_SCSI - ok
16:23:58.0086 3268  [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv          C:\Windows\system32\drivers\luafv.sys
16:23:58.0133 3268  luafv - ok
16:23:58.0289 3268  [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
16:23:58.0320 3268  McComponentHostService - ok
16:23:58.0352 3268  [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
16:23:58.0367 3268  Mcx2Svc - ok
16:23:58.0414 3268  [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas        C:\Windows\system32\drivers\megasas.sys
16:23:58.0430 3268  megasas - ok
16:23:58.0461 3268  [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
16:23:58.0476 3268  MegaSR - ok
16:23:58.0554 3268  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS          C:\Windows\system32\mmcss.dll
16:23:58.0601 3268  MMCSS - ok
16:23:58.0664 3268  [ 59848D5CC74606F0EE7557983BB73C2E ] Modem          C:\Windows\system32\drivers\modem.sys
16:23:58.0710 3268  Modem - ok
16:23:58.0726 3268  [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
16:23:58.0773 3268  monitor - ok
16:23:58.0804 3268  [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
16:23:58.0820 3268  mouclass - ok
16:23:58.0851 3268  [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
16:23:58.0898 3268  mouhid - ok
16:23:58.0929 3268  [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
16:23:58.0944 3268  MountMgr - ok
16:23:59.0038 3268  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
16:23:59.0054 3268  MozillaMaintenance - ok
16:23:59.0069 3268  [ F8276EB8698142884498A528DFEA8478 ] mpio            C:\Windows\system32\drivers\mpio.sys
16:23:59.0085 3268  mpio - ok
16:23:59.0147 3268  [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
16:23:59.0178 3268  mpsdrv - ok
16:23:59.0210 3268  [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
16:23:59.0225 3268  Mraid35x - ok
16:23:59.0272 3268  [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
16:23:59.0288 3268  MRxDAV - ok
16:23:59.0350 3268  [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
16:23:59.0381 3268  mrxsmb - ok
16:23:59.0444 3268  [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:23:59.0459 3268  mrxsmb10 - ok
16:23:59.0490 3268  [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:23:59.0506 3268  mrxsmb20 - ok
16:23:59.0568 3268  [ AA459F2AB3AB603C357FF117CAE3D818 ] msahci          C:\Windows\system32\drivers\msahci.sys
16:23:59.0584 3268  msahci - ok
16:23:59.0631 3268  [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
16:23:59.0646 3268  msdsm - ok
16:23:59.0678 3268  [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC          C:\Windows\System32\msdtc.exe
16:23:59.0724 3268  MSDTC - ok
16:23:59.0787 3268  [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs            C:\Windows\system32\drivers\Msfs.sys
16:23:59.0834 3268  Msfs - ok
16:23:59.0880 3268  [ 00EBC952961664780D43DCA157E79B27 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
16:23:59.0896 3268  msisadrv - ok
16:23:59.0927 3268  [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
16:23:59.0974 3268  MSiSCSI - ok
16:23:59.0990 3268  msiserver - ok
16:24:00.0036 3268  [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
16:24:00.0083 3268  MSKSSRV - ok
16:24:00.0083 3268  [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
16:24:00.0130 3268  MSPCLOCK - ok
16:24:00.0177 3268  [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
16:24:00.0224 3268  MSPQM - ok
16:24:00.0286 3268  [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
16:24:00.0302 3268  MsRPC - ok
16:24:00.0333 3268  [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
16:24:00.0348 3268  mssmbios - ok
16:24:00.0411 3268  [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
16:24:00.0442 3268  MSTEE - ok
16:24:00.0520 3268  [ 0CC49F78D8ACA0877D885F149084E543 ] Mup            C:\Windows\system32\Drivers\mup.sys
16:24:00.0551 3268  Mup - ok
16:24:00.0598 3268  [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent        C:\Windows\system32\qagentRT.dll
16:24:00.0629 3268  napagent - ok
16:24:00.0692 3268  [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
16:24:00.0723 3268  NativeWifiP - ok
16:24:00.0863 3268  NAVENG - ok
16:24:00.0879 3268  NAVEX15 - ok
16:24:01.0004 3268  [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS            C:\Windows\system32\drivers\ndis.sys
16:24:01.0066 3268  NDIS - ok
16:24:01.0128 3268  [ 64DF698A425478E321981431AC171334 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
16:24:01.0191 3268  NdisTapi - ok
16:24:01.0253 3268  [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
16:24:01.0331 3268  Ndisuio - ok
16:24:01.0378 3268  [ F8158771905260982CE724076419EF19 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
16:24:01.0409 3268  NdisWan - ok
16:24:01.0440 3268  [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
16:24:01.0472 3268  NDProxy - ok
16:24:01.0550 3268  [ 89FD76A90CBE63F03A70C2D1B85E802C ] NEOFLTR_710_19243 C:\Windows\system32\Drivers\NEOFLTR_710_19243.SYS
16:24:01.0565 3268  NEOFLTR_710_19243 - ok
16:24:01.0612 3268  Nero BackItUp Scheduler 4.0 - ok
16:24:01.0643 3268  [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
16:24:01.0674 3268  NetBIOS - ok
16:24:01.0737 3268  [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
16:24:01.0768 3268  netbt - ok
16:24:01.0830 3268  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon        C:\Windows\system32\lsass.exe
16:24:01.0846 3268  Netlogon - ok
16:24:01.0924 3268  [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman          C:\Windows\System32\netman.dll
16:24:01.0971 3268  Netman - ok
16:24:02.0033 3268  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:24:02.0080 3268  NetMsmqActivator - ok
16:24:02.0080 3268  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:24:02.0096 3268  NetPipeActivator - ok
16:24:02.0158 3268  [ 7846D0136CC2B264926A73047BA7688A ] netprofm        C:\Windows\System32\netprofm.dll
16:24:02.0205 3268  netprofm - ok
16:24:02.0236 3268  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:24:02.0252 3268  NetTcpActivator - ok
16:24:02.0252 3268  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
16:24:02.0267 3268  NetTcpPortSharing - ok
16:24:02.0564 3268  [ C86984AEE87900C1EEB6942EDE3BF4B6 ] NETw3v64        C:\Windows\system32\DRIVERS\NETw3v64.sys
16:24:02.0735 3268  NETw3v64 - ok
16:24:03.0484 3268  [ 2BDCB7B7917380794C9D87AC2153CE33 ] NETw5v64        C:\Windows\system32\DRIVERS\NETw5v64.sys
16:24:03.0796 3268  NETw5v64 - ok
16:24:03.0827 3268  [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
16:24:03.0858 3268  nfrd960 - ok
16:24:03.0905 3268  [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc          C:\Windows\System32\nlasvc.dll
16:24:03.0999 3268  NlaSvc - ok
16:24:04.0077 3268  [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64      C:\Windows\system32\drivers\ccdcmbox64.sys
16:24:04.0155 3268  nmwcdcx64 - ok
16:24:04.0202 3268  [ 76292103C5149EB140419F36DCF26C1B ] nmwcdnsucx64    C:\Windows\system32\drivers\nmwcdnsucx64.sys
16:24:04.0264 3268  nmwcdnsucx64 - ok
16:24:04.0326 3268  [ 2974296DA6296B4FEA3E313BF98C693D ] nmwcdnsux64    C:\Windows\system32\drivers\nmwcdnsux64.sys
16:24:04.0389 3268  nmwcdnsux64 - ok
16:24:04.0436 3268  [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64        C:\Windows\system32\drivers\ccdcmbx64.sys
16:24:04.0498 3268  nmwcdx64 - ok
16:24:04.0498 3268  Norton Internet Security - ok
16:24:04.0545 3268  [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
16:24:04.0607 3268  Npfs - ok
16:24:04.0638 3268  [ ACB62BAA1C319B17752553DF3026EEEB ] nsi            C:\Windows\system32\nsisvc.dll
16:24:04.0685 3268  nsi - ok
16:24:04.0748 3268  [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
16:24:04.0779 3268  nsiproxy - ok
16:24:04.0950 3268  [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
16:24:05.0013 3268  Ntfs - ok
16:24:05.0075 3268  [ DD5D684975352B85B52E3FD5347C20CB ] Null            C:\Windows\system32\drivers\Null.sys
16:24:05.0122 3268  Null - ok
16:24:05.0169 3268  [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
16:24:05.0184 3268  nvraid - ok
16:24:05.0231 3268  [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor          C:\Windows\system32\drivers\nvstor.sys
16:24:05.0247 3268  nvstor - ok
16:24:05.0262 3268  [ 19067CA93075EF4823E3938A686F532F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
16:24:05.0278 3268  nv_agp - ok
16:24:05.0294 3268  NwlnkFlt - ok
16:24:05.0294 3268  NwlnkFwd - ok
16:24:05.0372 3268  [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
16:24:05.0403 3268  ohci1394 - ok
16:24:05.0481 3268  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:24:05.0496 3268  ose - ok
16:24:05.0637 3268  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc        C:\Windows\system32\p2psvc.dll
16:24:05.0699 3268  p2pimsvc - ok
16:24:05.0715 3268  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc          C:\Windows\system32\p2psvc.dll
16:24:05.0746 3268  p2psvc - ok
16:24:05.0855 3268  [ AECD57F94C887F58919F307C35498EA0 ] Parport        C:\Windows\system32\drivers\parport.sys
16:24:05.0918 3268  Parport - ok
16:24:05.0996 3268  [ B43751085E2ABE389DA466BC62A4B987 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
16:24:06.0011 3268  partmgr - ok
16:24:06.0058 3268  [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc          C:\Windows\System32\pcasvc.dll
16:24:06.0074 3268  PcaSvc - ok
16:24:06.0152 3268  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
16:24:06.0214 3268  pccsmcfd - ok
16:24:06.0276 3268  [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci            C:\Windows\system32\drivers\pci.sys
16:24:06.0292 3268  pci - ok
16:24:06.0323 3268  [ 15E5C3F89A3452EFBDA3B39816DBC4EE ] pciide          C:\Windows\system32\drivers\pciide.sys
16:24:06.0339 3268  pciide - ok
16:24:06.0354 3268  [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
16:24:06.0386 3268  pcmcia - ok
16:24:06.0401 3268  [ 58865916F53592A61549B04941BFD80D ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
16:24:06.0479 3268  PEAUTH - ok
16:24:06.0635 3268  [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
16:24:06.0666 3268  PerfHost - ok
16:24:06.0822 3268  [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla            C:\Windows\system32\pla.dll
16:24:06.0932 3268  pla - ok
16:24:07.0025 3268  [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
16:24:07.0072 3268  PlugPlay - ok
16:24:07.0119 3268  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
16:24:07.0150 3268  PNRPAutoReg - ok
16:24:07.0166 3268  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc        C:\Windows\system32\p2psvc.dll
16:24:07.0197 3268  PNRPsvc - ok
16:24:07.0259 3268  [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
16:24:07.0306 3268  PolicyAgent - ok
16:24:07.0400 3268  [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
16:24:07.0431 3268  PptpMiniport - ok
16:24:07.0462 3268  [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor      C:\Windows\system32\drivers\processr.sys
16:24:07.0509 3268  Processor - ok
16:24:07.0571 3268  [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc        C:\Windows\system32\profsvc.dll
16:24:07.0602 3268  ProfSvc - ok
16:24:07.0649 3268  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
16:24:07.0665 3268  ProtectedStorage - ok
16:24:07.0743 3268  [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
16:24:07.0774 3268  PSched - ok
16:24:07.0961 3268  [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300          C:\Windows\system32\drivers\ql2300.sys
16:24:08.0055 3268  ql2300 - ok
16:24:08.0086 3268  [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
16:24:08.0102 3268  ql40xx - ok
16:24:08.0133 3268  [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE          C:\Windows\system32\qwave.dll
16:24:08.0148 3268  QWAVE - ok
16:24:08.0164 3268  [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
16:24:08.0195 3268  QWAVEdrv - ok
16:24:08.0242 3268  [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
16:24:08.0273 3268  RasAcd - ok
16:24:08.0304 3268  [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto        C:\Windows\System32\rasauto.dll
16:24:08.0351 3268  RasAuto - ok
16:24:08.0398 3268  [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
16:24:08.0429 3268  Rasl2tp - ok
16:24:08.0476 3268  [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan          C:\Windows\System32\rasmans.dll
16:24:08.0507 3268  RasMan - ok
16:24:08.0523 3268  [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
16:24:08.0554 3268  RasPppoe - ok
16:24:08.0648 3268  [ C6A593B51F34C33E5474539544072527 ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
16:24:08.0663 3268  RasSstp - ok
16:24:08.0694 3268  [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
16:24:08.0741 3268  rdbss - ok
16:24:08.0788 3268  [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
16:24:08.0835 3268  RDPCDD - ok
16:24:08.0882 3268  [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
16:24:08.0928 3268  rdpdr - ok
16:24:08.0975 3268  [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
16:24:09.0006 3268  RDPENCDD - ok
16:24:09.0069 3268  [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
16:24:09.0131 3268  RDPWD - ok
16:24:09.0194 3268  [ BC0A4D47472B042537F4E57B950415FA ] Recovery Service for Windows C:\Program Files (x86)\SMINST\BLService.exe
16:24:09.0225 3268  Recovery Service for Windows - ok
16:24:09.0287 3268  [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess    C:\Windows\System32\mprdim.dll
16:24:09.0334 3268  RemoteAccess - ok
16:24:09.0381 3268  [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
16:24:09.0412 3268  RemoteRegistry - ok
16:24:09.0537 3268  [ 805AE1F90C64758D19AAA001CF8CBA12 ] RichVideo      C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
16:24:09.0537 3268  RichVideo ( UnsignedFile.Multi.Generic ) - warning
16:24:09.0537 3268  RichVideo - detected UnsignedFile.Multi.Generic (1)
16:24:09.0615 3268  [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator      C:\Windows\system32\locator.exe
16:24:09.0662 3268  RpcLocator - ok
16:24:09.0708 3268  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs          C:\Windows\system32\rpcss.dll
16:24:09.0755 3268  RpcSs - ok
16:24:09.0818 3268  [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
16:24:09.0864 3268  rspndr - ok
16:24:09.0927 3268  [ 8B91737DA75ADD21CB1554B38089196A ] RTL8169        C:\Windows\system32\DRIVERS\Rtlh64.sys
16:24:09.0974 3268  RTL8169 - ok
16:24:09.0989 3268  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs          C:\Windows\system32\lsass.exe
16:24:10.0005 3268  SamSs - ok
16:24:10.0052 3268  [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
16:24:10.0067 3268  sbp2port - ok
16:24:10.0098 3268  [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr        C:\Windows\System32\SCardSvr.dll
16:24:10.0145 3268  SCardSvr - ok
16:24:10.0301 3268  [ 0F838C811AD295D2A4489B9993096C63 ] Schedule        C:\Windows\system32\schedsvc.dll
16:24:10.0364 3268  Schedule - ok
16:24:10.0457 3268  [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc    C:\Windows\System32\certprop.dll
16:24:10.0520 3268  SCPolicySvc - ok
16:24:10.0613 3268  [ B42EE50F7D24F837F925332EB349ECA5 ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
16:24:10.0691 3268  sdbus - ok
16:24:10.0769 3268  [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
16:24:10.0816 3268  SDRSVC - ok
16:24:11.0128 3268  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
16:24:11.0128 3268  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
16:24:11.0128 3268  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
16:24:11.0159 3268  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
16:24:11.0268 3268  secdrv - ok
16:24:11.0331 3268  [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon        C:\Windows\system32\seclogon.dll
16:24:11.0362 3268  seclogon - ok
16:24:11.0393 3268  [ 90973A64B96CD647FF81C79443618EED ] SENS            C:\Windows\System32\sens.dll
16:24:11.0424 3268  SENS - ok
16:24:11.0456 3268  [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum        C:\Windows\system32\drivers\serenum.sys
16:24:11.0487 3268  Serenum - ok
16:24:11.0518 3268  [ E62FAC91EE288DB29A9696A9D279929C ] Serial          C:\Windows\system32\drivers\serial.sys
16:24:11.0549 3268  Serial - ok
16:24:11.0580 3268  [ A842F04833684BCEEA7336211BE478DF ] sermouse        C:\Windows\system32\drivers\sermouse.sys
16:24:11.0612 3268  sermouse - ok
16:24:11.0690 3268  [ 58D5BFDF3ADF49FE9CABD78CC61D92F6 ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
16:24:11.0752 3268  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
16:24:11.0752 3268  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
16:24:11.0892 3268  [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv      C:\Windows\system32\sessenv.dll
16:24:11.0924 3268  SessionEnv - ok
16:24:11.0970 3268  [ 14D4B4465193A87C127933978E8C4106 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
16:24:12.0002 3268  sffdisk - ok
16:24:12.0033 3268  [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
16:24:12.0064 3268  sffp_mmc - ok
16:24:12.0095 3268  [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
16:24:12.0142 3268  sffp_sd - ok
16:24:12.0142 3268  [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
16:24:12.0220 3268  sfloppy - ok
16:24:12.0360 3268  [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
16:24:12.0407 3268  ShellHWDetection - ok
16:24:12.0470 3268  [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
16:24:12.0485 3268  SiSRaid2 - ok
16:24:12.0501 3268  [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
16:24:12.0516 3268  SiSRaid4 - ok
16:24:12.0594 3268  [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
16:24:12.0610 3268  SkypeUpdate - ok
16:24:12.0969 3268  [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc          C:\Windows\system32\SLsvc.exe
16:24:13.0172 3268  slsvc - ok
16:24:13.0281 3268  [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify      C:\Windows\system32\SLUINotify.dll
16:24:13.0343 3268  SLUINotify - ok
16:24:13.0359 3268  [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
16:24:13.0390 3268  Smb - ok
16:24:13.0437 3268  [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
16:24:13.0452 3268  SNMPTRAP - ok
16:24:13.0484 3268  [ 386C3C63F00A7040C7EC5E384217E89D ] spldr          C:\Windows\system32\drivers\spldr.sys
16:24:13.0499 3268  spldr - ok
16:24:13.0593 3268  [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler        C:\Windows\System32\spoolsv.exe
16:24:13.0624 3268  Spooler - ok
16:24:13.0624 3268  SRTSP - ok
16:24:13.0624 3268  SRTSPX - ok
16:24:13.0733 3268  [ 880A57FCCB571EBD063D4DD50E93E46D ] srv            C:\Windows\system32\DRIVERS\srv.sys
16:24:13.0780 3268  srv - ok
16:24:13.0889 3268  [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
16:24:13.0936 3268  srv2 - ok
16:24:13.0998 3268  [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
16:24:14.0014 3268  srvnet - ok
16:24:14.0061 3268  [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
16:24:14.0092 3268  SSDPSRV - ok
16:24:14.0170 3268  [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc        C:\Windows\system32\sstpsvc.dll
16:24:14.0186 3268  SstpSvc - ok
16:24:14.0435 3268  [ 72EB6157E892A674E47E08732BB5CCE3 ] STacSV          C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe
16:24:14.0451 3268  STacSV - ok
16:24:14.0529 3268  [ 0C7BDA7E9A329A071C080EB5210FE019 ] STHDA          C:\Windows\system32\DRIVERS\stwrt64.sys
16:24:14.0560 3268  STHDA - ok
16:24:14.0716 3268  [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc          C:\Windows\System32\wiaservc.dll
16:24:14.0747 3268  stisvc - ok
16:24:14.0778 3268  [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
16:24:14.0794 3268  swenum - ok
16:24:14.0903 3268  [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv          C:\Windows\System32\swprv.dll
16:24:14.0950 3268  swprv - ok
16:24:15.0028 3268  [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
16:24:15.0044 3268  Symc8xx - ok
16:24:15.0075 3268  [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
16:24:15.0090 3268  Sym_hi - ok
16:24:15.0106 3268  [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
16:24:15.0122 3268  Sym_u3 - ok
16:24:15.0215 3268  [ 3A706A967295E16511E40842B1A2761D ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
16:24:15.0231 3268  SynTP - ok
16:24:15.0543 3268  [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain        C:\Windows\system32\sysmain.dll
16:24:15.0636 3268  SysMain - ok
16:24:15.0683 3268  [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
16:24:15.0730 3268  TabletInputService - ok
16:24:15.0777 3268  [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv        C:\Windows\System32\tapisrv.dll
16:24:15.0824 3268  TapiSrv - ok
16:24:15.0839 3268  [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS            C:\Windows\System32\tbssvc.dll
16:24:15.0886 3268  TBS - ok
16:24:16.0338 3268  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
16:24:16.0463 3268  Tcpip - ok
16:24:16.0541 3268  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
16:24:16.0588 3268  Tcpip6 - ok
16:24:16.0635 3268  [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
16:24:16.0666 3268  tcpipreg - ok
16:24:16.0713 3268  [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
16:24:16.0744 3268  TDPIPE - ok
16:24:16.0744 3268  [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
16:24:16.0775 3268  TDTCP - ok
16:24:16.0806 3268  [ 458919C8C42E398DC4802178D5FFEE27 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
16:24:16.0838 3268  tdx - ok
16:24:16.0884 3268  [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
16:24:16.0900 3268  TermDD - ok
16:24:17.0040 3268  [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService    C:\Windows\System32\termsrv.dll
16:24:17.0072 3268  TermService - ok
16:24:17.0118 3268  [ 56793271ECDEDD350C5ADD305603E963 ] Themes          C:\Windows\system32\shsvcs.dll
16:24:17.0134 3268  Themes - ok
16:24:17.0196 3268  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER    C:\Windows\system32\mmcss.dll
16:24:17.0228 3268  THREADORDER - ok
16:24:17.0337 3268  [ 0407143F2BBC1A5DD5B518AC0704FCBF ] TomTomHOMEService C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
16:24:17.0337 3268  TomTomHOMEService - ok
16:24:17.0384 3268  [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks          C:\Windows\System32\trkwks.dll
16:24:17.0430 3268  TrkWks - ok
16:24:17.0508 3268  [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
16:24:17.0540 3268  TrustedInstaller - ok
16:24:17.0571 3268  [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
16:24:17.0618 3268  tssecsrv - ok
16:24:17.0664 3268  [ 89EC74A9E602D16A75A4170511029B3C ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
16:24:17.0727 3268  tunmp - ok
16:24:17.0789 3268  [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
16:24:17.0805 3268  tunnel - ok
16:24:18.0086 3268  [ 1C31169DDDC70C1605F703DA701EAEEA ] TVCapSvc        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
16:24:18.0117 3268  TVCapSvc - ok
16:24:18.0164 3268  [ 290B8C381DBC15D3DBCBD2BDB6B0BA12 ] TVSched        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
16:24:18.0195 3268  TVSched - ok
16:24:18.0242 3268  [ FEC266EF401966311744BD0F359F7F56 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
16:24:18.0273 3268  uagp35 - ok
16:24:18.0351 3268  [ FAF2640A2A76ED03D449E443194C4C34 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
16:24:18.0429 3268  udfs - ok
16:24:18.0538 3268  [ 060507C4113391394478F6953A79EEDC ] UI0Detect      C:\Windows\system32\UI0Detect.exe
16:24:18.0616 3268  UI0Detect - ok
16:24:18.0663 3268  [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
16:24:18.0694 3268  uliagpkx - ok
16:24:18.0725 3268  [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci        C:\Windows\system32\drivers\uliahci.sys
16:24:18.0756 3268  uliahci - ok
16:24:18.0788 3268  [ 31707F09846056651EA2C37858F5DDB0 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
16:24:18.0803 3268  UlSata - ok
16:24:18.0850 3268  [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
16:24:18.0866 3268  ulsata2 - ok
16:24:18.0881 3268  [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
16:24:18.0912 3268  umbus - ok
16:24:18.0975 3268  [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost        C:\Windows\System32\upnphost.dll
16:24:19.0006 3268  upnphost - ok
16:24:19.0053 3268  [ 9856C38AB8FAACCA4DD99DAC7B42F838 ] upperdev        C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
16:24:19.0084 3268  upperdev - ok
16:24:19.0162 3268  [ CD03479F2DA26500B203ED075C146A7A ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
16:24:19.0193 3268  USBAAPL64 - ok
16:24:19.0256 3268  [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
16:24:19.0287 3268  usbaudio - ok
16:24:19.0318 3268  [ 07E3498FC60834219D2356293DA0FECC ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
16:24:19.0349 3268  usbccgp - ok
16:24:19.0380 3268  [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
16:24:19.0427 3268  usbcir - ok
16:24:19.0458 3268  [ 827E44DE934A736EA31E91D353EB126F ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
16:24:19.0490 3268  usbehci - ok
16:24:19.0552 3268  [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
16:24:19.0583 3268  usbhub - ok
16:24:19.0614 3268  [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
16:24:19.0677 3268  usbohci - ok
16:24:19.0692 3268  [ ACFEE697AF477021BB3EC78C5431FED2 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
16:24:19.0755 3268  usbprint - ok
16:24:19.0817 3268  [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
16:24:19.0848 3268  usbscan - ok
16:24:19.0880 3268  [ F7386007FB19E7685FC7B298560AA81F ] usbser          C:\Windows\system32\drivers\usbser.sys
16:24:19.0911 3268  usbser - ok
16:24:19.0942 3268  [ 89123DC822AC7A708BD4C9E196A37610 ] UsbserFilt      C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys
16:24:19.0973 3268  UsbserFilt - ok
16:24:20.0020 3268  [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:24:20.0051 3268  USBSTOR - ok
16:24:20.0098 3268  [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
16:24:20.0129 3268  usbuhci - ok
16:24:20.0176 3268  [ FC33099877790D51B0927B7039059855 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
16:24:20.0223 3268  usbvideo - ok
16:24:20.0254 3268  [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms          C:\Windows\System32\uxsms.dll
16:24:20.0285 3268  UxSms - ok
16:24:20.0410 3268  [ 294945381DFA7CE58CECF0A9896AF327 ] vds            C:\Windows\System32\vds.exe
16:24:20.0457 3268  vds - ok
16:24:20.0535 3268  [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
16:24:20.0582 3268  vga - ok
16:24:20.0613 3268  [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave        C:\Windows\System32\drivers\vga.sys
16:24:20.0644 3268  VgaSave - ok
16:24:20.0722 3268  [ 4F964E6828156F0EF3FA8D3A9A7895DE ] viaide          C:\Windows\system32\drivers\viaide.sys
16:24:20.0738 3268  viaide - ok
16:24:20.0784 3268  [ 2B7E885ED951519A12C450D24535DFCA ] volmgr          C:\Windows\system32\drivers\volmgr.sys
16:24:20.0816 3268  volmgr - ok
16:24:20.0878 3268  [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
16:24:20.0909 3268  volmgrx - ok
16:24:21.0018 3268  [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap        C:\Windows\system32\drivers\volsnap.sys
16:24:21.0050 3268  volsnap - ok
16:24:21.0096 3268  [ A68F455ED2673835209318DD61BFBB0E ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
16:24:21.0112 3268  vsmraid - ok
16:24:21.0284 3268  [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS            C:\Windows\system32\vssvc.exe
16:24:21.0393 3268  VSS - ok
16:24:21.0471 3268  [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time        C:\Windows\system32\w32time.dll
16:24:21.0502 3268  W32Time - ok
16:24:21.0533 3268  [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
16:24:21.0642 3268  WacomPen - ok
16:24:21.0720 3268  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
16:24:21.0752 3268  Wanarp - ok
16:24:21.0752 3268  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
16:24:21.0798 3268  Wanarpv6 - ok
16:24:21.0954 3268  [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
16:24:21.0986 3268  wcncsvc - ok
16:24:22.0048 3268  [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
16:24:22.0079 3268  WcsPlugInService - ok
16:24:22.0110 3268  [ 0C17A0816F65B89E362E682AD5E7266E ] Wd              C:\Windows\system32\drivers\wd.sys
16:24:22.0126 3268  Wd - ok
16:24:22.0235 3268  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
16:24:22.0329 3268  Wdf01000 - ok
16:24:22.0344 3268  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost  C:\Windows\system32\wdi.dll
16:24:22.0391 3268  WdiServiceHost - ok
16:24:22.0391 3268  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost  C:\Windows\system32\wdi.dll
16:24:22.0438 3268  WdiSystemHost - ok
16:24:22.0563 3268  [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient      C:\Windows\System32\webclnt.dll
16:24:22.0594 3268  WebClient - ok
16:24:22.0641 3268  [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc          C:\Windows\system32\wecsvc.dll
16:24:22.0703 3268  Wecsvc - ok
16:24:22.0734 3268  [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
16:24:22.0766 3268  wercplsupport - ok
16:24:22.0812 3268  [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc          C:\Windows\System32\WerSvc.dll
16:24:22.0844 3268  WerSvc - ok
16:24:22.0844 3268  WinHttpAutoProxySvc - ok
16:24:23.0015 3268  [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
16:24:23.0046 3268  Winmgmt - ok
16:24:23.0327 3268  [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM          C:\Windows\system32\WsmSvc.dll
16:24:23.0483 3268  WinRM - ok
16:24:23.0530 3268  [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc        C:\Windows\System32\wlansvc.dll
16:24:23.0592 3268  Wlansvc - ok
16:24:24.0154 3268  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
16:24:24.0341 3268  wlidsvc - ok
16:24:24.0450 3268  [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
16:24:24.0466 3268  WmiAcpi - ok
16:24:24.0513 3268  [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
16:24:24.0544 3268  wmiApSrv - ok
16:24:24.0591 3268  WMPNetworkSvc - ok
16:24:24.0638 3268  [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
16:24:24.0700 3268  WPCSvc - ok
16:24:24.0762 3268  [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
16:24:24.0794 3268  WPDBusEnum - ok
16:24:24.0825 3268  [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
16:24:24.0840 3268  WpdUsb - ok
16:24:25.0605 3268  [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
16:24:25.0683 3268  WPFFontCache_v0400 - ok
16:24:25.0745 3268  [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
16:24:25.0839 3268  ws2ifsl - ok
16:24:25.0901 3268  WSearch - ok
16:24:25.0948 3268  [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
16:24:26.0057 3268  WUDFRd - ok
16:24:26.0088 3268  [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
16:24:26.0135 3268  wudfsvc - ok
16:24:26.0198 3268  [ 07F7285220307AAFB755D890295F0F9A ] yukonx64        C:\Windows\system32\DRIVERS\yk60x64.sys
16:24:26.0244 3268  yukonx64 - ok
16:24:26.0354 3268  [ 1CACFEF9E5DD866C5B79A135EE729E18 ] {55662437-DA8C-40c0-AADA-2C816A897A49} C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
16:24:26.0354 3268  {55662437-DA8C-40c0-AADA-2C816A897A49} - ok
16:24:26.0354 3268  ================ Scan global ===============================
16:24:26.0447 3268  [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
16:24:26.0603 3268  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
16:24:26.0634 3268  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
16:24:26.0712 3268  [ B8844F93D2C5F1DCDB179AAA9AF134B7 ] C:\Windows\system32\services.exe
16:24:26.0712 3268  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - infected
16:24:26.0712 3268  C:\Windows\system32\services.exe - detected Virus.Win64.ZAccess.a (0)
16:24:26.0712 3268  ================ Scan MBR ==================================
16:24:26.0744 3268  [ 588AE8F0C685C02BA11F30D9CD7E61A0 ] \Device\Harddisk0\DR0
16:24:27.0461 3268  \Device\Harddisk0\DR0 - ok
16:24:27.0461 3268  ================ Scan VBR ==================================
16:24:27.0508 3268  [ 4F671ACB12D2B23C2A215D3B242A1E8F ] \Device\Harddisk0\DR0\Partition1
16:24:27.0508 3268  \Device\Harddisk0\DR0\Partition1 - ok
16:24:27.0555 3268  [ 7B194D67144E38317068B1DBCA999781 ] \Device\Harddisk0\DR0\Partition2
16:24:27.0555 3268  \Device\Harddisk0\DR0\Partition2 - ok
16:24:27.0555 3268  ============================================================
16:24:27.0555 3268  Scan finished
16:24:27.0555 3268  ============================================================
16:24:27.0570 0908  Detected object count: 9
16:24:27.0570 0908  Actual detected object count: 9
16:24:39.0816 0908  Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0816 0908  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0816 0908  DokanMounter ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0816 0908  DokanMounter ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0816 0908  HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0816 0908  HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0832 0908  hpqwmiex ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0832 0908  hpqwmiex ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0832 0908  LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0832 0908  LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0832 0908  RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0832 0908  RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0832 0908  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0832 0908  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0832 0908  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
16:24:39.0832 0908  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:24:39.0848 0908  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - skipped by user
16:24:39.0848 0908  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - User select action: Skip


cosinus 08.10.2012 16:29

Zitat:

C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - skipped by user
Entweder falsches Log oder hast du den Eintrag geskipped, obwohl dieser gelöscht werden sollte

schustan 08.10.2012 16:50

ich hab den scan gemacht, dann cure. dann neu gebootet, dann neuer scan - und das ist der log davon gewesen.

ich hab das ganze jetzt nochmal gemacht .. hier der log NACH dem scan und VOR dem neu booten

Code:

17:38:34.0195 1368  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
17:38:34.0366 1368  ============================================================
17:38:34.0366 1368  Current date / time: 2012/10/08 17:38:34.0366
17:38:34.0366 1368  SystemInfo:
17:38:34.0366 1368 
17:38:34.0366 1368  OS Version: 6.0.6002 ServicePack: 2.0
17:38:34.0366 1368  Product type: Workstation
17:38:34.0366 1368  ComputerName: ANDREAS-PC
17:38:34.0366 1368  UserName: Andreas
17:38:34.0366 1368  Windows directory: C:\Windows
17:38:34.0366 1368  System windows directory: C:\Windows
17:38:34.0366 1368  Running under WOW64
17:38:34.0366 1368  Processor architecture: Intel x64
17:38:34.0366 1368  Number of processors: 2
17:38:34.0366 1368  Page size: 0x1000
17:38:34.0366 1368  Boot type: Normal boot
17:38:34.0366 1368  ============================================================
17:38:35.0895 1368  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:38:35.0895 1368  ============================================================
17:38:35.0895 1368  \Device\Harddisk0\DR0:
17:38:35.0895 1368  MBR partitions:
17:38:35.0895 1368  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x38B7A000
17:38:35.0895 1368  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38B7A800, BlocksNum 0x180A000
17:38:35.0895 1368  ============================================================
17:38:35.0942 1368  C: <-> \Device\Harddisk0\DR0\Partition1
17:38:36.0145 1368  D: <-> \Device\Harddisk0\DR0\Partition2
17:38:36.0145 1368  ============================================================
17:38:36.0145 1368  Initialize success
17:38:36.0145 1368  ============================================================
17:38:42.0166 4880  ============================================================
17:38:42.0166 4880  Scan started
17:38:42.0166 4880  Mode: Manual; SigCheck; TDLFS;
17:38:42.0166 4880  ============================================================
17:38:43.0227 4880  ================ Scan system memory ========================
17:38:43.0227 4880  System memory - ok
17:38:43.0227 4880  ================ Scan services =============================
17:38:43.0414 4880  [ 7EEB488346FBFA3731276C3EE8A8FD9E ] AAV UpdateService C:\Program Files (x86)\AAVUpdateManager\aavus.exe
17:38:43.0477 4880  AAV UpdateService - ok
17:38:43.0711 4880  [ 5C368F4B04ED2A923E6AFCA2D37BAFF5 ] Accelerometer  C:\Windows\system32\DRIVERS\Accelerometer.sys
17:38:43.0726 4880  Accelerometer - ok
17:38:43.0929 4880  [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI            C:\Windows\system32\drivers\acpi.sys
17:38:43.0945 4880  ACPI - ok
17:38:44.0210 4880  [ F84C9DEE4698DF3C1D76801B7B1B55D7 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
17:38:44.0226 4880  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
17:38:44.0226 4880  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
17:38:44.0413 4880  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
17:38:44.0428 4880  AdobeARMservice - ok
17:38:44.0538 4880  [ F14215E37CF124104575073F782111D2 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
17:38:44.0569 4880  adp94xx - ok
17:38:44.0631 4880  [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci        C:\Windows\system32\drivers\adpahci.sys
17:38:44.0647 4880  adpahci - ok
17:38:44.0694 4880  [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
17:38:44.0709 4880  adpu160m - ok
17:38:44.0772 4880  [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
17:38:44.0787 4880  adpu320 - ok
17:38:44.0850 4880  [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
17:38:44.0896 4880  AeLookupSvc - ok
17:38:45.0224 4880  [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe
17:38:45.0255 4880  AESTFilters - ok
17:38:45.0349 4880  [ C4F6CE6087760AD70960C9EB130E7943 ] AFD            C:\Windows\system32\drivers\afd.sys
17:38:45.0396 4880  AFD - ok
17:38:45.0474 4880  [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440          C:\Windows\system32\drivers\agp440.sys
17:38:45.0505 4880  agp440 - ok
17:38:45.0598 4880  [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
17:38:45.0630 4880  aic78xx - ok
17:38:45.0661 4880  [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG            C:\Windows\System32\alg.exe
17:38:45.0739 4880  ALG - ok
17:38:45.0801 4880  [ E0CA5BB8E6C79533DC6B1DA7361A201E ] aliide          C:\Windows\system32\drivers\aliide.sys
17:38:45.0817 4880  aliide - ok
17:38:45.0817 4880  [ 7034F8D1B9703D711D3F92C95DEB377D ] amdide          C:\Windows\system32\drivers\amdide.sys
17:38:45.0832 4880  amdide - ok
17:38:45.0879 4880  [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
17:38:45.0910 4880  AmdK8 - ok
17:38:46.0378 4880  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
17:38:46.0394 4880  AntiVirSchedulerService - ok
17:38:46.0503 4880  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
17:38:46.0519 4880  AntiVirService - ok
17:38:46.0566 4880  [ 676894FA57B671FEC5C3F05F8929E03B ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
17:38:46.0581 4880  AntiVirWebService - ok
17:38:46.0659 4880  [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo        C:\Windows\System32\appinfo.dll
17:38:46.0675 4880  Appinfo - ok
17:38:46.0987 4880  [ 70D7BE78061126DD0C3ACCDB7E129017 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
17:38:47.0018 4880  Apple Mobile Device - ok
17:38:47.0065 4880  [ BA8417D4765F3988FF921F30F630E303 ] arc            C:\Windows\system32\drivers\arc.sys
17:38:47.0096 4880  arc - ok
17:38:47.0158 4880  [ 9D41C435619733B34CC16A511E644B11 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
17:38:47.0190 4880  arcsas - ok
17:38:47.0736 4880  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
17:38:47.0767 4880  aspnet_state - ok
17:38:47.0829 4880  [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
17:38:47.0907 4880  AsyncMac - ok
17:38:48.0048 4880  [ E68D9B3A3905619732F7FE039466A623 ] atapi          C:\Windows\system32\drivers\atapi.sys
17:38:48.0063 4880  atapi - ok
17:38:48.0157 4880  [ 54CA8AAC988B441A692311E3B584D944 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
17:38:48.0204 4880  Ati External Event Utility - ok
17:38:48.0796 4880  [ 4B42547AE95A31D0E1E200B68A6C7647 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
17:38:48.0952 4880  atikmdag - ok
17:38:49.0062 4880  [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:38:49.0108 4880  AudioEndpointBuilder - ok
17:38:49.0108 4880  [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
17:38:49.0155 4880  AudioSrv - ok
17:38:49.0436 4880  [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
17:38:49.0452 4880  avgntflt - ok
17:38:49.0545 4880  [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
17:38:49.0576 4880  avipbb - ok
17:38:49.0623 4880  [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
17:38:49.0654 4880  avkmgr - ok
17:38:49.0764 4880  [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
17:38:49.0842 4880  blbdrive - ok
17:38:50.0013 4880  [ 673CF4F6BB1FBE09331B526802FBB892 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
17:38:50.0060 4880  Bonjour Service - ok
17:38:50.0107 4880  [ 2348447A80920B2493A9B582A23E81E1 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
17:38:50.0138 4880  bowser - ok
17:38:50.0232 4880  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
17:38:50.0294 4880  BrFiltLo - ok
17:38:50.0466 4880  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
17:38:50.0528 4880  BrFiltUp - ok
17:38:50.0590 4880  [ A1B39DE453433B115B4EA69EE0343816 ] Browser        C:\Windows\System32\browser.dll
17:38:50.0684 4880  Browser - ok
17:38:50.0746 4880  [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid        C:\Windows\system32\drivers\brserid.sys
17:38:50.0856 4880  Brserid - ok
17:38:50.0965 4880  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
17:38:51.0012 4880  BrSerWdm - ok
17:38:51.0043 4880  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
17:38:51.0074 4880  BrUsbMdm - ok
17:38:51.0090 4880  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
17:38:51.0136 4880  BrUsbSer - ok
17:38:51.0183 4880  [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
17:38:51.0230 4880  BTHMODEM - ok
17:38:51.0261 4880  [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
17:38:51.0277 4880  cdfs - ok
17:38:51.0339 4880  [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
17:38:51.0355 4880  cdrom - ok
17:38:51.0417 4880  [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc    C:\Windows\System32\certprop.dll
17:38:51.0433 4880  CertPropSvc - ok
17:38:51.0480 4880  [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
17:38:51.0511 4880  circlass - ok
17:38:51.0542 4880  [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS            C:\Windows\system32\CLFS.sys
17:38:51.0558 4880  CLFS - ok
17:38:51.0729 4880  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:38:51.0729 4880  clr_optimization_v2.0.50727_32 - ok
17:38:51.0823 4880  [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
17:38:51.0838 4880  clr_optimization_v2.0.50727_64 - ok
17:38:52.0384 4880  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:38:52.0416 4880  clr_optimization_v4.0.30319_32 - ok
17:38:52.0462 4880  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
17:38:52.0494 4880  clr_optimization_v4.0.30319_64 - ok
17:38:52.0556 4880  [ B52D9A14CE4101577900A364BA86F3DF ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
17:38:52.0634 4880  CmBatt - ok
17:38:52.0665 4880  [ 8C6AA24C1D7273A02284588426AB8CE3 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
17:38:52.0696 4880  cmdide - ok
17:38:52.0806 4880  [ 12E94E225BD7B05A2BCCD5C0B841E921 ] Com4QLBEx      C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
17:38:52.0821 4880  Com4QLBEx - ok
17:38:52.0946 4880  [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
17:38:52.0962 4880  Compbatt - ok
17:38:52.0993 4880  COMSysApp - ok
17:38:53.0398 4880  cpuz134 - ok
17:38:53.0508 4880  [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
17:38:53.0539 4880  crcdisk - ok
17:38:53.0726 4880  [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
17:38:53.0773 4880  CryptSvc - ok
17:38:53.0913 4880  [ BA8E5B2291C01EF71CA80E25F0C79D55 ] ctxusbm        C:\Windows\system32\DRIVERS\ctxusbm.sys
17:38:53.0929 4880  ctxusbm - ok
17:38:54.0038 4880  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch      C:\Windows\system32\rpcss.dll
17:38:54.0132 4880  DcomLaunch - ok
17:38:54.0178 4880  [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
17:38:54.0194 4880  DfsC - ok
17:38:54.0724 4880  [ C647F468F7DE343DF8C143655C5557D4 ] DFSR            C:\Windows\system32\DFSR.exe
17:38:54.0818 4880  DFSR - ok
17:38:54.0943 4880  [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
17:38:54.0958 4880  Dhcp - ok
17:38:55.0021 4880  [ B0107E40ECDB5FA692EBF832F295D905 ] disk            C:\Windows\system32\drivers\disk.sys
17:38:55.0036 4880  disk - ok
17:38:55.0083 4880  [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
17:38:55.0099 4880  Dnscache - ok
17:38:55.0161 4880  [ 57AE249F2C6A90476E8E400F0EEC3C56 ] Dokan          C:\Windows\system32\drivers\dokan.sys
17:38:55.0177 4880  Dokan - ok
17:38:55.0317 4880  [ F4FEAE56DA1B5B7DC78D5F9214CDEF5E ] DokanMounter    C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
17:38:55.0317 4880  DokanMounter ( UnsignedFile.Multi.Generic ) - warning
17:38:55.0333 4880  DokanMounter - detected UnsignedFile.Multi.Generic (1)
17:38:55.0426 4880  [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc        C:\Windows\System32\dot3svc.dll
17:38:55.0442 4880  dot3svc - ok
17:38:55.0504 4880  [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS            C:\Windows\system32\dps.dll
17:38:55.0536 4880  DPS - ok
17:38:55.0598 4880  [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
17:38:55.0629 4880  drmkaud - ok
17:38:55.0863 4880  [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
17:38:55.0926 4880  DXGKrnl - ok
17:38:56.0050 4880  [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60          C:\Windows\system32\DRIVERS\E1G6032E.sys
17:38:56.0128 4880  E1G60 - ok
17:38:56.0206 4880  [ C2303883FD9BE49DC36A6400643002EA ] EapHost        C:\Windows\System32\eapsvc.dll
17:38:56.0284 4880  EapHost - ok
17:38:56.0409 4880  [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache          C:\Windows\system32\drivers\ecache.sys
17:38:56.0440 4880  Ecache - ok
17:38:56.0550 4880  [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
17:38:56.0596 4880  ehRecvr - ok
17:38:56.0628 4880  [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched        C:\Windows\ehome\ehsched.exe
17:38:56.0659 4880  ehSched - ok
17:38:56.0721 4880  [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart        C:\Windows\ehome\ehstart.dll
17:38:56.0752 4880  ehstart - ok
17:38:56.0815 4880  [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
17:38:56.0846 4880  elxstor - ok
17:38:57.0033 4880  [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
17:38:57.0080 4880  EMDMgmt - ok
17:38:57.0142 4880  [ F218A3A27ED6592C0E22EC3595554447 ] enecir          C:\Windows\system32\DRIVERS\enecir.sys
17:38:57.0158 4880  enecir - ok
17:38:57.0267 4880  [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev          C:\Windows\system32\drivers\errdev.sys
17:38:57.0345 4880  ErrDev - ok
17:38:57.0486 4880  [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem    C:\Windows\system32\es.dll
17:38:57.0564 4880  EventSystem - ok
17:38:57.0626 4880  [ 486844F47B6636044A42454614ED4523 ] exfat          C:\Windows\system32\drivers\exfat.sys
17:38:57.0673 4880  exfat - ok
17:38:57.0673 4880  ezSharedSvc - ok
17:38:57.0766 4880  [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
17:38:57.0829 4880  fastfat - ok
17:38:58.0016 4880  [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
17:38:58.0063 4880  fdc - ok
17:38:58.0297 4880  [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost        C:\Windows\system32\fdPHost.dll
17:38:58.0390 4880  fdPHost - ok
17:38:58.0468 4880  [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub        C:\Windows\system32\fdrespub.dll
17:38:58.0546 4880  FDResPub - ok
17:38:58.0578 4880  Fildro - ok
17:38:58.0624 4880  [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
17:38:58.0640 4880  FileInfo - ok
17:38:58.0734 4880  [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
17:38:58.0780 4880  Filetrace - ok
17:38:58.0827 4880  [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
17:38:58.0874 4880  flpydisk - ok
17:38:58.0952 4880  [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
17:38:58.0968 4880  FltMgr - ok
17:38:59.0092 4880  [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache      C:\Windows\system32\FntCache.dll
17:38:59.0139 4880  FontCache - ok
17:38:59.0264 4880  [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
17:38:59.0280 4880  FontCache3.0.0.0 - ok
17:38:59.0342 4880  [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
17:38:59.0358 4880  Fs_Rec - ok
17:38:59.0436 4880  [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
17:38:59.0482 4880  gagp30kx - ok
17:38:59.0592 4880  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17:38:59.0623 4880  GEARAspiWDM - ok
17:38:59.0763 4880  [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc          C:\Windows\System32\gpsvc.dll
17:38:59.0826 4880  gpsvc - ok
17:38:59.0888 4880  [ 68E732382B32417FF61FD663259B4B09 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:38:59.0919 4880  HdAudAddService - ok
17:39:00.0044 4880  [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
17:39:00.0091 4880  HDAudBus - ok
17:39:00.0122 4880  [ B4881C84A180E75B8C25DC1D726C375F ] HidBth          C:\Windows\system32\drivers\hidbth.sys
17:39:00.0200 4880  HidBth - ok
17:39:00.0247 4880  [ 5F47839455D01FF6403B008D481A6F5B ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
17:39:00.0278 4880  HidIr - ok
17:39:00.0356 4880  [ 59361D38A297755D46A540E450202B2A ] hidserv        C:\Windows\system32\hidserv.dll
17:39:00.0387 4880  hidserv - ok
17:39:00.0512 4880  [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
17:39:00.0543 4880  HidUsb - ok
17:39:00.0621 4880  [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc          C:\Windows\system32\kmsvc.dll
17:39:00.0652 4880  hkmsvc - ok
17:39:00.0918 4880  [ A19B0BB5A7EB6DF2DD4A0711D36955EE ] HP Health Check Service c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
17:39:00.0918 4880  HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
17:39:00.0918 4880  HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
17:39:01.0011 4880  [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
17:39:01.0042 4880  HpCISSs - ok
17:39:01.0089 4880  [ 4E0BEC0F78096FFD6D3314B497FC49D3 ] hpdskflt        C:\Windows\system32\DRIVERS\hpdskflt.sys
17:39:01.0105 4880  hpdskflt - ok
17:39:01.0152 4880  [ 0ECC54FD34D6A089C300846B011E81D6 ] HpqKbFiltr      C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
17:39:01.0167 4880  HpqKbFiltr - ok
17:39:01.0245 4880  [ 188FF0ADF66768D53AD94F43972E1E9A ] hpqwmiex        C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
17:39:01.0245 4880  hpqwmiex ( UnsignedFile.Multi.Generic ) - warning
17:39:01.0245 4880  hpqwmiex - detected UnsignedFile.Multi.Generic (1)
17:39:01.0308 4880  [ FC7C13B5A9E9BE23B7AE72BBC7FDB278 ] hpsrv          C:\Windows\system32\Hpservice.exe
17:39:01.0323 4880  hpsrv - ok
17:39:01.0386 4880  [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
17:39:01.0417 4880  HTTP - ok
17:39:01.0464 4880  [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
17:39:01.0479 4880  i2omp - ok
17:39:01.0526 4880  [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
17:39:01.0573 4880  i8042prt - ok
17:39:01.0604 4880  [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
17:39:01.0651 4880  iaStorV - ok
17:39:01.0713 4880  [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
17:39:01.0744 4880  idsvc - ok
17:39:01.0807 4880  [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
17:39:01.0822 4880  iirsp - ok
17:39:01.0885 4880  [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT          C:\Windows\System32\ikeext.dll
17:39:01.0916 4880  IKEEXT - ok
17:39:01.0963 4880  [ 475490CAF376E55E6E8B37BBDFEB2E81 ] intelide        C:\Windows\system32\drivers\intelide.sys
17:39:01.0978 4880  intelide - ok
17:39:02.0010 4880  [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
17:39:02.0041 4880  intelppm - ok
17:39:02.0072 4880  [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
17:39:02.0103 4880  IPBusEnum - ok
17:39:02.0134 4880  [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:39:02.0150 4880  IpFilterDriver - ok
17:39:02.0150 4880  IpInIp - ok
17:39:02.0212 4880  [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
17:39:02.0228 4880  IPMIDRV - ok
17:39:02.0244 4880  [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
17:39:02.0275 4880  IPNAT - ok
17:39:02.0415 4880  [ 24595EC9236D7E421661A2D4FFBD901A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
17:39:02.0431 4880  iPod Service - ok
17:39:02.0478 4880  [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
17:39:02.0509 4880  IRENUM - ok
17:39:02.0556 4880  [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
17:39:02.0571 4880  isapnp - ok
17:39:02.0649 4880  [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
17:39:02.0680 4880  iScsiPrt - ok
17:39:02.0696 4880  [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
17:39:02.0712 4880  iteatapi - ok
17:39:02.0774 4880  [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid        C:\Windows\system32\drivers\iteraid.sys
17:39:02.0790 4880  iteraid - ok
17:39:02.0821 4880  [ BB86B1C3489463BBA1FD04C876DBE414 ] JMCR            C:\Windows\system32\DRIVERS\jmcr.sys
17:39:02.0836 4880  JMCR - ok
17:39:02.0868 4880  [ 423696F3BA6472DD17699209B933BC26 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
17:39:02.0883 4880  kbdclass - ok
17:39:02.0914 4880  [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
17:39:02.0946 4880  kbdhid - ok
17:39:02.0992 4880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso          C:\Windows\system32\lsass.exe
17:39:03.0008 4880  KeyIso - ok
17:39:03.0055 4880  [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
17:39:03.0086 4880  KSecDD - ok
17:39:03.0164 4880  [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
17:39:03.0211 4880  ksthunk - ok
17:39:03.0273 4880  [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm          C:\Windows\system32\msdtckrm.dll
17:39:03.0320 4880  KtmRm - ok
17:39:03.0414 4880  [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer    C:\Windows\system32\srvsvc.dll
17:39:03.0429 4880  LanmanServer - ok
17:39:03.0476 4880  [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:39:03.0492 4880  LanmanWorkstation - ok
17:39:03.0601 4880  [ 83D8BE94E1CBCBE2EA8372DB1A95A159 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
17:39:03.0601 4880  LightScribeService ( UnsignedFile.Multi.Generic ) - warning
17:39:03.0601 4880  LightScribeService - detected UnsignedFile.Multi.Generic (1)
17:39:03.0632 4880  [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
17:39:03.0663 4880  lltdio - ok
17:39:03.0710 4880  [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
17:39:03.0757 4880  lltdsvc - ok
17:39:03.0772 4880  [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts        C:\Windows\System32\lmhsvc.dll
17:39:03.0819 4880  lmhosts - ok
17:39:03.0850 4880  [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
17:39:03.0866 4880  LSI_FC - ok
17:39:03.0882 4880  [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
17:39:03.0897 4880  LSI_SAS - ok
17:39:03.0913 4880  [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
17:39:03.0928 4880  LSI_SCSI - ok
17:39:03.0975 4880  [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv          C:\Windows\system32\drivers\luafv.sys
17:39:04.0022 4880  luafv - ok
17:39:04.0178 4880  [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
17:39:04.0194 4880  McComponentHostService - ok
17:39:04.0240 4880  [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
17:39:04.0256 4880  Mcx2Svc - ok
17:39:04.0318 4880  [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas        C:\Windows\system32\drivers\megasas.sys
17:39:04.0334 4880  megasas - ok
17:39:04.0396 4880  [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
17:39:04.0412 4880  MegaSR - ok
17:39:04.0459 4880  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS          C:\Windows\system32\mmcss.dll
17:39:04.0506 4880  MMCSS - ok
17:39:04.0537 4880  [ 59848D5CC74606F0EE7557983BB73C2E ] Modem          C:\Windows\system32\drivers\modem.sys
17:39:04.0584 4880  Modem - ok
17:39:04.0584 4880  [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
17:39:04.0630 4880  monitor - ok
17:39:04.0646 4880  [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
17:39:04.0662 4880  mouclass - ok
17:39:04.0724 4880  [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
17:39:04.0771 4880  mouhid - ok
17:39:04.0786 4880  [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
17:39:04.0802 4880  MountMgr - ok
17:39:04.0911 4880  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
17:39:04.0927 4880  MozillaMaintenance - ok
17:39:04.0942 4880  [ F8276EB8698142884498A528DFEA8478 ] mpio            C:\Windows\system32\drivers\mpio.sys
17:39:04.0958 4880  mpio - ok
17:39:05.0005 4880  [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
17:39:05.0036 4880  mpsdrv - ok
17:39:05.0052 4880  [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
17:39:05.0067 4880  Mraid35x - ok
17:39:05.0114 4880  [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
17:39:05.0130 4880  MRxDAV - ok
17:39:05.0176 4880  [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
17:39:05.0208 4880  mrxsmb - ok
17:39:05.0254 4880  [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:39:05.0270 4880  mrxsmb10 - ok
17:39:05.0317 4880  [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:39:05.0332 4880  mrxsmb20 - ok
17:39:05.0379 4880  [ AA459F2AB3AB603C357FF117CAE3D818 ] msahci          C:\Windows\system32\drivers\msahci.sys
17:39:05.0410 4880  msahci - ok
17:39:05.0442 4880  [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
17:39:05.0457 4880  msdsm - ok
17:39:05.0504 4880  [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC          C:\Windows\System32\msdtc.exe
17:39:05.0551 4880  MSDTC - ok
17:39:05.0613 4880  [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs            C:\Windows\system32\drivers\Msfs.sys
17:39:05.0660 4880  Msfs - ok
17:39:05.0707 4880  [ 00EBC952961664780D43DCA157E79B27 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
17:39:05.0722 4880  msisadrv - ok
17:39:05.0754 4880  [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
17:39:05.0785 4880  MSiSCSI - ok
17:39:05.0800 4880  msiserver - ok
17:39:05.0847 4880  [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
17:39:05.0894 4880  MSKSSRV - ok
17:39:05.0910 4880  [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
17:39:05.0941 4880  MSPCLOCK - ok
17:39:05.0956 4880  [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
17:39:05.0988 4880  MSPQM - ok
17:39:06.0034 4880  [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
17:39:06.0050 4880  MsRPC - ok
17:39:06.0097 4880  [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
17:39:06.0112 4880  mssmbios - ok
17:39:06.0159 4880  [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
17:39:06.0175 4880  MSTEE - ok
17:39:06.0237 4880  [ 0CC49F78D8ACA0877D885F149084E543 ] Mup            C:\Windows\system32\Drivers\mup.sys
17:39:06.0237 4880  Mup - ok
17:39:06.0424 4880  [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent        C:\Windows\system32\qagentRT.dll
17:39:06.0502 4880  napagent - ok
17:39:06.0596 4880  [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
17:39:06.0612 4880  NativeWifiP - ok
17:39:06.0705 4880  NAVENG - ok
17:39:06.0705 4880  NAVEX15 - ok
17:39:06.0768 4880  [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS            C:\Windows\system32\drivers\ndis.sys
17:39:06.0799 4880  NDIS - ok
17:39:06.0846 4880  [ 64DF698A425478E321981431AC171334 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
17:39:06.0877 4880  NdisTapi - ok
17:39:06.0924 4880  [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
17:39:06.0970 4880  Ndisuio - ok
17:39:07.0017 4880  [ F8158771905260982CE724076419EF19 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
17:39:07.0048 4880  NdisWan - ok
17:39:07.0095 4880  [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
17:39:07.0126 4880  NDProxy - ok
17:39:07.0204 4880  [ 89FD76A90CBE63F03A70C2D1B85E802C ] NEOFLTR_710_19243 C:\Windows\system32\Drivers\NEOFLTR_710_19243.SYS
17:39:07.0220 4880  NEOFLTR_710_19243 - ok
17:39:07.0267 4880  Nero BackItUp Scheduler 4.0 - ok
17:39:07.0282 4880  [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
17:39:07.0314 4880  NetBIOS - ok
17:39:07.0360 4880  [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
17:39:07.0392 4880  netbt - ok
17:39:07.0407 4880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon        C:\Windows\system32\lsass.exe
17:39:07.0423 4880  Netlogon - ok
17:39:07.0470 4880  [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman          C:\Windows\System32\netman.dll
17:39:07.0501 4880  Netman - ok
17:39:07.0548 4880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:39:07.0563 4880  NetMsmqActivator - ok
17:39:07.0563 4880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:39:07.0579 4880  NetPipeActivator - ok
17:39:07.0594 4880  [ 7846D0136CC2B264926A73047BA7688A ] netprofm        C:\Windows\System32\netprofm.dll
17:39:07.0626 4880  netprofm - ok
17:39:07.0641 4880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:39:07.0641 4880  NetTcpActivator - ok
17:39:07.0657 4880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:39:07.0657 4880  NetTcpPortSharing - ok
17:39:07.0782 4880  [ C86984AEE87900C1EEB6942EDE3BF4B6 ] NETw3v64        C:\Windows\system32\DRIVERS\NETw3v64.sys
17:39:07.0875 4880  NETw3v64 - ok
17:39:08.0031 4880  [ 2BDCB7B7917380794C9D87AC2153CE33 ] NETw5v64        C:\Windows\system32\DRIVERS\NETw5v64.sys
17:39:08.0125 4880  NETw5v64 - ok
17:39:08.0172 4880  [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
17:39:08.0187 4880  nfrd960 - ok
17:39:08.0218 4880  [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc          C:\Windows\System32\nlasvc.dll
17:39:08.0265 4880  NlaSvc - ok
17:39:08.0343 4880  [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64      C:\Windows\system32\drivers\ccdcmbox64.sys
17:39:08.0374 4880  nmwcdcx64 - ok
17:39:08.0390 4880  [ 76292103C5149EB140419F36DCF26C1B ] nmwcdnsucx64    C:\Windows\system32\drivers\nmwcdnsucx64.sys
17:39:08.0421 4880  nmwcdnsucx64 - ok
17:39:08.0484 4880  [ 2974296DA6296B4FEA3E313BF98C693D ] nmwcdnsux64    C:\Windows\system32\drivers\nmwcdnsux64.sys
17:39:08.0515 4880  nmwcdnsux64 - ok
17:39:08.0562 4880  [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64        C:\Windows\system32\drivers\ccdcmbx64.sys
17:39:08.0593 4880  nmwcdx64 - ok
17:39:08.0593 4880  Norton Internet Security - ok
17:39:08.0640 4880  [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
17:39:08.0671 4880  Npfs - ok
17:39:08.0718 4880  [ ACB62BAA1C319B17752553DF3026EEEB ] nsi            C:\Windows\system32\nsisvc.dll
17:39:08.0764 4880  nsi - ok
17:39:08.0796 4880  [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
17:39:08.0842 4880  nsiproxy - ok
17:39:08.0920 4880  [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
17:39:08.0983 4880  Ntfs - ok
17:39:09.0014 4880  [ DD5D684975352B85B52E3FD5347C20CB ] Null            C:\Windows\system32\drivers\Null.sys
17:39:09.0061 4880  Null - ok
17:39:09.0076 4880  [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
17:39:09.0092 4880  nvraid - ok
17:39:09.0108 4880  [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor          C:\Windows\system32\drivers\nvstor.sys
17:39:09.0123 4880  nvstor - ok
17:39:09.0139 4880  [ 19067CA93075EF4823E3938A686F532F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
17:39:09.0154 4880  nv_agp - ok
17:39:09.0154 4880  NwlnkFlt - ok
17:39:09.0170 4880  NwlnkFwd - ok
17:39:09.0232 4880  [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
17:39:09.0264 4880  ohci1394 - ok
17:39:09.0342 4880  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:39:09.0357 4880  ose - ok
17:39:09.0451 4880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc        C:\Windows\system32\p2psvc.dll
17:39:09.0482 4880  p2pimsvc - ok
17:39:09.0498 4880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc          C:\Windows\system32\p2psvc.dll
17:39:09.0529 4880  p2psvc - ok
17:39:09.0591 4880  [ AECD57F94C887F58919F307C35498EA0 ] Parport        C:\Windows\system32\drivers\parport.sys
17:39:09.0654 4880  Parport - ok
17:39:09.0716 4880  [ B43751085E2ABE389DA466BC62A4B987 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
17:39:09.0732 4880  partmgr - ok
17:39:09.0778 4880  [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc          C:\Windows\System32\pcasvc.dll
17:39:09.0794 4880  PcaSvc - ok
17:39:09.0872 4880  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
17:39:09.0888 4880  pccsmcfd - ok
17:39:09.0950 4880  [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci            C:\Windows\system32\drivers\pci.sys
17:39:09.0966 4880  pci - ok
17:39:10.0012 4880  [ 15E5C3F89A3452EFBDA3B39816DBC4EE ] pciide          C:\Windows\system32\drivers\pciide.sys
17:39:10.0028 4880  pciide - ok
17:39:10.0059 4880  [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
17:39:10.0075 4880  pcmcia - ok
17:39:10.0090 4880  [ 58865916F53592A61549B04941BFD80D ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
17:39:10.0168 4880  PEAUTH - ok
17:39:10.0293 4880  [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
17:39:10.0340 4880  PerfHost - ok
17:39:10.0418 4880  [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla            C:\Windows\system32\pla.dll
17:39:10.0465 4880  pla - ok
17:39:10.0527 4880  [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
17:39:10.0574 4880  PlugPlay - ok
17:39:10.0605 4880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
17:39:10.0636 4880  PNRPAutoReg - ok
17:39:10.0652 4880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc        C:\Windows\system32\p2psvc.dll
17:39:10.0683 4880  PNRPsvc - ok
17:39:10.0761 4880  [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
17:39:10.0792 4880  PolicyAgent - ok
17:39:10.0870 4880  [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
17:39:10.0902 4880  PptpMiniport - ok
17:39:10.0948 4880  [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor      C:\Windows\system32\drivers\processr.sys
17:39:10.0995 4880  Processor - ok
17:39:11.0026 4880  [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc        C:\Windows\system32\profsvc.dll
17:39:11.0058 4880  ProfSvc - ok
17:39:11.0089 4880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
17:39:11.0104 4880  ProtectedStorage - ok
17:39:11.0151 4880  [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
17:39:11.0182 4880  PSched - ok
17:39:11.0245 4880  [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300          C:\Windows\system32\drivers\ql2300.sys
17:39:11.0323 4880  ql2300 - ok
17:39:11.0354 4880  [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
17:39:11.0370 4880  ql40xx - ok
17:39:11.0416 4880  [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE          C:\Windows\system32\qwave.dll
17:39:11.0432 4880  QWAVE - ok
17:39:11.0463 4880  [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
17:39:11.0479 4880  QWAVEdrv - ok
17:39:11.0526 4880  [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
17:39:11.0572 4880  RasAcd - ok
17:39:11.0588 4880  [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto        C:\Windows\System32\rasauto.dll
17:39:11.0635 4880  RasAuto - ok
17:39:11.0682 4880  [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
17:39:11.0728 4880  Rasl2tp - ok
17:39:11.0760 4880  [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan          C:\Windows\System32\rasmans.dll
17:39:11.0791 4880  RasMan - ok
17:39:11.0822 4880  [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
17:39:11.0853 4880  RasPppoe - ok
17:39:11.0900 4880  [ C6A593B51F34C33E5474539544072527 ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
17:39:11.0931 4880  RasSstp - ok
17:39:11.0947 4880  [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
17:39:11.0978 4880  rdbss - ok
17:39:12.0025 4880  [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
17:39:12.0072 4880  RDPCDD - ok
17:39:12.0087 4880  [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
17:39:12.0134 4880  rdpdr - ok
17:39:12.0150 4880  [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
17:39:12.0196 4880  RDPENCDD - ok
17:39:12.0243 4880  [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
17:39:12.0259 4880  RDPWD - ok
17:39:12.0306 4880  [ BC0A4D47472B042537F4E57B950415FA ] Recovery Service for Windows C:\Program Files (x86)\SMINST\BLService.exe
17:39:12.0337 4880  Recovery Service for Windows - ok
17:39:12.0384 4880  [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess    C:\Windows\System32\mprdim.dll
17:39:12.0430 4880  RemoteAccess - ok
17:39:12.0493 4880  [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
17:39:12.0524 4880  RemoteRegistry - ok
17:39:12.0633 4880  [ 805AE1F90C64758D19AAA001CF8CBA12 ] RichVideo      C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
17:39:12.0649 4880  RichVideo ( UnsignedFile.Multi.Generic ) - warning
17:39:12.0649 4880  RichVideo - detected UnsignedFile.Multi.Generic (1)
17:39:12.0696 4880  [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator      C:\Windows\system32\locator.exe
17:39:12.0711 4880  RpcLocator - ok
17:39:12.0758 4880  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs          C:\Windows\system32\rpcss.dll
17:39:12.0852 4880  RpcSs - ok
17:39:12.0914 4880  [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
17:39:12.0961 4880  rspndr - ok
17:39:13.0023 4880  [ 8B91737DA75ADD21CB1554B38089196A ] RTL8169        C:\Windows\system32\DRIVERS\Rtlh64.sys
17:39:13.0054 4880  RTL8169 - ok
17:39:13.0070 4880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs          C:\Windows\system32\lsass.exe
17:39:13.0086 4880  SamSs - ok
17:39:13.0132 4880  [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
17:39:13.0148 4880  sbp2port - ok
17:39:13.0179 4880  [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr        C:\Windows\System32\SCardSvr.dll
17:39:13.0226 4880  SCardSvr - ok
17:39:13.0304 4880  [ 0F838C811AD295D2A4489B9993096C63 ] Schedule        C:\Windows\system32\schedsvc.dll
17:39:13.0335 4880  Schedule - ok
17:39:13.0382 4880  [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc    C:\Windows\System32\certprop.dll
17:39:13.0413 4880  SCPolicySvc - ok
17:39:13.0460 4880  [ B42EE50F7D24F837F925332EB349ECA5 ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
17:39:13.0507 4880  sdbus - ok
17:39:13.0554 4880  [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
17:39:13.0569 4880  SDRSVC - ok
17:39:13.0756 4880  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
17:39:13.0772 4880  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
17:39:13.0772 4880  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
17:39:13.0788 4880  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
17:39:13.0897 4880  secdrv - ok
17:39:13.0928 4880  [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon        C:\Windows\system32\seclogon.dll
17:39:13.0944 4880  seclogon - ok
17:39:13.0975 4880  [ 90973A64B96CD647FF81C79443618EED ] SENS            C:\Windows\System32\sens.dll
17:39:14.0006 4880  SENS - ok
17:39:14.0022 4880  [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum        C:\Windows\system32\drivers\serenum.sys
17:39:14.0068 4880  Serenum - ok
17:39:14.0084 4880  [ E62FAC91EE288DB29A9696A9D279929C ] Serial          C:\Windows\system32\drivers\serial.sys
17:39:14.0131 4880  Serial - ok
17:39:14.0131 4880  [ A842F04833684BCEEA7336211BE478DF ] sermouse        C:\Windows\system32\drivers\sermouse.sys
17:39:14.0162 4880  sermouse - ok
17:39:14.0240 4880  [ 58D5BFDF3ADF49FE9CABD78CC61D92F6 ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
17:39:14.0256 4880  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
17:39:14.0256 4880  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
17:39:14.0334 4880  [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv      C:\Windows\system32\sessenv.dll
17:39:14.0365 4880  SessionEnv - ok
17:39:14.0396 4880  [ 14D4B4465193A87C127933978E8C4106 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
17:39:14.0427 4880  sffdisk - ok
17:39:14.0443 4880  [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
17:39:14.0474 4880  sffp_mmc - ok
17:39:14.0490 4880  [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
17:39:14.0521 4880  sffp_sd - ok
17:39:14.0536 4880  [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
17:39:14.0568 4880  sfloppy - ok
17:39:14.0630 4880  [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:39:14.0630 4880  ShellHWDetection - ok
17:39:14.0692 4880  [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
17:39:14.0692 4880  SiSRaid2 - ok
17:39:14.0724 4880  [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
17:39:14.0724 4880  SiSRaid4 - ok
17:39:14.0817 4880  [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
17:39:14.0817 4880  SkypeUpdate - ok
17:39:14.0942 4880  [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc          C:\Windows\system32\SLsvc.exe
17:39:15.0004 4880  slsvc - ok
17:39:15.0067 4880  [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify      C:\Windows\system32\SLUINotify.dll
17:39:15.0098 4880  SLUINotify - ok
17:39:15.0145 4880  [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
17:39:15.0176 4880  Smb - ok
17:39:15.0238 4880  [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
17:39:15.0254 4880  SNMPTRAP - ok
17:39:15.0285 4880  [ 386C3C63F00A7040C7EC5E384217E89D ] spldr          C:\Windows\system32\drivers\spldr.sys
17:39:15.0301 4880  spldr - ok
17:39:15.0332 4880  [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler        C:\Windows\System32\spoolsv.exe
17:39:15.0348 4880  Spooler - ok
17:39:15.0363 4880  SRTSP - ok
17:39:15.0363 4880  SRTSPX - ok
17:39:15.0410 4880  [ 880A57FCCB571EBD063D4DD50E93E46D ] srv            C:\Windows\system32\DRIVERS\srv.sys
17:39:15.0426 4880  srv - ok
17:39:15.0488 4880  [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
17:39:15.0504 4880  srv2 - ok
17:39:15.0535 4880  [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
17:39:15.0550 4880  srvnet - ok
17:39:15.0597 4880  [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
17:39:15.0644 4880  SSDPSRV - ok
17:39:15.0722 4880  [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc        C:\Windows\system32\sstpsvc.dll
17:39:15.0753 4880  SstpSvc - ok
17:39:15.0894 4880  [ 72EB6157E892A674E47E08732BB5CCE3 ] STacSV          C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe
17:39:15.0909 4880  STacSV - ok
17:39:15.0987 4880  [ 0C7BDA7E9A329A071C080EB5210FE019 ] STHDA          C:\Windows\system32\DRIVERS\stwrt64.sys
17:39:16.0003 4880  STHDA - ok
17:39:16.0065 4880  [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc          C:\Windows\System32\wiaservc.dll
17:39:16.0096 4880  stisvc - ok
17:39:16.0128 4880  [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
17:39:16.0143 4880  swenum - ok
17:39:16.0206 4880  [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv          C:\Windows\System32\swprv.dll
17:39:16.0237 4880  swprv - ok
17:39:16.0268 4880  [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
17:39:16.0284 4880  Symc8xx - ok
17:39:16.0330 4880  [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
17:39:16.0346 4880  Sym_hi - ok
17:39:16.0346 4880  [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
17:39:16.0362 4880  Sym_u3 - ok
17:39:16.0440 4880  [ 3A706A967295E16511E40842B1A2761D ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
17:39:16.0455 4880  SynTP - ok
17:39:16.0533 4880  [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain        C:\Windows\system32\sysmain.dll
17:39:16.0580 4880  SysMain - ok
17:39:16.0627 4880  [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:39:16.0642 4880  TabletInputService - ok
17:39:16.0689 4880  [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv        C:\Windows\System32\tapisrv.dll
17:39:16.0720 4880  TapiSrv - ok
17:39:16.0736 4880  [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS            C:\Windows\System32\tbssvc.dll
17:39:16.0783 4880  TBS - ok
17:39:16.0861 4880  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
17:39:16.0908 4880  Tcpip - ok
17:39:16.0923 4880  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
17:39:16.0986 4880  Tcpip6 - ok
17:39:17.0017 4880  [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
17:39:17.0032 4880  tcpipreg - ok
17:39:17.0079 4880  [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
17:39:17.0110 4880  TDPIPE - ok
17:39:17.0126 4880  [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
17:39:17.0173 4880  TDTCP - ok
17:39:17.0220 4880  [ 458919C8C42E398DC4802178D5FFEE27 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
17:39:17.0251 4880  tdx - ok
17:39:17.0298 4880  [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
17:39:17.0313 4880  TermDD - ok
17:39:17.0344 4880  [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService    C:\Windows\System32\termsrv.dll
17:39:17.0391 4880  TermService - ok
17:39:17.0407 4880  [ 56793271ECDEDD350C5ADD305603E963 ] Themes          C:\Windows\system32\shsvcs.dll
17:39:17.0438 4880  Themes - ok
17:39:17.0469 4880  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER    C:\Windows\system32\mmcss.dll
17:39:17.0516 4880  THREADORDER - ok
17:39:17.0594 4880  [ 0407143F2BBC1A5DD5B518AC0704FCBF ] TomTomHOMEService C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
17:39:17.0610 4880  TomTomHOMEService - ok
17:39:17.0656 4880  [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks          C:\Windows\System32\trkwks.dll
17:39:17.0703 4880  TrkWks - ok
17:39:17.0766 4880  [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:39:17.0797 4880  TrustedInstaller - ok
17:39:17.0828 4880  [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
17:39:17.0875 4880  tssecsrv - ok
17:39:17.0906 4880  [ 89EC74A9E602D16A75A4170511029B3C ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
17:39:17.0922 4880  tunmp - ok
17:39:17.0953 4880  [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
17:39:17.0968 4880  tunnel - ok
17:39:18.0156 4880  [ 1C31169DDDC70C1605F703DA701EAEEA ] TVCapSvc        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
17:39:18.0187 4880  TVCapSvc - ok
17:39:18.0187 4880  [ 290B8C381DBC15D3DBCBD2BDB6B0BA12 ] TVSched        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
17:39:18.0202 4880  TVSched - ok
17:39:18.0234 4880  [ FEC266EF401966311744BD0F359F7F56 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
17:39:18.0249 4880  uagp35 - ok
17:39:18.0312 4880  [ FAF2640A2A76ED03D449E443194C4C34 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
17:39:18.0343 4880  udfs - ok
17:39:18.0390 4880  [ 060507C4113391394478F6953A79EEDC ] UI0Detect      C:\Windows\system32\UI0Detect.exe
17:39:18.0436 4880  UI0Detect - ok
17:39:18.0452 4880  [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
17:39:18.0468 4880  uliagpkx - ok
17:39:18.0499 4880  [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci        C:\Windows\system32\drivers\uliahci.sys
17:39:18.0514 4880  uliahci - ok
17:39:18.0546 4880  [ 31707F09846056651EA2C37858F5DDB0 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
17:39:18.0561 4880  UlSata - ok
17:39:18.0592 4880  [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
17:39:18.0608 4880  ulsata2 - ok
17:39:18.0624 4880  [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
17:39:18.0670 4880  umbus - ok
17:39:18.0717 4880  [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost        C:\Windows\System32\upnphost.dll
17:39:18.0780 4880  upnphost - ok
17:39:18.0811 4880  [ 9856C38AB8FAACCA4DD99DAC7B42F838 ] upperdev        C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
17:39:18.0842 4880  upperdev - ok
17:39:18.0920 4880  [ CD03479F2DA26500B203ED075C146A7A ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
17:39:18.0936 4880  USBAAPL64 - ok
17:39:19.0029 4880  [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
17:39:19.0060 4880  usbaudio - ok
17:39:19.0123 4880  [ 07E3498FC60834219D2356293DA0FECC ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
17:39:19.0154 4880  usbccgp - ok
17:39:19.0185 4880  [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
17:39:19.0248 4880  usbcir - ok
17:39:19.0263 4880  [ 827E44DE934A736EA31E91D353EB126F ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
17:39:19.0294 4880  usbehci - ok
17:39:19.0341 4880  [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
17:39:19.0372 4880  usbhub - ok
17:39:19.0419 4880  [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
17:39:19.0482 4880  usbohci - ok
17:39:19.0482 4880  [ ACFEE697AF477021BB3EC78C5431FED2 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
17:39:19.0560 4880  usbprint - ok
17:39:19.0591 4880  [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
17:39:19.0622 4880  usbscan - ok
17:39:19.0669 4880  [ F7386007FB19E7685FC7B298560AA81F ] usbser          C:\Windows\system32\drivers\usbser.sys
17:39:19.0684 4880  usbser - ok
17:39:19.0716 4880  [ 89123DC822AC7A708BD4C9E196A37610 ] UsbserFilt      C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys
17:39:19.0731 4880  UsbserFilt - ok
17:39:19.0794 4880  [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:39:19.0809 4880  USBSTOR - ok
17:39:19.0840 4880  [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
17:39:19.0872 4880  usbuhci - ok
17:39:19.0918 4880  [ FC33099877790D51B0927B7039059855 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
17:39:19.0950 4880  usbvideo - ok
17:39:19.0981 4880  [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms          C:\Windows\System32\uxsms.dll
17:39:20.0012 4880  UxSms - ok
17:39:20.0043 4880  [ 294945381DFA7CE58CECF0A9896AF327 ] vds            C:\Windows\System32\vds.exe
17:39:20.0074 4880  vds - ok
17:39:20.0137 4880  [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
17:39:20.0168 4880  vga - ok
17:39:20.0184 4880  [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave        C:\Windows\System32\drivers\vga.sys
17:39:20.0215 4880  VgaSave - ok
17:39:20.0230 4880  [ 4F964E6828156F0EF3FA8D3A9A7895DE ] viaide          C:\Windows\system32\drivers\viaide.sys
17:39:20.0230 4880  viaide - ok
17:39:20.0262 4880  [ 2B7E885ED951519A12C450D24535DFCA ] volmgr          C:\Windows\system32\drivers\volmgr.sys
17:39:20.0277 4880  volmgr - ok
17:39:20.0340 4880  [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
17:39:20.0355 4880  volmgrx - ok
17:39:20.0418 4880  [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap        C:\Windows\system32\drivers\volsnap.sys
17:39:20.0433 4880  volsnap - ok
17:39:20.0464 4880  [ A68F455ED2673835209318DD61BFBB0E ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
17:39:20.0480 4880  vsmraid - ok
17:39:20.0558 4880  [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS            C:\Windows\system32\vssvc.exe
17:39:20.0605 4880  VSS - ok
17:39:20.0652 4880  [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time        C:\Windows\system32\w32time.dll
17:39:20.0683 4880  W32Time - ok
17:39:20.0730 4880  [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
17:39:20.0792 4880  WacomPen - ok
17:39:20.0870 4880  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
17:39:20.0886 4880  Wanarp - ok
17:39:20.0886 4880  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
17:39:20.0917 4880  Wanarpv6 - ok
17:39:20.0979 4880  [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
17:39:20.0995 4880  wcncsvc - ok
17:39:21.0042 4880  [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:39:21.0073 4880  WcsPlugInService - ok
17:39:21.0104 4880  [ 0C17A0816F65B89E362E682AD5E7266E ] Wd              C:\Windows\system32\drivers\wd.sys
17:39:21.0104 4880  Wd - ok
17:39:21.0166 4880  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
17:39:21.0182 4880  Wdf01000 - ok
17:39:21.0213 4880  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost  C:\Windows\system32\wdi.dll
17:39:21.0244 4880  WdiServiceHost - ok
17:39:21.0260 4880  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost  C:\Windows\system32\wdi.dll
17:39:21.0291 4880  WdiSystemHost - ok
17:39:21.0322 4880  [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient      C:\Windows\System32\webclnt.dll
17:39:21.0338 4880  WebClient - ok
17:39:21.0400 4880  [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc          C:\Windows\system32\wecsvc.dll
17:39:21.0416 4880  Wecsvc - ok
17:39:21.0447 4880  [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
17:39:21.0478 4880  wercplsupport - ok
17:39:21.0494 4880  [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc          C:\Windows\System32\WerSvc.dll
17:39:21.0525 4880  WerSvc - ok
17:39:21.0541 4880  WinHttpAutoProxySvc - ok
17:39:21.0588 4880  [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
17:39:21.0619 4880  Winmgmt - ok
17:39:21.0712 4880  [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM          C:\Windows\system32\WsmSvc.dll
17:39:21.0744 4880  WinRM - ok
17:39:21.0822 4880  [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc        C:\Windows\System32\wlansvc.dll
17:39:21.0868 4880  Wlansvc - ok
17:39:22.0071 4880  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:39:22.0134 4880  wlidsvc - ok
17:39:22.0180 4880  [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
17:39:22.0212 4880  WmiAcpi - ok
17:39:22.0243 4880  [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
17:39:22.0290 4880  wmiApSrv - ok
17:39:22.0336 4880  WMPNetworkSvc - ok
17:39:22.0383 4880  [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
17:39:22.0399 4880  WPCSvc - ok
17:39:22.0461 4880  [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
17:39:22.0508 4880  WPDBusEnum - ok
17:39:22.0555 4880  [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
17:39:22.0586 4880  WpdUsb - ok
17:39:23.0038 4880  [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
17:39:23.0101 4880  WPFFontCache_v0400 - ok
17:39:23.0148 4880  [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
17:39:23.0226 4880  ws2ifsl - ok
17:39:23.0272 4880  WSearch - ok
17:39:23.0319 4880  [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
17:39:23.0397 4880  WUDFRd - ok
17:39:23.0428 4880  [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
17:39:23.0475 4880  wudfsvc - ok
17:39:23.0538 4880  [ 07F7285220307AAFB755D890295F0F9A ] yukonx64        C:\Windows\system32\DRIVERS\yk60x64.sys
17:39:23.0600 4880  yukonx64 - ok
17:39:23.0678 4880  [ 1CACFEF9E5DD866C5B79A135EE729E18 ] {55662437-DA8C-40c0-AADA-2C816A897A49} C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
17:39:23.0694 4880  {55662437-DA8C-40c0-AADA-2C816A897A49} - ok
17:39:23.0694 4880  ================ Scan global ===============================
17:39:23.0756 4880  [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
17:39:23.0818 4880  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
17:39:23.0834 4880  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
17:39:23.0912 4880  [ B8844F93D2C5F1DCDB179AAA9AF134B7 ] C:\Windows\system32\services.exe
17:39:23.0912 4880  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - infected
17:39:23.0912 4880  C:\Windows\system32\services.exe - detected Virus.Win64.ZAccess.a (0)
17:39:23.0912 4880  ================ Scan MBR ==================================
17:39:23.0928 4880  [ 588AE8F0C685C02BA11F30D9CD7E61A0 ] \Device\Harddisk0\DR0
17:39:25.0144 4880  \Device\Harddisk0\DR0 - ok
17:39:25.0144 4880  ================ Scan VBR ==================================
17:39:25.0176 4880  [ 4F671ACB12D2B23C2A215D3B242A1E8F ] \Device\Harddisk0\DR0\Partition1
17:39:25.0191 4880  \Device\Harddisk0\DR0\Partition1 - ok
17:39:25.0222 4880  [ 7B194D67144E38317068B1DBCA999781 ] \Device\Harddisk0\DR0\Partition2
17:39:25.0222 4880  \Device\Harddisk0\DR0\Partition2 - ok
17:39:25.0222 4880  ============================================================
17:39:25.0222 4880  Scan finished
17:39:25.0222 4880  ============================================================
17:39:25.0254 2116  Detected object count: 9
17:39:25.0254 2116  Actual detected object count: 9
17:40:12.0007 2116  Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0007 2116  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0007 2116  DokanMounter ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0007 2116  DokanMounter ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0007 2116  HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0007 2116  HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0007 2116  hpqwmiex ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0007 2116  hpqwmiex ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0022 2116  LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0022 2116  LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0022 2116  RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0022 2116  RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0022 2116  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0022 2116  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0022 2116  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
17:40:12.0022 2116  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:40:12.0475 2116  C:\Windows\system32\services.exe - copied to quarantine
17:40:13.0114 2116  C:\Windows\assembly\GAC_32\desktop.ini - copied to quarantine
17:40:13.0114 2116  C:\Windows\assembly\GAC_64\desktop.ini - copied to quarantine
17:40:54.0813 2116  Backup copy not found, trying to cure infected file..
17:40:54.0813 2116  C:\Windows\system32\services.exe - Cure failed (FFFFFFFF)
17:40:54.0813 2116  C:\Windows\system32\services.exe - processing error
17:40:54.0813 2116  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - User select action: Cure


schustan 08.10.2012 16:51

und das ist der log nach dem rebooten

Hinweis: ich hatte Avira in allen fällen deaktiviert, dh de echtzeit-scanner deaktiviert. das (inaktive) programm läuft aber im hintergrund ..

Code:

17:46:51.0202 1180  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
17:46:51.0217 1180  ============================================================
17:46:51.0217 1180  Current date / time: 2012/10/08 17:46:51.0217
17:46:51.0217 1180  SystemInfo:
17:46:51.0217 1180 
17:46:51.0217 1180  OS Version: 6.0.6002 ServicePack: 2.0
17:46:51.0217 1180  Product type: Workstation
17:46:51.0217 1180  ComputerName: ANDREAS-PC
17:46:51.0217 1180  UserName: Andreas
17:46:51.0217 1180  Windows directory: C:\Windows
17:46:51.0217 1180  System windows directory: C:\Windows
17:46:51.0217 1180  Running under WOW64
17:46:51.0217 1180  Processor architecture: Intel x64
17:46:51.0217 1180  Number of processors: 2
17:46:51.0217 1180  Page size: 0x1000
17:46:51.0217 1180  Boot type: Normal boot
17:46:51.0217 1180  ============================================================
17:46:53.0058 1180  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:46:53.0074 1180  ============================================================
17:46:53.0074 1180  \Device\Harddisk0\DR0:
17:46:53.0074 1180  MBR partitions:
17:46:53.0074 1180  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x38B7A000
17:46:53.0074 1180  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38B7A800, BlocksNum 0x180A000
17:46:53.0074 1180  ============================================================
17:46:53.0323 1180  C: <-> \Device\Harddisk0\DR0\Partition1
17:46:53.0745 1180  D: <-> \Device\Harddisk0\DR0\Partition2
17:46:53.0745 1180  ============================================================
17:46:53.0745 1180  Initialize success
17:46:53.0745 1180  ============================================================
17:46:58.0487 2652  ============================================================
17:46:58.0487 2652  Scan started
17:46:58.0487 2652  Mode: Manual; SigCheck; TDLFS;
17:46:58.0487 2652  ============================================================
17:47:00.0172 2652  ================ Scan system memory ========================
17:47:00.0172 2652  System memory - ok
17:47:00.0172 2652  ================ Scan services =============================
17:47:00.0406 2652  [ 7EEB488346FBFA3731276C3EE8A8FD9E ] AAV UpdateService C:\Program Files (x86)\AAVUpdateManager\aavus.exe
17:47:00.0531 2652  AAV UpdateService - ok
17:47:01.0233 2652  [ 5C368F4B04ED2A923E6AFCA2D37BAFF5 ] Accelerometer  C:\Windows\system32\DRIVERS\Accelerometer.sys
17:47:01.0326 2652  Accelerometer - ok
17:47:01.0498 2652  [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI            C:\Windows\system32\drivers\acpi.sys
17:47:01.0513 2652  ACPI - ok
17:47:02.0137 2652  [ F84C9DEE4698DF3C1D76801B7B1B55D7 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
17:47:02.0465 2652  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
17:47:02.0465 2652  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
17:47:02.0902 2652  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
17:47:02.0917 2652  AdobeARMservice - ok
17:47:03.0105 2652  [ F14215E37CF124104575073F782111D2 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
17:47:03.0198 2652  adp94xx - ok
17:47:03.0307 2652  [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci        C:\Windows\system32\drivers\adpahci.sys
17:47:03.0323 2652  adpahci - ok
17:47:03.0354 2652  [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
17:47:03.0354 2652  adpu160m - ok
17:47:03.0417 2652  [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
17:47:03.0432 2652  adpu320 - ok
17:47:03.0526 2652  [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
17:47:03.0775 2652  AeLookupSvc - ok
17:47:04.0119 2652  [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe
17:47:04.0197 2652  AESTFilters - ok
17:47:04.0259 2652  [ C4F6CE6087760AD70960C9EB130E7943 ] AFD            C:\Windows\system32\drivers\afd.sys
17:47:04.0353 2652  AFD - ok
17:47:04.0431 2652  [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440          C:\Windows\system32\drivers\agp440.sys
17:47:04.0446 2652  agp440 - ok
17:47:04.0477 2652  [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
17:47:04.0493 2652  aic78xx - ok
17:47:04.0509 2652  [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG            C:\Windows\System32\alg.exe
17:47:04.0696 2652  ALG - ok
17:47:04.0774 2652  [ E0CA5BB8E6C79533DC6B1DA7361A201E ] aliide          C:\Windows\system32\drivers\aliide.sys
17:47:04.0774 2652  aliide - ok
17:47:04.0789 2652  [ 7034F8D1B9703D711D3F92C95DEB377D ] amdide          C:\Windows\system32\drivers\amdide.sys
17:47:04.0789 2652  amdide - ok
17:47:04.0852 2652  [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
17:47:04.0899 2652  AmdK8 - ok
17:47:05.0195 2652  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
17:47:05.0211 2652  AntiVirSchedulerService - ok
17:47:05.0304 2652  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
17:47:05.0304 2652  AntiVirService - ok
17:47:05.0351 2652  [ 676894FA57B671FEC5C3F05F8929E03B ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
17:47:05.0367 2652  AntiVirWebService - ok
17:47:05.0445 2652  [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo        C:\Windows\System32\appinfo.dll
17:47:05.0523 2652  Appinfo - ok
17:47:05.0897 2652  [ 70D7BE78061126DD0C3ACCDB7E129017 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
17:47:05.0975 2652  Apple Mobile Device - ok
17:47:06.0022 2652  [ BA8417D4765F3988FF921F30F630E303 ] arc            C:\Windows\system32\drivers\arc.sys
17:47:06.0037 2652  arc - ok
17:47:06.0084 2652  [ 9D41C435619733B34CC16A511E644B11 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
17:47:06.0100 2652  arcsas - ok
17:47:06.0786 2652  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
17:47:06.0849 2652  aspnet_state - ok
17:47:06.0880 2652  [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
17:47:06.0958 2652  AsyncMac - ok
17:47:07.0005 2652  [ E68D9B3A3905619732F7FE039466A623 ] atapi          C:\Windows\system32\drivers\atapi.sys
17:47:07.0005 2652  atapi - ok
17:47:07.0114 2652  [ 54CA8AAC988B441A692311E3B584D944 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
17:47:07.0192 2652  Ati External Event Utility - ok
17:47:08.0065 2652  [ 4B42547AE95A31D0E1E200B68A6C7647 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
17:47:08.0299 2652  atikmdag - ok
17:47:08.0424 2652  [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:47:08.0471 2652  AudioEndpointBuilder - ok
17:47:08.0487 2652  [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
17:47:08.0518 2652  AudioSrv - ok
17:47:08.0611 2652  [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
17:47:08.0627 2652  avgntflt - ok
17:47:08.0705 2652  [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
17:47:08.0721 2652  avipbb - ok
17:47:08.0767 2652  [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
17:47:08.0783 2652  avkmgr - ok
17:47:08.0845 2652  [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
17:47:08.0892 2652  blbdrive - ok
17:47:09.0048 2652  [ 673CF4F6BB1FBE09331B526802FBB892 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
17:47:09.0064 2652  Bonjour Service - ok
17:47:09.0142 2652  [ 2348447A80920B2493A9B582A23E81E1 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
17:47:09.0204 2652  bowser - ok
17:47:09.0282 2652  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
17:47:09.0360 2652  BrFiltLo - ok
17:47:09.0376 2652  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
17:47:09.0438 2652  BrFiltUp - ok
17:47:09.0485 2652  [ A1B39DE453433B115B4EA69EE0343816 ] Browser        C:\Windows\System32\browser.dll
17:47:09.0532 2652  Browser - ok
17:47:09.0594 2652  [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid        C:\Windows\system32\drivers\brserid.sys
17:47:09.0781 2652  Brserid - ok
17:47:09.0844 2652  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
17:47:09.0969 2652  BrSerWdm - ok
17:47:09.0984 2652  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
17:47:10.0078 2652  BrUsbMdm - ok
17:47:10.0093 2652  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
17:47:10.0171 2652  BrUsbSer - ok
17:47:10.0234 2652  [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
17:47:10.0296 2652  BTHMODEM - ok
17:47:10.0327 2652  [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
17:47:10.0390 2652  cdfs - ok
17:47:10.0437 2652  [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
17:47:10.0499 2652  cdrom - ok
17:47:10.0561 2652  [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc    C:\Windows\System32\certprop.dll
17:47:10.0593 2652  CertPropSvc - ok
17:47:10.0639 2652  [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
17:47:10.0702 2652  circlass - ok
17:47:10.0780 2652  [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS            C:\Windows\system32\CLFS.sys
17:47:10.0811 2652  CLFS - ok
17:47:10.0983 2652  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:47:10.0998 2652  clr_optimization_v2.0.50727_32 - ok
17:47:11.0045 2652  [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
17:47:11.0061 2652  clr_optimization_v2.0.50727_64 - ok
17:47:11.0451 2652  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:47:11.0778 2652  clr_optimization_v4.0.30319_32 - ok
17:47:11.0825 2652  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
17:47:11.0887 2652  clr_optimization_v4.0.30319_64 - ok
17:47:11.0950 2652  [ B52D9A14CE4101577900A364BA86F3DF ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
17:47:12.0012 2652  CmBatt - ok
17:47:12.0043 2652  [ 8C6AA24C1D7273A02284588426AB8CE3 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
17:47:12.0059 2652  cmdide - ok
17:47:12.0215 2652  [ 12E94E225BD7B05A2BCCD5C0B841E921 ] Com4QLBEx      C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
17:47:12.0231 2652  Com4QLBEx - ok
17:47:12.0293 2652  [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
17:47:12.0309 2652  Compbatt - ok
17:47:12.0340 2652  COMSysApp - ok
17:47:12.0948 2652  cpuz134 - ok
17:47:12.0995 2652  [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
17:47:13.0011 2652  crcdisk - ok
17:47:13.0120 2652  [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
17:47:13.0510 2652  CryptSvc - ok
17:47:13.0603 2652  [ BA8E5B2291C01EF71CA80E25F0C79D55 ] ctxusbm        C:\Windows\system32\DRIVERS\ctxusbm.sys
17:47:13.0619 2652  ctxusbm - ok
17:47:13.0697 2652  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch      C:\Windows\system32\rpcss.dll
17:47:13.0759 2652  DcomLaunch - ok
17:47:13.0837 2652  [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
17:47:13.0900 2652  DfsC - ok
17:47:14.0508 2652  [ C647F468F7DE343DF8C143655C5557D4 ] DFSR            C:\Windows\system32\DFSR.exe
17:47:14.0742 2652  DFSR - ok
17:47:14.0820 2652  [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
17:47:14.0883 2652  Dhcp - ok
17:47:14.0929 2652  [ B0107E40ECDB5FA692EBF832F295D905 ] disk            C:\Windows\system32\drivers\disk.sys
17:47:14.0945 2652  disk - ok
17:47:15.0007 2652  [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
17:47:15.0085 2652  Dnscache - ok
17:47:15.0148 2652  [ 57AE249F2C6A90476E8E400F0EEC3C56 ] Dokan          C:\Windows\system32\drivers\dokan.sys
17:47:15.0163 2652  Dokan - ok
17:47:15.0319 2652  [ F4FEAE56DA1B5B7DC78D5F9214CDEF5E ] DokanMounter    C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
17:47:15.0335 2652  DokanMounter ( UnsignedFile.Multi.Generic ) - warning
17:47:15.0335 2652  DokanMounter - detected UnsignedFile.Multi.Generic (1)
17:47:15.0444 2652  [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc        C:\Windows\System32\dot3svc.dll
17:47:15.0491 2652  dot3svc - ok
17:47:15.0522 2652  [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS            C:\Windows\system32\dps.dll
17:47:15.0600 2652  DPS - ok
17:47:15.0647 2652  [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
17:47:15.0709 2652  drmkaud - ok
17:47:15.0834 2652  [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
17:47:15.0865 2652  DXGKrnl - ok
17:47:15.0912 2652  [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60          C:\Windows\system32\DRIVERS\E1G6032E.sys
17:47:15.0959 2652  E1G60 - ok
17:47:16.0021 2652  [ C2303883FD9BE49DC36A6400643002EA ] EapHost        C:\Windows\System32\eapsvc.dll
17:47:16.0068 2652  EapHost - ok
17:47:16.0146 2652  [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache          C:\Windows\system32\drivers\ecache.sys
17:47:16.0162 2652  Ecache - ok
17:47:16.0255 2652  [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
17:47:16.0333 2652  ehRecvr - ok
17:47:16.0365 2652  [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched        C:\Windows\ehome\ehsched.exe
17:47:16.0396 2652  ehSched - ok
17:47:16.0443 2652  [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart        C:\Windows\ehome\ehstart.dll
17:47:16.0505 2652  ehstart - ok
17:47:16.0552 2652  [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
17:47:16.0583 2652  elxstor - ok
17:47:16.0630 2652  [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
17:47:16.0708 2652  EMDMgmt - ok
17:47:16.0770 2652  [ F218A3A27ED6592C0E22EC3595554447 ] enecir          C:\Windows\system32\DRIVERS\enecir.sys
17:47:16.0817 2652  enecir - ok
17:47:16.0911 2652  [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev          C:\Windows\system32\drivers\errdev.sys
17:47:16.0957 2652  ErrDev - ok
17:47:17.0035 2652  [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem    C:\Windows\system32\es.dll
17:47:17.0098 2652  EventSystem - ok
17:47:17.0129 2652  [ 486844F47B6636044A42454614ED4523 ] exfat          C:\Windows\system32\drivers\exfat.sys
17:47:17.0207 2652  exfat - ok
17:47:17.0207 2652  ezSharedSvc - ok
17:47:17.0223 2652  [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
17:47:17.0285 2652  fastfat - ok
17:47:17.0316 2652  [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
17:47:17.0394 2652  fdc - ok
17:47:17.0441 2652  [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost        C:\Windows\system32\fdPHost.dll
17:47:17.0503 2652  fdPHost - ok
17:47:17.0519 2652  [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub        C:\Windows\system32\fdrespub.dll
17:47:17.0581 2652  FDResPub - ok
17:47:17.0597 2652  Fildro - ok
17:47:17.0628 2652  [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
17:47:17.0644 2652  FileInfo - ok
17:47:17.0659 2652  [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
17:47:17.0722 2652  Filetrace - ok
17:47:17.0737 2652  [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
17:47:17.0800 2652  flpydisk - ok
17:47:17.0893 2652  [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
17:47:17.0909 2652  FltMgr - ok
17:47:18.0112 2652  [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache      C:\Windows\system32\FntCache.dll
17:47:18.0252 2652  FontCache - ok
17:47:18.0330 2652  [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
17:47:18.0346 2652  FontCache3.0.0.0 - ok
17:47:18.0393 2652  [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
17:47:18.0455 2652  Fs_Rec - ok
17:47:18.0533 2652  [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
17:47:18.0533 2652  gagp30kx - ok
17:47:18.0642 2652  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17:47:18.0658 2652  GEARAspiWDM - ok
17:47:18.0861 2652  [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc          C:\Windows\System32\gpsvc.dll
17:47:18.0892 2652  gpsvc - ok
17:47:19.0017 2652  [ 68E732382B32417FF61FD663259B4B09 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:47:19.0063 2652  HdAudAddService - ok
17:47:19.0141 2652  [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
17:47:19.0219 2652  HDAudBus - ok
17:47:19.0297 2652  [ B4881C84A180E75B8C25DC1D726C375F ] HidBth          C:\Windows\system32\drivers\hidbth.sys
17:47:19.0391 2652  HidBth - ok
17:47:19.0500 2652  [ 5F47839455D01FF6403B008D481A6F5B ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
17:47:19.0594 2652  HidIr - ok
17:47:19.0641 2652  [ 59361D38A297755D46A540E450202B2A ] hidserv        C:\Windows\system32\hidserv.dll
17:47:19.0672 2652  hidserv - ok
17:47:19.0703 2652  [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
17:47:19.0750 2652  HidUsb - ok
17:47:19.0781 2652  [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc          C:\Windows\system32\kmsvc.dll
17:47:19.0859 2652  hkmsvc - ok
17:47:19.0968 2652  [ A19B0BB5A7EB6DF2DD4A0711D36955EE ] HP Health Check Service c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
17:47:19.0984 2652  HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
17:47:19.0984 2652  HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
17:47:20.0077 2652  [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
17:47:20.0093 2652  HpCISSs - ok
17:47:20.0124 2652  [ 4E0BEC0F78096FFD6D3314B497FC49D3 ] hpdskflt        C:\Windows\system32\DRIVERS\hpdskflt.sys
17:47:20.0140 2652  hpdskflt - ok
17:47:20.0233 2652  [ 0ECC54FD34D6A089C300846B011E81D6 ] HpqKbFiltr      C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
17:47:20.0296 2652  HpqKbFiltr - ok
17:47:20.0389 2652  [ 188FF0ADF66768D53AD94F43972E1E9A ] hpqwmiex        C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
17:47:20.0421 2652  hpqwmiex ( UnsignedFile.Multi.Generic ) - warning
17:47:20.0421 2652  hpqwmiex - detected UnsignedFile.Multi.Generic (1)
17:47:20.0467 2652  [ FC7C13B5A9E9BE23B7AE72BBC7FDB278 ] hpsrv          C:\Windows\system32\Hpservice.exe
17:47:20.0483 2652  hpsrv - ok
17:47:20.0592 2652  [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
17:47:20.0655 2652  HTTP - ok
17:47:20.0701 2652  [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
17:47:20.0717 2652  i2omp - ok
17:47:20.0764 2652  [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
17:47:20.0811 2652  i8042prt - ok
17:47:20.0889 2652  [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
17:47:20.0904 2652  iaStorV - ok
17:47:21.0045 2652  [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
17:47:21.0107 2652  idsvc - ok
17:47:21.0169 2652  [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
17:47:21.0185 2652  iirsp - ok
17:47:21.0279 2652  [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT          C:\Windows\System32\ikeext.dll
17:47:21.0325 2652  IKEEXT - ok
17:47:21.0372 2652  [ 475490CAF376E55E6E8B37BBDFEB2E81 ] intelide        C:\Windows\system32\drivers\intelide.sys
17:47:21.0403 2652  intelide - ok
17:47:21.0435 2652  [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
17:47:21.0481 2652  intelppm - ok
17:47:21.0513 2652  [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
17:47:21.0575 2652  IPBusEnum - ok
17:47:21.0653 2652  [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:47:21.0747 2652  IpFilterDriver - ok
17:47:21.0747 2652  IpInIp - ok
17:47:21.0793 2652  [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
17:47:21.0871 2652  IPMIDRV - ok
17:47:21.0887 2652  [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
17:47:21.0949 2652  IPNAT - ok
17:47:22.0121 2652  [ 24595EC9236D7E421661A2D4FFBD901A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
17:47:22.0137 2652  iPod Service - ok
17:47:22.0183 2652  [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
17:47:22.0230 2652  IRENUM - ok
17:47:22.0293 2652  [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
17:47:22.0293 2652  isapnp - ok
17:47:22.0371 2652  [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
17:47:22.0386 2652  iScsiPrt - ok
17:47:22.0417 2652  [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
17:47:22.0433 2652  iteatapi - ok
17:47:22.0511 2652  [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid        C:\Windows\system32\drivers\iteraid.sys
17:47:22.0527 2652  iteraid - ok
17:47:22.0542 2652  [ BB86B1C3489463BBA1FD04C876DBE414 ] JMCR            C:\Windows\system32\DRIVERS\jmcr.sys
17:47:22.0620 2652  JMCR - ok
17:47:22.0667 2652  [ 423696F3BA6472DD17699209B933BC26 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
17:47:22.0667 2652  kbdclass - ok
17:47:22.0729 2652  [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
17:47:22.0807 2652  kbdhid - ok
17:47:22.0854 2652  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso          C:\Windows\system32\lsass.exe
17:47:22.0901 2652  KeyIso - ok
17:47:22.0995 2652  [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
17:47:23.0010 2652  KSecDD - ok
17:47:23.0088 2652  [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
17:47:23.0151 2652  ksthunk - ok
17:47:23.0197 2652  [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm          C:\Windows\system32\msdtckrm.dll
17:47:23.0275 2652  KtmRm - ok
17:47:23.0338 2652  [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer    C:\Windows\system32\srvsvc.dll
17:47:23.0385 2652  LanmanServer - ok
17:47:23.0431 2652  [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:47:23.0494 2652  LanmanWorkstation - ok
17:47:23.0650 2652  [ 83D8BE94E1CBCBE2EA8372DB1A95A159 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
17:47:23.0681 2652  LightScribeService ( UnsignedFile.Multi.Generic ) - warning
17:47:23.0681 2652  LightScribeService - detected UnsignedFile.Multi.Generic (1)
17:47:23.0697 2652  [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
17:47:23.0743 2652  lltdio - ok
17:47:23.0790 2652  [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
17:47:23.0853 2652  lltdsvc - ok
17:47:23.0884 2652  [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts        C:\Windows\System32\lmhsvc.dll
17:47:23.0962 2652  lmhosts - ok
17:47:24.0024 2652  [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
17:47:24.0040 2652  LSI_FC - ok
17:47:24.0055 2652  [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
17:47:24.0071 2652  LSI_SAS - ok
17:47:24.0087 2652  [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
17:47:24.0102 2652  LSI_SCSI - ok
17:47:24.0149 2652  [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv          C:\Windows\system32\drivers\luafv.sys
17:47:24.0227 2652  luafv - ok
17:47:24.0399 2652  [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
17:47:24.0430 2652  McComponentHostService - ok
17:47:24.0461 2652  [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
17:47:24.0477 2652  Mcx2Svc - ok
17:47:24.0539 2652  [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas        C:\Windows\system32\drivers\megasas.sys
17:47:24.0555 2652  megasas - ok
17:47:24.0617 2652  [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
17:47:24.0633 2652  MegaSR - ok
17:47:24.0711 2652  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS          C:\Windows\system32\mmcss.dll
17:47:24.0757 2652  MMCSS - ok
17:47:24.0789 2652  [ 59848D5CC74606F0EE7557983BB73C2E ] Modem          C:\Windows\system32\drivers\modem.sys
17:47:24.0882 2652  Modem - ok
17:47:24.0898 2652  [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
17:47:24.0960 2652  monitor - ok
17:47:24.0976 2652  [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
17:47:24.0991 2652  mouclass - ok
17:47:25.0069 2652  [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
17:47:25.0132 2652  mouhid - ok
17:47:25.0194 2652  [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
17:47:25.0210 2652  MountMgr - ok
17:47:25.0303 2652  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
17:47:25.0319 2652  MozillaMaintenance - ok
17:47:25.0350 2652  [ F8276EB8698142884498A528DFEA8478 ] mpio            C:\Windows\system32\drivers\mpio.sys
17:47:25.0366 2652  mpio - ok
17:47:25.0413 2652  [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
17:47:25.0459 2652  mpsdrv - ok
17:47:25.0475 2652  [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
17:47:25.0491 2652  Mraid35x - ok
17:47:25.0537 2652  [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
17:47:25.0553 2652  MRxDAV - ok
17:47:25.0631 2652  [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
17:47:25.0693 2652  mrxsmb - ok
17:47:25.0756 2652  [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:47:25.0787 2652  mrxsmb10 - ok
17:47:25.0803 2652  [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:47:25.0849 2652  mrxsmb20 - ok
17:47:25.0912 2652  [ AA459F2AB3AB603C357FF117CAE3D818 ] msahci          C:\Windows\system32\drivers\msahci.sys
17:47:25.0927 2652  msahci - ok
17:47:26.0005 2652  [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
17:47:26.0021 2652  msdsm - ok
17:47:26.0083 2652  [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC          C:\Windows\System32\msdtc.exe
17:47:26.0130 2652  MSDTC - ok
17:47:26.0193 2652  [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs            C:\Windows\system32\drivers\Msfs.sys
17:47:26.0255 2652  Msfs - ok
17:47:26.0286 2652  [ 00EBC952961664780D43DCA157E79B27 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
17:47:26.0302 2652  msisadrv - ok
17:47:26.0380 2652  [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
17:47:26.0458 2652  MSiSCSI - ok
17:47:26.0473 2652  msiserver - ok
17:47:26.0505 2652  [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
17:47:26.0551 2652  MSKSSRV - ok
17:47:26.0567 2652  [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
17:47:26.0661 2652  MSPCLOCK - ok
17:47:26.0676 2652  [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
17:47:26.0723 2652  MSPQM - ok
17:47:26.0801 2652  [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
17:47:26.0817 2652  MsRPC - ok
17:47:26.0863 2652  [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
17:47:26.0879 2652  mssmbios - ok
17:47:26.0926 2652  [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
17:47:26.0988 2652  MSTEE - ok
17:47:27.0066 2652  [ 0CC49F78D8ACA0877D885F149084E543 ] Mup            C:\Windows\system32\Drivers\mup.sys
17:47:27.0066 2652  Mup - ok
17:47:27.0144 2652  [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent        C:\Windows\system32\qagentRT.dll
17:47:27.0191 2652  napagent - ok
17:47:27.0269 2652  [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
17:47:27.0300 2652  NativeWifiP - ok
17:47:27.0425 2652  NAVENG - ok
17:47:27.0425 2652  NAVEX15 - ok
17:47:27.0675 2652  [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS            C:\Windows\system32\drivers\ndis.sys
17:47:27.0706 2652  NDIS - ok
17:47:27.0768 2652  [ 64DF698A425478E321981431AC171334 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
17:47:27.0815 2652  NdisTapi - ok
17:47:27.0862 2652  [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
17:47:27.0924 2652  Ndisuio - ok
17:47:27.0987 2652  [ F8158771905260982CE724076419EF19 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
17:47:28.0033 2652  NdisWan - ok
17:47:28.0080 2652  [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
17:47:28.0143 2652  NDProxy - ok
17:47:28.0221 2652  [ 89FD76A90CBE63F03A70C2D1B85E802C ] NEOFLTR_710_19243 C:\Windows\system32\Drivers\NEOFLTR_710_19243.SYS
17:47:28.0236 2652  NEOFLTR_710_19243 - ok
17:47:28.0283 2652  Nero BackItUp Scheduler 4.0 - ok
17:47:28.0299 2652  [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
17:47:28.0408 2652  NetBIOS - ok
17:47:28.0470 2652  [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
17:47:28.0501 2652  netbt - ok
17:47:28.0533 2652  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon        C:\Windows\system32\lsass.exe
17:47:28.0548 2652  Netlogon - ok
17:47:28.0704 2652  [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman          C:\Windows\System32\netman.dll
17:47:28.0813 2652  Netman - ok
17:47:28.0860 2652  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:47:28.0907 2652  NetMsmqActivator - ok
17:47:28.0907 2652  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:47:28.0923 2652  NetPipeActivator - ok
17:47:28.0969 2652  [ 7846D0136CC2B264926A73047BA7688A ] netprofm        C:\Windows\System32\netprofm.dll
17:47:29.0032 2652  netprofm - ok
17:47:29.0047 2652  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:47:29.0063 2652  NetTcpActivator - ok
17:47:29.0063 2652  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:47:29.0079 2652  NetTcpPortSharing - ok
17:47:29.0406 2652  [ C86984AEE87900C1EEB6942EDE3BF4B6 ] NETw3v64        C:\Windows\system32\DRIVERS\NETw3v64.sys
17:47:29.0749 2652  NETw3v64 - ok
17:47:30.0295 2652  [ 2BDCB7B7917380794C9D87AC2153CE33 ] NETw5v64        C:\Windows\system32\DRIVERS\NETw5v64.sys
17:47:31.0403 2652  NETw5v64 - ok
17:47:31.0419 2652  [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
17:47:31.0419 2652  nfrd960 - ok
17:47:31.0465 2652  [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc          C:\Windows\System32\nlasvc.dll
17:47:31.0512 2652  NlaSvc - ok
17:47:31.0575 2652  [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64      C:\Windows\system32\drivers\ccdcmbox64.sys
17:47:31.0637 2652  nmwcdcx64 - ok
17:47:31.0684 2652  [ 76292103C5149EB140419F36DCF26C1B ] nmwcdnsucx64    C:\Windows\system32\drivers\nmwcdnsucx64.sys
17:47:31.0715 2652  nmwcdnsucx64 - ok
17:47:31.0762 2652  [ 2974296DA6296B4FEA3E313BF98C693D ] nmwcdnsux64    C:\Windows\system32\drivers\nmwcdnsux64.sys
17:47:31.0824 2652  nmwcdnsux64 - ok
17:47:31.0871 2652  [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64        C:\Windows\system32\drivers\ccdcmbx64.sys
17:47:31.0918 2652  nmwcdx64 - ok
17:47:31.0918 2652  Norton Internet Security - ok
17:47:31.0965 2652  [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
17:47:31.0996 2652  Npfs - ok
17:47:32.0058 2652  [ ACB62BAA1C319B17752553DF3026EEEB ] nsi            C:\Windows\system32\nsisvc.dll
17:47:32.0136 2652  nsi - ok
17:47:32.0214 2652  [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
17:47:32.0323 2652  nsiproxy - ok
17:47:32.0620 2652  [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
17:47:32.0807 2652  Ntfs - ok
17:47:32.0885 2652  [ DD5D684975352B85B52E3FD5347C20CB ] Null            C:\Windows\system32\drivers\Null.sys
17:47:32.0994 2652  Null - ok
17:47:33.0072 2652  [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
17:47:33.0088 2652  nvraid - ok
17:47:33.0103 2652  [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor          C:\Windows\system32\drivers\nvstor.sys
17:47:33.0103 2652  nvstor - ok
17:47:33.0135 2652  [ 19067CA93075EF4823E3938A686F532F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
17:47:33.0150 2652  nv_agp - ok
17:47:33.0150 2652  NwlnkFlt - ok
17:47:33.0150 2652  NwlnkFwd - ok
17:47:33.0228 2652  [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
17:47:33.0259 2652  ohci1394 - ok
17:47:33.0322 2652  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:47:33.0337 2652  ose - ok
17:47:33.0447 2652  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc        C:\Windows\system32\p2psvc.dll
17:47:33.0509 2652  p2pimsvc - ok
17:47:33.0509 2652  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc          C:\Windows\system32\p2psvc.dll
17:47:33.0540 2652  p2psvc - ok
17:47:33.0587 2652  [ AECD57F94C887F58919F307C35498EA0 ] Parport        C:\Windows\system32\drivers\parport.sys
17:47:33.0649 2652  Parport - ok
17:47:33.0712 2652  [ B43751085E2ABE389DA466BC62A4B987 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
17:47:33.0712 2652  partmgr - ok
17:47:33.0759 2652  [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc          C:\Windows\System32\pcasvc.dll
17:47:33.0852 2652  PcaSvc - ok
17:47:33.0915 2652  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
17:47:33.0977 2652  pccsmcfd - ok
17:47:34.0039 2652  [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci            C:\Windows\system32\drivers\pci.sys
17:47:34.0055 2652  pci - ok
17:47:34.0227 2652  [ 15E5C3F89A3452EFBDA3B39816DBC4EE ] pciide          C:\Windows\system32\drivers\pciide.sys
17:47:34.0242 2652  pciide - ok
17:47:34.0320 2652  [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
17:47:34.0336 2652  pcmcia - ok
17:47:34.0367 2652  [ 58865916F53592A61549B04941BFD80D ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
17:47:34.0492 2652  PEAUTH - ok
17:47:34.0757 2652  [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
17:47:34.0882 2652  PerfHost - ok
17:47:35.0038 2652  [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla            C:\Windows\system32\pla.dll
17:47:35.0178 2652  pla - ok
17:47:35.0319 2652  [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
17:47:35.0350 2652  PlugPlay - ok
17:47:35.0490 2652  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
17:47:35.0521 2652  PNRPAutoReg - ok
17:47:35.0662 2652  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc        C:\Windows\system32\p2psvc.dll
17:47:35.0693 2652  PNRPsvc - ok
17:47:35.0927 2652  [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
17:47:36.0021 2652  PolicyAgent - ok
17:47:36.0177 2652  [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
17:47:36.0270 2652  PptpMiniport - ok
17:47:36.0364 2652  [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor      C:\Windows\system32\drivers\processr.sys
17:47:36.0442 2652  Processor - ok
17:47:36.0520 2652  [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc        C:\Windows\system32\profsvc.dll
17:47:36.0551 2652  ProfSvc - ok
17:47:36.0567 2652  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
17:47:36.0582 2652  ProtectedStorage - ok
17:47:36.0645 2652  [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
17:47:36.0676 2652  PSched - ok
17:47:36.0785 2652  [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300          C:\Windows\system32\drivers\ql2300.sys
17:47:36.0832 2652  ql2300 - ok
17:47:36.0847 2652  [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
17:47:36.0879 2652  ql40xx - ok
17:47:36.0925 2652  [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE          C:\Windows\system32\qwave.dll
17:47:36.0941 2652  QWAVE - ok
17:47:36.0957 2652  [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
17:47:37.0003 2652  QWAVEdrv - ok
17:47:37.0050 2652  [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
17:47:37.0097 2652  RasAcd - ok
17:47:37.0113 2652  [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto        C:\Windows\System32\rasauto.dll
17:47:37.0175 2652  RasAuto - ok
17:47:37.0237 2652  [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
17:47:37.0300 2652  Rasl2tp - ok
17:47:37.0331 2652  [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan          C:\Windows\System32\rasmans.dll
17:47:37.0378 2652  RasMan - ok
17:47:37.0425 2652  [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
17:47:37.0487 2652  RasPppoe - ok
17:47:37.0518 2652  [ C6A593B51F34C33E5474539544072527 ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
17:47:37.0534 2652  RasSstp - ok
17:47:37.0612 2652  [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
17:47:37.0690 2652  rdbss - ok
17:47:37.0721 2652  [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
17:47:37.0768 2652  RDPCDD - ok
17:47:37.0783 2652  [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
17:47:37.0830 2652  rdpdr - ok
17:47:37.0861 2652  [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
17:47:37.0908 2652  RDPENCDD - ok
17:47:37.0986 2652  [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
17:47:38.0049 2652  RDPWD - ok
17:47:38.0111 2652  [ BC0A4D47472B042537F4E57B950415FA ] Recovery Service for Windows C:\Program Files (x86)\SMINST\BLService.exe
17:47:38.0127 2652  Recovery Service for Windows - ok
17:47:38.0173 2652  [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess    C:\Windows\System32\mprdim.dll
17:47:38.0251 2652  RemoteAccess - ok
17:47:38.0361 2652  [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
17:47:38.0392 2652  RemoteRegistry - ok
17:47:38.0532 2652  [ 805AE1F90C64758D19AAA001CF8CBA12 ] RichVideo      C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
17:47:38.0595 2652  RichVideo ( UnsignedFile.Multi.Generic ) - warning
17:47:38.0595 2652  RichVideo - detected UnsignedFile.Multi.Generic (1)
17:47:38.0626 2652  [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator      C:\Windows\system32\locator.exe
17:47:38.0688 2652  RpcLocator - ok
17:47:38.0922 2652  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs          C:\Windows\system32\rpcss.dll
17:47:39.0000 2652  RpcSs - ok
17:47:39.0063 2652  [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
17:47:39.0125 2652  rspndr - ok
17:47:39.0187 2652  [ 8B91737DA75ADD21CB1554B38089196A ] RTL8169        C:\Windows\system32\DRIVERS\Rtlh64.sys
17:47:39.0265 2652  RTL8169 - ok
17:47:39.0281 2652  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs          C:\Windows\system32\lsass.exe
17:47:39.0281 2652  SamSs - ok
17:47:39.0328 2652  [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
17:47:39.0343 2652  sbp2port - ok
17:47:39.0375 2652  [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr        C:\Windows\System32\SCardSvr.dll
17:47:39.0390 2652  SCardSvr - ok
17:47:39.0484 2652  [ 0F838C811AD295D2A4489B9993096C63 ] Schedule        C:\Windows\system32\schedsvc.dll
17:47:39.0546 2652  Schedule - ok
17:47:39.0640 2652  [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc    C:\Windows\System32\certprop.dll
17:47:39.0671 2652  SCPolicySvc - ok
17:47:39.0702 2652  [ B42EE50F7D24F837F925332EB349ECA5 ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
17:47:39.0765 2652  sdbus - ok
17:47:39.0796 2652  [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
17:47:39.0858 2652  SDRSVC - ok
17:47:40.0092 2652  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
17:47:40.0092 2652  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
17:47:40.0092 2652  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
17:47:40.0139 2652  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
17:47:40.0295 2652  secdrv - ok
17:47:40.0404 2652  [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon        C:\Windows\system32\seclogon.dll
17:47:40.0529 2652  seclogon - ok
17:47:40.0545 2652  [ 90973A64B96CD647FF81C79443618EED ] SENS            C:\Windows\System32\sens.dll
17:47:40.0607 2652  SENS - ok
17:47:40.0638 2652  [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum        C:\Windows\system32\drivers\serenum.sys
17:47:40.0685 2652  Serenum - ok
17:47:40.0701 2652  [ E62FAC91EE288DB29A9696A9D279929C ] Serial          C:\Windows\system32\drivers\serial.sys
17:47:40.0747 2652  Serial - ok
17:47:40.0763 2652  [ A842F04833684BCEEA7336211BE478DF ] sermouse        C:\Windows\system32\drivers\sermouse.sys
17:47:40.0810 2652  sermouse - ok
17:47:40.0966 2652  [ 58D5BFDF3ADF49FE9CABD78CC61D92F6 ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
17:47:41.0013 2652  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
17:47:41.0013 2652  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
17:47:41.0091 2652  [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv      C:\Windows\system32\sessenv.dll
17:47:41.0153 2652  SessionEnv - ok
17:47:41.0200 2652  [ 14D4B4465193A87C127933978E8C4106 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
17:47:41.0231 2652  sffdisk - ok
17:47:41.0247 2652  [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
17:47:41.0293 2652  sffp_mmc - ok
17:47:41.0325 2652  [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
17:47:41.0387 2652  sffp_sd - ok
17:47:41.0403 2652  [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
17:47:41.0465 2652  sfloppy - ok
17:47:41.0574 2652  [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:47:41.0637 2652  ShellHWDetection - ok
17:47:41.0683 2652  [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
17:47:41.0699 2652  SiSRaid2 - ok
17:47:41.0730 2652  [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
17:47:41.0746 2652  SiSRaid4 - ok
17:47:41.0839 2652  [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
17:47:41.0855 2652  SkypeUpdate - ok
17:47:42.0432 2652  [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc          C:\Windows\system32\SLsvc.exe
17:47:42.0604 2652  slsvc - ok
17:47:42.0682 2652  [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify      C:\Windows\system32\SLUINotify.dll
17:47:42.0744 2652  SLUINotify - ok
17:47:42.0760 2652  [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
17:47:42.0822 2652  Smb - ok
17:47:42.0869 2652  [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
17:47:42.0916 2652  SNMPTRAP - ok
17:47:42.0947 2652  [ 386C3C63F00A7040C7EC5E384217E89D ] spldr          C:\Windows\system32\drivers\spldr.sys
17:47:42.0963 2652  spldr - ok
17:47:43.0041 2652  [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler        C:\Windows\System32\spoolsv.exe
17:47:43.0087 2652  Spooler - ok
17:47:43.0103 2652  SRTSP - ok
17:47:43.0103 2652  SRTSPX - ok
17:47:43.0150 2652  [ 880A57FCCB571EBD063D4DD50E93E46D ] srv            C:\Windows\system32\DRIVERS\srv.sys
17:47:43.0197 2652  srv - ok
17:47:43.0259 2652  [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
17:47:43.0337 2652  srv2 - ok
17:47:43.0353 2652  [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
17:47:43.0399 2652  srvnet - ok
17:47:43.0431 2652  [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
17:47:43.0524 2652  SSDPSRV - ok
17:47:43.0633 2652  [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc        C:\Windows\system32\sstpsvc.dll
17:47:43.0665 2652  SstpSvc - ok
17:47:43.0899 2652  [ 72EB6157E892A674E47E08732BB5CCE3 ] STacSV          C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe
17:47:43.0961 2652  STacSV - ok
17:47:44.0117 2652  [ 0C7BDA7E9A329A071C080EB5210FE019 ] STHDA          C:\Windows\system32\DRIVERS\stwrt64.sys
17:47:44.0195 2652  STHDA - ok
17:47:44.0335 2652  [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc          C:\Windows\System32\wiaservc.dll
17:47:44.0429 2652  stisvc - ok
17:47:44.0476 2652  [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
17:47:44.0507 2652  swenum - ok
17:47:44.0616 2652  [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv          C:\Windows\System32\swprv.dll
17:47:44.0710 2652  swprv - ok
17:47:44.0741 2652  [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
17:47:44.0772 2652  Symc8xx - ok
17:47:44.0819 2652  [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
17:47:44.0850 2652  Sym_hi - ok
17:47:44.0866 2652  [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
17:47:44.0897 2652  Sym_u3 - ok
17:47:44.0975 2652  [ 3A706A967295E16511E40842B1A2761D ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
17:47:44.0991 2652  SynTP - ok
17:47:45.0069 2652  [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain        C:\Windows\system32\sysmain.dll
17:47:45.0115 2652  SysMain - ok
17:47:45.0178 2652  [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:47:45.0240 2652  TabletInputService - ok
17:47:45.0287 2652  [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv        C:\Windows\System32\tapisrv.dll
17:47:45.0349 2652  TapiSrv - ok
17:47:45.0412 2652  [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS            C:\Windows\System32\tbssvc.dll
17:47:45.0490 2652  TBS - ok
17:47:45.0724 2652  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
17:47:45.0786 2652  Tcpip - ok
17:47:45.0802 2652  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
17:47:45.0849 2652  Tcpip6 - ok
17:47:45.0927 2652  [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
17:47:45.0989 2652  tcpipreg - ok
17:47:46.0051 2652  [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
17:47:46.0129 2652  TDPIPE - ok
17:47:46.0145 2652  [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
17:47:46.0223 2652  TDTCP - ok
17:47:46.0363 2652  [ 458919C8C42E398DC4802178D5FFEE27 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
17:47:46.0395 2652  tdx - ok
17:47:46.0441 2652  [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
17:47:46.0457 2652  TermDD - ok
17:47:46.0597 2652  [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService    C:\Windows\System32\termsrv.dll
17:47:46.0675 2652  TermService - ok
17:47:46.0707 2652  [ 56793271ECDEDD350C5ADD305603E963 ] Themes          C:\Windows\system32\shsvcs.dll
17:47:46.0738 2652  Themes - ok
17:47:46.0785 2652  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER    C:\Windows\system32\mmcss.dll
17:47:46.0831 2652  THREADORDER - ok
17:47:46.0925 2652  [ 0407143F2BBC1A5DD5B518AC0704FCBF ] TomTomHOMEService C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
17:47:46.0941 2652  TomTomHOMEService - ok
17:47:46.0987 2652  [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks          C:\Windows\System32\trkwks.dll
17:47:47.0065 2652  TrkWks - ok
17:47:47.0143 2652  [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:47:47.0206 2652  TrustedInstaller - ok
17:47:47.0268 2652  [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
17:47:47.0299 2652  tssecsrv - ok
17:47:47.0346 2652  [ 89EC74A9E602D16A75A4170511029B3C ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
17:47:47.0393 2652  tunmp - ok
17:47:47.0424 2652  [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
17:47:47.0471 2652  tunnel - ok
17:47:47.0752 2652  [ 1C31169DDDC70C1605F703DA701EAEEA ] TVCapSvc        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
17:47:47.0783 2652  TVCapSvc - ok
17:47:47.0799 2652  [ 290B8C381DBC15D3DBCBD2BDB6B0BA12 ] TVSched        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
17:47:47.0830 2652  TVSched - ok
17:47:47.0861 2652  [ FEC266EF401966311744BD0F359F7F56 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
17:47:47.0892 2652  uagp35 - ok
17:47:48.0095 2652  [ FAF2640A2A76ED03D449E443194C4C34 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
17:47:48.0189 2652  udfs - ok
17:47:48.0235 2652  [ 060507C4113391394478F6953A79EEDC ] UI0Detect      C:\Windows\system32\UI0Detect.exe
17:47:48.0313 2652  UI0Detect - ok
17:47:48.0345 2652  [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
17:47:48.0360 2652  uliagpkx - ok
17:47:48.0391 2652  [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci        C:\Windows\system32\drivers\uliahci.sys
17:47:48.0407 2652  uliahci - ok
17:47:48.0423 2652  [ 31707F09846056651EA2C37858F5DDB0 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
17:47:48.0438 2652  UlSata - ok
17:47:48.0485 2652  [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
17:47:48.0516 2652  ulsata2 - ok
17:47:48.0547 2652  [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
17:47:48.0579 2652  umbus - ok
17:47:48.0641 2652  [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost        C:\Windows\System32\upnphost.dll
17:47:48.0688 2652  upnphost - ok
17:47:48.0735 2652  [ 9856C38AB8FAACCA4DD99DAC7B42F838 ] upperdev        C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
17:47:48.0797 2652  upperdev - ok
17:47:48.0859 2652  [ CD03479F2DA26500B203ED075C146A7A ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
17:47:48.0906 2652  USBAAPL64 - ok
17:47:48.0984 2652  [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
17:47:49.0047 2652  usbaudio - ok
17:47:49.0093 2652  [ 07E3498FC60834219D2356293DA0FECC ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
17:47:49.0156 2652  usbccgp - ok
17:47:49.0249 2652  [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
17:47:49.0312 2652  usbcir - ok
17:47:49.0374 2652  [ 827E44DE934A736EA31E91D353EB126F ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
17:47:49.0405 2652  usbehci - ok
17:47:49.0515 2652  [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
17:47:49.0593 2652  usbhub - ok
17:47:49.0655 2652  [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
17:47:49.0733 2652  usbohci - ok
17:47:49.0764 2652  [ ACFEE697AF477021BB3EC78C5431FED2 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
17:47:49.0842 2652  usbprint - ok
17:47:49.0905 2652  [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
17:47:49.0936 2652  usbscan - ok
17:47:49.0967 2652  [ F7386007FB19E7685FC7B298560AA81F ] usbser          C:\Windows\system32\drivers\usbser.sys
17:47:50.0014 2652  usbser - ok
17:47:50.0045 2652  [ 89123DC822AC7A708BD4C9E196A37610 ] UsbserFilt      C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys
17:47:50.0123 2652  UsbserFilt - ok
17:47:50.0170 2652  [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:47:50.0217 2652  USBSTOR - ok
17:47:50.0295 2652  [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
17:47:50.0341 2652  usbuhci - ok
17:47:50.0388 2652  [ FC33099877790D51B0927B7039059855 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
17:47:50.0419 2652  usbvideo - ok
17:47:50.0466 2652  [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms          C:\Windows\System32\uxsms.dll
17:47:50.0513 2652  UxSms - ok
17:47:50.0544 2652  [ 294945381DFA7CE58CECF0A9896AF327 ] vds            C:\Windows\System32\vds.exe
17:47:50.0591 2652  vds - ok
17:47:50.0669 2652  [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
17:47:50.0731 2652  vga - ok
17:47:50.0778 2652  [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave        C:\Windows\System32\drivers\vga.sys
17:47:50.0809 2652  VgaSave - ok
17:47:50.0841 2652  [ 4F964E6828156F0EF3FA8D3A9A7895DE ] viaide          C:\Windows\system32\drivers\viaide.sys
17:47:50.0856 2652  viaide - ok
17:47:50.0887 2652  [ 2B7E885ED951519A12C450D24535DFCA ] volmgr          C:\Windows\system32\drivers\volmgr.sys
17:47:50.0903 2652  volmgr - ok
17:47:50.0950 2652  [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
17:47:50.0965 2652  volmgrx - ok
17:47:51.0028 2652  [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap        C:\Windows\system32\drivers\volsnap.sys
17:47:51.0059 2652  volsnap - ok
17:47:51.0106 2652  [ A68F455ED2673835209318DD61BFBB0E ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
17:47:51.0121 2652  vsmraid - ok
17:47:51.0418 2652  [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS            C:\Windows\system32\vssvc.exe
17:47:51.0589 2652  VSS - ok
17:47:51.0636 2652  [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time        C:\Windows\system32\w32time.dll
17:47:51.0714 2652  W32Time - ok
17:47:51.0745 2652  [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
17:47:51.0839 2652  WacomPen - ok
17:47:51.0933 2652  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
17:47:51.0964 2652  Wanarp - ok
17:47:51.0964 2652  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
17:47:52.0011 2652  Wanarpv6 - ok
17:47:52.0104 2652  [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
17:47:52.0151 2652  wcncsvc - ok
17:47:52.0213 2652  [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:47:52.0245 2652  WcsPlugInService - ok
17:47:52.0276 2652  [ 0C17A0816F65B89E362E682AD5E7266E ] Wd              C:\Windows\system32\drivers\wd.sys
17:47:52.0291 2652  Wd - ok
17:47:52.0479 2652  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
17:47:52.0510 2652  Wdf01000 - ok
17:47:52.0557 2652  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost  C:\Windows\system32\wdi.dll
17:47:52.0619 2652  WdiServiceHost - ok
17:47:52.0619 2652  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost  C:\Windows\system32\wdi.dll
17:47:52.0666 2652  WdiSystemHost - ok
17:47:52.0728 2652  [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient      C:\Windows\System32\webclnt.dll
17:47:52.0775 2652  WebClient - ok
17:47:52.0837 2652  [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc          C:\Windows\system32\wecsvc.dll
17:47:52.0900 2652  Wecsvc - ok
17:47:52.0931 2652  [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
17:47:52.0993 2652  wercplsupport - ok
17:47:53.0009 2652  [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc          C:\Windows\System32\WerSvc.dll
17:47:53.0056 2652  WerSvc - ok
17:47:53.0071 2652  WinHttpAutoProxySvc - ok
17:47:53.0212 2652  [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
17:47:53.0274 2652  Winmgmt - ok
17:47:53.0461 2652  [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM          C:\Windows\system32\WsmSvc.dll
17:47:53.0602 2652  WinRM - ok
17:47:53.0649 2652  [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc        C:\Windows\System32\wlansvc.dll
17:47:53.0758 2652  Wlansvc - ok
17:47:54.0319 2652  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:47:54.0507 2652  wlidsvc - ok
17:47:54.0553 2652  [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
17:47:54.0616 2652  WmiAcpi - ok
17:47:54.0694 2652  [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
17:47:54.0756 2652  wmiApSrv - ok
17:47:54.0803 2652  WMPNetworkSvc - ok
17:47:54.0928 2652  [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
17:47:54.0990 2652  WPCSvc - ok
17:47:55.0053 2652  [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
17:47:55.0099 2652  WPDBusEnum - ok
17:47:55.0146 2652  [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
17:47:55.0177 2652  WpdUsb - ok
17:47:56.0067 2652  [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
17:47:56.0191 2652  WPFFontCache_v0400 - ok
17:47:56.0238 2652  [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
17:47:56.0347 2652  ws2ifsl - ok
17:47:56.0394 2652  WSearch - ok
17:47:56.0425 2652  [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
17:47:56.0472 2652  WUDFRd - ok
17:47:56.0503 2652  [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
17:47:56.0566 2652  wudfsvc - ok
17:47:56.0628 2652  [ 07F7285220307AAFB755D890295F0F9A ] yukonx64        C:\Windows\system32\DRIVERS\yk60x64.sys
17:47:56.0722 2652  yukonx64 - ok
17:47:56.0800 2652  [ 1CACFEF9E5DD866C5B79A135EE729E18 ] {55662437-DA8C-40c0-AADA-2C816A897A49} C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
17:47:56.0815 2652  {55662437-DA8C-40c0-AADA-2C816A897A49} - ok
17:47:56.0815 2652  ================ Scan global ===============================
17:47:56.0893 2652  [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
17:47:57.0049 2652  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
17:47:57.0065 2652  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
17:47:57.0190 2652  [ B8844F93D2C5F1DCDB179AAA9AF134B7 ] C:\Windows\system32\services.exe
17:47:57.0205 2652  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - infected
17:47:57.0205 2652  C:\Windows\system32\services.exe - detected Virus.Win64.ZAccess.a (0)
17:47:57.0205 2652  ================ Scan MBR ==================================
17:47:57.0221 2652  [ 588AE8F0C685C02BA11F30D9CD7E61A0 ] \Device\Harddisk0\DR0
17:47:57.0985 2652  \Device\Harddisk0\DR0 - ok
17:47:57.0985 2652  ================ Scan VBR ==================================
17:47:58.0017 2652  [ 4F671ACB12D2B23C2A215D3B242A1E8F ] \Device\Harddisk0\DR0\Partition1
17:47:58.0017 2652  \Device\Harddisk0\DR0\Partition1 - ok
17:47:58.0063 2652  [ 7B194D67144E38317068B1DBCA999781 ] \Device\Harddisk0\DR0\Partition2
17:47:58.0079 2652  \Device\Harddisk0\DR0\Partition2 - ok
17:47:58.0079 2652  ============================================================
17:47:58.0079 2652  Scan finished
17:47:58.0079 2652  ============================================================
17:47:58.0095 4060  Detected object count: 9
17:47:58.0095 4060  Actual detected object count: 9
17:48:04.0756 4060  Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0756 4060  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0756 4060  DokanMounter ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0756 4060  DokanMounter ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0756 4060  HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0756 4060  HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0756 4060  hpqwmiex ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0756 4060  hpqwmiex ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0756 4060  LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0756 4060  LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0771 4060  RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0771 4060  RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0771 4060  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0771 4060  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0771 4060  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
17:48:04.0771 4060  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:48:04.0771 4060  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - skipped by user
17:48:04.0771 4060  C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - User select action: Skip


cosinus 08.10.2012 16:57

Ok, der TDSS-Killer schafft es nicht

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

schustan 08.10.2012 17:21

jetzt kommt die meldung, dass ein real-time-scanner aktiv sein:

antivirus: avira desktop
antispyware: avira desktop

ich soll beides beenden ehe ich auf OK klicke. allerdings hab ich avira vorsichtshalber sogar mal deinstalliert. ich versteh nicht, wie das angeblich noch laufen kann ..
auch im taskmanager finde ich nichts, was nach "avira desktop" aussieht ..

was mach ich jetzt? ich kann bei der combo-fix-warnmeldung ja nur "OK" klicken, oder oben rechts mit dem "X" schließen ...

im taskmanager unter "dienste" läuft noch der "AAV UpdateService" .. soll ich den beenden?

cosinus 08.10.2012 18:34

Das ist ein Bug, ignorier es und lass CF laufen

schustan 08.10.2012 19:36

seit ca 40min heißts in diesem DOS-Fenster jetzt ..

System file is infected !! attempting to restore
"C:\Windows\system32.exe"

ist das normal, dass das soo lang dauert?

so .. endlich ;-)

bin schon nervös geworden, nachdem es hieß "etwa 10min" ..

Code:

ComboFix 12-10-08.02 - Andreas 08.10.2012  19:42:28.1.2 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.4092.2842 [GMT 2:00]
ausgeführt von:: c:\users\Andreas\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\xp-AntiSpy
c:\program files (x86)\xp-AntiSpy\Uninstall.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.chm
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.url
c:\users\Andreas\AppData\Local\lame_enc.dll
c:\users\Andreas\AppData\Local\no23xwrapper.dll
c:\users\Andreas\AppData\Local\ogg.dll
c:\users\Andreas\AppData\Local\vorbis.dll
c:\users\Andreas\AppData\Local\vorbisenc.dll
c:\users\Andreas\AppData\Local\vorbisfile.dll
c:\users\Andreas\Favorites\Lesezeichen Firefix 2010-03-19.json
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\IsUn0407.exe
.
c:\windows\system32\Services.exe . . . ist infiziert!!
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-08 bis 2012-10-08  ))))))))))))))))))))))))))))))
.
.
2012-10-08 19:26 . 2012-10-08 19:26        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-08 14:23 . 2012-10-08 14:23        208216        ----a-w-        c:\windows\system32\drivers\54311847.sys
2012-10-08 14:15 . 2012-10-08 15:40        --------        d-----w-        C:\TDSSKiller_Quarantine
2012-10-07 20:29 . 2012-10-07 20:29        --------        d-----w-        C:\_OTL
2012-10-05 18:39 . 2012-10-05 18:39        --------        d-----w-        c:\program files (x86)\ESET
2012-10-05 18:39 . 2012-10-05 18:39        --------        d-sh--w-        c:\windows\SysWow64\%APPDATA%
2012-10-04 15:27 . 2012-10-04 15:27        --------        d-----w-        c:\users\Andreas\AppData\Roaming\Malwarebytes
2012-10-04 15:26 . 2012-10-04 15:26        --------        d-----w-        c:\programdata\Malwarebytes
2012-10-04 15:26 . 2012-10-04 15:26        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-04 15:26 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-10-03 10:46 . 2012-10-03 10:46        --------        d-----w-        c:\program files\Reimage
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\users\Andreas\AppData\Local\Macroplant_LLC
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\program files (x86)\Dokan
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\program files (x86)\Phone Disk
2012-10-02 06:16 . 2012-08-30 07:27        9308616        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{A803EFB6-DF71-4A90-8D14-9BAD4D5468FB}\mpengine.dll
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\program files (x86)\Common Files\Adobe AIR
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\program files (x86)\GMX SMS-Manager
2012-09-26 19:51 . 2012-09-26 19:51        --------        d-----w-        c:\program files (x86)\Bigasoft Audio Converter
2012-09-26 19:46 . 2012-09-26 19:46        --------        d-----w-        c:\programdata\AVS4YOU
2012-09-26 19:46 . 2012-09-26 19:46        --------        d-----w-        c:\users\Andreas\AppData\Roaming\AVS4YOU
2012-09-26 19:45 . 2012-09-26 19:49        --------        d-----w-        c:\program files (x86)\AVS4YOU
2012-09-26 19:44 . 2012-03-26 10:27        11137024        ----a-w-        c:\windows\SysWow64\libmfxsw32.dll
2012-09-26 19:44 . 2010-11-12 18:18        1700352        ----a-w-        c:\windows\SysWow64\GdiPlus.dll
2012-09-26 19:44 . 2010-11-12 18:18        24576        ----a-w-        c:\windows\SysWow64\msxml3a.dll
2012-09-26 19:43 . 2012-09-26 19:49        --------        d-----w-        c:\program files (x86)\Common Files\AVSMedia
2012-09-18 18:56 . 2012-09-18 18:56        --------        d-----w-        c:\program files (x86)\No.23 Recorder
2012-09-18 18:29 . 2012-09-18 18:29        --------        d-----w-        c:\program files (x86)\Lame For Audacity
2012-09-18 18:15 . 2012-06-09 17:21        206336        ----a-w-        c:\windows\system32\unrar.dll
2012-09-18 18:15 . 2011-12-07 17:37        148992        ----a-w-        c:\windows\system32\lagarith.dll
2012-09-18 18:15 . 2012-08-17 18:00        127488        ----a-w-        c:\windows\system32\ff_vfw.dll
2012-09-18 18:15 . 2012-09-18 18:15        --------        d-----w-        c:\program files\K-Lite Codec Pack x64
2012-09-18 17:24 . 2012-09-18 17:24        --------        d-----w-        c:\users\AppData
2012-09-18 17:23 . 2012-09-18 18:12        --------        d-----w-        c:\users\Andreas\AppData\Roaming\NCH Software
2012-09-18 17:21 . 2012-09-18 18:12        --------        d-----w-        c:\programdata\NCH Software
2012-09-17 10:44 . 2012-09-17 10:44        --------        d-----w-        c:\users\Andreas\AppData\Roaming\HandBrake
2012-09-17 10:40 . 2012-09-17 10:41        --------        d-----w-        c:\program files (x86)\DVDVideoSoft Free Studio
2012-09-15 15:24 . 2012-09-18 18:14        --------        d-----w-        c:\programdata\VistaCodecs
2012-09-15 14:17 . 2012-09-15 14:17        --------        d-----w-        c:\users\Andreas\AppData\Roaming\TuneUp Software
2012-09-15 14:16 . 2012-09-15 14:18        --------        d-----w-        c:\programdata\TuneUp Software
2012-09-15 14:16 . 2012-09-15 14:16        --------        d-sh--w-        c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-09-15 14:16 . 2012-09-15 14:16        --------        d--h--w-        c:\programdata\Common Files
2012-09-15 14:16 . 2009-09-27 07:39        369152        ----a-w-        c:\windows\SysWow64\avisynth.dll
2012-09-15 14:16 . 2005-07-14 10:31        32256        ----a-w-        c:\windows\SysWow64\AVSredirect.dll
2012-09-15 14:16 . 2004-02-22 08:11        719872        ----a-w-        c:\windows\SysWow64\devil.dll
2012-09-15 14:16 . 2004-01-24 22:00        70656        ----a-w-        c:\windows\SysWow64\yv12vfw.dll
2012-09-15 14:16 . 2004-01-24 22:00        70656        ----a-w-        c:\windows\SysWow64\i420vfw.dll
2012-09-15 14:16 . 2012-09-15 14:16        --------        d-----w-        c:\program files (x86)\AviSynth 2.5
2012-09-15 14:14 . 2004-07-01 23:00        327749        ----a-w-        c:\windows\SysWow64\drvc.dll
2012-09-15 14:13 . 2012-09-15 14:13        --------        d-----w-        c:\program files (x86)\eRightSoft
2012-09-15 11:26 . 2012-09-15 11:26        --------        d-----w-        c:\programdata\xml_param
2012-09-15 11:22 . 2012-09-15 11:22        --------        d-----w-        c:\users\Andreas\AppData\Roaming\iSkysoft Video Converter
2012-09-15 11:22 . 2011-08-31 12:39        892928        ----a-w-        c:\windows\SysWow64\iconv.dll
2012-09-15 11:22 . 2011-08-31 12:39        675840        ----a-w-        c:\windows\SysWow64\ac3filter.ax
2012-09-15 11:22 . 2011-08-31 12:39        496640        ----a-w-        c:\windows\SysWow64\xvid.ax
2012-09-15 10:56 . 2012-09-15 10:56        --------        d-----w-        c:\program files (x86)\Ashampoo
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-03 10:11 . 2012-08-18 18:25        696240        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-03 10:11 . 2011-05-31 06:56        73136        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-12 11:38 . 2006-11-02 12:35        64462936        ----a-w-        c:\windows\system32\mrt.exe
2012-08-28 18:24 . 2012-08-18 17:52        477168        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll
2012-08-28 18:24 . 2010-05-12 05:05        473072        ----a-w-        c:\windows\SysWow64\deployJava1.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-04-10 . B8844F93D2C5F1DCDB179AAA9AF134B7 . 381952 . . [6.0.6000.16386] .. c:\windows\system32\services.exe
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"Infium"="c:\program files (x86)\QIP 2010\qip.exe" [2011-08-22 6821248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2009-09-12 103768]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"PDFPrint"="c:\program files (x86)\pdf24\pdf24.exe" [2011-12-16 220744]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
Microsoft Office.lnk - c:\programme\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
S2 AAV UpdateService;AAV UpdateService;c:\program files (x86)\AAVUpdateManager\aavus.exe [2008-10-24 128296]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe [2009-03-02 89600]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11        451872        ----a-w-        c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2010-07-06 c:\windows\Tasks\{05622D7C-E102-421F-B9BD-F587BF569F37}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2010-07-06 c:\windows\Tasks\{26D45942-2C27-4338-93C2-049F1A435729}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
2010-07-06 c:\windows\Tasks\{5B63F7D2-B10D-4B25-BCB3-4D2BBBDB9ABC}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
2010-07-06 c:\windows\Tasks\{6E02B945-C0CE-453A-9BA6-230DC76E1BAC}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2011-04-01 c:\windows\Tasks\{83EBD7E3-5521-4D5A-897A-E105084669EA}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2009-05-18 c:\windows\Tasks\{B9B31758-9ABD-4FBC-875D-D4AA867B25D5}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-03 442368]
"Launch LCDMon"="c:\program files\Common Files\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 790552]
"Ocs_SM"="c:\users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2012-08-21 106496]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = https://webzugang.brnet.de/dana-na/auth/url_default/welcome.cgi
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mStart Page =
mDefault_Page_URL =
mLocal Page =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Free YouTube Download - c:\users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to Mp3 Converter - c:\users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\programme\Microsoft Office\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
LSP: mswsock.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\
FF - prefs.js: browser.startup.homepage - heute.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SmartMenu - c:\program files (x86)\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
AddRemove-Siedler3Deinstall - c:\windows\IsUn0407.exe
AddRemove-Siedler3MissionUninstall - c:\windows\IsUn0407.exe
AddRemove-Winamp - c:\programme\Winamp\UninstWA.exe
AddRemove-WinRAR archiver - c:\programme\WinRaR\uninstall.exe
AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BFE]
"ImagePath"="."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MpsSvc]
"ImagePath"="."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Dokan\DokanLibrary\mounter.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\SMINST\BLService.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
c:\program files (x86)\Citrix\ICA Client\wfcrun32.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
c:\program files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-10-08  21:38:51 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-10-08 19:38
.
Vor Suchlauf: 12 Verzeichnis(se), 240.287.813.632 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 240.238.755.840 Bytes frei
.
- - End Of File - - D05ECE5EC57DEA1AE8909F528533F940


cosinus 09.10.2012 10:52

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

Filelook::
c:\windows\system32\drivers\54311847.sys
c:\windows\system32\services.exe

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

schustan 09.10.2012 17:07

jetzt heißt es erstmal:

Zitat:

There's a newer version of ComboFix available.

Would you like to update ComboFix?
Ja/Nein?

cosinus 09.10.2012 18:55

Ja! So steht es auch in meiner ersten Anleitung

Zitat:

führe die Updates durch (falls vorgeschlagen),

schustan 09.10.2012 21:04

sorry .. is mir irgendwie durchgegangen

hier der neue log:

Code:

ComboFix 12-10-09.01 - Andreas 09.10.2012  20:08:29.1.2 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.4092.2604 [GMT 2:00]
ausgeführt von:: c:\users\Andreas\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Andreas\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\Services.exe . . . ist infiziert!!
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-09 bis 2012-10-09  ))))))))))))))))))))))))))))))
.
.
2012-10-09 19:47 . 2012-10-09 19:47        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-08 14:23 . 2012-10-08 14:23        208216        ----a-w-        c:\windows\system32\drivers\54311847.sys
2012-10-08 14:15 . 2012-10-08 15:40        --------        d-----w-        C:\TDSSKiller_Quarantine
2012-10-07 20:29 . 2012-10-07 20:29        --------        d-----w-        C:\_OTL
2012-10-05 18:39 . 2012-10-05 18:39        --------        d-----w-        c:\program files (x86)\ESET
2012-10-05 18:39 . 2012-10-05 18:39        --------        d-sh--w-        c:\windows\SysWow64\%APPDATA%
2012-10-04 15:27 . 2012-10-04 15:27        --------        d-----w-        c:\users\Andreas\AppData\Roaming\Malwarebytes
2012-10-04 15:26 . 2012-10-04 15:26        --------        d-----w-        c:\programdata\Malwarebytes
2012-10-04 15:26 . 2012-10-04 15:26        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-04 15:26 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-10-03 10:46 . 2012-10-03 10:46        --------        d-----w-        c:\program files\Reimage
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\users\Andreas\AppData\Local\Macroplant_LLC
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\program files (x86)\Dokan
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\program files (x86)\Phone Disk
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\program files (x86)\Common Files\Adobe AIR
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\program files (x86)\GMX SMS-Manager
2012-09-26 19:51 . 2012-09-26 19:51        --------        d-----w-        c:\program files (x86)\Bigasoft Audio Converter
2012-09-26 19:46 . 2012-09-26 19:46        --------        d-----w-        c:\programdata\AVS4YOU
2012-09-26 19:46 . 2012-09-26 19:46        --------        d-----w-        c:\users\Andreas\AppData\Roaming\AVS4YOU
2012-09-26 19:45 . 2012-09-26 19:49        --------        d-----w-        c:\program files (x86)\AVS4YOU
2012-09-26 19:44 . 2012-03-26 10:27        11137024        ----a-w-        c:\windows\SysWow64\libmfxsw32.dll
2012-09-26 19:44 . 2010-11-12 18:18        1700352        ----a-w-        c:\windows\SysWow64\GdiPlus.dll
2012-09-26 19:44 . 2010-11-12 18:18        24576        ----a-w-        c:\windows\SysWow64\msxml3a.dll
2012-09-26 19:43 . 2012-09-26 19:49        --------        d-----w-        c:\program files (x86)\Common Files\AVSMedia
2012-09-18 18:56 . 2012-09-18 18:56        --------        d-----w-        c:\program files (x86)\No.23 Recorder
2012-09-18 18:29 . 2012-09-18 18:29        --------        d-----w-        c:\program files (x86)\Lame For Audacity
2012-09-18 18:15 . 2012-06-09 17:21        206336        ----a-w-        c:\windows\system32\unrar.dll
2012-09-18 18:15 . 2011-12-07 17:37        148992        ----a-w-        c:\windows\system32\lagarith.dll
2012-09-18 18:15 . 2012-08-17 18:00        127488        ----a-w-        c:\windows\system32\ff_vfw.dll
2012-09-18 18:15 . 2012-09-18 18:15        --------        d-----w-        c:\program files\K-Lite Codec Pack x64
2012-09-18 17:24 . 2012-10-08 19:38        --------        d-----w-        c:\users\AppData
2012-09-18 17:23 . 2012-09-18 18:12        --------        d-----w-        c:\users\Andreas\AppData\Roaming\NCH Software
2012-09-18 17:21 . 2012-09-18 18:12        --------        d-----w-        c:\programdata\NCH Software
2012-09-17 10:44 . 2012-09-17 10:44        --------        d-----w-        c:\users\Andreas\AppData\Roaming\HandBrake
2012-09-17 10:40 . 2012-09-17 10:41        --------        d-----w-        c:\program files (x86)\DVDVideoSoft Free Studio
2012-09-15 15:24 . 2012-09-18 18:14        --------        d-----w-        c:\programdata\VistaCodecs
2012-09-15 14:17 . 2012-09-15 14:17        --------        d-----w-        c:\users\Andreas\AppData\Roaming\TuneUp Software
2012-09-15 14:16 . 2012-09-15 14:18        --------        d-----w-        c:\programdata\TuneUp Software
2012-09-15 14:16 . 2012-09-15 14:16        --------        d-sh--w-        c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-09-15 14:16 . 2012-09-15 14:16        --------        d--h--w-        c:\programdata\Common Files
2012-09-15 14:16 . 2009-09-27 07:39        369152        ----a-w-        c:\windows\SysWow64\avisynth.dll
2012-09-15 14:16 . 2005-07-14 10:31        32256        ----a-w-        c:\windows\SysWow64\AVSredirect.dll
2012-09-15 14:16 . 2004-02-22 08:11        719872        ----a-w-        c:\windows\SysWow64\devil.dll
2012-09-15 14:16 . 2004-01-24 22:00        70656        ----a-w-        c:\windows\SysWow64\yv12vfw.dll
2012-09-15 14:16 . 2004-01-24 22:00        70656        ----a-w-        c:\windows\SysWow64\i420vfw.dll
2012-09-15 14:16 . 2012-09-15 14:16        --------        d-----w-        c:\program files (x86)\AviSynth 2.5
2012-09-15 14:14 . 2004-07-01 23:00        327749        ----a-w-        c:\windows\SysWow64\drvc.dll
2012-09-15 14:13 . 2012-09-15 14:13        --------        d-----w-        c:\program files (x86)\eRightSoft
2012-09-15 11:26 . 2012-09-15 11:26        --------        d-----w-        c:\programdata\xml_param
2012-09-15 11:22 . 2012-09-15 11:22        --------        d-----w-        c:\users\Andreas\AppData\Roaming\iSkysoft Video Converter
2012-09-15 11:22 . 2011-08-31 12:39        892928        ----a-w-        c:\windows\SysWow64\iconv.dll
2012-09-15 11:22 . 2011-08-31 12:39        675840        ----a-w-        c:\windows\SysWow64\ac3filter.ax
2012-09-15 11:22 . 2011-08-31 12:39        496640        ----a-w-        c:\windows\SysWow64\xvid.ax
2012-09-15 10:56 . 2012-09-15 10:56        --------        d-----w-        c:\program files (x86)\Ashampoo
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-03 10:11 . 2012-08-18 18:25        696240        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-03 10:11 . 2011-05-31 06:56        73136        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-12 11:38 . 2006-11-02 12:35        64462936        ----a-w-        c:\windows\system32\mrt.exe
2012-08-30 07:27 . 2012-10-09 16:14        9308616        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{E00222FC-A86C-4DD0-99E7-86FF04D7C87F}\mpengine.dll
2012-08-28 18:24 . 2012-08-18 17:52        477168        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll
2012-08-28 18:24 . 2010-05-12 05:05        473072        ----a-w-        c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((((((((((  Look  )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--- c:\windows\system32\drivers\54311847.sys ---
Company: Kaspersky Lab, GERT
File Description: Kaspersky Lab Mini Driver
File Version: 2.8.4.0 built by: WinDDK
Product Name: Kaspersky Lab Mini Driver
Copyright: Copyright (c) Kaspersky Lab, GERT
Original Filename: klmd.sys
File size: 208216
Created time: 2012-10-08 14:23
Modified time: 2012-10-08 14:23
MD5: F146E2BA475893DD77B2370DC1211FC6
SHA1: B34C5CDBC9597694131FD20562DB201F62E6D1FE
.
.
--- c:\windows\system32\services.exe ---
Company: Microsoft Corporation
File Description: Anwendung für Dienste und Controller
File Version: 6.0.6000.16386 (vista_rtm.061101-2205)
Product Name: Betriebssystem Microsoft® Windows®
Copyright: © Microsoft Corporation. Alle Rechte vorbehalten.
Original Filename: services.exe.mui
File size: 381952
Created time: 2009-05-26 20:40
Modified time: 2009-04-10 22:10
MD5: B8844F93D2C5F1DCDB179AAA9AF134B7
SHA1: 6EA7D8B4EBA6063B1B13CA8A4EF8BF295B43E83D
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-04-10 . B8844F93D2C5F1DCDB179AAA9AF134B7 . 381952 . . [6.0.6000.16386] .. c:\windows\system32\services.exe
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"Infium"="c:\program files (x86)\QIP 2010\qip.exe" [2011-08-22 6821248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2009-09-12 103768]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"PDFPrint"="c:\program files (x86)\pdf24\pdf24.exe" [2011-12-16 220744]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
Microsoft Office.lnk - c:\programme\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
S2 AAV UpdateService;AAV UpdateService;c:\program files (x86)\AAVUpdateManager\aavus.exe [2008-10-24 128296]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe [2009-03-02 89600]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11        451872        ----a-w-        c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2010-07-06 c:\windows\Tasks\{05622D7C-E102-421F-B9BD-F587BF569F37}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2010-07-06 c:\windows\Tasks\{26D45942-2C27-4338-93C2-049F1A435729}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
2010-07-06 c:\windows\Tasks\{5B63F7D2-B10D-4B25-BCB3-4D2BBBDB9ABC}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
2010-07-06 c:\windows\Tasks\{6E02B945-C0CE-453A-9BA6-230DC76E1BAC}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2011-04-01 c:\windows\Tasks\{83EBD7E3-5521-4D5A-897A-E105084669EA}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2009-05-18 c:\windows\Tasks\{B9B31758-9ABD-4FBC-875D-D4AA867B25D5}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-03 442368]
"SmartMenu"="c:\program files (x86)\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [BU]
"Launch LCDMon"="c:\program files\Common Files\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 790552]
"Ocs_SM"="c:\users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2012-08-21 106496]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = https://webzugang.brnet.de/dana-na/auth/url_default/welcome.cgi
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mStart Page =
mDefault_Page_URL =
mLocal Page =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Free YouTube Download - c:\users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to Mp3 Converter - c:\users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\programme\Microsoft Office\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
LSP: mswsock.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\
FF - prefs.js: browser.startup.homepage - heute.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Siedler3Deinstall - c:\windows\IsUn0407.exe
AddRemove-Siedler3MissionUninstall - c:\windows\IsUn0407.exe
AddRemove-Winamp - c:\programme\Winamp\UninstWA.exe
AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MpsSvc]
"ImagePath"="."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Dokan\DokanLibrary\mounter.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\SMINST\BLService.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
c:\program files (x86)\Citrix\ICA Client\wfcrun32.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
c:\program files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-10-09  22:00:07 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-10-09 20:00
ComboFix2.txt  2012-10-08 19:38
.
Vor Suchlauf: 18 Verzeichnis(se), 252.608.864.256 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 252.591.325.184 Bytes frei
.
- - End Of File - - F7D804CE17BDE496C091EC41B6B8780E


cosinus 10.10.2012 10:58

Lade mal diese Datei => File-Upload.net - services.exe runter direkt auf den Desktop

Dann gehts so weiter:

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.


Code:

FCopy::
c:\users\Andreas\Desktop\services.exe | c:\windows\system32\Services.exe

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

schustan 10.10.2012 12:53

und das nächste :-)

Code:

ComboFix 12-10-09.01 - Andreas 10.10.2012  12:47:02.1.2 - x64
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.4092.2602 [GMT 2:00]
ausgeführt von:: c:\users\Andreas\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Andreas\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
.
.
--------------- FCopy ---------------
.
c:\users\Andreas\Desktop\services.exe --> c:\windows\system32\Services.exe
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-10 bis 2012-10-10  ))))))))))))))))))))))))))))))
.
.
2012-10-10 10:56 . 2012-10-10 10:56        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-10 10:37 . 2012-10-10 10:37        --------        d-----w-        C:\TB
2012-10-09 16:14 . 2012-08-30 07:27        9308616        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{E00222FC-A86C-4DD0-99E7-86FF04D7C87F}\mpengine.dll
2012-10-08 14:23 . 2012-10-08 14:23        208216        ----a-w-        c:\windows\system32\drivers\54311847.sys
2012-10-08 14:15 . 2012-10-08 15:40        --------        d-----w-        C:\TDSSKiller_Quarantine
2012-10-07 20:29 . 2012-10-07 20:29        --------        d-----w-        C:\_OTL
2012-10-05 18:39 . 2012-10-05 18:39        --------        d-----w-        c:\program files (x86)\ESET
2012-10-05 18:39 . 2012-10-05 18:39        --------        d-sh--w-        c:\windows\SysWow64\%APPDATA%
2012-10-04 15:27 . 2012-10-04 15:27        --------        d-----w-        c:\users\Andreas\AppData\Roaming\Malwarebytes
2012-10-04 15:26 . 2012-10-04 15:26        --------        d-----w-        c:\programdata\Malwarebytes
2012-10-04 15:26 . 2012-10-04 15:26        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-04 15:26 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-10-03 10:46 . 2012-10-03 10:46        --------        d-----w-        c:\program files\Reimage
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\users\Andreas\AppData\Local\Macroplant_LLC
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\program files (x86)\Dokan
2012-10-03 09:12 . 2012-10-03 09:12        --------        d-----w-        c:\program files (x86)\Phone Disk
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\users\Andreas\AppData\Roaming\com.unitedinternet.ums.sms-mms-manager
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\program files (x86)\Common Files\Adobe AIR
2012-09-30 06:46 . 2012-09-30 06:46        --------        d-----w-        c:\program files (x86)\GMX SMS-Manager
2012-09-26 19:51 . 2012-09-26 19:51        --------        d-----w-        c:\program files (x86)\Bigasoft Audio Converter
2012-09-26 19:46 . 2012-09-26 19:46        --------        d-----w-        c:\programdata\AVS4YOU
2012-09-26 19:46 . 2012-09-26 19:46        --------        d-----w-        c:\users\Andreas\AppData\Roaming\AVS4YOU
2012-09-26 19:45 . 2012-09-26 19:49        --------        d-----w-        c:\program files (x86)\AVS4YOU
2012-09-26 19:44 . 2012-03-26 10:27        11137024        ----a-w-        c:\windows\SysWow64\libmfxsw32.dll
2012-09-26 19:44 . 2010-11-12 18:18        1700352        ----a-w-        c:\windows\SysWow64\GdiPlus.dll
2012-09-26 19:44 . 2010-11-12 18:18        24576        ----a-w-        c:\windows\SysWow64\msxml3a.dll
2012-09-26 19:43 . 2012-09-26 19:49        --------        d-----w-        c:\program files (x86)\Common Files\AVSMedia
2012-09-18 18:56 . 2012-09-18 18:56        --------        d-----w-        c:\program files (x86)\No.23 Recorder
2012-09-18 18:29 . 2012-09-18 18:29        --------        d-----w-        c:\program files (x86)\Lame For Audacity
2012-09-18 18:15 . 2012-06-09 17:21        206336        ----a-w-        c:\windows\system32\unrar.dll
2012-09-18 18:15 . 2011-12-07 17:37        148992        ----a-w-        c:\windows\system32\lagarith.dll
2012-09-18 18:15 . 2012-08-17 18:00        127488        ----a-w-        c:\windows\system32\ff_vfw.dll
2012-09-18 18:15 . 2012-09-18 18:15        --------        d-----w-        c:\program files\K-Lite Codec Pack x64
2012-09-18 17:24 . 2012-10-08 19:38        --------        d-----w-        c:\users\AppData
2012-09-18 17:23 . 2012-09-18 18:12        --------        d-----w-        c:\users\Andreas\AppData\Roaming\NCH Software
2012-09-18 17:21 . 2012-09-18 18:12        --------        d-----w-        c:\programdata\NCH Software
2012-09-17 10:44 . 2012-09-17 10:44        --------        d-----w-        c:\users\Andreas\AppData\Roaming\HandBrake
2012-09-17 10:40 . 2012-09-17 10:41        --------        d-----w-        c:\program files (x86)\DVDVideoSoft Free Studio
2012-09-15 15:24 . 2012-09-18 18:14        --------        d-----w-        c:\programdata\VistaCodecs
2012-09-15 14:17 . 2012-09-15 14:17        --------        d-----w-        c:\users\Andreas\AppData\Roaming\TuneUp Software
2012-09-15 14:16 . 2012-09-15 14:18        --------        d-----w-        c:\programdata\TuneUp Software
2012-09-15 14:16 . 2012-09-15 14:16        --------        d-sh--w-        c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-09-15 14:16 . 2012-09-15 14:16        --------        d--h--w-        c:\programdata\Common Files
2012-09-15 14:16 . 2009-09-27 07:39        369152        ----a-w-        c:\windows\SysWow64\avisynth.dll
2012-09-15 14:16 . 2005-07-14 10:31        32256        ----a-w-        c:\windows\SysWow64\AVSredirect.dll
2012-09-15 14:16 . 2004-02-22 08:11        719872        ----a-w-        c:\windows\SysWow64\devil.dll
2012-09-15 14:16 . 2004-01-24 22:00        70656        ----a-w-        c:\windows\SysWow64\yv12vfw.dll
2012-09-15 14:16 . 2004-01-24 22:00        70656        ----a-w-        c:\windows\SysWow64\i420vfw.dll
2012-09-15 14:16 . 2012-09-15 14:16        --------        d-----w-        c:\program files (x86)\AviSynth 2.5
2012-09-15 14:14 . 2004-07-01 23:00        327749        ----a-w-        c:\windows\SysWow64\drvc.dll
2012-09-15 14:13 . 2012-09-15 14:13        --------        d-----w-        c:\program files (x86)\eRightSoft
2012-09-15 11:26 . 2012-09-15 11:26        --------        d-----w-        c:\programdata\xml_param
2012-09-15 11:22 . 2012-09-15 11:22        --------        d-----w-        c:\users\Andreas\AppData\Roaming\iSkysoft Video Converter
2012-09-15 11:22 . 2011-08-31 12:39        892928        ----a-w-        c:\windows\SysWow64\iconv.dll
2012-09-15 11:22 . 2011-08-31 12:39        675840        ----a-w-        c:\windows\SysWow64\ac3filter.ax
2012-09-15 11:22 . 2011-08-31 12:39        496640        ----a-w-        c:\windows\SysWow64\xvid.ax
2012-09-15 10:56 . 2012-09-15 10:56        --------        d-----w-        c:\program files (x86)\Ashampoo
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 10:39 . 2009-05-26 20:40        384512        ----a-w-        c:\windows\system32\Services.exe
2012-10-03 10:11 . 2012-08-18 18:25        696240        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-03 10:11 . 2011-05-31 06:56        73136        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-09-12 11:38 . 2006-11-02 12:35        64462936        ----a-w-        c:\windows\system32\mrt.exe
2012-08-28 18:24 . 2012-08-18 17:52        477168        ----a-w-        c:\windows\SysWow64\npdeployJava1.dll
2012-08-28 18:24 . 2010-05-12 05:05        473072        ----a-w-        c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        94208        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"Infium"="c:\program files (x86)\QIP 2010\qip.exe" [2011-08-22 6821248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2009-09-12 103768]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"PDFPrint"="c:\program files (x86)\pdf24\pdf24.exe" [2011-12-16 220744]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
Microsoft Office.lnk - c:\programme\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute        REG_MULTI_SZ          autocheck autochk *\0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
S2 AAV UpdateService;AAV UpdateService;c:\program files (x86)\AAVUpdateManager\aavus.exe [2008-10-24 128296]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe [2009-03-02 89600]
.
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11        451872        ----a-w-        c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2010-07-06 c:\windows\Tasks\{05622D7C-E102-421F-B9BD-F587BF569F37}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2010-07-06 c:\windows\Tasks\{26D45942-2C27-4338-93C2-049F1A435729}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
2010-07-06 c:\windows\Tasks\{5B63F7D2-B10D-4B25-BCB3-4D2BBBDB9ABC}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
2010-07-06 c:\windows\Tasks\{6E02B945-C0CE-453A-9BA6-230DC76E1BAC}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2011-04-01 c:\windows\Tasks\{83EBD7E3-5521-4D5A-897A-E105084669EA}.job
- c:\program files (x86)\mozilla firefox\firefox.exe [2012-09-08 09:37]
.
2009-05-18 c:\windows\Tasks\{B9B31758-9ABD-4FBC-875D-D4AA867B25D5}.job
- c:\program files (x86)\Skype\Phone\Skype.exe [2012-02-29 07:55]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58        97792        ----a-w-        c:\users\Andreas\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-03 442368]
"SmartMenu"="c:\program files (x86)\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [BU]
"Launch LCDMon"="c:\program files\Common Files\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 790552]
"Ocs_SM"="c:\users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2012-08-21 106496]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = https://webzugang.brnet.de/dana-na/auth/url_default/welcome.cgi
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mStart Page =
mDefault_Page_URL =
mLocal Page =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Free YouTube Download - c:\users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to Mp3 Converter - c:\users\Andreas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\programme\Microsoft Office\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\pn21nwmv.default\
FF - prefs.js: browser.startup.homepage - heute.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Siedler3Deinstall - c:\windows\IsUn0407.exe
AddRemove-Siedler3MissionUninstall - c:\windows\IsUn0407.exe
AddRemove-Winamp - c:\programme\Winamp\UninstWA.exe
AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BFE]
"ImagePath"="."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MpsSvc]
"ImagePath"="."
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\SMINST\BLService.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
c:\program files (x86)\Citrix\ICA Client\wfcrun32.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
c:\program files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-10-10  13:13:04 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-10-10 11:12
ComboFix2.txt  2012-10-09 20:00
ComboFix3.txt  2012-10-08 19:38
.
Vor Suchlauf: 19 Verzeichnis(se), 249.362.980.864 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 250.012.704.768 Bytes frei
.
- - End Of File - - 37D272C0B6A07F79618B318C3C227904


cosinus 10.10.2012 14:12

Das ist wesentlich besser :daumenhoc

Der TDSS-Killer sollte nun auch nichts mehr anzeigen, mach damit bitte nochmal ein neues Log um das zu demonstrieren

schustan 10.10.2012 17:08

:-) das klingt gut!

hier nochmal der log ...

Code:

18:05:46.0356 2056  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
18:05:46.0512 2056  ============================================================
18:05:46.0512 2056  Current date / time: 2012/10/10 18:05:46.0512
18:05:46.0512 2056  SystemInfo:
18:05:46.0512 2056 
18:05:46.0512 2056  OS Version: 6.0.6002 ServicePack: 2.0
18:05:46.0512 2056  Product type: Workstation
18:05:46.0512 2056  ComputerName: ANDREAS-PC
18:05:46.0512 2056  UserName: Andreas
18:05:46.0512 2056  Windows directory: C:\Windows
18:05:46.0512 2056  System windows directory: C:\Windows
18:05:46.0512 2056  Running under WOW64
18:05:46.0512 2056  Processor architecture: Intel x64
18:05:46.0512 2056  Number of processors: 2
18:05:46.0512 2056  Page size: 0x1000
18:05:46.0512 2056  Boot type: Normal boot
18:05:46.0512 2056  ============================================================
18:05:48.0322 2056  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:05:48.0400 2056  ============================================================
18:05:48.0400 2056  \Device\Harddisk0\DR0:
18:05:48.0400 2056  MBR partitions:
18:05:48.0400 2056  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x38B7A000
18:05:48.0400 2056  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38B7A800, BlocksNum 0x180A000
18:05:48.0400 2056  ============================================================
18:05:48.0525 2056  C: <-> \Device\Harddisk0\DR0\Partition1
18:05:48.0712 2056  D: <-> \Device\Harddisk0\DR0\Partition2
18:05:48.0712 2056  ============================================================
18:05:48.0712 2056  Initialize success
18:05:48.0712 2056  ============================================================
18:06:33.0188 2880  ============================================================
18:06:33.0188 2880  Scan started
18:06:33.0188 2880  Mode: Manual; SigCheck; TDLFS;
18:06:33.0188 2880  ============================================================
18:06:34.0031 2880  ================ Scan system memory ========================
18:06:34.0031 2880  System memory - ok
18:06:34.0031 2880  ================ Scan services =============================
18:06:34.0187 2880  [ 7EEB488346FBFA3731276C3EE8A8FD9E ] AAV UpdateService C:\Program Files (x86)\AAVUpdateManager\aavus.exe
18:06:34.0296 2880  AAV UpdateService - ok
18:06:34.0624 2880  [ 5C368F4B04ED2A923E6AFCA2D37BAFF5 ] Accelerometer  C:\Windows\system32\DRIVERS\Accelerometer.sys
18:06:34.0639 2880  Accelerometer - ok
18:06:34.0717 2880  [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI            C:\Windows\system32\drivers\acpi.sys
18:06:34.0733 2880  ACPI - ok
18:06:34.0842 2880  [ F84C9DEE4698DF3C1D76801B7B1B55D7 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
18:06:34.0858 2880  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
18:06:34.0858 2880  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
18:06:35.0029 2880  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
18:06:35.0045 2880  AdobeARMservice - ok
18:06:35.0138 2880  [ F14215E37CF124104575073F782111D2 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
18:06:35.0154 2880  adp94xx - ok
18:06:35.0216 2880  [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci        C:\Windows\system32\drivers\adpahci.sys
18:06:35.0279 2880  adpahci - ok
18:06:35.0310 2880  [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
18:06:35.0326 2880  adpu160m - ok
18:06:35.0357 2880  [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
18:06:35.0372 2880  adpu320 - ok
18:06:35.0435 2880  [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
18:06:35.0466 2880  AeLookupSvc - ok
18:06:35.0747 2880  [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\AESTSr64.exe
18:06:35.0825 2880  AESTFilters - ok
18:06:35.0903 2880  [ C4F6CE6087760AD70960C9EB130E7943 ] AFD            C:\Windows\system32\drivers\afd.sys
18:06:36.0043 2880  AFD - ok
18:06:36.0121 2880  [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440          C:\Windows\system32\drivers\agp440.sys
18:06:36.0152 2880  agp440 - ok
18:06:36.0199 2880  [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
18:06:36.0230 2880  aic78xx - ok
18:06:36.0262 2880  [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG            C:\Windows\System32\alg.exe
18:06:36.0355 2880  ALG - ok
18:06:36.0402 2880  [ E0CA5BB8E6C79533DC6B1DA7361A201E ] aliide          C:\Windows\system32\drivers\aliide.sys
18:06:36.0418 2880  aliide - ok
18:06:36.0433 2880  [ 7034F8D1B9703D711D3F92C95DEB377D ] amdide          C:\Windows\system32\drivers\amdide.sys
18:06:36.0433 2880  amdide - ok
18:06:36.0480 2880  [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
18:06:36.0527 2880  AmdK8 - ok
18:06:36.0589 2880  [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo        C:\Windows\System32\appinfo.dll
18:06:36.0605 2880  Appinfo - ok
18:06:36.0948 2880  [ 70D7BE78061126DD0C3ACCDB7E129017 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:06:36.0979 2880  Apple Mobile Device - ok
18:06:37.0073 2880  [ BA8417D4765F3988FF921F30F630E303 ] arc            C:\Windows\system32\drivers\arc.sys
18:06:37.0104 2880  arc - ok
18:06:37.0166 2880  [ 9D41C435619733B34CC16A511E644B11 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
18:06:37.0198 2880  arcsas - ok
18:06:37.0837 2880  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
18:06:37.0868 2880  aspnet_state - ok
18:06:37.0915 2880  [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
18:06:37.0993 2880  AsyncMac - ok
18:06:38.0056 2880  [ E68D9B3A3905619732F7FE039466A623 ] atapi          C:\Windows\system32\drivers\atapi.sys
18:06:38.0071 2880  atapi - ok
18:06:38.0149 2880  [ 54CA8AAC988B441A692311E3B584D944 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
18:06:38.0227 2880  Ati External Event Utility - ok
18:06:38.0617 2880  [ 4B42547AE95A31D0E1E200B68A6C7647 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
18:06:38.0789 2880  atikmdag - ok
18:06:38.0898 2880  [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:06:38.0976 2880  AudioEndpointBuilder - ok
18:06:38.0992 2880  [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
18:06:39.0023 2880  AudioSrv - ok
18:06:39.0038 2880  Beep - ok
18:06:39.0054 2880  BFE - ok
18:06:39.0257 2880  [ 6D316F4859634071CC25C4FD4589AD2C ] BITS            C:\Windows\system32\qmgr.dll
18:06:39.0335 2880  BITS - ok
18:06:39.0397 2880  [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
18:06:39.0428 2880  blbdrive - ok
18:06:39.0600 2880  [ 673CF4F6BB1FBE09331B526802FBB892 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
18:06:39.0616 2880  Bonjour Service - ok
18:06:39.0678 2880  [ 2348447A80920B2493A9B582A23E81E1 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
18:06:39.0725 2880  bowser - ok
18:06:39.0803 2880  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
18:06:39.0818 2880  BrFiltLo - ok
18:06:39.0881 2880  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
18:06:39.0912 2880  BrFiltUp - ok
18:06:39.0990 2880  [ A1B39DE453433B115B4EA69EE0343816 ] Browser        C:\Windows\System32\browser.dll
18:06:40.0037 2880  Browser - ok
18:06:40.0099 2880  [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid        C:\Windows\system32\drivers\brserid.sys
18:06:40.0162 2880  Brserid - ok
18:06:40.0224 2880  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
18:06:40.0286 2880  BrSerWdm - ok
18:06:40.0318 2880  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
18:06:40.0396 2880  BrUsbMdm - ok
18:06:40.0489 2880  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
18:06:40.0536 2880  BrUsbSer - ok
18:06:40.0614 2880  [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
18:06:40.0661 2880  BTHMODEM - ok
18:06:40.0692 2880  catchme - ok
18:06:40.0708 2880  [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
18:06:40.0739 2880  cdfs - ok
18:06:40.0817 2880  [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
18:06:40.0832 2880  cdrom - ok
18:06:40.0895 2880  [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc    C:\Windows\System32\certprop.dll
18:06:40.0910 2880  CertPropSvc - ok
18:06:40.0973 2880  [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
18:06:41.0004 2880  circlass - ok
18:06:41.0129 2880  [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS            C:\Windows\system32\CLFS.sys
18:06:41.0207 2880  CLFS - ok
18:06:41.0316 2880  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:06:41.0332 2880  clr_optimization_v2.0.50727_32 - ok
18:06:41.0363 2880  [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:06:41.0363 2880  clr_optimization_v2.0.50727_64 - ok
18:06:41.0940 2880  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:06:41.0956 2880  clr_optimization_v4.0.30319_32 - ok
18:06:42.0018 2880  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:06:42.0034 2880  clr_optimization_v4.0.30319_64 - ok
18:06:42.0096 2880  [ B52D9A14CE4101577900A364BA86F3DF ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
18:06:42.0174 2880  CmBatt - ok
18:06:42.0190 2880  [ 8C6AA24C1D7273A02284588426AB8CE3 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
18:06:42.0205 2880  cmdide - ok
18:06:42.0299 2880  [ 12E94E225BD7B05A2BCCD5C0B841E921 ] Com4QLBEx      C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
18:06:42.0314 2880  Com4QLBEx - ok
18:06:42.0346 2880  [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
18:06:42.0361 2880  Compbatt - ok
18:06:42.0392 2880  COMSysApp - ok
18:06:42.0876 2880  cpuz134 - ok
18:06:43.0001 2880  [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
18:06:43.0032 2880  crcdisk - ok
18:06:43.0094 2880  [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
18:06:43.0126 2880  CryptSvc - ok
18:06:43.0235 2880  [ BA8E5B2291C01EF71CA80E25F0C79D55 ] ctxusbm        C:\Windows\system32\DRIVERS\ctxusbm.sys
18:06:43.0250 2880  ctxusbm - ok
18:06:43.0422 2880  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch      C:\Windows\system32\rpcss.dll
18:06:43.0516 2880  DcomLaunch - ok
18:06:43.0578 2880  [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
18:06:43.0609 2880  DfsC - ok
18:06:44.0171 2880  [ C647F468F7DE343DF8C143655C5557D4 ] DFSR            C:\Windows\system32\DFSR.exe
18:06:44.0389 2880  DFSR - ok
18:06:44.0483 2880  [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
18:06:44.0498 2880  Dhcp - ok
18:06:44.0545 2880  [ B0107E40ECDB5FA692EBF832F295D905 ] disk            C:\Windows\system32\drivers\disk.sys
18:06:44.0561 2880  disk - ok
18:06:44.0639 2880  [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
18:06:44.0670 2880  Dnscache - ok
18:06:44.0732 2880  [ 57AE249F2C6A90476E8E400F0EEC3C56 ] Dokan          C:\Windows\system32\drivers\dokan.sys
18:06:44.0748 2880  Dokan - ok
18:06:44.0826 2880  [ F4FEAE56DA1B5B7DC78D5F9214CDEF5E ] DokanMounter    C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
18:06:44.0826 2880  DokanMounter ( UnsignedFile.Multi.Generic ) - warning
18:06:44.0826 2880  DokanMounter - detected UnsignedFile.Multi.Generic (1)
18:06:44.0920 2880  [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc        C:\Windows\System32\dot3svc.dll
18:06:44.0951 2880  dot3svc - ok
18:06:45.0029 2880  [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS            C:\Windows\system32\dps.dll
18:06:45.0060 2880  DPS - ok
18:06:45.0122 2880  [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
18:06:45.0154 2880  drmkaud - ok
18:06:45.0325 2880  [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
18:06:45.0372 2880  DXGKrnl - ok
18:06:45.0450 2880  [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60          C:\Windows\system32\DRIVERS\E1G6032E.sys
18:06:45.0497 2880  E1G60 - ok
18:06:45.0559 2880  [ C2303883FD9BE49DC36A6400643002EA ] EapHost        C:\Windows\System32\eapsvc.dll
18:06:45.0590 2880  EapHost - ok
18:06:45.0684 2880  [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache          C:\Windows\system32\drivers\ecache.sys
18:06:45.0715 2880  Ecache - ok
18:06:46.0339 2880  [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
18:06:46.0448 2880  ehRecvr - ok
18:06:46.0745 2880  [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched        C:\Windows\ehome\ehsched.exe
18:06:46.0776 2880  ehSched - ok
18:06:46.0854 2880  [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart        C:\Windows\ehome\ehstart.dll
18:06:46.0885 2880  ehstart - ok
18:06:47.0244 2880  [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
18:06:47.0291 2880  elxstor - ok
18:06:47.0369 2880  [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
18:06:47.0431 2880  EMDMgmt - ok
18:06:47.0494 2880  [ F218A3A27ED6592C0E22EC3595554447 ] enecir          C:\Windows\system32\DRIVERS\enecir.sys
18:06:47.0525 2880  enecir - ok
18:06:47.0572 2880  [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev          C:\Windows\system32\drivers\errdev.sys
18:06:47.0634 2880  ErrDev - ok
18:06:47.0930 2880  [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem    C:\Windows\system32\es.dll
18:06:48.0055 2880  EventSystem - ok
18:06:48.0133 2880  [ 486844F47B6636044A42454614ED4523 ] exfat          C:\Windows\system32\drivers\exfat.sys
18:06:48.0196 2880  exfat - ok
18:06:48.0211 2880  ezSharedSvc - ok
18:06:48.0242 2880  [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
18:06:48.0305 2880  fastfat - ok
18:06:48.0336 2880  [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
18:06:48.0383 2880  fdc - ok
18:06:48.0461 2880  [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost        C:\Windows\system32\fdPHost.dll
18:06:48.0508 2880  fdPHost - ok
18:06:48.0679 2880  [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub        C:\Windows\system32\fdrespub.dll
18:06:48.0851 2880  FDResPub - ok
18:06:48.0882 2880  Fildro - ok
18:06:48.0929 2880  [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
18:06:48.0944 2880  FileInfo - ok
18:06:48.0976 2880  [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
18:06:49.0022 2880  Filetrace - ok
18:06:49.0100 2880  [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
18:06:49.0147 2880  flpydisk - ok
18:06:49.0272 2880  [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
18:06:49.0288 2880  FltMgr - ok
18:06:49.0678 2880  [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache      C:\Windows\system32\FntCache.dll
18:06:49.0740 2880  FontCache - ok
18:06:49.0927 2880  [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:06:49.0943 2880  FontCache3.0.0.0 - ok
18:06:50.0005 2880  [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
18:06:50.0068 2880  Fs_Rec - ok
18:06:50.0114 2880  [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
18:06:50.0130 2880  gagp30kx - ok
18:06:50.0224 2880  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
18:06:50.0239 2880  GEARAspiWDM - ok
18:06:50.0286 2880  [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc          C:\Windows\System32\gpsvc.dll
18:06:50.0317 2880  gpsvc - ok
18:06:50.0411 2880  [ 68E732382B32417FF61FD663259B4B09 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:06:50.0426 2880  HdAudAddService - ok
18:06:50.0504 2880  [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
18:06:50.0536 2880  HDAudBus - ok
18:06:50.0567 2880  [ B4881C84A180E75B8C25DC1D726C375F ] HidBth          C:\Windows\system32\drivers\hidbth.sys
18:06:50.0645 2880  HidBth - ok
18:06:50.0692 2880  [ 5F47839455D01FF6403B008D481A6F5B ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
18:06:50.0707 2880  HidIr - ok
18:06:50.0754 2880  [ 59361D38A297755D46A540E450202B2A ] hidserv        C:\Windows\System32\hidserv.dll
18:06:50.0785 2880  hidserv - ok
18:06:50.0816 2880  [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
18:06:50.0863 2880  HidUsb - ok
18:06:50.0894 2880  [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc          C:\Windows\system32\kmsvc.dll
18:06:50.0926 2880  hkmsvc - ok
18:06:51.0004 2880  [ A19B0BB5A7EB6DF2DD4A0711D36955EE ] HP Health Check Service c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
18:06:51.0019 2880  HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
18:06:51.0019 2880  HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
18:06:51.0082 2880  [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
18:06:51.0097 2880  HpCISSs - ok
18:06:51.0144 2880  [ 4E0BEC0F78096FFD6D3314B497FC49D3 ] hpdskflt        C:\Windows\system32\DRIVERS\hpdskflt.sys
18:06:51.0160 2880  hpdskflt - ok
18:06:51.0191 2880  [ 0ECC54FD34D6A089C300846B011E81D6 ] HpqKbFiltr      C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
18:06:51.0238 2880  HpqKbFiltr - ok
18:06:51.0300 2880  [ 188FF0ADF66768D53AD94F43972E1E9A ] hpqwmiex        C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
18:06:51.0316 2880  hpqwmiex ( UnsignedFile.Multi.Generic ) - warning
18:06:51.0316 2880  hpqwmiex - detected UnsignedFile.Multi.Generic (1)
18:06:51.0362 2880  [ FC7C13B5A9E9BE23B7AE72BBC7FDB278 ] hpsrv          C:\Windows\system32\Hpservice.exe
18:06:51.0378 2880  hpsrv - ok
18:06:51.0440 2880  [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
18:06:51.0503 2880  HTTP - ok
18:06:51.0550 2880  [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
18:06:51.0565 2880  i2omp - ok
18:06:51.0612 2880  [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
18:06:51.0643 2880  i8042prt - ok
18:06:51.0674 2880  [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
18:06:51.0690 2880  iaStorV - ok
18:06:51.0752 2880  [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:06:51.0784 2880  idsvc - ok
18:06:51.0846 2880  [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
18:06:51.0862 2880  iirsp - ok
18:06:51.0940 2880  [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT          C:\Windows\System32\ikeext.dll
18:06:51.0986 2880  IKEEXT - ok
18:06:52.0018 2880  [ 475490CAF376E55E6E8B37BBDFEB2E81 ] intelide        C:\Windows\system32\drivers\intelide.sys
18:06:52.0033 2880  intelide - ok
18:06:52.0064 2880  [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
18:06:52.0111 2880  intelppm - ok
18:06:52.0142 2880  [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
18:06:52.0189 2880  IPBusEnum - ok
18:06:52.0236 2880  [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:06:52.0267 2880  IpFilterDriver - ok
18:06:52.0314 2880  [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
18:06:52.0376 2880  iphlpsvc - ok
18:06:52.0376 2880  IpInIp - ok
18:06:52.0423 2880  [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
18:06:52.0486 2880  IPMIDRV - ok
18:06:52.0517 2880  [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
18:06:52.0564 2880  IPNAT - ok
18:06:52.0704 2880  [ 24595EC9236D7E421661A2D4FFBD901A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
18:06:52.0735 2880  iPod Service - ok
18:06:52.0766 2880  [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
18:06:52.0844 2880  IRENUM - ok
18:06:52.0876 2880  [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
18:06:52.0891 2880  isapnp - ok
18:06:52.0969 2880  [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
18:06:52.0985 2880  iScsiPrt - ok
18:06:53.0016 2880  [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
18:06:53.0016 2880  iteatapi - ok
18:06:53.0078 2880  [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid        C:\Windows\system32\drivers\iteraid.sys
18:06:53.0094 2880  iteraid - ok
18:06:53.0125 2880  [ BB86B1C3489463BBA1FD04C876DBE414 ] JMCR            C:\Windows\system32\DRIVERS\jmcr.sys
18:06:53.0172 2880  JMCR - ok
18:06:53.0203 2880  [ 423696F3BA6472DD17699209B933BC26 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
18:06:53.0219 2880  kbdclass - ok
18:06:53.0266 2880  [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
18:06:53.0328 2880  kbdhid - ok
18:06:53.0390 2880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso          C:\Windows\system32\lsass.exe
18:06:53.0406 2880  KeyIso - ok
18:06:53.0484 2880  [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
18:06:53.0546 2880  KSecDD - ok
18:06:53.0609 2880  [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
18:06:53.0656 2880  ksthunk - ok
18:06:53.0718 2880  [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm          C:\Windows\system32\msdtckrm.dll
18:06:53.0812 2880  KtmRm - ok
18:06:53.0874 2880  [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer    C:\Windows\System32\srvsvc.dll
18:06:53.0905 2880  LanmanServer - ok
18:06:53.0952 2880  [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:06:53.0999 2880  LanmanWorkstation - ok
18:06:54.0108 2880  [ 83D8BE94E1CBCBE2EA8372DB1A95A159 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
18:06:54.0139 2880  LightScribeService ( UnsignedFile.Multi.Generic ) - warning
18:06:54.0139 2880  LightScribeService - detected UnsignedFile.Multi.Generic (1)
18:06:54.0170 2880  [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
18:06:54.0248 2880  lltdio - ok
18:06:54.0295 2880  [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
18:06:54.0342 2880  lltdsvc - ok
18:06:54.0373 2880  [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts        C:\Windows\System32\lmhsvc.dll
18:06:54.0420 2880  lmhosts - ok
18:06:54.0482 2880  [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
18:06:54.0482 2880  LSI_FC - ok
18:06:54.0498 2880  [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
18:06:54.0514 2880  LSI_SAS - ok
18:06:54.0545 2880  [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
18:06:54.0545 2880  LSI_SCSI - ok
18:06:54.0592 2880  [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv          C:\Windows\system32\drivers\luafv.sys
18:06:54.0638 2880  luafv - ok
18:06:54.0779 2880  [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
18:06:54.0794 2880  McComponentHostService - ok
18:06:54.0841 2880  [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
18:06:54.0857 2880  Mcx2Svc - ok
18:06:54.0919 2880  [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas        C:\Windows\system32\drivers\megasas.sys
18:06:54.0935 2880  megasas - ok
18:06:54.0997 2880  [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
18:06:55.0013 2880  MegaSR - ok
18:06:55.0044 2880  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS          C:\Windows\system32\mmcss.dll
18:06:55.0091 2880  MMCSS - ok
18:06:55.0106 2880  [ 59848D5CC74606F0EE7557983BB73C2E ] Modem          C:\Windows\system32\drivers\modem.sys
18:06:55.0169 2880  Modem - ok
18:06:55.0200 2880  [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
18:06:55.0247 2880  monitor - ok
18:06:55.0262 2880  [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
18:06:55.0278 2880  mouclass - ok
18:06:55.0340 2880  [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
18:06:55.0372 2880  mouhid - ok
18:06:55.0372 2880  [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
18:06:55.0387 2880  MountMgr - ok
18:06:55.0481 2880  [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
18:06:55.0481 2880  MozillaMaintenance - ok
18:06:55.0528 2880  [ F8276EB8698142884498A528DFEA8478 ] mpio            C:\Windows\system32\drivers\mpio.sys
18:06:55.0543 2880  mpio - ok
18:06:55.0590 2880  [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
18:06:55.0637 2880  mpsdrv - ok
18:06:55.0652 2880  MpsSvc - ok
18:06:55.0684 2880  [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
18:06:55.0699 2880  Mraid35x - ok
18:06:55.0746 2880  [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
18:06:55.0762 2880  MRxDAV - ok
18:06:55.0808 2880  [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
18:06:55.0855 2880  mrxsmb - ok
18:06:55.0918 2880  [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:06:55.0933 2880  mrxsmb10 - ok
18:06:55.0964 2880  [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:06:55.0980 2880  mrxsmb20 - ok
18:06:56.0058 2880  [ AA459F2AB3AB603C357FF117CAE3D818 ] msahci          C:\Windows\system32\drivers\msahci.sys
18:06:56.0058 2880  msahci - ok
18:06:56.0105 2880  [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
18:06:56.0120 2880  msdsm - ok
18:06:56.0167 2880  [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC          C:\Windows\System32\msdtc.exe
18:06:56.0198 2880  MSDTC - ok
18:06:56.0276 2880  [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs            C:\Windows\system32\drivers\Msfs.sys
18:06:56.0339 2880  Msfs - ok
18:06:56.0370 2880  [ 00EBC952961664780D43DCA157E79B27 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
18:06:56.0386 2880  msisadrv - ok
18:06:56.0417 2880  [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
18:06:56.0479 2880  MSiSCSI - ok
18:06:56.0495 2880  msiserver - ok
18:06:56.0542 2880  [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
18:06:56.0588 2880  MSKSSRV - ok
18:06:56.0588 2880  [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
18:06:56.0651 2880  MSPCLOCK - ok
18:06:56.0682 2880  [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
18:06:56.0729 2880  MSPQM - ok
18:06:56.0776 2880  [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
18:06:56.0807 2880  MsRPC - ok
18:06:56.0838 2880  [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
18:06:56.0854 2880  mssmbios - ok
18:06:56.0900 2880  [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
18:06:56.0978 2880  MSTEE - ok
18:06:57.0025 2880  [ 0CC49F78D8ACA0877D885F149084E543 ] Mup            C:\Windows\system32\Drivers\mup.sys
18:06:57.0041 2880  Mup - ok
18:06:57.0103 2880  [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent        C:\Windows\system32\qagentRT.dll
18:06:57.0150 2880  napagent - ok
18:06:57.0212 2880  [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
18:06:57.0244 2880  NativeWifiP - ok
18:06:57.0337 2880  NAVENG - ok
18:06:57.0337 2880  NAVEX15 - ok
18:06:57.0415 2880  [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS            C:\Windows\system32\drivers\ndis.sys
18:06:57.0446 2880  NDIS - ok
18:06:57.0478 2880  [ 64DF698A425478E321981431AC171334 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
18:06:57.0540 2880  NdisTapi - ok
18:06:57.0556 2880  [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
18:06:57.0618 2880  Ndisuio - ok
18:06:57.0680 2880  [ F8158771905260982CE724076419EF19 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
18:06:57.0743 2880  NdisWan - ok
18:06:57.0774 2880  [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
18:06:57.0821 2880  NDProxy - ok
18:06:57.0899 2880  [ 89FD76A90CBE63F03A70C2D1B85E802C ] NEOFLTR_710_19243 C:\Windows\system32\Drivers\NEOFLTR_710_19243.SYS
18:06:57.0914 2880  NEOFLTR_710_19243 - ok
18:06:57.0946 2880  Nero BackItUp Scheduler 4.0 - ok
18:06:57.0977 2880  [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
18:06:58.0039 2880  NetBIOS - ok
18:06:58.0102 2880  [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
18:06:58.0133 2880  netbt - ok
18:06:58.0164 2880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon        C:\Windows\system32\lsass.exe
18:06:58.0180 2880  Netlogon - ok
18:06:58.0226 2880  [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman          C:\Windows\System32\netman.dll
18:06:58.0273 2880  Netman - ok
18:06:58.0320 2880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:06:58.0336 2880  NetMsmqActivator - ok
18:06:58.0336 2880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:06:58.0351 2880  NetPipeActivator - ok
18:06:58.0382 2880  [ 7846D0136CC2B264926A73047BA7688A ] netprofm        C:\Windows\System32\netprofm.dll
18:06:58.0445 2880  netprofm - ok
18:06:58.0460 2880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:06:58.0476 2880  NetTcpActivator - ok
18:06:58.0476 2880  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
18:06:58.0492 2880  NetTcpPortSharing - ok
18:06:58.0616 2880  [ C86984AEE87900C1EEB6942EDE3BF4B6 ] NETw3v64        C:\Windows\system32\DRIVERS\NETw3v64.sys
18:06:58.0757 2880  NETw3v64 - ok
18:06:58.0944 2880  [ 2BDCB7B7917380794C9D87AC2153CE33 ] NETw5v64        C:\Windows\system32\DRIVERS\NETw5v64.sys
18:06:59.0162 2880  NETw5v64 - ok
18:06:59.0178 2880  [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
18:06:59.0194 2880  nfrd960 - ok
18:06:59.0240 2880  [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc          C:\Windows\System32\nlasvc.dll
18:06:59.0318 2880  NlaSvc - ok
18:06:59.0365 2880  [ 02C1198276C0D4F39E54EB5148AF1E2A ] nmwcdcx64      C:\Windows\system32\drivers\ccdcmbox64.sys
18:06:59.0428 2880  nmwcdcx64 - ok
18:06:59.0459 2880  [ 76292103C5149EB140419F36DCF26C1B ] nmwcdnsucx64    C:\Windows\system32\drivers\nmwcdnsucx64.sys
18:06:59.0506 2880  nmwcdnsucx64 - ok
18:06:59.0552 2880  [ 2974296DA6296B4FEA3E313BF98C693D ] nmwcdnsux64    C:\Windows\system32\drivers\nmwcdnsux64.sys
18:06:59.0584 2880  nmwcdnsux64 - ok
18:06:59.0630 2880  [ D8F00FCC82451BDAA3DB93BB62AE6AC3 ] nmwcdx64        C:\Windows\system32\drivers\ccdcmbx64.sys
18:06:59.0693 2880  nmwcdx64 - ok
18:06:59.0693 2880  Norton Internet Security - ok
18:06:59.0740 2880  [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
18:06:59.0771 2880  Npfs - ok
18:06:59.0818 2880  [ ACB62BAA1C319B17752553DF3026EEEB ] nsi            C:\Windows\system32\nsisvc.dll
18:06:59.0880 2880  nsi - ok
18:06:59.0927 2880  [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
18:07:00.0005 2880  nsiproxy - ok
18:07:00.0083 2880  [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
18:07:00.0192 2880  Ntfs - ok
18:07:00.0254 2880  [ DD5D684975352B85B52E3FD5347C20CB ] Null            C:\Windows\system32\drivers\Null.sys
18:07:00.0286 2880  Null - ok
18:07:00.0317 2880  [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
18:07:00.0332 2880  nvraid - ok
18:07:00.0348 2880  [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor          C:\Windows\system32\drivers\nvstor.sys
18:07:00.0364 2880  nvstor - ok
18:07:00.0379 2880  [ 19067CA93075EF4823E3938A686F532F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
18:07:00.0395 2880  nv_agp - ok
18:07:00.0410 2880  NwlnkFlt - ok
18:07:00.0410 2880  NwlnkFwd - ok
18:07:00.0488 2880  [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
18:07:00.0535 2880  ohci1394 - ok
18:07:00.0598 2880  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:07:00.0598 2880  ose - ok
18:07:00.0691 2880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc        C:\Windows\system32\p2psvc.dll
18:07:00.0738 2880  p2pimsvc - ok
18:07:00.0754 2880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc          C:\Windows\system32\p2psvc.dll
18:07:00.0785 2880  p2psvc - ok
18:07:00.0832 2880  [ AECD57F94C887F58919F307C35498EA0 ] Parport        C:\Windows\system32\drivers\parport.sys
18:07:00.0910 2880  Parport - ok
18:07:00.0972 2880  [ B43751085E2ABE389DA466BC62A4B987 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
18:07:00.0988 2880  partmgr - ok
18:07:01.0050 2880  [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc          C:\Windows\System32\pcasvc.dll
18:07:01.0081 2880  PcaSvc - ok
18:07:01.0144 2880  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
18:07:01.0159 2880  pccsmcfd - ok
18:07:01.0206 2880  [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci            C:\Windows\system32\drivers\pci.sys
18:07:01.0222 2880  pci - ok
18:07:01.0268 2880  [ 15E5C3F89A3452EFBDA3B39816DBC4EE ] pciide          C:\Windows\system32\drivers\pciide.sys
18:07:01.0284 2880  pciide - ok
18:07:01.0300 2880  [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
18:07:01.0331 2880  pcmcia - ok
18:07:01.0346 2880  [ 58865916F53592A61549B04941BFD80D ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
18:07:01.0487 2880  PEAUTH - ok
18:07:01.0627 2880  [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
18:07:01.0705 2880  PerfHost - ok
18:07:01.0814 2880  [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla            C:\Windows\system32\pla.dll
18:07:01.0877 2880  pla - ok
18:07:01.0939 2880  [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
18:07:01.0970 2880  PlugPlay - ok
18:07:02.0017 2880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
18:07:02.0048 2880  PNRPAutoReg - ok
18:07:02.0064 2880  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc        C:\Windows\system32\p2psvc.dll
18:07:02.0095 2880  PNRPsvc - ok
18:07:02.0158 2880  [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
18:07:02.0236 2880  PolicyAgent - ok
18:07:02.0314 2880  [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
18:07:02.0376 2880  PptpMiniport - ok
18:07:02.0438 2880  [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor      C:\Windows\system32\drivers\processr.sys
18:07:02.0485 2880  Processor - ok
18:07:02.0501 2880  [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc        C:\Windows\system32\profsvc.dll
18:07:02.0532 2880  ProfSvc - ok
18:07:02.0563 2880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
18:07:02.0579 2880  ProtectedStorage - ok
18:07:02.0626 2880  [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
18:07:02.0641 2880  PSched - ok
18:07:02.0704 2880  [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300          C:\Windows\system32\drivers\ql2300.sys
18:07:02.0797 2880  ql2300 - ok
18:07:02.0828 2880  [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
18:07:02.0844 2880  ql40xx - ok
18:07:02.0875 2880  [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE          C:\Windows\system32\qwave.dll
18:07:02.0891 2880  QWAVE - ok
18:07:02.0922 2880  [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
18:07:02.0953 2880  QWAVEdrv - ok
18:07:03.0000 2880  [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
18:07:03.0047 2880  RasAcd - ok
18:07:03.0078 2880  [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto        C:\Windows\System32\rasauto.dll
18:07:03.0140 2880  RasAuto - ok
18:07:03.0187 2880  [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
18:07:03.0234 2880  Rasl2tp - ok
18:07:03.0265 2880  [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan          C:\Windows\System32\rasmans.dll
18:07:03.0312 2880  RasMan - ok
18:07:03.0359 2880  [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
18:07:03.0406 2880  RasPppoe - ok
18:07:03.0421 2880  [ C6A593B51F34C33E5474539544072527 ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
18:07:03.0437 2880  RasSstp - ok
18:07:03.0515 2880  [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
18:07:03.0562 2880  rdbss - ok
18:07:03.0593 2880  [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
18:07:03.0640 2880  RDPCDD - ok
18:07:03.0671 2880  [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
18:07:03.0718 2880  rdpdr - ok
18:07:03.0718 2880  [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
18:07:03.0764 2880  RDPENCDD - ok
18:07:03.0811 2880  [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
18:07:03.0827 2880  RDPWD - ok
18:07:03.0874 2880  [ BC0A4D47472B042537F4E57B950415FA ] Recovery Service for Windows C:\Program Files (x86)\SMINST\BLService.exe
18:07:03.0905 2880  Recovery Service for Windows - ok
18:07:03.0952 2880  [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess    C:\Windows\System32\mprdim.dll
18:07:04.0030 2880  RemoteAccess - ok
18:07:04.0076 2880  [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
18:07:04.0123 2880  RemoteRegistry - ok
18:07:04.0232 2880  [ 805AE1F90C64758D19AAA001CF8CBA12 ] RichVideo      C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
18:07:04.0264 2880  RichVideo ( UnsignedFile.Multi.Generic ) - warning
18:07:04.0264 2880  RichVideo - detected UnsignedFile.Multi.Generic (1)
18:07:04.0295 2880  [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator      C:\Windows\system32\locator.exe
18:07:04.0357 2880  RpcLocator - ok
18:07:04.0420 2880  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs          C:\Windows\System32\rpcss.dll
18:07:04.0498 2880  RpcSs - ok
18:07:04.0544 2880  [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
18:07:04.0591 2880  rspndr - ok
18:07:04.0654 2880  [ 8B91737DA75ADD21CB1554B38089196A ] RTL8169        C:\Windows\system32\DRIVERS\Rtlh64.sys
18:07:04.0700 2880  RTL8169 - ok
18:07:04.0716 2880  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs          C:\Windows\system32\lsass.exe
18:07:04.0732 2880  SamSs - ok
18:07:04.0763 2880  [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
18:07:04.0778 2880  sbp2port - ok
18:07:04.0810 2880  [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr        C:\Windows\System32\SCardSvr.dll
18:07:04.0841 2880  SCardSvr - ok
18:07:04.0919 2880  [ 0F838C811AD295D2A4489B9993096C63 ] Schedule        C:\Windows\system32\schedsvc.dll
18:07:04.0981 2880  Schedule - ok
18:07:05.0012 2880  [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc    C:\Windows\System32\certprop.dll
18:07:05.0028 2880  SCPolicySvc - ok
18:07:05.0090 2880  [ B42EE50F7D24F837F925332EB349ECA5 ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
18:07:05.0122 2880  sdbus - ok
18:07:05.0168 2880  [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
18:07:05.0184 2880  SDRSVC - ok
18:07:05.0387 2880  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\Andreas\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
18:07:05.0387 2880  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - warning
18:07:05.0387 2880  SearchAnonymizer - detected UnsignedFile.Multi.Generic (1)
18:07:05.0402 2880  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
18:07:05.0480 2880  secdrv - ok
18:07:05.0512 2880  [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon        C:\Windows\system32\seclogon.dll
18:07:05.0558 2880  seclogon - ok
18:07:05.0574 2880  [ 90973A64B96CD647FF81C79443618EED ] SENS            C:\Windows\system32\sens.dll
18:07:05.0636 2880  SENS - ok
18:07:05.0668 2880  [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum        C:\Windows\system32\drivers\serenum.sys
18:07:05.0699 2880  Serenum - ok
18:07:05.0730 2880  [ E62FAC91EE288DB29A9696A9D279929C ] Serial          C:\Windows\system32\drivers\serial.sys
18:07:05.0761 2880  Serial - ok
18:07:05.0777 2880  [ A842F04833684BCEEA7336211BE478DF ] sermouse        C:\Windows\system32\drivers\sermouse.sys
18:07:05.0824 2880  sermouse - ok
18:07:05.0902 2880  [ 58D5BFDF3ADF49FE9CABD78CC61D92F6 ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
18:07:05.0917 2880  ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
18:07:05.0917 2880  ServiceLayer - detected UnsignedFile.Multi.Generic (1)
18:07:05.0980 2880  [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv      C:\Windows\system32\sessenv.dll
18:07:06.0042 2880  SessionEnv - ok
18:07:06.0089 2880  [ 14D4B4465193A87C127933978E8C4106 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
18:07:06.0120 2880  sffdisk - ok
18:07:06.0136 2880  [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
18:07:06.0182 2880  sffp_mmc - ok
18:07:06.0198 2880  [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
18:07:06.0245 2880  sffp_sd - ok
18:07:06.0260 2880  [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
18:07:06.0338 2880  sfloppy - ok
18:07:06.0370 2880  [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
18:07:06.0494 2880  SharedAccess - ok
18:07:06.0541 2880  [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:07:06.0557 2880  ShellHWDetection - ok
18:07:06.0604 2880  [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
18:07:06.0619 2880  SiSRaid2 - ok
18:07:06.0666 2880  [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
18:07:06.0682 2880  SiSRaid4 - ok
18:07:06.0775 2880  [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
18:07:06.0775 2880  SkypeUpdate - ok
18:07:06.0884 2880  [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc          C:\Windows\system32\SLsvc.exe
18:07:06.0994 2880  slsvc - ok
18:07:07.0056 2880  [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify      C:\Windows\system32\SLUINotify.dll
18:07:07.0072 2880  SLUINotify - ok
18:07:07.0087 2880  [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
18:07:07.0134 2880  Smb - ok
18:07:07.0181 2880  [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
18:07:07.0212 2880  SNMPTRAP - ok
18:07:07.0259 2880  [ 386C3C63F00A7040C7EC5E384217E89D ] spldr          C:\Windows\system32\drivers\spldr.sys
18:07:07.0259 2880  spldr - ok
18:07:07.0306 2880  [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler        C:\Windows\System32\spoolsv.exe
18:07:07.0306 2880  Spooler - ok
18:07:07.0321 2880  SRTSP - ok
18:07:07.0321 2880  SRTSPX - ok
18:07:07.0352 2880  [ 880A57FCCB571EBD063D4DD50E93E46D ] srv            C:\Windows\system32\DRIVERS\srv.sys
18:07:07.0399 2880  srv - ok
18:07:07.0462 2880  [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
18:07:07.0493 2880  srv2 - ok
18:07:07.0508 2880  [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
18:07:07.0524 2880  srvnet - ok
18:07:07.0571 2880  [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
18:07:07.0602 2880  SSDPSRV - ok
18:07:07.0696 2880  [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc        C:\Windows\system32\sstpsvc.dll
18:07:07.0711 2880  SstpSvc - ok
18:07:07.0852 2880  [ 72EB6157E892A674E47E08732BB5CCE3 ] STacSV          C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_6ef279c8\STacSV64.exe
18:07:07.0883 2880  STacSV - ok
18:07:07.0961 2880  [ 0C7BDA7E9A329A071C080EB5210FE019 ] STHDA          C:\Windows\system32\DRIVERS\stwrt64.sys
18:07:08.0008 2880  STHDA - ok
18:07:08.0086 2880  [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc          C:\Windows\System32\wiaservc.dll
18:07:08.0179 2880  stisvc - ok
18:07:08.0210 2880  [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
18:07:08.0226 2880  swenum - ok
18:07:08.0273 2880  [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv          C:\Windows\System32\swprv.dll
18:07:08.0320 2880  swprv - ok
18:07:08.0351 2880  [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
18:07:08.0351 2880  Symc8xx - ok
18:07:08.0382 2880  [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
18:07:08.0398 2880  Sym_hi - ok
18:07:08.0398 2880  [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
18:07:08.0413 2880  Sym_u3 - ok
18:07:08.0491 2880  [ 3A706A967295E16511E40842B1A2761D ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
18:07:08.0507 2880  SynTP - ok
18:07:08.0569 2880  [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain        C:\Windows\system32\sysmain.dll
18:07:08.0616 2880  SysMain - ok
18:07:08.0663 2880  [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:07:08.0694 2880  TabletInputService - ok
18:07:08.0725 2880  [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv        C:\Windows\System32\tapisrv.dll
18:07:08.0756 2880  TapiSrv - ok
18:07:08.0788 2880  [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS            C:\Windows\System32\tbssvc.dll
18:07:08.0850 2880  TBS - ok
18:07:08.0928 2880  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
18:07:09.0006 2880  Tcpip - ok
18:07:09.0084 2880  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
18:07:09.0178 2880  Tcpip6 - ok
18:07:09.0240 2880  [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
18:07:09.0256 2880  tcpipreg - ok
18:07:09.0334 2880  [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
18:07:09.0396 2880  TDPIPE - ok
18:07:09.0412 2880  [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
18:07:09.0490 2880  TDTCP - ok
18:07:09.0536 2880  [ 458919C8C42E398DC4802178D5FFEE27 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
18:07:09.0568 2880  tdx - ok
18:07:09.0614 2880  [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
18:07:09.0630 2880  TermDD - ok
18:07:09.0677 2880  [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService    C:\Windows\System32\termsrv.dll
18:07:09.0786 2880  TermService - ok
18:07:09.0817 2880  [ 56793271ECDEDD350C5ADD305603E963 ] Themes          C:\Windows\system32\shsvcs.dll
18:07:09.0833 2880  Themes - ok
18:07:09.0864 2880  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER    C:\Windows\system32\mmcss.dll
18:07:09.0911 2880  THREADORDER - ok
18:07:10.0004 2880  [ 0407143F2BBC1A5DD5B518AC0704FCBF ] TomTomHOMEService C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
18:07:10.0004 2880  TomTomHOMEService - ok
18:07:10.0067 2880  [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks          C:\Windows\System32\trkwks.dll
18:07:10.0145 2880  TrkWks - ok
18:07:10.0207 2880  [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:07:10.0301 2880  TrustedInstaller - ok
18:07:10.0332 2880  [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
18:07:10.0363 2880  tssecsrv - ok
18:07:10.0410 2880  [ 89EC74A9E602D16A75A4170511029B3C ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
18:07:10.0426 2880  tunmp - ok
18:07:10.0457 2880  [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
18:07:10.0488 2880  tunnel - ok
18:07:10.0660 2880  [ 1C31169DDDC70C1605F703DA701EAEEA ] TVCapSvc        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
18:07:10.0675 2880  TVCapSvc - ok
18:07:10.0675 2880  [ 290B8C381DBC15D3DBCBD2BDB6B0BA12 ] TVSched        C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
18:07:10.0691 2880  TVSched - ok
18:07:10.0722 2880  [ FEC266EF401966311744BD0F359F7F56 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
18:07:10.0738 2880  uagp35 - ok
18:07:10.0784 2880  [ FAF2640A2A76ED03D449E443194C4C34 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
18:07:10.0800 2880  udfs - ok
18:07:10.0847 2880  [ 060507C4113391394478F6953A79EEDC ] UI0Detect      C:\Windows\system32\UI0Detect.exe
18:07:10.0878 2880  UI0Detect - ok
18:07:10.0894 2880  [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
18:07:10.0909 2880  uliagpkx - ok
18:07:10.0925 2880  [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci        C:\Windows\system32\drivers\uliahci.sys
18:07:10.0940 2880  uliahci - ok
18:07:10.0956 2880  [ 31707F09846056651EA2C37858F5DDB0 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
18:07:10.0972 2880  UlSata - ok
18:07:11.0018 2880  [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
18:07:11.0018 2880  ulsata2 - ok
18:07:11.0034 2880  [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
18:07:11.0065 2880  umbus - ok
18:07:11.0128 2880  [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost        C:\Windows\System32\upnphost.dll
18:07:11.0159 2880  upnphost - ok
18:07:11.0206 2880  [ 9856C38AB8FAACCA4DD99DAC7B42F838 ] upperdev        C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
18:07:11.0237 2880  upperdev - ok
18:07:11.0315 2880  [ CD03479F2DA26500B203ED075C146A7A ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
18:07:11.0346 2880  USBAAPL64 - ok
18:07:11.0408 2880  [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
18:07:11.0440 2880  usbaudio - ok
18:07:11.0486 2880  [ 07E3498FC60834219D2356293DA0FECC ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
18:07:11.0549 2880  usbccgp - ok
18:07:11.0580 2880  [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
18:07:11.0642 2880  usbcir - ok
18:07:11.0705 2880  [ 827E44DE934A736EA31E91D353EB126F ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
18:07:11.0736 2880  usbehci - ok
18:07:11.0783 2880  [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
18:07:11.0845 2880  usbhub - ok
18:07:11.0892 2880  [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
18:07:11.0954 2880  usbohci - ok
18:07:11.0954 2880  [ ACFEE697AF477021BB3EC78C5431FED2 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
18:07:12.0032 2880  usbprint - ok
18:07:12.0079 2880  [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
18:07:12.0110 2880  usbscan - ok
18:07:12.0157 2880  [ F7386007FB19E7685FC7B298560AA81F ] usbser          C:\Windows\system32\drivers\usbser.sys
18:07:12.0204 2880  usbser - ok
18:07:12.0220 2880  [ 89123DC822AC7A708BD4C9E196A37610 ] UsbserFilt      C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys
18:07:12.0235 2880  UsbserFilt - ok
18:07:12.0298 2880  [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:07:12.0344 2880  USBSTOR - ok
18:07:12.0376 2880  [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
18:07:12.0407 2880  usbuhci - ok
18:07:12.0454 2880  [ FC33099877790D51B0927B7039059855 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
18:07:12.0485 2880  usbvideo - ok
18:07:12.0516 2880  [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms          C:\Windows\System32\uxsms.dll
18:07:12.0563 2880  UxSms - ok
18:07:12.0578 2880  [ 294945381DFA7CE58CECF0A9896AF327 ] vds            C:\Windows\System32\vds.exe
18:07:12.0610 2880  vds - ok
18:07:12.0672 2880  [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
18:07:12.0719 2880  vga - ok
18:07:12.0750 2880  [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave        C:\Windows\System32\drivers\vga.sys
18:07:12.0781 2880  VgaSave - ok
18:07:12.0797 2880  [ 4F964E6828156F0EF3FA8D3A9A7895DE ] viaide          C:\Windows\system32\drivers\viaide.sys
18:07:12.0797 2880  viaide - ok
18:07:12.0828 2880  [ 2B7E885ED951519A12C450D24535DFCA ] volmgr          C:\Windows\system32\drivers\volmgr.sys
18:07:12.0844 2880  volmgr - ok
18:07:12.0906 2880  [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
18:07:12.0937 2880  volmgrx - ok
18:07:12.0984 2880  [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap        C:\Windows\system32\drivers\volsnap.sys
18:07:13.0015 2880  volsnap - ok
18:07:13.0062 2880  [ A68F455ED2673835209318DD61BFBB0E ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
18:07:13.0078 2880  vsmraid - ok
18:07:13.0156 2880  [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS            C:\Windows\system32\vssvc.exe
18:07:13.0265 2880  VSS - ok
18:07:13.0327 2880  [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time        C:\Windows\system32\w32time.dll
18:07:13.0390 2880  W32Time - ok
18:07:13.0421 2880  [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
18:07:13.0514 2880  WacomPen - ok
18:07:13.0592 2880  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
18:07:13.0624 2880  Wanarp - ok
18:07:13.0624 2880  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
18:07:13.0655 2880  Wanarpv6 - ok
18:07:13.0717 2880  [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
18:07:13.0748 2880  wcncsvc - ok
18:07:13.0795 2880  [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:07:13.0811 2880  WcsPlugInService - ok
18:07:13.0858 2880  [ 0C17A0816F65B89E362E682AD5E7266E ] Wd              C:\Windows\system32\drivers\wd.sys
18:07:13.0858 2880  Wd - ok
18:07:13.0920 2880  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
18:07:13.0936 2880  Wdf01000 - ok
18:07:13.0982 2880  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost  C:\Windows\system32\wdi.dll
18:07:14.0029 2880  WdiServiceHost - ok
18:07:14.0029 2880  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost  C:\Windows\system32\wdi.dll
18:07:14.0060 2880  WdiSystemHost - ok
18:07:14.0107 2880  [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient      C:\Windows\System32\webclnt.dll
18:07:14.0154 2880  WebClient - ok
18:07:14.0216 2880  [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc          C:\Windows\system32\wecsvc.dll
18:07:14.0232 2880  Wecsvc - ok
18:07:14.0263 2880  [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
18:07:14.0294 2880  wercplsupport - ok
18:07:14.0310 2880  [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc          C:\Windows\System32\WerSvc.dll
18:07:14.0341 2880  WerSvc - ok
18:07:14.0388 2880  WinDefend - ok
18:07:14.0388 2880  WinHttpAutoProxySvc - ok
18:07:14.0450 2880  [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
18:07:14.0497 2880  Winmgmt - ok
18:07:14.0591 2880  [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM          C:\Windows\system32\WsmSvc.dll
18:07:14.0653 2880  WinRM - ok
18:07:14.0700 2880  [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc        C:\Windows\System32\wlansvc.dll
18:07:14.0778 2880  Wlansvc - ok
18:07:15.0028 2880  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
18:07:15.0152 2880  wlidsvc - ok
18:07:15.0184 2880  [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
18:07:15.0230 2880  WmiAcpi - ok
18:07:15.0277 2880  [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
18:07:15.0308 2880  wmiApSrv - ok
18:07:15.0340 2880  WMPNetworkSvc - ok
18:07:15.0371 2880  [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
18:07:15.0418 2880  WPCSvc - ok
18:07:15.0449 2880  [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
18:07:15.0480 2880  WPDBusEnum - ok
18:07:15.0511 2880  [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
18:07:15.0542 2880  WpdUsb - ok
18:07:15.0995 2880  [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:07:16.0088 2880  WPFFontCache_v0400 - ok
18:07:16.0151 2880  [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
18:07:16.0244 2880  ws2ifsl - ok
18:07:16.0354 2880  [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc          C:\Windows\system32\wscsvc.dll
18:07:16.0416 2880  wscsvc - ok
18:07:16.0432 2880  WSearch - ok
18:07:16.0572 2880  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
18:07:16.0697 2880  wuauserv - ok
18:07:16.0759 2880  [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
18:07:16.0806 2880  WUDFRd - ok
18:07:16.0837 2880  [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
18:07:16.0884 2880  wudfsvc - ok
18:07:16.0931 2880  [ 07F7285220307AAFB755D890295F0F9A ] yukonx64        C:\Windows\system32\DRIVERS\yk60x64.sys
18:07:16.0978 2880  yukonx64 - ok
18:07:17.0056 2880  [ 1CACFEF9E5DD866C5B79A135EE729E18 ] {55662437-DA8C-40c0-AADA-2C816A897A49} C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
18:07:17.0071 2880  {55662437-DA8C-40c0-AADA-2C816A897A49} - ok
18:07:17.0071 2880  ================ Scan global ===============================
18:07:17.0102 2880  [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
18:07:17.0149 2880  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
18:07:17.0165 2880  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
18:07:17.0243 2880  [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe
18:07:17.0243 2880  [Global] - ok
18:07:17.0243 2880  ================ Scan MBR ==================================
18:07:17.0274 2880  [ 588AE8F0C685C02BA11F30D9CD7E61A0 ] \Device\Harddisk0\DR0
18:07:18.0428 2880  \Device\Harddisk0\DR0 - ok
18:07:18.0428 2880  ================ Scan VBR ==================================
18:07:18.0460 2880  [ 4F671ACB12D2B23C2A215D3B242A1E8F ] \Device\Harddisk0\DR0\Partition1
18:07:18.0460 2880  \Device\Harddisk0\DR0\Partition1 - ok
18:07:18.0506 2880  [ 7B194D67144E38317068B1DBCA999781 ] \Device\Harddisk0\DR0\Partition2
18:07:18.0506 2880  \Device\Harddisk0\DR0\Partition2 - ok
18:07:18.0506 2880  ============================================================
18:07:18.0506 2880  Scan finished
18:07:18.0506 2880  ============================================================
18:07:18.0538 0292  Detected object count: 8
18:07:18.0538 0292  Actual detected object count: 8
18:07:28.0428 0292  Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0428 0292  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:07:28.0428 0292  DokanMounter ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0428 0292  DokanMounter ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:07:28.0428 0292  HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0428 0292  HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:07:28.0428 0292  hpqwmiex ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0428 0292  hpqwmiex ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:07:28.0444 0292  LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0444 0292  LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:07:28.0444 0292  RichVideo ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0444 0292  RichVideo ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:07:28.0444 0292  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0444 0292  SearchAnonymizer ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:07:28.0444 0292  ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
18:07:28.0444 0292  ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 10.10.2012 20:33

Jupp, der Part wurde erledigt! :daumenhoc

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

schustan 10.10.2012 21:47

hier mal der GMER-Log

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-10 22:46:39
Windows 6.0.6002 Service Pack 2
Running: lz3vxv5e.exe


---- Services - GMER 1.0.15 ----

Service  C:\Windows\system32 (*** hidden *** )  [MANUAL] BFE      <-- ROOTKIT !!!
Service  C:\Windows\system32 (*** hidden *** )  [MANUAL] MpsSvc  <-- ROOTKIT !!!

---- EOF - GMER 1.0.15 ----

bei OSAM kann ich nach dem Scan die Log-Datei nicht abspeichern. ich kann zwar auf "save" klicken, aber es passiert nichts :-(

hier aber der log von aswMBR.exe

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-10 23:12:32
-----------------------------
23:12:32.825    OS Version: Windows x64 6.0.6002 Service Pack 2
23:12:32.825    Number of processors: 2 586 0x1706
23:12:32.825    ComputerName: ANDREAS-PC  UserName: Andreas
23:12:34.105    Initialize success
23:12:38.691    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:12:38.691    Disk 0 Vendor: TOSHIBA_MK5055GSX FG002C Size: 476940MB BusType: 3
23:12:38.707    Disk 0 MBR read successfully
23:12:38.722    Disk 0 MBR scan
23:12:38.722    Disk 0 unknown MBR code
23:12:38.753    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      464628 MB offset 2048
23:12:38.785    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS        12308 MB offset 951560192
23:12:38.816    Disk 0 scanning C:\Windows\system32\drivers
23:13:02.824    Service scanning
23:13:48.173    Modules scanning
23:13:48.189    Disk 0 trace - called modules:
23:13:48.220    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys acpi.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
23:13:48.220    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004f51260]
23:13:48.236    3 CLASSPNP.SYS[fffffa6000a32c33] -> nt!IofCallDriver -> [0xfffffa8004f51b10]
23:13:48.251    5 hpdskflt.sys[fffffa6001a02189] -> nt!IofCallDriver -> [0xfffffa8004bdd600]
23:13:48.267    7 acpi.sys[fffffa60008c1fde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004be6940]
23:13:48.267    Scan finished successfully
23:13:58.064    Disk 0 MBR has been saved successfully to "C:\Users\Andreas\Desktop\MBR.dat"
23:13:58.064    The log file has been saved successfully to "C:\Users\Andreas\Desktop\aswMBR.txt"

avira meldet gerade, dass "2 Viren oder unerwünschte Programme" gefunden wurden :-/

wenn ich auf "details" klicke, steht 2x in je 2 verschiedenen Zeilen da:

OBJEKT: Desktop.ini.vir
FUND: TR/ATRAPS.Gen2

und dann kann ich die Aktion "In Quarantäne verschieben" wählen

und jetzt? ich dachte wir hätten das ding schon eliminiert :-/

cosinus 11.10.2012 13:39

Zitat:

avira meldet gerade, dass "2 Viren oder unerwünschte Programme" gefunden wurden :-/

wenn ich auf "details" klicke, steht 2x in je 2 verschiedenen Zeilen da:

OBJEKT: Desktop.ini.vir
FUND: TR/ATRAPS.Gen2
Mit sowas kann ich nichts anfangen, das Log dazu bitte komplett posten :kloppen:

schustan 11.10.2012 14:00

der rechner ist mittlerweile neu gebootet - seitdem kam die meldung nicht mehr ...:wtf:

was sagen denn die Logs von GMER und aswMBR.exe?

soll ich noch weitere scans machen? wenn ja, welche?

cosinus 11.10.2012 15:23

Dann schau bitte ins Log nach, damit ich weiß ob noch was aktiv war oder ob nut etwas in den Q-Ordnern gefunden wurde :kloppen:

schustan 11.10.2012 17:18

das ist die avira-meldung von gestern abend .. seitdem kam nichts mehr ..

Code:


Avira Free Antivirus
Erstellungsdatum der Reportdatei: Mittwoch, 10. Oktober 2012  23:37


Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  : Avira AntiVir Personal - Free Antivirus
Seriennummer  : 0000149996-ADJIE-0000001
Plattform      : Windows (TM) Vista Home Premium
Windowsversion : (Service Pack 2)  [6.0.6002]
Boot Modus    : Normal gebootet
Benutzername  : SYSTEM
Computername  : ANDREAS-PC

Versionsinformationen:
BUILD.DAT      : 13.0.0.2688    48279 Bytes  28.09.2012 10:06:00
AVSCAN.EXE    : 13.4.0.190    625440 Bytes  26.09.2012 13:58:14
AVSCANRC.DLL  : 13.4.0.163    64800 Bytes  19.09.2012 17:20:53
LUKE.DLL      : 13.4.0.184    66848 Bytes  25.09.2012 09:00:15
AVSCPLR.DLL    : 13.4.0.190    93984 Bytes  26.09.2012 13:58:22
AVREG.DLL      : 13.4.0.180    245536 Bytes  24.09.2012 11:05:45
avlode.dll    : 13.4.0.202    419616 Bytes  10.10.2012 21:21:15
avlode.rdf    : 13.0.0.24      7196 Bytes  27.09.2012 09:30:38
VBASE000.VDF  : 7.10.0.0    19875328 Bytes  06.11.2009 13:50:29
VBASE001.VDF  : 7.11.0.0    13342208 Bytes  14.12.2010 13:50:31
VBASE002.VDF  : 7.11.19.170 14374912 Bytes  20.12.2011 13:50:34
VBASE003.VDF  : 7.11.21.238  4472832 Bytes  01.02.2012 13:50:36
VBASE004.VDF  : 7.11.26.44  4329472 Bytes  28.03.2012 13:50:37
VBASE005.VDF  : 7.11.34.116  4034048 Bytes  29.06.2012 13:42:40
VBASE006.VDF  : 7.11.41.250  4902400 Bytes  06.09.2012 13:42:40
VBASE007.VDF  : 7.11.41.251    2048 Bytes  06.09.2012 13:42:40
VBASE008.VDF  : 7.11.41.252    2048 Bytes  06.09.2012 13:42:40
VBASE009.VDF  : 7.11.41.253    2048 Bytes  06.09.2012 13:42:40
VBASE010.VDF  : 7.11.41.254    2048 Bytes  06.09.2012 13:42:40
VBASE011.VDF  : 7.11.41.255    2048 Bytes  06.09.2012 13:42:40
VBASE012.VDF  : 7.11.42.0      2048 Bytes  06.09.2012 13:42:40
VBASE013.VDF  : 7.11.42.1      2048 Bytes  06.09.2012 13:42:40
VBASE014.VDF  : 7.11.42.65    203264 Bytes  09.09.2012 13:42:40
VBASE015.VDF  : 7.11.42.125  156672 Bytes  11.09.2012 13:42:40
VBASE016.VDF  : 7.11.42.171  187904 Bytes  12.09.2012 13:42:40
VBASE017.VDF  : 7.11.42.235  141312 Bytes  13.09.2012 13:42:40
VBASE018.VDF  : 7.11.43.35    133632 Bytes  15.09.2012 13:42:40
VBASE019.VDF  : 7.11.43.89    129024 Bytes  18.09.2012 13:42:40
VBASE020.VDF  : 7.11.43.141  130560 Bytes  19.09.2012 17:02:38
VBASE021.VDF  : 7.11.43.187  121856 Bytes  21.09.2012 07:40:42
VBASE022.VDF  : 7.11.43.251  147456 Bytes  24.09.2012 08:56:45
VBASE023.VDF  : 7.11.44.43    152064 Bytes  25.09.2012 08:31:00
VBASE024.VDF  : 7.11.44.103  165888 Bytes  27.09.2012 12:16:14
VBASE025.VDF  : 7.11.44.167  160256 Bytes  30.09.2012 21:21:07
VBASE026.VDF  : 7.11.44.223  199680 Bytes  02.10.2012 21:21:08
VBASE027.VDF  : 7.11.45.29    196096 Bytes  04.10.2012 21:21:08
VBASE028.VDF  : 7.11.45.111  202752 Bytes  08.10.2012 21:21:09
VBASE029.VDF  : 7.11.45.112    2048 Bytes  08.10.2012 21:21:09
VBASE030.VDF  : 7.11.45.113    2048 Bytes  08.10.2012 21:21:09
VBASE031.VDF  : 7.11.45.180  124416 Bytes  10.10.2012 21:21:09
Engineversion  : 8.2.10.182
AEVDF.DLL      : 8.1.2.10      102772 Bytes  19.09.2012 13:42:55
AESCRIPT.DLL  : 8.1.4.60      463227 Bytes  10.10.2012 21:21:15
AESCN.DLL      : 8.1.9.2      131444 Bytes  26.09.2012 13:54:07
AESBX.DLL      : 8.2.5.12      606578 Bytes  28.08.2012 15:58:06
AERDL.DLL      : 8.1.9.15      639348 Bytes  27.08.2012 13:50:15
AEPACK.DLL    : 8.3.0.38      811382 Bytes  10.10.2012 21:21:14
AEOFFICE.DLL  : 8.1.2.48      201082 Bytes  24.09.2012 13:06:59
AEHEUR.DLL    : 8.1.4.114    5353847 Bytes  10.10.2012 21:21:13
AEHELP.DLL    : 8.1.25.0      258423 Bytes  10.10.2012 21:21:09
AEGEN.DLL      : 8.1.5.38      434548 Bytes  26.09.2012 13:54:07
AEEXP.DLL      : 8.2.0.4      115060 Bytes  10.10.2012 21:21:15
AEEMU.DLL      : 8.1.3.2      393587 Bytes  19.09.2012 13:42:55
AECORE.DLL    : 8.1.28.2      201079 Bytes  26.09.2012 13:54:07
AEBB.DLL      : 8.1.1.0        53618 Bytes  27.08.2012 13:50:12
AVWINLL.DLL    : 13.4.0.163    25888 Bytes  19.09.2012 17:09:30
AVPREF.DLL    : 13.4.0.163    50464 Bytes  19.09.2012 17:07:51
AVREP.DLL      : 13.4.0.163    177952 Bytes  19.09.2012 17:08:15
AVARKT.DLL    : 13.4.0.184    260384 Bytes  25.09.2012 08:51:51
AVEVTLOG.DLL  : 13.4.0.185    167200 Bytes  25.09.2012 08:52:37
SQLITE3.DLL    : 3.7.0.1      397088 Bytes  19.09.2012 17:17:40
AVSMTP.DLL    : 13.4.0.163    62240 Bytes  19.09.2012 17:08:54
NETNT.DLL      : 13.4.0.163    15648 Bytes  19.09.2012 17:16:26
RCIMAGE.DLL    : 13.4.0.163  4780832 Bytes  19.09.2012 17:21:16
RCTEXT.DLL    : 13.4.0.163    68384 Bytes  19.09.2012 17:21:16

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: AVGuardAsyncScan
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_5075e76d\guard_slideup.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: quarantäne
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: aus
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: aus
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: vollständig

Beginn des Suchlaufs: Mittwoch, 10. Oktober 2012  23:37

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'svchost.exe' - '40' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'Ati2evxx.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '64' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '102' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '139' Modul(e) wurden durchsucht
Durchsuche Prozess 'STacSV64.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'SLsvc.exe' - '23' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '87' Modul(e) wurden durchsucht
Durchsuche Prozess 'Ati2evxx.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'Hpservice.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '91' Modul(e) wurden durchsucht
Durchsuche Prozess 'spoolsv.exe' - '79' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '53' Modul(e) wurden durchsucht
Durchsuche Prozess 'Dwm.exe' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'Explorer.EXE' - '144' Modul(e) wurden durchsucht
Durchsuche Prozess 'aavus.exe' - '42' Modul(e) wurden durchsucht
Durchsuche Prozess 'armsvc.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'AESTSr64.exe' - '5' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '82' Modul(e) wurden durchsucht
Durchsuche Prozess 'AppleMobileDeviceService.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'mDNSResponder.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'mounter.exe' - '17' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'LSSrvc.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'BLService.exe' - '30' Modul(e) wurden durchsucht
Durchsuche Prozess 'RichVideo.exe' - '24' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchAnonymizerHelper.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '44' Modul(e) wurden durchsucht
Durchsuche Prozess 'TomTomHOMEService.exe' - '13' Modul(e) wurden durchsucht
Durchsuche Prozess 'TVCapSvc.exe' - '82' Modul(e) wurden durchsucht
Durchsuche Prozess 'TVSched.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '7' Modul(e) wurden durchsucht
Durchsuche Prozess 'WLIDSVC.EXE' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchIndexer.exe' - '66' Modul(e) wurden durchsucht
Durchsuche Prozess 'WLIDSvcM.exe' - '16' Modul(e) wurden durchsucht
Durchsuche Prozess 'SynTPEnh.exe' - '42' Modul(e) wurden durchsucht
Durchsuche Prozess 'sttray64.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'avshadow.exe' - '24' Modul(e) wurden durchsucht
Durchsuche Prozess 'LCDMon.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'ehtray.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'ehmsas.exe' - '21' Modul(e) wurden durchsucht
Durchsuche Prozess 'HPWAMain.exe' - '92' Modul(e) wurden durchsucht
Durchsuche Prozess 'QLBCTRL.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'MOM.exe' - '58' Modul(e) wurden durchsucht
Durchsuche Prozess 'concentr.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '92' Modul(e) wurden durchsucht
Durchsuche Prozess 'wfcrun32.exe' - '53' Modul(e) wurden durchsucht
Durchsuche Prozess 'LCDPOP3.exe' - '30' Modul(e) wurden durchsucht
Durchsuche Prozess 'LCDClock.exe' - '30' Modul(e) wurden durchsucht
Durchsuche Prozess 'LCDMedia.exe' - '42' Modul(e) wurden durchsucht
Durchsuche Prozess 'CCC.exe' - '161' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpqwmiex.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmiprvse.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'SynTPHelper.exe' - '14' Modul(e) wurden durchsucht
Durchsuche Prozess 'Com4QLBEx.exe' - '23' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpqToaster.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '21' Modul(e) wurden durchsucht
Durchsuche Prozess 'hphc_service.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'wuauclt.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'TrustedInstaller.exe' - '56' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '97' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '99' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '84' Modul(e) wurden durchsucht
Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '14' Modul(e) wurden durchsucht
Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '14' Modul(e) wurden durchsucht
Durchsuche Prozess 'services.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsass.exe' - '60' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsm.exe' - '22' Modul(e) wurden durchsucht
Durchsuche Prozess 'winlogon.exe' - '30' Modul(e) wurden durchsucht

Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\Qoobox\Quarantine\C\Windows\assembly\GAC_32\Desktop.ini.vir'
C:\Qoobox\Quarantine\C\Windows\assembly\GAC_32\Desktop.ini.vir
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen2
Beginne mit der Suche in 'C:\Qoobox\Quarantine\C\Windows\assembly\GAC_64\Desktop.ini.vir'
C:\Qoobox\Quarantine\C\Windows\assembly\GAC_64\Desktop.ini.vir
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen2

Beginne mit der Desinfektion:
C:\Qoobox\Quarantine\C\Windows\assembly\GAC_64\Desktop.ini.vir
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen2
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '57e64655.qua' verschoben!
C:\Qoobox\Quarantine\C\Windows\assembly\GAC_32\Desktop.ini.vir
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen2
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4f7169f2.qua' verschoben!


Ende des Suchlaufs: Mittwoch, 10. Oktober 2012  23:37
Benötigte Zeit: 00:09 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

      0 Verzeichnisse wurden überprüft
    824 Dateien wurden geprüft
      2 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      2 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
    822 Dateien ohne Befall
      0 Archive wurden durchsucht
      0 Warnungen
      2 Hinweise


Die Suchergebnisse werden an den Guard übermittelt.


cosinus 11.10.2012 19:03

C:\Qoobox ist die Q von Combofix! Da war nichts mehr aktiv! :kloppen:

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

schustan 11.10.2012 19:48

und hier noch der aswMBR-log nach dem fixen ..

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-11 20:45:14
-----------------------------
20:45:14.707    OS Version: Windows x64 6.0.6002 Service Pack 2
20:45:14.707    Number of processors: 2 586 0x1706
20:45:14.707    ComputerName: ANDREAS-PC  UserName: Andreas
20:45:16.470    Initialize success
20:45:27.187    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:45:27.187    Disk 0 Vendor: TOSHIBA_MK5055GSX FG002C Size: 476940MB BusType: 3
20:45:27.234    Disk 0 MBR read successfully
20:45:27.234    Disk 0 MBR scan
20:45:27.234    Disk 0 Windows VISTA default MBR code
20:45:27.250    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      464628 MB offset 2048
20:45:27.297    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS        12308 MB offset 951560192
20:45:27.328    Disk 0 scanning C:\Windows\system32\drivers
20:45:39.106    Service scanning
20:46:19.447    Modules scanning
20:46:19.447    Disk 0 trace - called modules:
20:46:19.510    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys acpi.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
20:46:19.525    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004f30560]
20:46:19.525    3 CLASSPNP.SYS[fffffa6000a25c33] -> nt!IofCallDriver -> [0xfffffa8004f2b230]
20:46:19.541    5 hpdskflt.sys[fffffa60019d9189] -> nt!IofCallDriver -> [0xfffffa8004be7780]
20:46:19.541    7 acpi.sys[fffffa60008c5fde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004bd1060]
20:46:19.557    Scan finished successfully
20:47:07.901    Disk 0 MBR has been saved successfully to "C:\Users\Andreas\Desktop\MBR.dat"
20:47:07.917    The log file has been saved successfully to "C:\Users\Andreas\Desktop\aswMBR.txt"


cosinus 12.10.2012 10:20

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

schustan 12.10.2012 18:18

einmal der malware-log ..

Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.12.02

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Andreas :: ANDREAS-PC [Administrator]

12.10.2012 13:38:36
mbam-log-2012-10-12 (19-17-15).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 464304
Laufzeit: 3 Stunde(n), 9 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\_OTL\MovedFiles\10072012_222944\C_Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Keine Aktion durchgeführt.
C:\_OTL\MovedFiles\10072012_222944\C_Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\000000cb.@ (Rootkit.0Access) -> Keine Aktion durchgeführt.
C:\_OTL\MovedFiles\10072012_222944\C_Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\80000000.@ (Rootkit.0Access.64) -> Keine Aktion durchgeführt.

(Ende)


cosinus 12.10.2012 20:24

Das sind nur Funde in der Q von OTL

schustan 12.10.2012 23:08

und das ist der superantispyware-log

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/13/2012 at 00:07 AM

Application Version : 5.6.1010

Core Rules Database Version : 9394
Trace Rules Database Version: 7206

Scan type      : Complete Scan
Total Scan Time : 04:27:07

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User

Memory items scanned      : 620
Memory threats detected  : 0
Registry items scanned    : 72912
Registry threats detected : 0
File items scanned        : 244937
File threats detected    : 605

Adware.Tracking Cookie
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@a6.adserver01[1].txt [ /a6.adserver01 ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@a7.adserver01[2].txt [ /a7.adserver01 ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@adbrite[1].txt [ /adbrite ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@ads.moviemaze[1].txt [ /ads.moviemaze ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@adtech[1].txt [ /adtech ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@adviva[2].txt [ /adviva ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@adx.chip[1].txt [ /adx.chip ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@aolde.122.2o7[1].txt [ /aolde.122.2o7 ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@ar.atwola[2].txt [ /ar.atwola ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@at.atwola[2].txt [ /at.atwola ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@atwola[2].txt [ /atwola ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@cdn.at.atwola[2].txt [ /cdn.at.atwola ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@cdn5.specificclick[1].txt [ /cdn5.specificclick ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@count.rbc[1].txt [ /count.rbc ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@cz2.clickzs[2].txt [ /cz2.clickzs ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@cz7.clickzs[1].txt [ /cz7.clickzs ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@de.at.atwola[1].txt [ /de.at.atwola ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@specificclick[2].txt [ /specificclick ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@tacoda.at.atwola[2].txt [ /tacoda.at.atwola ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@tns-counter[1].txt [ /tns-counter ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@tradedoubler[1].txt [ /tradedoubler ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@vip2.clickzs[1].txt [ /vip2.clickzs ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@www.etracker[2].txt [ /www.etracker ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@www.megapornstarvids[1].txt [ /www.megapornstarvids ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@www.megapornstarvids[2].txt [ /www.megapornstarvids ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@xiti[1].txt [ /xiti ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\KWZXVZ21.txt [ /adform.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\WCZ1EV6F.txt [ /ad.360yield.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\PNJK797A.txt [ /de.sitestat.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\PUAK2PGB.txt [ /smartadserver.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\1W6TFLLK.txt [ /ww251.smartadserver.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\RXYJ6DUX.txt [ /apmebf.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\I5NP0603.txt [ /2o7.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\LXTFJYQR.txt [ /doubleclick.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\4CDAZB0B.txt [ /im.banner.t-online.de ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\PUL97Q02.txt [ /imrworldwide.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\5YGFXDSW.txt [ /ad.zanox.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\QI5R1MFR.txt [ /zanox-affiliate.de ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\SVGL09V5.txt [ /advertising.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\RP4GXP45.txt [ /webmasterplan.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\V24TCDZZ.txt [ /ad1.adfarm1.adition.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\QTQ3B25H.txt [ /de.sitestat.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\1U8LX7IJ.txt [ /www.zanox-affiliate.de ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\PPJ1GGRB.txt [ /server.lon.liveperson.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\ERVO5GEG.txt [ /serving-sys.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\YG874JD0.txt [ /dyntracker.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\NFWLZ0PB.txt [ /fastclick.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\GMS4HA0J.txt [ /atdmt.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\10B4WVOC.txt [ /ad.ad-srv.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\BYVHYNAR.txt [ /liveperson.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\TNIGK41O.txt [ /mediaplex.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\andreas@rambler[1].txt [ /rambler.ru ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\J96B831U.txt [ /liveperson.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\RQBFFP5X.txt [ /ad.yieldmanager.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\BMXJF7AD.txt [ /zanox.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\JA76EE5A.txt [ /img.mediaplex.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\2XH1SAUA.txt [ /revsci.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\5OJF825G.txt [ /c.atdmt.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\PI21KQDF.txt [ /eas.apm.emediate.eu ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\XV6L656I.txt [ /tracking.quisma.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\7D5VWMT3.txt [ /yadro.ru ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\VKBSZG7A.txt [ /track.adform.net ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\373EWEDO.txt [ /adfarm1.adition.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\Y1TAN4TK.txt [ /statse.webtrendslive.com ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\83GPEFNM.txt [ /ad.dyntracker.de ]
        C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Cookies\5CXQVV6A.txt [ /bs.serving-sys.com ]
        C:\USERS\ANDREAS\AppData\Roaming\Microsoft\Windows\Cookies\8YTAFAO8.txt [ Cookie:andreas@clkads.com/adServe ]
        C:\USERS\ANDREAS\AppData\Roaming\Microsoft\Windows\Cookies\Low\andreas@de.at.atwola[1].txt [ Cookie:andreas@de.at.atwola.com/ ]
        C:\USERS\ANDREAS\AppData\Roaming\Microsoft\Windows\Cookies\Low\andreas@doubleclick[1].txt [ Cookie:andreas@doubleclick.net/ ]
        C:\USERS\ANDREAS\AppData\Roaming\Microsoft\Windows\Cookies\Low\andreas@advertising[2].txt [ Cookie:andreas@advertising.com/ ]
        C:\USERS\ANDREAS\AppData\Roaming\Microsoft\Windows\Cookies\Low\andreas@aolde.122.2o7[1].txt [ Cookie:andreas@aolde.122.2o7.net/ ]
        C:\USERS\ANDREAS\AppData\Roaming\Microsoft\Windows\Cookies\Low\andreas@adtech[1].txt [ Cookie:andreas@adtech.de/ ]
        C:\USERS\ANDREAS\Cookies\andreas@cdn.at.atwola[2].txt [ Cookie:andreas@cdn.at.atwola.com/ ]
        C:\USERS\ANDREAS\Cookies\KWZXVZ21.txt [ Cookie:andreas@adform.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@adbrite[1].txt [ Cookie:andreas@adbrite.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@count.rbc[1].txt [ Cookie:andreas@count.rbc.ru/ ]
        C:\USERS\ANDREAS\Cookies\PNJK797A.txt [ Cookie:andreas@de.sitestat.com/sportscheck/ ]
        C:\USERS\ANDREAS\Cookies\PUAK2PGB.txt [ Cookie:andreas@smartadserver.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@vip2.clickzs[1].txt [ Cookie:andreas@vip2.clickzs.com/ ]
        C:\USERS\ANDREAS\Cookies\1W6TFLLK.txt [ Cookie:andreas@ww251.smartadserver.com/ ]
        C:\USERS\ANDREAS\Cookies\RXYJ6DUX.txt [ Cookie:andreas@apmebf.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@cdn5.specificclick[1].txt [ Cookie:andreas@cdn5.specificclick.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@de.at.atwola[1].txt [ Cookie:andreas@de.at.atwola.com/ ]
        C:\USERS\ANDREAS\Cookies\LXTFJYQR.txt [ Cookie:andreas@doubleclick.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@tacoda.at.atwola[2].txt [ Cookie:andreas@tacoda.at.atwola.com/ ]
        C:\USERS\ANDREAS\Cookies\4CDAZB0B.txt [ Cookie:andreas@im.banner.t-online.de/ ]
        C:\USERS\ANDREAS\Cookies\PUL97Q02.txt [ Cookie:andreas@imrworldwide.com/cgi-bin ]
        C:\USERS\ANDREAS\Cookies\5YGFXDSW.txt [ Cookie:andreas@ad.zanox.com/ ]
        C:\USERS\ANDREAS\Cookies\QI5R1MFR.txt [ Cookie:andreas@zanox-affiliate.de/ ]
        C:\USERS\ANDREAS\Cookies\SVGL09V5.txt [ Cookie:andreas@advertising.com/ ]
        C:\USERS\ANDREAS\Cookies\8YTAFAO8.txt [ Cookie:andreas@clkads.com/adServe ]
        C:\USERS\ANDREAS\Cookies\V24TCDZZ.txt [ Cookie:andreas@ad1.adfarm1.adition.com/ ]
        C:\USERS\ANDREAS\Cookies\QTQ3B25H.txt [ Cookie:andreas@de.sitestat.com/sportscheck/shop-de/ ]
        C:\USERS\ANDREAS\Cookies\ERVO5GEG.txt [ Cookie:andreas@serving-sys.com/ ]
        C:\USERS\ANDREAS\Cookies\YG874JD0.txt [ Cookie:andreas@dyntracker.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@ar.atwola[2].txt [ Cookie:andreas@ar.atwola.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@tns-counter[1].txt [ Cookie:andreas@tns-counter.ru/ ]
        C:\USERS\ANDREAS\Cookies\NFWLZ0PB.txt [ Cookie:andreas@fastclick.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@adviva[2].txt [ Cookie:andreas@adviva.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@aolde.122.2o7[1].txt [ Cookie:andreas@aolde.122.2o7.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@tradedoubler[1].txt [ Cookie:andreas@tradedoubler.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@a6.adserver01[1].txt [ Cookie:andreas@a6.adserver01.de/ ]
        C:\USERS\ANDREAS\Cookies\andreas@cz2.clickzs[2].txt [ Cookie:andreas@cz2.clickzs.com/ ]
        C:\USERS\ANDREAS\Cookies\BYVHYNAR.txt [ Cookie:andreas@liveperson.net/ ]
        C:\USERS\ANDREAS\Cookies\TNIGK41O.txt [ Cookie:andreas@mediaplex.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@rambler[1].txt [ Cookie:andreas@rambler.ru/ ]
        C:\USERS\ANDREAS\Cookies\J96B831U.txt [ Cookie:andreas@liveperson.net/hc/85950269 ]
        C:\USERS\ANDREAS\Cookies\RQBFFP5X.txt [ Cookie:andreas@ad.yieldmanager.com/ ]
        C:\USERS\ANDREAS\Cookies\BMXJF7AD.txt [ Cookie:andreas@zanox.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@xiti[1].txt [ Cookie:andreas@xiti.com/ ]
        C:\USERS\ANDREAS\Cookies\JA76EE5A.txt [ Cookie:andreas@img.mediaplex.com/ ]
        C:\USERS\ANDREAS\Cookies\2XH1SAUA.txt [ Cookie:andreas@revsci.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@cz7.clickzs[1].txt [ Cookie:andreas@cz7.clickzs.com/ ]
        C:\USERS\ANDREAS\Cookies\5OJF825G.txt [ Cookie:andreas@c.atdmt.com/ ]
        C:\USERS\ANDREAS\Cookies\PI21KQDF.txt [ Cookie:andreas@eas.apm.emediate.eu/ ]
        C:\USERS\ANDREAS\Cookies\XV6L656I.txt [ Cookie:andreas@tracking.quisma.com/ ]
        C:\USERS\ANDREAS\Cookies\andreas@www.etracker[2].txt [ Cookie:andreas@www.etracker.de/ ]
        C:\USERS\ANDREAS\Cookies\VKBSZG7A.txt [ Cookie:andreas@track.adform.net/ ]
        C:\USERS\ANDREAS\Cookies\andreas@adtech[1].txt [ Cookie:andreas@adtech.de/ ]
        C:\USERS\ANDREAS\Cookies\andreas@atwola[2].txt [ Cookie:andreas@atwola.com/ ]
        C:\USERS\ANDREAS\Cookies\83GPEFNM.txt [ Cookie:andreas@ad.dyntracker.de/ ]
        C:\USERS\ANDREAS\Cookies\5CXQVV6A.txt [ Cookie:andreas@bs.serving-sys.com/ ]
        C:\USERS\ANDREAS\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ANDREAS@2O7[1].TXT [ /2O7 ]
        .imrworldwide.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.pornhub.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .122.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adxpansion.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .traffichaus.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .im.banner.t-online.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .247realmedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .hardsextube.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .amazon-adsystem.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.crakmedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .enoratraffic.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .bs.serving-sys.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .eyewonder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .xxxylive.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .clickfuse.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tto2.traffictrack.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultadworld.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adnetwork.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .hawaiianairlines.112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.porn.to [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .porn.to [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .porn.to [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .geobanner.adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .banners.adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .qksrv.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .usatoday1.112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        piwik.ddnewmedia.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ad.adnet.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .generaltracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .generaltracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .generaltracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .generaltracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .generaltracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.pornerbros.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ads.ventivmedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .a.revenuemax.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.m-adserver.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adxvalue.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.barclaycard-adserver.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        s03.flagcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .technoratimedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        stat.ed.cupidplc.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .porntubevidz.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .porntubevidz.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        openx.sexsearchcom.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornup.me [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornup.me [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.pornup.me [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .freefuckvidz.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .freefuckvidz.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        hellporno.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .hellporno.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .hellporno.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .h2porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .h2porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .h2porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        h2porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.pornerbros.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .h2porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .h2porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.trackingindahouse.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.pornerbros.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornerbros.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornerbros.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .unister-adservices.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .blogads.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .alphaporno.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .alphaporno.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .girlsteachsex.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .discounthawaiicarrental.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .discounthawaiicarrental.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.discounthawaiicarrental.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .dmtracker.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .overture.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .qksrv.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .qksrv.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .andomedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webservices.evolvemediacorp.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webservices.evolvemediacorp.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .marketlive.122.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eas.apm.emediate.eu [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .hardsextube.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .hardsextube.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.hardsextube.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adserver.hardsextube.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .plug-media.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .plug-media.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .xxxymovies.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .xxxymovies.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornsharia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornsharia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        pornsharia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .porn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .xxxkinky.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .xxxkinky.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.xxxkinky.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornbanana.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornbanana.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.pornhub.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornyeah.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornyeah.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.pornyeah.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornicom.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornicom.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .realgfporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .realgfporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.realgfporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornicom.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultadworld.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.youporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .sexad.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .unrulymedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .traveladvertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webresint.122.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        tracking.dc-storm.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .count.eon.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .mm.chitika.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adxpansion.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ads2.zeusclicks.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .mediaforge.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        in.getclicky.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adxpose.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .msnbc.112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adinterax.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.adition.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .aim4media.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .e-2dj6wblyaldzglp.stats.esomniture.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .c.atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        targeting.revenuemax.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .banners.victor.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .prisacom.112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        partners.webmasterplan.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        track.effiliation.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .mediaforge.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .mediaforge.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .rbc.bridgetrack.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .rbc.bridgetrack.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .rbc.bridgetrack.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .zedo.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .eliteprospects.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        stat.dealtime.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adserver.adworxs.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        zbox.zanox.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .traffictrack.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.active-tracking.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .flagcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .serving-sys.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        server.adform.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad4.adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .syndication.traffichaus.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .syndication.traffichaus.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .zanox-affiliate.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tracker.vinsight.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adbrite.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .atwola.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adtech.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .burstnet.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adtechus.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adtechus.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .casalemedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .interclick.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .collective-media.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .kontera.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .legolas-media.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .mediaplex.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .media6degrees.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .specificmedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .specificclick.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adviva.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tribalfusion.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ads.pointroll.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ru4.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .revsci.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        media.antenne-bayern.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .lucidmedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        track.zalando.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        tracking.s24.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .questionmarket.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        openx.microsites.transcontinentalmedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de-fourmedia.videoplaza.tv [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .stats.paypal.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .paypal.112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        counter.hitslink.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .yieldmanager.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www6.addfreestats.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .openstat.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .spylog.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .fastclick.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .ero-advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ads.trafficjunky.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .c1.atdmt.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .youporn.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .pornstars.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .urbia.wwe-media.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.googleadservices.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ads.crakmedia.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adultfriendfinder.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .nhl.112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad1.adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad3.adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ox-d.secure-clicks.org [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ads.pornerbros.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        eas4.emediate.eu [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.counter-go.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .smartadserver.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad2.adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .olympiaverlag.122.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.zanox-affiliate.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .toplist.cz [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .serialnumber.in [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adfarm1.adition.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .tradedoubler.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .apmebf.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .adform.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        e2.emediate.se [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .estat.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        server.lon.liveperson.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        ad.yieldmanager.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adx2.chip.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .advertising.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adx.chip.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        adserv.cinecitta.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .everysport.112.2o7.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        panzertraffic.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        cs.traffichold.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\ANDREAS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\PN21NWMV.DEFAULT\COOKIES.SQLITE ]

Trojan.Agent/Gen-MSFake
        C:\USERS\ANDREAS\APPDATA\ROAMING\DESKTOPICONFORAMAZON\ICONFORAMAZON.EXE

kann man das zeug in der Q eigentl löschen? wird ja eh nicht mehr "gebraucht" .. und was weg ist, ist weg .. oder? ;-)

cosinus 13.10.2012 15:50

Was habt ihr alle immer nur mit der Quarantäne? :wtf:
Überleg doch mal was eine Quarantäne ist. Ob da die schädliche Datei drinbleibt oder nicht, das hat keine Auswirkungen. Schädlinge in der Quarantäne können nichts mehr anrichten, sie sind dort isoliert. Du solltest grundsätzlich mit der Quarantäne arbeiten, denn falls der Virenscanner durch einen Fehlalarm was wichtiges löscht, kannst Du notfalls noch über die Quarantäne an die Datei ran.


Code:

UAC On - Limited User
Wie hast du sasw gestartet? Einfach per Doppelklick?

Bitte so wie es in der Anleitung steht auch ausführen!

Zitat:

Zitat von cosinus (Beitrag 324870)
Teil 2: Programm ausführen
Das Programm wurde nun installiert, eine Verknüpfung auf dem Desktop sollte erstellt worden sein. Nachdem du es gestartet hast, wird es sich erstmalig beim Updateserver nach neuen Schädlingssignaturen umsehen und Updates installieren. Diesen Vorgang NICHT abbrechen!

Benutzer mit Windows Vista und Windows 7 starten das Tool bitte wieder per Rechtsklick => als Administrator ausführen!


schustan 14.10.2012 02:43

hier der neue log, .. ich hab zwar "als administrator" ausgeführt, auch wenn es wieder "limited user" heißt .. kA warum :confused:

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/13/2012 at 10:25 PM

Application Version : 5.6.1010

Core Rules Database Version : 9400
Trace Rules Database Version: 7212

Scan type      : Complete Scan
Total Scan Time : 04:14:00

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User

Memory items scanned      : 650
Memory threats detected  : 0
Registry items scanned    : 72912
Registry threats detected : 0
File items scanned        : 240836
File threats detected    : 1

Trojan.Agent/Gen-MSFake
        C:\USERS\ANDREAS\APPDATA\ROAMING\DESKTOPICONFORAMAZON\ICONFORAMAZON.EXE


cosinus 14.10.2012 17:45

Das ist offensichtlich ein SASW Bug

Sieht ok aus, da wurden nur Cookies gefunden, die können alle weg, der andere angebliche Fund ist imho ein Fehlalarm.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

schustan 14.10.2012 18:35

ok, das klingt gut ..

an dieser stelle ein ganz ganz großes DANKE - die Hilfe war absolut sensationell!!

ansonsten hab ich keine weiteren probleme mit dem rechner, läuft alles rund.

eine frage noch zu dem einen fund, den mir superantispyware anzeigt .. du gehst davon aus, dass es ein fehlalarm ist .. soll ich das ding trotzdem sicherheitshalber mit superantispyware entfernen? .. iconforamazon.exe rühr ich zwar eh nicht an, aber es ist ja keine datei bzw ein programm das ich brauche.

solange die datei nicht geöffnet wird, tut sie mir ja auch nichts, oder?

cosinus 14.10.2012 20:10

Ja kann alles weg ;)

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

schustan 30.10.2012 15:03

hey

ich bin's nochmal - mit einer kleinen rückfrage ...
und zwar hab ich seit dem virus-runterlöschen standardmäßig offenbar nicht mehr jedes prog als admin ausführt .. kann ich das ändern?

auch die standard-abfragen bei ausführen von programmen sind etwas störend .. das hatte ich zuvor deaktiviert, weiß aber nicht mehr wie ...

danke schonmal!


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:21 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131