Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Ca. 50 PUP.Blabber Trojaner ! (https://www.trojaner-board.de/131121-ca-50-pup-blabber-trojaner.html)

JannikLR 16.02.2013 00:29

Ca. 50 PUP.Blabber Trojaner !
 
Hallo. Ich habe einen Quick Scan durchlaufen lassen und mehrere PUP.Blabbers ( ca.50 ) Trojaner gefunden. Nun wollte ich fragen , wie ich vorgehen muss. Ich bitte um Hilfe.

markusg 16.02.2013 01:20

Hi
ein guter Anfang währe es, uns das Log zu zeigen :-)

JannikLR 16.02.2013 01:37

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.02.15.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Rohr :: ROHR-PC [Administrator]

16.02.2013 00:03:19
MBAM-log-2013-02-16 (00-29-47).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 211117
Laufzeit: 3 Minute(n), 23 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 19
HKCR\CLSID\{00cbb66b-1d3b-46d3-9577-323a336acb50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\wit4ie.WitBHO.2 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\wit4ie.WitBHO (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\tdataprotocol.CTData.1 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\tdataprotocol.CTData (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\updatebho.TimerBHO.1 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\updatebho.TimerBHO (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\PROTOCOLS\HANDLER\BASE64 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\PROTOCOLS\HANDLER\CHROME (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\PROTOCOLS\HANDLER\PROX (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 3
HKCR\protocols\Handler\base64|CLSID (PUP.Blabbers) -> Daten: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Keine Aktion durchgeführt.
HKCR\protocols\Handler\chrome|CLSID (PUP.Blabbers) -> Daten: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Keine Aktion durchgeführt.
HKCR\protocols\Handler\prox|CLSID (PUP.Blabbers) -> Daten: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 3
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Dateien: 14
C:\Program Files (x86)\GinyasBrowserCompanion\jsloader.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\GinyasBrowserCompanion\tdataprotocol.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\GinyasBrowserCompanion\updatebhoWin32.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix2.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix3.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix4.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix5.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\icon.png (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\jquery4toolbar.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\lock.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witapi.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witmain.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\wittoolbar.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witwidgetapi.js (PUP.Blabbers) -> Keine Aktion durchgeführt.

(Ende)

JannikLR 17.02.2013 13:42

JETZT:
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.02.15.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Rohr :: ROHR-PC [Administrator]

17.02.2013 13:35:47
MBAM-log-2013-02-17 (13-39-17).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 211966
Laufzeit: 3 Minute(n), 3 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 22
HKCR\CLSID\{00cbb66b-1d3b-46d3-9577-323a336acb50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\wit4ie.WitBHO.2 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\wit4ie.WitBHO (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\tdataprotocol.CTData.1 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\tdataprotocol.CTData (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\updatebho.TimerBHO.1 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\updatebho.TimerBHO (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\PROTOCOLS\HANDLER\BASE64 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\PROTOCOLS\HANDLER\PROX (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 2
HKCR\protocols\Handler\base64|CLSID (PUP.Blabbers) -> Daten: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Keine Aktion durchgeführt.
HKCR\protocols\Handler\prox|CLSID (PUP.Blabbers) -> Daten: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 3
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Dateien: 36
C:\Program Files (x86)\GinyasBrowserCompanion\jsloader.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\GinyasBrowserCompanion\tdataprotocol.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\GinyasBrowserCompanion\updatebhoWin32.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix2.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix3.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix4.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix5.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\icon.png (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\jquery4toolbar.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\lock.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witapi.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witmain.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\wittoolbar.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witwidgetapi.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\6e76926b3b0d85fcd902b6d863053026 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\6e76926b3b0d85fcd902b6d863053026_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\91ed24cba47f3cabaaaf7bdb0e620066 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\91ed24cba47f3cabaaaf7bdb0e620066_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\9432a59cebc26f248a26b37875994d5e (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\9432a59cebc26f248a26b37875994d5e_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\a7e0abb80dabcdbb6dbaec920aa126a0 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\a7e0abb80dabcdbb6dbaec920aa126a0_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.

(Ende)

markusg 17.02.2013 16:13

sind das alle logs? ich wollte die älteren auch sehen
http://www.trojaner-board.de/125889-...en-posten.html

JannikLR 24.02.2013 21:00

Welche älteren ?
Soll ich einen Fullscan durchlaufen lassen ?

markusg 25.02.2013 16:30

ob es ältere Fundmeldungen gibt, einfach mal in der Anleitung gucken und von dort dann in den instalierten Programmen alle Berichte mit funden posten, die hier evtl noch nicht stehen

JannikLR 07.03.2013 20:43

Ältere gibt es nicht. Aber ich hab nochmal den Quickscan durchlaufen lassen :

Datenbank Version: v2013.03.02.11

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Rohr :: ROHR-PC [Administrator]

08.03.2013 20:38:26
MBAM-log-2013-03-08 (20-34-12).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 204113
Laufzeit: 47 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 22
HKCR\CLSID\{00cbb66b-1d3b-46d3-9577-323a336acb50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\wit4ie.WitBHO.2 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\wit4ie.WitBHO (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\tdataprotocol.CTData.1 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\tdataprotocol.CTData (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\updatebho.TimerBHO.1 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\updatebho.TimerBHO (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\PROTOCOLS\HANDLER\BASE64 (PUP.Blabbers) -> Keine Aktion durchgeführt.
HKCR\PROTOCOLS\HANDLER\PROX (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 2
HKCR\protocols\Handler\base64|CLSID (PUP.Blabbers) -> Daten: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Keine Aktion durchgeführt.
HKCR\protocols\Handler\prox|CLSID (PUP.Blabbers) -> Daten: {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -> Keine Aktion durchgeführt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 3
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache (PUP.Blabbers) -> Keine Aktion durchgeführt.

Infizierte Dateien: 36
C:\Program Files (x86)\GinyasBrowserCompanion\jsloader.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\GinyasBrowserCompanion\tdataprotocol.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\GinyasBrowserCompanion\updatebhoWin32.dll (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix2.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix3.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix4.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\fix5.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\icon.png (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\jquery4toolbar.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\lock.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witapi.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witmain.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\wittoolbar.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\witwidgetapi.js (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\0324adea3b6ec02af09ea4ae9424591b_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\292124057d00cb0fa73db6b90d079658_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\4d3d10bd28ff623813254a49b26be41f_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\6e76926b3b0d85fcd902b6d863053026 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\6e76926b3b0d85fcd902b6d863053026_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\91ed24cba47f3cabaaaf7bdb0e620066 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\91ed24cba47f3cabaaaf7bdb0e620066_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\9432a59cebc26f248a26b37875994d5e (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\9432a59cebc26f248a26b37875994d5e_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\a7e0abb80dabcdbb6dbaec920aa126a0 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\a7e0abb80dabcdbb6dbaec920aa126a0_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271 (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\e919434ec29526b28593c426e4264271_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\f03527c67e08602d2e4c18ae7867300d_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\fa74672918974682c82b8d91dfbe0d6b_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f (PUP.Blabbers) -> Keine Aktion durchgeführt.
C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f_expire (PUP.Blabbers) -> Keine Aktion durchgeführt.

(Ende)

markusg 08.03.2013 19:32

bitte das machen was da steht, wenn ich nach alten logs frage, und es gibt keine, einfach bescheid sagen, neues solltest du nicht erstellen.
danke.
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

JannikLR 09.03.2013 12:25

12:15:01.0683 4856 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
12:15:03.0596 4856 ============================================================
12:15:03.0596 4856 Current date / time: 2013/03/10 12:15:03.0596
12:15:03.0596 4856 SystemInfo:
12:15:03.0596 4856
12:15:03.0596 4856 OS Version: 6.1.7601 ServicePack: 1.0
12:15:03.0596 4856 Product type: Workstation
12:15:03.0596 4856 ComputerName: ROHR-PC
12:15:03.0596 4856 UserName: Rohr
12:15:03.0596 4856 Windows directory: C:\Windows
12:15:03.0596 4856 System windows directory: C:\Windows
12:15:03.0596 4856 Running under WOW64
12:15:03.0596 4856 Processor architecture: Intel x64
12:15:03.0596 4856 Number of processors: 4
12:15:03.0596 4856 Page size: 0x1000
12:15:03.0596 4856 Boot type: Normal boot
12:15:03.0596 4856 ============================================================
12:15:04.0901 4856 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:15:04.0921 4856 ============================================================
12:15:04.0921 4856 \Device\Harddisk0\DR0:
12:15:04.0922 4856 MBR partitions:
12:15:04.0922 4856 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
12:15:04.0922 4856 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000
12:15:04.0922 4856 ============================================================
12:15:04.0967 4856 C: <-> \Device\Harddisk0\DR0\Partition2
12:15:04.0967 4856 ============================================================
12:15:04.0967 4856 Initialize success
12:15:04.0967 4856 ============================================================
12:15:38.0597 2164 ============================================================
12:15:38.0597 2164 Scan started
12:15:38.0597 2164 Mode: Manual; SigCheck; TDLFS;
12:15:38.0597 2164 ============================================================
12:15:39.0350 2164 ================ Scan system memory ========================
12:15:39.0350 2164 System memory - ok
12:15:39.0350 2164 ================ Scan services =============================
12:15:40.0635 2164 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
12:15:40.0778 2164 1394ohci - ok
12:15:40.0818 2164 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
12:15:40.0836 2164 ACPI - ok
12:15:40.0882 2164 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
12:15:40.0955 2164 AcpiPmi - ok
12:15:42.0131 2164 [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:15:42.0162 2164 AdobeFlashPlayerUpdateSvc - ok
12:15:42.0226 2164 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
12:15:42.0258 2164 adp94xx - ok
12:15:42.0298 2164 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
12:15:42.0348 2164 adpahci - ok
12:15:42.0373 2164 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
12:15:42.0397 2164 adpu320 - ok
12:15:42.0438 2164 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
12:15:42.0566 2164 AeLookupSvc - ok
12:15:42.0618 2164 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
12:15:42.0684 2164 AFD - ok
12:15:42.0722 2164 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
12:15:42.0736 2164 agp440 - ok
12:15:42.0759 2164 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
12:15:42.0816 2164 ALG - ok
12:15:42.0845 2164 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
12:15:42.0863 2164 aliide - ok
12:15:42.0925 2164 [ 4EAAAAB8759644D572522FBCDD196A13 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
12:15:43.0026 2164 AMD External Events Utility - ok
12:15:43.0081 2164 AMD FUEL Service - ok
12:15:43.0092 2164 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
12:15:43.0108 2164 amdide - ok
12:15:43.0139 2164 [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys
12:15:43.0167 2164 amdiox64 - ok
12:15:43.0227 2164 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
12:15:43.0275 2164 AmdK8 - ok
12:15:43.0472 2164 [ 22A14DF59FB8D0BE918C597988AF4296 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
12:15:43.0750 2164 amdkmdag - ok
12:15:43.0855 2164 [ EE22D3ED6D55A855E709F811CCCA97ED ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
12:15:43.0939 2164 amdkmdap - ok
12:15:43.0963 2164 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
12:15:44.0022 2164 AmdPPM - ok
12:15:44.0080 2164 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
12:15:44.0130 2164 amdsata - ok
12:15:44.0187 2164 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
12:15:44.0233 2164 amdsbs - ok
12:15:44.0271 2164 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
12:15:44.0293 2164 amdxata - ok
12:15:44.0327 2164 [ 5A528A540B1AEE8B1C77ED65094E8CDF ] AODDriver4.01 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
12:15:44.0351 2164 AODDriver4.01 - ok
12:15:44.0392 2164 [ 5A528A540B1AEE8B1C77ED65094E8CDF ] AODDriver4.2 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
12:15:44.0401 2164 AODDriver4.2 - ok
12:15:44.0445 2164 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
12:15:44.0574 2164 AppID - ok
12:15:44.0589 2164 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
12:15:44.0641 2164 AppIDSvc - ok
12:15:44.0671 2164 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
12:15:44.0718 2164 Appinfo - ok
12:15:44.0856 2164 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:15:44.0881 2164 Apple Mobile Device - ok
12:15:44.0931 2164 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
12:15:44.0961 2164 arc - ok
12:15:44.0979 2164 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
12:15:44.0993 2164 arcsas - ok
12:15:45.0023 2164 [ FEF9DD9EA587F8886ADE43C1BEFBDAFE ] AsIO C:\Windows\syswow64\drivers\AsIO.sys
12:15:45.0034 2164 AsIO - ok
12:15:45.0061 2164 [ 22842362DF890F5492F85AA60916A697 ] asmthub3 C:\Windows\system32\DRIVERS\asmthub3.sys
12:15:45.0102 2164 asmthub3 - ok
12:15:45.0120 2164 [ 08E2D77766CC05E75A0707207D9FC684 ] asmtxhci C:\Windows\system32\DRIVERS\asmtxhci.sys
12:15:45.0168 2164 asmtxhci - ok
12:15:45.0547 2164 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
12:15:45.0585 2164 aspnet_state - ok
12:15:45.0623 2164 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
12:15:45.0703 2164 AsyncMac - ok
12:15:45.0722 2164 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
12:15:45.0732 2164 atapi - ok
12:15:45.0782 2164 [ E857EEE6B92AAA473EBB3465ADD8F7E7 ] athr C:\Windows\system32\DRIVERS\athrx.sys
12:15:45.0852 2164 athr - ok
12:15:45.0902 2164 [ 437F55435623D4D54D36197F5AD8B435 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
12:15:45.0972 2164 AtiHDAudioService - ok
12:15:46.0040 2164 [ C07A040D6B5A42DD41EE386CF90974C8 ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie.sys
12:15:46.0061 2164 AtiPcie - ok
12:15:46.0109 2164 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:15:46.0179 2164 AudioEndpointBuilder - ok
12:15:46.0204 2164 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
12:15:46.0238 2164 AudioSrv - ok
12:15:46.0274 2164 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
12:15:46.0332 2164 AxInstSV - ok
12:15:46.0384 2164 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
12:15:46.0456 2164 b06bdrv - ok
12:15:46.0485 2164 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
12:15:46.0518 2164 b57nd60a - ok
12:15:46.0551 2164 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
12:15:46.0590 2164 BDESVC - ok
12:15:46.0624 2164 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
12:15:46.0664 2164 Beep - ok
12:15:46.0741 2164 [ 06C1E887BF34C0E31EB8E2C999E4842F ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
12:15:46.0750 2164 BEService ( UnsignedFile.Multi.Generic ) - warning
12:15:46.0750 2164 BEService - detected UnsignedFile.Multi.Generic (1)
12:15:46.0814 2164 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
12:15:46.0878 2164 BFE - ok
12:15:47.0068 2164 [ 866335C9C0E6733C753FB472C539A6B9 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20130301.001\BHDrvx64.sys
12:15:47.0119 2164 BHDrvx64 - ok
12:15:47.0151 2164 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
12:15:47.0211 2164 BITS - ok
12:15:47.0237 2164 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
12:15:47.0259 2164 blbdrive - ok
12:15:47.0329 2164 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
12:15:47.0359 2164 Bonjour Service - ok
12:15:47.0429 2164 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
12:15:47.0479 2164 bowser - ok
12:15:47.0489 2164 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
12:15:47.0517 2164 BrFiltLo - ok
12:15:47.0543 2164 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
12:15:47.0559 2164 BrFiltUp - ok
12:15:47.0591 2164 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
12:15:47.0615 2164 Browser - ok
12:15:47.0643 2164 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
12:15:47.0700 2164 Brserid - ok
12:15:47.0709 2164 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
12:15:47.0735 2164 BrSerWdm - ok
12:15:47.0766 2164 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
12:15:47.0803 2164 BrUsbMdm - ok
12:15:47.0820 2164 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
12:15:47.0846 2164 BrUsbSer - ok
12:15:47.0862 2164 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
12:15:47.0887 2164 BTHMODEM - ok
12:15:47.0916 2164 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
12:15:47.0948 2164 bthserv - ok
12:15:48.0016 2164 [ 2C6FFCCA37B002AAB3C7C31A6D780A76 ] ccSet_NIS C:\Windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys
12:15:48.0042 2164 ccSet_NIS - ok
12:15:48.0075 2164 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
12:15:48.0129 2164 cdfs - ok
12:15:48.0149 2164 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
12:15:48.0163 2164 cdrom - ok
12:15:48.0220 2164 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
12:15:48.0294 2164 CertPropSvc - ok
12:15:48.0339 2164 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
12:15:48.0388 2164 circlass - ok
12:15:48.0413 2164 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
12:15:48.0431 2164 CLFS - ok
12:15:48.0563 2164 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:15:48.0582 2164 clr_optimization_v2.0.50727_32 - ok
12:15:48.0706 2164 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:15:48.0730 2164 clr_optimization_v2.0.50727_64 - ok
12:15:48.0813 2164 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:15:48.0841 2164 clr_optimization_v4.0.30319_32 - ok
12:15:48.0857 2164 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:15:48.0869 2164 clr_optimization_v4.0.30319_64 - ok
12:15:48.0894 2164 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
12:15:48.0930 2164 CmBatt - ok
12:15:48.0947 2164 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
12:15:48.0959 2164 cmdide - ok
12:15:49.0035 2164 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
12:15:49.0072 2164 CNG - ok
12:15:49.0097 2164 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
12:15:49.0109 2164 Compbatt - ok
12:15:49.0131 2164 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
12:15:49.0156 2164 CompositeBus - ok
12:15:49.0167 2164 COMSysApp - ok
12:15:49.0184 2164 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
12:15:49.0195 2164 crcdisk - ok
12:15:49.0250 2164 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
12:15:49.0304 2164 CryptSvc - ok
12:15:49.0350 2164 [ E6CE7188CC47AE5DAFDAF552D370C52F ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys
12:15:49.0374 2164 dc3d - ok
12:15:49.0412 2164 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
12:15:49.0468 2164 DcomLaunch - ok
12:15:49.0503 2164 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
12:15:49.0548 2164 defragsvc - ok
12:15:49.0577 2164 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
12:15:49.0616 2164 DfsC - ok
12:15:49.0648 2164 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
12:15:49.0717 2164 Dhcp - ok
12:15:49.0735 2164 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
12:15:49.0778 2164 discache - ok
12:15:49.0833 2164 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
12:15:49.0862 2164 Disk - ok
12:15:49.0900 2164 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
12:15:49.0975 2164 Dnscache - ok
12:15:50.0066 2164 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
12:15:50.0130 2164 dot3svc - ok
12:15:50.0149 2164 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
12:15:50.0189 2164 DPS - ok
12:15:50.0220 2164 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
12:15:50.0248 2164 drmkaud - ok
12:15:50.0289 2164 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
12:15:50.0316 2164 DXGKrnl - ok
12:15:50.0345 2164 EagleX64 - ok
12:15:50.0361 2164 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
12:15:50.0407 2164 EapHost - ok
12:15:50.0475 2164 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
12:15:50.0566 2164 ebdrv - ok
12:15:50.0612 2164 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
12:15:50.0658 2164 eeCtrl - ok
12:15:50.0694 2164 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
12:15:50.0754 2164 EFS - ok
12:15:50.0804 2164 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
12:15:50.0887 2164 ehRecvr - ok
12:15:50.0929 2164 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
12:15:50.0957 2164 ehSched - ok
12:15:50.0990 2164 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
12:15:51.0018 2164 elxstor - ok
12:15:51.0050 2164 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
12:15:51.0061 2164 EraserUtilRebootDrv - ok
12:15:51.0078 2164 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
12:15:51.0091 2164 ErrDev - ok
12:15:51.0123 2164 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
12:15:51.0173 2164 EventSystem - ok
12:15:51.0213 2164 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
12:15:51.0248 2164 exfat - ok
12:15:51.0266 2164 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
12:15:51.0321 2164 fastfat - ok
12:15:51.0348 2164 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
12:15:51.0391 2164 Fax - ok
12:15:51.0395 2164 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
12:15:51.0419 2164 fdc - ok
12:15:51.0434 2164 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
12:15:51.0466 2164 fdPHost - ok
12:15:51.0475 2164 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
12:15:51.0518 2164 FDResPub - ok
12:15:51.0540 2164 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
12:15:51.0552 2164 FileInfo - ok
12:15:51.0562 2164 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
12:15:51.0610 2164 Filetrace - ok
12:15:51.0614 2164 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
12:15:51.0626 2164 flpydisk - ok
12:15:51.0651 2164 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
12:15:51.0666 2164 FltMgr - ok
12:15:51.0723 2164 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
12:15:51.0783 2164 FontCache - ok
12:15:51.0827 2164 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:15:51.0850 2164 FontCache3.0.0.0 - ok
12:15:51.0866 2164 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
12:15:51.0889 2164 FsDepends - ok
12:15:51.0928 2164 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
12:15:51.0940 2164 Fs_Rec - ok
12:15:51.0978 2164 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
12:15:51.0996 2164 fvevol - ok
12:15:52.0014 2164 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
12:15:52.0026 2164 gagp30kx - ok
12:15:52.0059 2164 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
12:15:52.0082 2164 GEARAspiWDM - ok
12:15:52.0111 2164 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
12:15:52.0168 2164 gpsvc - ok
12:15:52.0242 2164 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:15:52.0267 2164 gupdate - ok
12:15:52.0296 2164 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:15:52.0306 2164 gupdatem - ok
12:15:52.0349 2164 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
12:15:52.0361 2164 gusvc - ok
12:15:52.0416 2164 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
12:15:52.0441 2164 hamachi - ok
12:15:52.0571 2164 [ 785FD63B74B30986A9F2C7D965CA509F ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
12:15:52.0692 2164 Hamachi2Svc - ok
12:15:52.0714 2164 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
12:15:52.0761 2164 hcw85cir - ok
12:15:52.0793 2164 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:15:52.0823 2164 HdAudAddService - ok
12:15:52.0845 2164 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
12:15:52.0877 2164 HDAudBus - ok
12:15:52.0900 2164 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
12:15:52.0926 2164 HidBatt - ok
12:15:52.0941 2164 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
12:15:52.0958 2164 HidBth - ok
12:15:52.0974 2164 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
12:15:52.0990 2164 HidIr - ok
12:15:53.0004 2164 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
12:15:53.0040 2164 hidserv - ok
12:15:53.0067 2164 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
12:15:53.0079 2164 HidUsb - ok
12:15:53.0126 2164 [ FD1837DEE0A1D7F180D7B301C0656511 ] HiPatchService C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
12:15:53.0145 2164 HiPatchService ( UnsignedFile.Multi.Generic ) - warning
12:15:53.0145 2164 HiPatchService - detected UnsignedFile.Multi.Generic (1)
12:15:53.0181 2164 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
12:15:53.0254 2164 hkmsvc - ok
12:15:53.0288 2164 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:15:53.0332 2164 HomeGroupListener - ok
12:15:53.0351 2164 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:15:53.0377 2164 HomeGroupProvider - ok
12:15:53.0409 2164 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
12:15:53.0421 2164 HpSAMD - ok
12:15:53.0444 2164 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
12:15:53.0492 2164 HTTP - ok
12:15:53.0509 2164 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
12:15:53.0518 2164 hwpolicy - ok
12:15:53.0551 2164 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
12:15:53.0564 2164 i8042prt - ok
12:15:53.0600 2164 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
12:15:53.0617 2164 iaStorV - ok
12:15:53.0662 2164 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:15:53.0687 2164 idsvc - ok
12:15:53.0810 2164 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20130308.001\IDSvia64.sys
12:15:53.0841 2164 IDSVia64 - ok
12:15:53.0868 2164 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
12:15:53.0879 2164 iirsp - ok
12:15:53.0912 2164 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
12:15:54.0019 2164 IKEEXT - ok
12:15:54.0035 2164 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
12:15:54.0047 2164 intelide - ok
12:15:54.0077 2164 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\drivers\intelppm.sys
12:15:54.0102 2164 intelppm - ok
12:15:54.0124 2164 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
12:15:54.0173 2164 IPBusEnum - ok
12:15:54.0189 2164 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:15:54.0220 2164 IpFilterDriver - ok
12:15:54.0252 2164 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
12:15:54.0305 2164 iphlpsvc - ok
12:15:54.0320 2164 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
12:15:54.0342 2164 IPMIDRV - ok
12:15:54.0355 2164 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
12:15:54.0401 2164 IPNAT - ok
12:15:54.0486 2164 [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
12:15:54.0532 2164 iPod Service - ok
12:15:54.0560 2164 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
12:15:54.0595 2164 IRENUM - ok
12:15:54.0616 2164 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
12:15:54.0627 2164 isapnp - ok
12:15:54.0646 2164 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
12:15:54.0662 2164 iScsiPrt - ok
12:15:54.0689 2164 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
12:15:54.0700 2164 kbdclass - ok
12:15:54.0720 2164 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
12:15:54.0742 2164 kbdhid - ok
12:15:54.0758 2164 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
12:15:54.0768 2164 KeyIso - ok
12:15:54.0789 2164 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
12:15:54.0801 2164 KSecDD - ok
12:15:54.0812 2164 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
12:15:54.0825 2164 KSecPkg - ok
12:15:54.0846 2164 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
12:15:54.0886 2164 ksthunk - ok
12:15:54.0907 2164 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
12:15:54.0959 2164 KtmRm - ok
12:15:55.0023 2164 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
12:15:55.0087 2164 LanmanServer - ok
12:15:55.0118 2164 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:15:55.0195 2164 LanmanWorkstation - ok
12:15:55.0217 2164 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
12:15:55.0263 2164 lltdio - ok
12:15:55.0288 2164 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
12:15:55.0333 2164 lltdsvc - ok
12:15:55.0351 2164 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
12:15:55.0383 2164 lmhosts - ok
12:15:55.0406 2164 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
12:15:55.0419 2164 LSI_FC - ok
12:15:55.0446 2164 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
12:15:55.0459 2164 LSI_SAS - ok
12:15:55.0491 2164 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
12:15:55.0503 2164 LSI_SAS2 - ok
12:15:55.0537 2164 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
12:15:55.0567 2164 LSI_SCSI - ok
12:15:55.0593 2164 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
12:15:55.0637 2164 luafv - ok
12:15:55.0702 2164 [ 92EB844D90615CB266F84C3202B8786E ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
12:15:55.0713 2164 MBAMProtector - ok
12:15:55.0775 2164 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
12:15:55.0807 2164 MBAMScheduler - ok
12:15:55.0835 2164 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
12:15:55.0854 2164 MBAMService - ok
12:15:55.0960 2164 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe
12:15:55.0989 2164 McComponentHostService - ok
12:15:56.0003 2164 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
12:15:56.0049 2164 Mcx2Svc - ok
12:15:56.0063 2164 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
12:15:56.0076 2164 megasas - ok
12:15:56.0112 2164 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
12:15:56.0142 2164 MegaSR - ok
12:15:56.0168 2164 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
12:15:56.0211 2164 MMCSS - ok
12:15:56.0231 2164 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
12:15:56.0277 2164 Modem - ok
12:15:56.0305 2164 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
12:15:56.0335 2164 monitor - ok
12:15:56.0356 2164 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
12:15:56.0367 2164 mouclass - ok
12:15:56.0397 2164 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
12:15:56.0426 2164 mouhid - ok
12:15:56.0476 2164 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
12:15:56.0501 2164 mountmgr - ok
12:15:56.0575 2164 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
12:15:56.0610 2164 MozillaMaintenance - ok
12:15:56.0631 2164 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
12:15:56.0648 2164 mpio - ok
12:15:56.0657 2164 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
12:15:56.0690 2164 mpsdrv - ok
12:15:56.0741 2164 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
12:15:56.0799 2164 MpsSvc - ok
12:15:56.0827 2164 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
12:15:56.0858 2164 MRxDAV - ok
12:15:56.0891 2164 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
12:15:56.0944 2164 mrxsmb - ok
12:15:56.0966 2164 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:15:56.0986 2164 mrxsmb10 - ok
12:15:57.0011 2164 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:15:57.0029 2164 mrxsmb20 - ok
12:15:57.0043 2164 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
12:15:57.0054 2164 msahci - ok
12:15:57.0073 2164 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
12:15:57.0085 2164 msdsm - ok
12:15:57.0095 2164 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
12:15:57.0124 2164 MSDTC - ok
12:15:57.0150 2164 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
12:15:57.0192 2164 Msfs - ok
12:15:57.0220 2164 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
12:15:57.0262 2164 mshidkmdf - ok
12:15:57.0281 2164 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
12:15:57.0293 2164 msisadrv - ok
12:15:57.0328 2164 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
12:15:57.0413 2164 MSiSCSI - ok
12:15:57.0417 2164 msiserver - ok
12:15:57.0437 2164 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
12:15:57.0485 2164 MSKSSRV - ok
12:15:57.0512 2164 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
12:15:57.0558 2164 MSPCLOCK - ok
12:15:57.0562 2164 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
12:15:57.0607 2164 MSPQM - ok
12:15:57.0635 2164 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
12:15:57.0651 2164 MsRPC - ok
12:15:57.0664 2164 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
12:15:57.0674 2164 mssmbios - ok
12:15:57.0687 2164 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
12:15:57.0727 2164 MSTEE - ok
12:15:57.0730 2164 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
12:15:57.0743 2164 MTConfig - ok
12:15:57.0800 2164 [ 19B006B181E3875FD254F7B67ACF1E7C ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
12:15:57.0811 2164 MTsensor - ok
12:15:57.0831 2164 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
12:15:57.0842 2164 Mup - ok
12:15:57.0872 2164 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
12:15:57.0924 2164 napagent - ok
12:15:57.0956 2164 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
12:15:57.0989 2164 NativeWifiP - ok
12:15:58.0047 2164 [ 88A2F45CE66B904285978D6BB13AFEB2 ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20130308.032\ENG64.SYS
12:15:58.0078 2164 NAVENG - ok
12:15:58.0138 2164 [ D2A545DA3A90BBFA40E020C23F1B7A48 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\VirusDefs\20130308.032\EX64.SYS
12:15:58.0215 2164 NAVEX15 - ok
12:15:58.0262 2164 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
12:15:58.0288 2164 NDIS - ok
12:15:58.0310 2164 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
12:15:58.0342 2164 NdisCap - ok
12:15:58.0367 2164 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
12:15:58.0397 2164 NdisTapi - ok
12:15:58.0411 2164 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
12:15:58.0454 2164 Ndisuio - ok
12:15:58.0482 2164 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
12:15:58.0528 2164 NdisWan - ok
12:15:58.0546 2164 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
12:15:58.0577 2164 NDProxy - ok
12:15:58.0600 2164 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
12:15:58.0639 2164 NetBIOS - ok
12:15:58.0654 2164 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
12:15:58.0686 2164 NetBT - ok
12:15:58.0729 2164 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
12:15:58.0756 2164 Netlogon - ok
12:15:58.0798 2164 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
12:15:58.0846 2164 Netman - ok
12:15:58.0875 2164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:15:58.0888 2164 NetMsmqActivator - ok
12:15:58.0897 2164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:15:58.0907 2164 NetPipeActivator - ok
12:15:58.0931 2164 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
12:15:58.0983 2164 netprofm - ok
12:15:58.0997 2164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:15:59.0007 2164 NetTcpActivator - ok
12:15:59.0010 2164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:15:59.0020 2164 NetTcpPortSharing - ok
12:15:59.0045 2164 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
12:15:59.0058 2164 nfrd960 - ok
12:15:59.0131 2164 [ F2840DBFE9322F35557219AE82CC4597 ] NIS C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
12:15:59.0149 2164 NIS - ok
12:15:59.0181 2164 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
12:15:59.0215 2164 NlaSvc - ok
12:15:59.0248 2164 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
12:15:59.0283 2164 Npfs - ok
12:15:59.0371 2164 npggsvc - ok
12:15:59.0392 2164 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
12:15:59.0451 2164 nsi - ok
12:15:59.0461 2164 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
12:15:59.0509 2164 nsiproxy - ok
12:15:59.0559 2164 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
12:15:59.0608 2164 Ntfs - ok
12:15:59.0654 2164 [ 317020D31F1696334679B9D0416EB62E ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys
12:15:59.0665 2164 NuidFltr - ok
12:15:59.0690 2164 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
12:15:59.0751 2164 Null - ok
12:15:59.0783 2164 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
12:15:59.0796 2164 nvraid - ok
12:15:59.0824 2164 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
12:15:59.0838 2164 nvstor - ok
12:15:59.0859 2164 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
12:15:59.0872 2164 nv_agp - ok
12:15:59.0887 2164 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
12:15:59.0916 2164 ohci1394 - ok
12:15:59.0945 2164 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
12:15:59.0986 2164 p2pimsvc - ok
12:16:00.0018 2164 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
12:16:00.0037 2164 p2psvc - ok
12:16:00.0062 2164 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
12:16:00.0088 2164 Parport - ok
12:16:00.0109 2164 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
12:16:00.0121 2164 partmgr - ok
12:16:00.0143 2164 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
12:16:00.0178 2164 PcaSvc - ok
12:16:00.0202 2164 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
12:16:00.0215 2164 pci - ok
12:16:00.0235 2164 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
12:16:00.0247 2164 pciide - ok
12:16:00.0267 2164 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
12:16:00.0288 2164 pcmcia - ok
12:16:00.0304 2164 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
12:16:00.0315 2164 pcw - ok
12:16:00.0339 2164 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
12:16:00.0393 2164 PEAUTH - ok
12:16:01.0692 2164 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
12:16:01.0722 2164 PerfHost - ok
12:16:01.0780 2164 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
12:16:01.0861 2164 pla - ok
12:16:01.0899 2164 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
12:16:01.0943 2164 PlugPlay - ok
12:16:01.0978 2164 PnkBstrA - ok
12:16:01.0990 2164 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
12:16:02.0010 2164 PNRPAutoReg - ok
12:16:02.0027 2164 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
12:16:02.0040 2164 PNRPsvc - ok
12:16:02.0083 2164 [ 5BC4D480DD527EB0CF33A67A090A130E ] Point64 C:\Windows\system32\DRIVERS\point64.sys
12:16:02.0095 2164 Point64 - ok
12:16:02.0127 2164 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
12:16:02.0177 2164 PolicyAgent - ok
12:16:02.0201 2164 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
12:16:02.0236 2164 Power - ok
12:16:02.0267 2164 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
12:16:02.0315 2164 PptpMiniport - ok
12:16:02.0335 2164 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
12:16:02.0347 2164 Processor - ok
12:16:02.0379 2164 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
12:16:02.0421 2164 ProfSvc - ok
12:16:02.0433 2164 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
12:16:02.0443 2164 ProtectedStorage - ok
12:16:02.0474 2164 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
12:16:02.0513 2164 Psched - ok
12:16:02.0564 2164 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
12:16:02.0620 2164 ql2300 - ok
12:16:02.0635 2164 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
12:16:02.0648 2164 ql40xx - ok
12:16:02.0673 2164 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
12:16:02.0693 2164 QWAVE - ok
12:16:02.0703 2164 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
12:16:02.0727 2164 QWAVEdrv - ok
12:16:02.0741 2164 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
12:16:02.0771 2164 RasAcd - ok
12:16:02.0812 2164 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
12:16:02.0844 2164 RasAgileVpn - ok
12:16:02.0857 2164 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
12:16:02.0906 2164 RasAuto - ok
12:16:02.0931 2164 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
12:16:02.0976 2164 Rasl2tp - ok
12:16:02.0998 2164 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
12:16:03.0032 2164 RasMan - ok
12:16:03.0043 2164 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
12:16:03.0082 2164 RasPppoe - ok
12:16:03.0113 2164 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
12:16:03.0157 2164 RasSstp - ok
12:16:03.0177 2164 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
12:16:03.0212 2164 rdbss - ok
12:16:03.0229 2164 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
12:16:03.0243 2164 rdpbus - ok
12:16:03.0256 2164 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
12:16:03.0287 2164 RDPCDD - ok
12:16:03.0333 2164 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
12:16:03.0378 2164 RDPENCDD - ok
12:16:03.0398 2164 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
12:16:03.0428 2164 RDPREFMP - ok
12:16:03.0492 2164 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
12:16:03.0649 2164 RDPWD - ok
12:16:03.0708 2164 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
12:16:03.0737 2164 rdyboost - ok
12:16:03.0790 2164 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
12:16:03.0826 2164 RemoteAccess - ok
12:16:03.0848 2164 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
12:16:03.0902 2164 RemoteRegistry - ok
12:16:03.0912 2164 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
12:16:03.0969 2164 RpcEptMapper - ok
12:16:03.0980 2164 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
12:16:04.0004 2164 RpcLocator - ok
12:16:04.0049 2164 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
12:16:04.0084 2164 RpcSs - ok
12:16:04.0106 2164 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
12:16:04.0138 2164 rspndr - ok
12:16:04.0187 2164 [ 8181B5E7BFC040E0B26349C73E719335 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
12:16:04.0209 2164 RTL8167 - ok
12:16:04.0266 2164 [ 20FF3D56E9BF9C8FAE2582C5EF6355F2 ] SaiK1708 C:\Windows\system32\DRIVERS\SaiK1708.sys
12:16:04.0308 2164 SaiK1708 - ok
12:16:04.0378 2164 [ A7CEE5D110C7F07B20490398E673E4EA ] SaiMini C:\Windows\system32\DRIVERS\SaiMini.sys
12:16:04.0428 2164 SaiMini - ok
12:16:04.0484 2164 [ 86BDC00D124A611F1ECA5681D5123E26 ] SaiNtBus C:\Windows\system32\drivers\SaiBus.sys
12:16:04.0529 2164 SaiNtBus - ok
12:16:04.0611 2164 [ 79C7A79943FDB25615C97CF84AA873BE ] SaiU1708 C:\Windows\system32\DRIVERS\SaiU1708.sys
12:16:04.0661 2164 SaiU1708 - ok
12:16:04.0681 2164 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
12:16:04.0692 2164 SamSs - ok
12:16:04.0714 2164 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
12:16:04.0727 2164 sbp2port - ok
12:16:04.0750 2164 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
12:16:04.0795 2164 SCardSvr - ok
12:16:04.0803 2164 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
12:16:04.0845 2164 scfilter - ok
12:16:04.0918 2164 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
12:16:04.0992 2164 Schedule - ok
12:16:05.0020 2164 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
12:16:05.0051 2164 SCPolicySvc - ok
12:16:05.0070 2164 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
12:16:05.0109 2164 SDRSVC - ok
12:16:05.0167 2164 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
12:16:05.0247 2164 secdrv - ok
12:16:05.0292 2164 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
12:16:05.0349 2164 seclogon - ok
12:16:05.0362 2164 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
12:16:05.0426 2164 SENS - ok
12:16:05.0449 2164 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
12:16:05.0523 2164 SensrSvc - ok
12:16:05.0547 2164 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
12:16:05.0577 2164 Serenum - ok
12:16:05.0631 2164 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
12:16:05.0682 2164 Serial - ok
12:16:05.0731 2164 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
12:16:05.0790 2164 sermouse - ok
12:16:05.0808 2164 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
12:16:05.0847 2164 SessionEnv - ok
12:16:05.0867 2164 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
12:16:05.0893 2164 sffdisk - ok
12:16:05.0934 2164 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
12:16:05.0988 2164 sffp_mmc - ok
12:16:06.0007 2164 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
12:16:06.0066 2164 sffp_sd - ok
12:16:06.0088 2164 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
12:16:06.0163 2164 sfloppy - ok
12:16:06.0195 2164 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
12:16:06.0234 2164 SharedAccess - ok
12:16:06.0258 2164 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:16:06.0328 2164 ShellHWDetection - ok
12:16:06.0350 2164 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
12:16:06.0361 2164 SiSRaid2 - ok
12:16:06.0393 2164 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
12:16:06.0436 2164 SiSRaid4 - ok
12:16:06.0509 2164 [ 8C4F0DCC6A5100D48F9B2F950CDD220F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
12:16:06.0551 2164 SkypeUpdate - ok
12:16:06.0580 2164 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
12:16:06.0665 2164 Smb - ok
12:16:06.0742 2164 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
12:16:06.0804 2164 SNMPTRAP - ok
12:16:06.0830 2164 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
12:16:06.0865 2164 spldr - ok
12:16:06.0938 2164 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
12:16:06.0974 2164 Spooler - ok
12:16:07.0079 2164 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
12:16:07.0194 2164 sppsvc - ok
12:16:07.0216 2164 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
12:16:07.0248 2164 sppuinotify - ok
12:16:07.0356 2164 [ 891793E00432FA055CF040605C260E49 ] SRTSP C:\Windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS
12:16:07.0388 2164 SRTSP - ok
12:16:07.0413 2164 [ 1CB7BB3B0561FB5ECFE37F7731E8BF3E ] SRTSPX C:\Windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS
12:16:07.0442 2164 SRTSPX - ok
12:16:07.0494 2164 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
12:16:07.0563 2164 srv - ok
12:16:07.0585 2164 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
12:16:07.0619 2164 srv2 - ok
12:16:07.0659 2164 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
12:16:07.0680 2164 srvnet - ok
12:16:07.0724 2164 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
12:16:07.0782 2164 SSDPSRV - ok
12:16:07.0808 2164 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
12:16:07.0839 2164 SstpSvc - ok
12:16:07.0910 2164 Steam Client Service - ok
12:16:07.0947 2164 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
12:16:07.0992 2164 stexstor - ok
12:16:08.0051 2164 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
12:16:08.0113 2164 stisvc - ok
12:16:08.0138 2164 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
12:16:08.0151 2164 swenum - ok
12:16:08.0197 2164 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
12:16:08.0286 2164 swprv - ok
12:16:08.0334 2164 [ 8B2430762099598DA40686F754632EFD ] SymDS C:\Windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS
12:16:08.0379 2164 SymDS - ok
12:16:08.0464 2164 [ 5CB7F2FD7E30A0F52F93574BFC3A8041 ] SymEFA C:\Windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS
12:16:08.0530 2164 SymEFA - ok
12:16:08.0564 2164 [ 898BB48C797483420DF523B2BBC1ECDB ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
12:16:08.0590 2164 SymEvent - ok
12:16:08.0626 2164 [ 5013A76CAAA1D7CF1C55214B490B4E35 ] SymIRON C:\Windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS
12:16:08.0639 2164 SymIRON - ok
12:16:08.0690 2164 [ 3911BD0E68C010E5438A87706ABBE9AB ] SymNetS C:\Windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS
12:16:08.0708 2164 SymNetS - ok
12:16:08.0748 2164 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
12:16:08.0821 2164 SysMain - ok
12:16:08.0843 2164 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:16:08.0861 2164 TabletInputService - ok
12:16:08.0920 2164 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
12:16:08.0968 2164 TapiSrv - ok
12:16:08.0999 2164 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
12:16:09.0038 2164 TBS - ok
12:16:09.0115 2164 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
12:16:09.0201 2164 Tcpip - ok
12:16:09.0436 2164 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
12:16:09.0519 2164 TCPIP6 - ok
12:16:09.0561 2164 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
12:16:09.0603 2164 tcpipreg - ok
12:16:09.0639 2164 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
12:16:09.0723 2164 TDPIPE - ok
12:16:09.0768 2164 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
12:16:09.0818 2164 TDTCP - ok
12:16:09.0860 2164 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:16:09.0929 2164 tdx - ok
12:16:09.0946 2164 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
12:16:09.0982 2164 TermDD - ok
12:16:10.0009 2164 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
12:16:10.0070 2164 TermService - ok
12:16:10.0096 2164 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
12:16:10.0115 2164 Themes - ok
12:16:10.0137 2164 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
12:16:10.0176 2164 THREADORDER - ok
12:16:10.0212 2164 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
12:16:10.0286 2164 TrkWks - ok
12:16:10.0342 2164 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:16:10.0400 2164 TrustedInstaller - ok
12:16:10.0427 2164 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
12:16:10.0482 2164 tssecsrv - ok
12:16:10.0509 2164 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
12:16:10.0549 2164 TsUsbFlt - ok
12:16:10.0558 2164 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
12:16:10.0584 2164 TsUsbGD - ok
12:16:10.0912 2164 [ 50D8102EECC446F160C8C31AF927242D ] TuneUp.UtilitiesSvc C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
12:16:10.0961 2164 TuneUp.UtilitiesSvc - ok
12:16:11.0047 2164 [ 7BC3381C0713F613B31ACDE38B71CB53 ] TuneUpUtilitiesDrv C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys
12:16:11.0071 2164 TuneUpUtilitiesDrv - ok
12:16:11.0116 2164 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:16:11.0185 2164 tunnel - ok
12:16:11.0202 2164 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
12:16:11.0235 2164 uagp35 - ok
12:16:11.0302 2164 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:16:11.0386 2164 udfs - ok
12:16:11.0407 2164 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:16:11.0440 2164 UI0Detect - ok
12:16:11.0456 2164 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
12:16:11.0494 2164 uliagpkx - ok
12:16:11.0522 2164 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
12:16:11.0574 2164 umbus - ok
12:16:11.0578 2164 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
12:16:11.0633 2164 UmPass - ok
12:16:11.0675 2164 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
12:16:11.0738 2164 upnphost - ok
12:16:11.0804 2164 [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
12:16:11.0888 2164 USBAAPL64 - ok
12:16:11.0917 2164 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
12:16:12.0063 2164 usbccgp - ok
12:16:12.0130 2164 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
12:16:12.0165 2164 usbcir - ok
12:16:12.0182 2164 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
12:16:12.0204 2164 usbehci - ok
12:16:12.0230 2164 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
12:16:12.0258 2164 usbhub - ok
12:16:12.0274 2164 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
12:16:12.0300 2164 usbohci - ok
12:16:12.0327 2164 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys
12:16:12.0345 2164 usbprint - ok
12:16:12.0360 2164 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:16:12.0411 2164 USBSTOR - ok
12:16:12.0423 2164 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
12:16:12.0459 2164 usbuhci - ok
12:16:12.0485 2164 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
12:16:12.0535 2164 UxSms - ok
12:16:12.0549 2164 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
12:16:12.0561 2164 VaultSvc - ok
12:16:12.0589 2164 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
12:16:12.0601 2164 vdrvroot - ok
12:16:12.0629 2164 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
12:16:12.0694 2164 vds - ok
12:16:12.0722 2164 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
12:16:12.0743 2164 vga - ok
12:16:12.0763 2164 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
12:16:12.0806 2164 VgaSave - ok
12:16:12.0827 2164 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
12:16:12.0843 2164 vhdmp - ok
12:16:12.0913 2164 [ EECF5B7210D773F3501CEDA848D53D31 ] VIAHdAudAddService C:\Windows\system32\drivers\viahduaa.sys
12:16:12.0992 2164 VIAHdAudAddService - ok
12:16:13.0028 2164 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
12:16:13.0039 2164 viaide - ok
12:16:13.0065 2164 [ 43412F74D9516EF87988F2397A9B8E78 ] VIAKaraokeService C:\Windows\system32\viakaraokesrv.exe
12:16:13.0079 2164 VIAKaraokeService - ok
12:16:13.0087 2164 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
12:16:13.0099 2164 volmgr - ok
12:16:13.0116 2164 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:16:13.0142 2164 volmgrx - ok
12:16:13.0171 2164 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
12:16:13.0191 2164 volsnap - ok
12:16:13.0212 2164 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
12:16:13.0227 2164 vsmraid - ok
12:16:13.0308 2164 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
12:16:13.0382 2164 VSS - ok
12:16:13.0403 2164 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
12:16:13.0439 2164 vwifibus - ok
12:16:13.0486 2164 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
12:16:13.0515 2164 vwififlt - ok
12:16:13.0548 2164 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
12:16:13.0584 2164 W32Time - ok
12:16:13.0601 2164 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
12:16:13.0640 2164 WacomPen - ok
12:16:13.0719 2164 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
12:16:13.0790 2164 WANARP - ok
12:16:13.0823 2164 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:16:13.0864 2164 Wanarpv6 - ok
12:16:14.0037 2164 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
12:16:14.0187 2164 wbengine - ok
12:16:14.0221 2164 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
12:16:14.0253 2164 WbioSrvc - ok
12:16:14.0324 2164 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:16:14.0379 2164 wcncsvc - ok
12:16:14.0439 2164 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:16:14.0561 2164 WcsPlugInService - ok
12:16:14.0610 2164 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
12:16:14.0660 2164 Wd - ok
12:16:14.0764 2164 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:16:14.0851 2164 Wdf01000 - ok
12:16:14.0890 2164 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:16:15.0166 2164 WdiServiceHost - ok
12:16:15.0175 2164 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:16:15.0207 2164 WdiSystemHost - ok
12:16:15.0259 2164 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
12:16:15.0324 2164 WebClient - ok
12:16:15.0385 2164 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:16:15.0458 2164 Wecsvc - ok
12:16:15.0482 2164 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:16:15.0518 2164 wercplsupport - ok
12:16:15.0561 2164 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
12:16:15.0614 2164 WerSvc - ok
12:16:15.0680 2164 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
12:16:15.0724 2164 WfpLwf - ok
12:16:15.0739 2164 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
12:16:15.0755 2164 WIMMount - ok
12:16:15.0776 2164 WinDefend - ok
12:16:15.0781 2164 WinHttpAutoProxySvc - ok
12:16:15.0852 2164 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:16:15.0924 2164 Winmgmt - ok
12:16:16.0031 2164 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
12:16:16.0149 2164 WinRM - ok
12:16:16.0206 2164 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
12:16:16.0256 2164 WinUsb - ok
12:16:16.0296 2164 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
12:16:16.0350 2164 Wlansvc - ok
12:16:16.0374 2164 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
12:16:16.0387 2164 WmiAcpi - ok
12:16:16.0410 2164 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:16:16.0449 2164 wmiApSrv - ok
12:16:16.0478 2164 WMPNetworkSvc - ok
12:16:16.0504 2164 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
12:16:16.0531 2164 WPCSvc - ok
12:16:16.0551 2164 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:16:16.0579 2164 WPDBusEnum - ok
12:16:16.0602 2164 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:16:16.0633 2164 ws2ifsl - ok
12:16:16.0651 2164 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
12:16:16.0699 2164 wscsvc - ok
12:16:16.0703 2164 WSearch - ok
12:16:17.0009 2164 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
12:16:17.0114 2164 wuauserv - ok
12:16:17.0157 2164 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
12:16:17.0289 2164 WudfPf - ok
12:16:17.0374 2164 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
12:16:17.0446 2164 WUDFRd - ok
12:16:17.0489 2164 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:16:17.0579 2164 wudfsvc - ok
12:16:17.0640 2164 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
12:16:17.0687 2164 WwanSvc - ok
12:16:20.0735 2164 X6va009 - ok
12:16:20.0855 2164 X6va011 - ok
12:16:20.0873 2164 ================ Scan global ===============================
12:16:20.0889 2164 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
12:16:20.0944 2164 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
12:16:20.0968 2164 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
12:16:21.0002 2164 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
12:16:21.0057 2164 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
12:16:21.0089 2164 [Global] - ok
12:16:21.0090 2164 ================ Scan MBR ==================================
12:16:21.0110 2164 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:16:21.0780 2164 \Device\Harddisk0\DR0 - ok
12:16:21.0780 2164 ================ Scan VBR ==================================
12:16:21.0783 2164 [ 3CC9BD83A9CF6C55C55686BCD094E1D3 ] \Device\Harddisk0\DR0\Partition1
12:16:21.0785 2164 \Device\Harddisk0\DR0\Partition1 - ok
12:16:21.0814 2164 [ 522BDD23427669EFA9737F060EC788B8 ] \Device\Harddisk0\DR0\Partition2
12:16:21.0816 2164 \Device\Harddisk0\DR0\Partition2 - ok
12:16:21.0816 2164 ============================================================
12:16:21.0816 2164 Scan finished
12:16:21.0816 2164 ============================================================
12:16:21.0826 0908 Detected object count: 2
12:16:21.0826 0908 Actual detected object count: 2
12:22:10.0977 0908 C:\Program Files (x86)\Common Files\BattlEye\BEService.exe - copied to quarantine
12:22:10.0978 0908 BEService ( UnsignedFile.Multi.Generic ) - User select action: Quarantine
12:22:11.0026 0908 C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe - copied to quarantine
12:22:11.0027 0908 HiPatchService ( UnsignedFile.Multi.Generic ) - User select action: Quarantine

markusg 11.03.2013 18:14

hi,
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


JannikLR 16.03.2013 00:18

Combofix Logfile:
Code:

ComboFix 13-03-15.01 - Rohr 17.03.2013  0:06.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4078.2871 [GMT 1:00]
ausgeführt von:: c:\users\Rohr\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\windows\jestertb.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-02-16 bis 2013-03-16  ))))))))))))))))))))))))))))))
.
.
2013-03-16 23:13 . 2013-03-16 23:13        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-03-10 11:22 . 2013-03-10 11:22        --------        d-----w-        C:\TDSSKiller_Quarantine
2013-03-10 11:11 . 2013-03-10 11:11        --------        d-----w-        c:\users\Rohr\AppData\Roaming\TuneUp Software
2013-03-10 11:10 . 2013-03-10 11:11        --------        d-----w-        c:\programdata\TuneUp Software
2013-03-10 11:10 . 2013-03-10 11:10        --------        d-sh--w-        c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-03-10 11:10 . 2013-03-10 11:10        --------        d--h--w-        c:\programdata\Common Files
2013-03-10 11:07 . 2013-03-10 11:07        --------        d-----w-        c:\users\Rohr\AppData\Local\Mozilla
2013-03-10 11:06 . 2013-03-10 11:06        --------        d-----w-        c:\program files (x86)\Mozilla Maintenance Service
2013-03-09 15:18 . 2013-03-09 15:18        95648        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-09 15:18 . 2013-03-09 15:18        --------        d-----w-        c:\program files (x86)\Java
2013-02-27 15:33 . 2013-02-27 15:33        --------        d-----w-        c:\users\Rohr\AppData\Local\ESN
2013-02-27 15:33 . 2013-03-08 14:31        --------        d-----w-        c:\program files (x86)\Battlelog Web Plugins
2013-02-27 15:31 . 2013-02-27 15:31        --------        d-----w-        c:\programdata\EA Core
2013-02-27 15:31 . 2013-02-27 16:23        --------        d-----w-        c:\programdata\EA Logs
2013-02-27 15:31 . 2013-02-27 15:31        --------        d--h--w-        c:\program files (x86)\Common Files\EAInstaller
2013-02-26 20:49 . 2013-02-27 13:26        --------        d-----w-        c:\program files (x86)\Origin Games
2013-02-26 20:49 . 2013-02-27 15:31        --------        d-----w-        c:\users\Rohr\AppData\Local\Origin
2013-02-26 20:48 . 2013-02-27 15:31        --------        d-----w-        c:\programdata\Electronic Arts
2013-02-26 20:48 . 2013-02-26 20:49        --------        d-----w-        c:\program files (x86)\Origin
2013-02-21 15:08 . 2013-02-28 17:01        --------        d-----w-        c:\programdata\MTA San Andreas All
2013-02-21 15:08 . 2013-02-28 17:01        --------        d-----w-        c:\program files (x86)\MTA San Andreas 1.3
2013-02-18 23:15 . 2013-02-18 23:15        --------        d-----w-        c:\programdata\TERA
2013-02-18 23:14 . 2013-02-18 23:15        --------        d-----w-        c:\program files (x86)\TERA
2013-02-17 22:18 . 2008-07-12 07:18        467984        ----a-w-        c:\windows\SysWow64\d3dx10_39.dll
2013-02-17 22:18 . 2008-07-12 07:18        1493528        ----a-w-        c:\windows\SysWow64\D3DCompiler_39.dll
2013-02-17 20:18 . 2013-02-17 20:19        --------        d-----w-        c:\users\Rohr\AppData\Local\NPE
2013-02-16 23:47 . 2010-05-26 10:41        2106216        ----a-w-        c:\windows\SysWow64\D3DCompiler_43.dll
2013-02-16 23:47 . 2010-05-26 10:41        1998168        ----a-w-        c:\windows\SysWow64\D3DX9_43.dll
2013-02-16 19:24 . 2009-03-18 15:35        33856        ---ha-w-        c:\windows\system32\hamachi.sys
2013-02-16 19:24 . 2013-02-16 19:24        --------        d-----w-        c:\program files (x86)\LogMeIn Hamachi
2013-02-16 19:24 . 2013-03-13 17:56        --------        d-----w-        c:\users\Rohr\AppData\Local\LogMeIn Hamachi
2013-02-16 12:50 . 2003-08-15 15:02        69632        ------w-        c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe
2013-02-16 12:50 . 2003-08-15 15:01        380928        ------w-        c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2013-02-16 12:50 . 2003-08-15 14:57        212992        ------w-        c:\program files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
2013-02-16 10:06 . 2013-02-16 10:06        --------        d-----w-        c:\program files (x86)\Common Files\Symantec Shared
2013-02-16 09:59 . 2013-02-16 09:59        --------        d-----w-        c:\program files\Symantec
2013-02-16 09:59 . 2013-02-16 09:59        175736        ----a-w-        c:\windows\system32\drivers\SYMEVENT64x86.SYS
2013-02-16 09:59 . 2013-02-16 09:59        --------        d-----w-        c:\program files\Common Files\Symantec Shared
2013-02-16 09:59 . 2013-02-18 11:59        --------        d-----w-        c:\windows\system32\drivers\NISx64
2013-02-16 09:59 . 2013-02-16 09:59        --------        d-----w-        c:\program files (x86)\Norton Internet Security
2013-02-16 09:59 . 2013-02-16 09:59        --------        d-----w-        c:\program files (x86)\NortonInstaller
2013-02-16 09:58 . 2013-02-17 20:19        --------        d-----w-        c:\programdata\Norton
2013-02-16 01:17 . 2013-01-09 01:10        996352        ----a-w-        c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-16 01:17 . 2013-01-08 22:01        768000        ----a-w-        c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-15 23:01 . 2013-02-15 23:01        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-02-15 23:01 . 2012-12-14 15:49        24176        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-02-15 22:11 . 2013-01-05 05:53        5553512        ----a-w-        c:\windows\system32\ntoskrnl.exe
2013-02-15 22:11 . 2013-01-05 05:00        3967848        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2013-02-15 22:11 . 2013-01-05 05:00        3913064        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2013-02-15 22:11 . 2013-01-04 05:46        215040        ----a-w-        c:\windows\system32\winsrv.dll
2013-02-15 22:11 . 2013-01-04 04:51        5120        ----a-w-        c:\windows\SysWow64\wow32.dll
2013-02-15 22:11 . 2013-01-04 02:47        25600        ----a-w-        c:\windows\SysWow64\setup16.exe
2013-02-15 22:11 . 2013-01-04 02:47        7680        ----a-w-        c:\windows\SysWow64\instnm.exe
2013-02-15 22:11 . 2013-01-04 02:47        2048        ----a-w-        c:\windows\SysWow64\user.exe
2013-02-15 22:11 . 2013-01-04 02:47        14336        ----a-w-        c:\windows\SysWow64\ntvdm64.dll
2013-02-15 22:11 . 2013-01-03 06:00        1913192        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-02-15 22:11 . 2013-01-03 06:00        288088        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-15 22:10 . 2013-01-08 05:32        9161176        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{4A94A37F-A81E-4478-A088-F58068B09DFE}\mpengine.dll
2013-02-15 19:45 . 2013-02-15 22:04        --------        d-----w-        c:\program files (x86)\Nova Social Client
2013-02-15 19:45 . 2013-02-15 19:45        --------        d-----w-        c:\users\Rohr\AppData\Local\Programs
2013-02-15 15:12 . 2013-02-15 22:04        --------        d-----w-        c:\windows\SysWow64\Adobe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-16 18:55 . 2012-08-08 20:57        291088        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
2013-03-16 18:55 . 2012-08-08 20:44        291088        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
2013-03-16 18:54 . 2012-08-08 20:44        291088        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
2013-03-15 21:54 . 2012-08-11 19:50        72013344        ----a-w-        c:\windows\system32\MRT.exe
2013-03-13 20:13 . 2012-08-07 16:37        73432        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-13 20:13 . 2012-08-07 16:37        693976        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-09 15:18 . 2012-08-07 21:03        861088        ----a-w-        c:\windows\SysWow64\npDeployJava1.dll
2013-03-09 15:18 . 2012-08-07 21:03        782240        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2013-02-27 15:59 . 2012-08-08 20:44        76888        ----a-w-        c:\windows\SysWow64\PnkBstrA.exe
2013-02-12 05:45 . 2013-03-15 15:04        135168        ----a-w-        c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-15 15:04        350208        ----a-w-        c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-15 15:04        308736        ----a-w-        c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-15 15:04        111104        ----a-w-        c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-15 15:04        474112        ----a-w-        c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-15 15:04        2176512        ----a-w-        c:\windows\apppatch\AcGenral.dll
2013-01-17 00:28 . 2010-11-21 03:27        273840        ------w-        c:\windows\system32\MpSigStub.exe
2013-01-04 04:43 . 2013-02-15 22:11        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
2013-01-04 03:26 . 2013-02-13 13:18        3153408        ----a-w-        c:\windows\system32\win32k.sys
2012-12-19 20:50 . 2012-01-17 04:43        5630200        ----a-w-        c:\windows\SysWow64\atiumdag.dll
2012-12-19 20:48 . 2012-12-19 20:48        11278336        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2012-12-19 20:29 . 2012-12-19 20:29        23461376        ----a-w-        c:\windows\system32\atio6axx.dll
2012-12-19 20:22 . 2012-12-19 20:22        70144        ----a-w-        c:\windows\system32\coinst_9.012.dll
2012-12-19 20:19 . 2012-12-19 20:19        163840        ----a-w-        c:\windows\system32\atiapfxx.exe
2012-12-19 20:18 . 2012-12-19 20:18        51200        ----a-w-        c:\windows\system32\aticalrt64.dll
2012-12-19 20:18 . 2012-12-19 20:18        46080        ----a-w-        c:\windows\SysWow64\aticalrt.dll
2012-12-19 20:17 . 2012-12-19 20:17        44544        ----a-w-        c:\windows\system32\aticalcl64.dll
2012-12-19 20:17 . 2012-12-19 20:17        44032        ----a-w-        c:\windows\SysWow64\aticalcl.dll
2012-12-19 20:17 . 2012-12-19 20:17        16082944        ----a-w-        c:\windows\system32\aticaldd64.dll
2012-12-19 20:13 . 2012-12-19 20:13        13703168        ----a-w-        c:\windows\SysWow64\aticaldd.dll
2012-12-19 20:12 . 2012-12-19 20:12        18982400        ----a-w-        c:\windows\SysWow64\atioglxx.dll
2012-12-19 20:09 . 2012-01-17 05:23        960512        ----a-w-        c:\windows\SysWow64\aticfx32.dll
2012-12-19 20:08 . 2012-01-17 05:22        1151488        ----a-w-        c:\windows\system32\aticfx64.dll
2012-12-19 20:06 . 2012-12-19 20:06        6681088        ----a-w-        c:\windows\SysWow64\atidxx32.dll
2012-12-19 19:59 . 2012-12-19 19:59        5087744        ----a-w-        c:\windows\system32\atiumd6a.dll
2012-12-19 19:57 . 2012-12-19 19:57        442368        ----a-w-        c:\windows\system32\atidemgy.dll
2012-12-19 19:56 . 2012-12-19 19:56        550912        ----a-w-        c:\windows\system32\atieclxx.exe
2012-12-19 19:56 . 2012-12-19 19:56        240640        ----a-w-        c:\windows\system32\atiesrxx.exe
2012-12-19 19:54 . 2012-12-19 19:54        120320        ----a-w-        c:\windows\system32\atitmm64.dll
2012-12-19 19:54 . 2012-12-19 19:54        21504        ----a-w-        c:\windows\system32\atimuixx.dll
2012-12-19 19:54 . 2012-12-19 19:54        59392        ----a-w-        c:\windows\system32\atiedu64.dll
2012-12-19 19:54 . 2012-12-19 19:54        43520        ----a-w-        c:\windows\SysWow64\ati2edxx.dll
2012-12-19 19:49 . 2012-01-17 04:59        7370752        ----a-w-        c:\windows\system32\atidxx64.dll
2012-12-19 19:44 . 2012-01-17 04:46        4162048        ----a-w-        c:\windows\SysWow64\atiumdva.dll
2012-12-19 19:44 . 2012-12-19 19:44        6786560        ----a-w-        c:\windows\system32\atiumd64.dll
2012-12-19 19:34 . 2012-12-19 19:34        79360        ----a-w-        c:\windows\system32\amdave64.dll
2012-12-19 19:34 . 2012-12-19 19:34        78336        ----a-w-        c:\windows\SysWow64\amdave32.dll
2012-12-19 19:34 . 2012-12-19 19:34        74240        ----a-w-        c:\windows\system32\atisamu64.dll
2012-12-19 19:34 . 2012-12-19 19:34        71168        ----a-w-        c:\windows\SysWow64\atisamu32.dll
2012-12-19 19:33 . 2012-12-19 19:33        56320        ----a-w-        c:\windows\system32\atimpc64.dll
2012-12-19 19:33 . 2012-12-19 19:33        56320        ----a-w-        c:\windows\system32\amdpcom64.dll
2012-12-19 19:33 . 2012-01-17 04:24        619008        ----a-w-        c:\windows\system32\atiadlxx.dll
2012-12-19 19:33 . 2012-12-19 19:33        56832        ----a-w-        c:\windows\SysWow64\atimpc32.dll
2012-12-19 19:33 . 2012-12-19 19:33        56832        ----a-w-        c:\windows\SysWow64\amdpcom32.dll
2012-12-19 19:33 . 2012-12-19 19:33        421888        ----a-w-        c:\windows\SysWow64\atiadlxy.dll
2012-12-19 19:33 . 2012-12-19 19:33        17920        ----a-w-        c:\windows\system32\atig6pxx.dll
2012-12-19 19:33 . 2012-12-19 19:33        14848        ----a-w-        c:\windows\SysWow64\atiglpxx.dll
2012-12-19 19:33 . 2012-12-19 19:33        14848        ----a-w-        c:\windows\system32\atiglpxx.dll
2012-12-19 19:33 . 2012-12-19 19:33        41984        ----a-w-        c:\windows\system32\atig6txx.dll
2012-12-19 19:33 . 2012-12-19 19:33        33280        ----a-w-        c:\windows\SysWow64\atigktxx.dll
2012-12-19 19:32 . 2012-12-19 19:32        552960        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2012-12-19 19:31 . 2012-01-17 04:23        130048        ----a-w-        c:\windows\system32\atiuxp64.dll
2012-12-19 19:31 . 2012-12-19 19:31        109568        ----a-w-        c:\windows\SysWow64\atiuxpag.dll
2012-12-19 19:31 . 2012-12-19 19:31        104448        ----a-w-        c:\windows\system32\atiu9p64.dll
2012-12-19 19:30 . 2012-01-17 04:23        83968        ----a-w-        c:\windows\SysWow64\atiu9pag.dll
2012-12-19 19:30 . 2012-12-19 19:30        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2012-12-19 14:45 . 2012-12-19 14:45        222720        ----a-w-        c:\windows\system32\clinfo.exe
2012-12-19 14:44 . 2012-12-19 14:44        76288        ----a-w-        c:\windows\system32\OpenVideo64.dll
2012-12-19 14:44 . 2012-12-19 14:44        65536        ----a-w-        c:\windows\SysWow64\OpenVideo.dll
2012-12-19 14:44 . 2012-12-19 14:44        64000        ----a-w-        c:\windows\system32\OVDecode64.dll
2012-12-19 14:44 . 2012-12-19 14:44        56320        ----a-w-        c:\windows\SysWow64\OVDecode.dll
2012-12-19 14:44 . 2012-12-19 14:44        34518016        ----a-w-        c:\windows\system32\amdocl64.dll
2012-12-19 14:38 . 2012-12-19 14:38        28732928        ----a-w-        c:\windows\SysWow64\amdocl.dll
2012-12-19 14:34 . 2012-12-19 14:34        54784        ----a-w-        c:\windows\system32\OpenCL.dll
2012-12-19 14:34 . 2012-12-19 14:34        50176        ----a-w-        c:\windows\SysWow64\OpenCL.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{00cbb66b-1d3b-46d3-9577-323a336acb50}]
2012-12-17 14:12        228032        ----a-w-        c:\program files (x86)\GinyasBrowserCompanion\jsloader.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-08-07 39408]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2012-02-09 5015040]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\Rohr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
tbhcn.lnk - c:\users\Rohr\AppData\Roaming\GinyasBrowserCompanion\tbhcn.exe [2012-12-17 753856]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe [2013-02-11 49152]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2012-11-01 75928]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2012-11-02 50856]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736]
R3 X6va009;X6va009;c:\windows\SysWOW64\Drivers\X6va009 [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS [2012-04-17 451192]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [2012-05-22 1129120]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-02-07 1388120]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [2012-06-07 167072]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\Definitions\IPSDefs\20130313.003\IDSvia64.sys [2013-02-15 513184]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [2012-04-18 190072]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [2012-04-18 405624]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-12-19 240640]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-12-19 361984]
S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [2012-06-16 138272]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2011-11-11 27760]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-11-03 130536]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-11-03 395752]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-11-06 96256]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-02-15 138912]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-03 677480]
S3 SaiK1708;SaiK1708;c:\windows\system32\DRIVERS\SaiK1708.sys [2012-09-20 180544]
S3 SaiU1708;SaiU1708;c:\windows\system32\DRIVERS\SaiU1708.sys [2012-09-20 47168]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2011-11-11 2182768]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-03-14 20:39        1629648        ----a-w-        c:\program files (x86)\Google\Chrome\Application\25.0.1364.172\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-03-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-07 20:13]
.
2013-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-06 12:15]
.
2013-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-06 12:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ProfilerU"="c:\program files\SmartTechnology\Software\ProfilerU.exe" [2012-10-15 454144]
"SaiMfd"="c:\program files\SmartTechnology\Software\SaiMfd.exe" [2012-10-15 158208]
"IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944]
"IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - LocalService
FontCache
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files (x86)\GinyasBrowserCompanion\tdataprotocol.dll
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files (x86)\GinyasBrowserCompanion\tdataprotocol.dll
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files (x86)\GinyasBrowserCompanion\tdataprotocol.dll
FF - ProfilePath - c:\users\Rohr\AppData\Roaming\Mozilla\Firefox\Profiles\xtanz4ff.default\
FF - ExtSQL: 2013-03-10 10:43; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\coFFPlgn
FF - ExtSQL: 2013-03-10 11:04; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.8.0.14\IPSFFPlgn
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
AddRemove-BattlEye for A2 - c:\program files (x86)\steam\steamapps\common\arma 2BattlEye\UnInstallBE.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va009]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va009"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-03-17  00:15:50
ComboFix-quarantined-files.txt  2013-03-16 23:15
.
Vor Suchlauf: 16 Verzeichnis(se), 319.924.203.520 Bytes frei
Nach Suchlauf: 19 Verzeichnis(se), 320.466.161.664 Bytes frei
.
- - End Of File - - 2F5B40A45F8B57A26B428510F2D8F797

--- --- ---


Lief alles einwandfrei :)

markusg 28.03.2013 19:50

sorry, war im urlaub und krank
lade den CCleaner standard:
CCleaner - Download - Filepony
falls der CCleaner
bereits instaliert, überspringen.
öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

JannikLR 29.03.2013 02:52

Adobe Flash Player 11 ActiveX Adobe Systems Incorporated 13.03.2013 6,00MB 11.6.602.180 ,notwendig
Adobe Flash Player 11 Plugin Adobe Systems Incorporated 13.03.2013 6,00MB 11.6.602.180 ,notwendig
AMD Catalyst Install Manager Advanced Micro Devices, Inc. 27.01.2013 26,3MB 8.0.903.0 ,notwendig
Apple Application Support Apple Inc. 06.09.2012 61,0MB 2.1.9 ,notwendig
Apple Mobile Device Support Apple Inc. 06.09.2012 24,9MB 5.2.0.6 ,notwendig
Apple Software Update Apple Inc. 06.09.2012 2,38MB 2.1.3.127 ,notwendig
ARMA 2 Bohemia Interactive 25.08.2012 ,notwendig
ARMA 2: Operation Arrowhead Bohemia Interactive 25.08.2012 ,notwendig
Asmedia ASM104x USB 3.0 Host Controller Driver Asmedia Technology 06.08.2012 2,27MB 1.14.3.0 ,unbekannt
Battlefield 3™ Electronic Arts 27.02.2013 1.5.0.0 ,notwendig
Battlelog Web Plugins EA Digital Illusions CE AB 07.03.2013 2.1.3 ,notwendig
BattlEye for OA Uninstall 25.08.2012 ,notwendig
BattlEye Uninstall 25.08.2012 ,notwendig
Blobby Volley 2 Version 1.0RC3 17.03.2013 3,28MB ,unnötig
Bonjour Apple Inc. 06.09.2012 2,00MB 3.0.0.10 ,unbekannt
Call of Duty: Black Ops II 27.12.2012 ,notwendig
Call of Duty: Black Ops II - Multiplayer 27.12.2012 ,notwendig
Call of Duty: Black Ops II - Zombies 27.12.2012 ,notwendig
Call of Duty: Modern Warfare 2 - Multiplayer Infinity Ward 22.03.2013 ,notwendig
Call of Duty: Modern Warfare 3 Infinity Ward - Sledgehammer Games 26.01.2013 ,notwendig
Call of Duty: Modern Warfare 3 - Multiplayer Infinity Ward - Sledgehammer Games 16.02.2013 ,notwendig
CCleaner Piriform 25.03.2013 4.00 ,notwendig
Cool & Quiet 02.10.2012 ,unbekannt
DayZ Commander Dotjosh Studios 27.01.2013 3,97MB 0.9.123 ,notwendig
Download Updater (AOL Inc.) 07.08.2012 ,unbekannt
EPU-4 Engine 06.08.2012 1.03.03 ,unbekannt
ESN Sonar ESN Social Software AB 07.03.2013 0.70.4 ,unbekannt
Fraps (remove only) 11.01.2013 ,notwendig
GinyasBrowserCompanion Ginyas 23.12.2012 ,unbekannt
Google Chrome Google Inc. 06.08.2012 25.0.1364.172 ,notwendig
Google Toolbar for Internet Explorer Google Inc. 17.12.2012 7.4.3607.2246 ,unnötig
Hi-Rez Studios Authenticate and Update Service Hi-Rez Studios 09.08.2012 3.0.0.0 ,notwendig
iTunes Apple Inc. 06.09.2012 184MB 10.6.3.25 ,notwendig
Java 7 Update 17 Oracle 09.03.2013 129MB 7.0.170 ,notwendig
JavaFX 2.1.1 Oracle Corporation 07.08.2012 20,8MB 2.1.1 ,notwendig
League of Legends Riot Games 17.02.2013 1.3 ,notwendig
LogMeIn Hamachi LogMeIn, Inc. 16.02.2013 2.1.0.294 ,notwendig
LOLReplay League Replays | Home 24.11.2012 0.8.0.1 ,notwendig
LOST PLANET 2 Benchmark Version CAPCOM CO., LTD. 06.08.2012 0,98GB 1.00.0000 ,unnötig
Malwarebytes Anti-Malware Version 1.70.0.1100 Malwarebytes Corporation 16.02.2013 18,4MB 1.70.0.1100 ,unnötig
McAfee Security Scan Plus McAfee, Inc. 08.02.2013 10,2MB 3.0.318.3 ,notwendig(?)
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 09.08.2012 38,8MB 4.0.30319 ,unbekannt
Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 09.08.2012 2,93MB 4.0.30319 ,unbekannt
Microsoft .NET Framework 4 Extended Microsoft Corporation 14.08.2012 51,9MB 4.0.30319 ,unbekannt
Microsoft Chart Controls for Microsoft .NET Framework 3.5 Microsoft Corporation 10.08.2012 13,8MB 3.5.30730.0 ,unbekannt
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 26.08.2012 300KB 8.0.59193 ,unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Corporation 08.08.2012 252KB 9.0.30729 ,unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 06.08.2012 788KB 9.0.30729.4148 ,unbekannt
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 08.08.2012 788KB 9.0.30729.6161 ,unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 14.08.2012 240KB 9.0.30729 ,unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 09.08.2012 594KB 9.0.30729.4148 ,unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 10.08.2012 600KB 9.0.30729.6161 ,unbekannt
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 27.01.2013 15,2MB 10.0.40219 ,unbekannt
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 27.08.2012 15,0MB 10.0.40219 ,unbekannt
Microsoft-Maus- und Tastatur-Center Microsoft Corporation 24.12.2012 2.0.162.0 ,unnötig
Mozilla Firefox 19.0.2 (x86 de) Mozilla 10.03.2013 43,6MB 19.0.2 ,notwendig
Mozilla Maintenance Service Mozilla 10.03.2013 217KB 19.0.2 ,notwendig
Nexon Game Manager 10.08.2012 ,unbekannt
Norton Internet Security Symantec Corporation 16.02.2013 19.9.1.14 ,notwendig
NVIDIA PhysX NVIDIA Corporation 08.08.2012 90,5MB 9.12.0213 ,notwendig
OpenAL 25.08.2012 ,unbekannt
Origin Electronic Arts, Inc. 26.02.2013 9.1.13.85 ,notwendig
Pando Media Booster Pando Networks Inc. 07.08.2012 5,46MB 2.6.0.8 ,unbekannt
Play withSIX SIX Networks 27.01.2013 12,8MB 1.20.0288 ,unnötig
PunkBuster Services Even Balance, Inc. 27.02.2013 0.991 ,notwendig
puush Dean Herbert 25.03.2013 537KB 1.0.0.0 ,notwendig
Rapture3D 2.4.11 Game Blue Ripple Sound 25.08.2012 ,unbekannt
Realtek Ethernet Controller Driver Realtek 06.08.2012 7.52.203.2012 ,unbekannt
Skype™ 6.1 Skype Technologies S.A. 10.02.2013 21,1MB 6.1.129 ,notwendig
Smart Technology Programming Software 7.0.23.0 Mad Catz 24.12.2012 131MB 7.0.23.0 ,unbekannt
Steam Valve Corporation 08.08.2012 35,4MB 1.0.0.0 ,notwendig
System Requirements Lab CYRI Husdawg, LLC 02.11.2012 579KB 5.0.6.0 ,unbekannt
System Requirements Lab Detection Husdawg, LLC 25.02.2013 631KB 1.0.5.0 ,unbekannt
TeamSpeak 3 Client TeamSpeak Systems GmbH 05.03.2013 3.0.10 ,notwendig
TERA Gameforge Productions GmbH 19.02.2013 42,5MB 19.04.02.03.hf3 ,notwendig
The Binding of Isaac 07.08.2012 ,notwendig
TrackMania Nations Forever Nadeo 03.02.2013 ,unnötig
Trials Evolution Gold Edition RedLynx and Ubisoft Shanghai 17.03.2013 ,notwendig
Uplay Ubisoft 17.03.2013 2.0 ,notwendig
VIA Plattform-Geräte-Manager VIA Technologies, Inc. 06.08.2012 2,62MB 1.39 ,unbekannt
Winamp Nullsoft, Inc 07.08.2012 5.63 ,notwendig
Winamp Erkennungs-Plug-in Nullsoft, Inc 08.08.2012 63,0KB 1.0.0.1 ,notwendig
Winamp Toolbar 07.08.2012 ,notwendig
WinRAR 4.20 (64-Bit) win.rar GmbH 07.08.2012 4.20.0 ,notwendig

JannikLR 06.04.2013 18:58

Viel zu tun ? :)

JannikLR 24.04.2013 18:53

Sorry , aber kommt noch was ?

markusg 11.05.2013 16:33

hi
deinstaliere:
Blobby
ESN
Google Toolbar
Java : alle
downloade Java jre:
Java-Downloads für alle Betriebssysteme
klicke:
Download der Java-Software für Windows Offline
laden, und instalieren
deinstaliere:
LOST PLANET
McAfee
TrackMania
Winamp Toolbar : verzichte bitte auf Tollbars, sie sind nur ein unnötiges Zusatzrisiko

Öffne CCleaner, analysieren, starten PC neustarten.
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

JannikLR 12.05.2013 01:09

AdwCleaner v2.300 - Datei am 12/05/2013 um 02:02:43 erstellt
# Aktualisiert am 28/04/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Rohr - ROHR-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Rohr\Downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\Rohr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tbhcn.lnk
Datei Gelöscht : C:\Users\Rohr\AppData\Roaming\Mozilla\Firefox\Profiles\xtanz4ff.default\searchplugins\Babylon.xml
Datei Gelöscht : C:\Users\Rohr\AppData\Roaming\Mozilla\Firefox\Profiles\xtanz4ff.default\searchplugins\BrowserProtect.xml
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Software Update Utility
Ordner Gelöscht : C:\Program Files (x86)\GinyasBrowserCompanion
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\IBUpdaterService
Ordner Gelöscht : C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf
Ordner Gelöscht : C:\Users\Rohr\AppData\LocalLow\bbrs_002.tb
Ordner Gelöscht : C:\Users\Rohr\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Rohr\AppData\Roaming\GinyasBrowserCompanion
Ordner Gelöscht : C:\Users\Rohr\AppData\Roaming\Mozilla\Firefox\Profiles\xtanz4ff.default\extensions\ffxtlbr@babylon.com
Ordner Gelöscht : C:\Users\Rohr\AppData\Roaming\PerformerSoft

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\1ClickDownload
Schlüssel Gelöscht : HKCU\Software\BabylonToolbar
Schlüssel Gelöscht : HKCU\Software\Blabbers
Schlüssel Gelöscht : HKCU\Software\BrowserCompanion
Schlüssel Gelöscht : HKCU\Software\DataMngr
Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\BrowserCompanion
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\GinyasBrowserCompanion
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\853dfdab36de514
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bodddioamolcibagionmmobehnbhiakf
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GinyasBrowserCompanion
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16476

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.holasearch.com/?affID=121962&tt=gc_&babsrc=HP_ss&mntrId=CE1390F652BE8D6D --> hxxp://www.google.com

-\\ Mozilla Firefox v19.0.2 (de)

Datei : C:\Users\Rohr\AppData\Roaming\Mozilla\Firefox\Profiles\xtanz4ff.default\prefs.js

C:\Users\Rohr\AppData\Roaming\Mozilla\Firefox\Profiles\xtanz4ff.default\user.js ... Gelöscht !

Gelöscht : user_pref("browser.startup.homepage", "hxxp://www.holasearch.com/?affID=121962&tt=gc_&babsrc=HP_ss&m[...]

-\\ Google Chrome v26.0.1410.64

Datei : C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Preferences

Gelöscht [l.50] : icon_url = "hxxp://www.holasearch.com/favicon.ico",
Gelöscht [l.53] : keyword = "holasearch.com",
Gelöscht [l.57] : search_url = "hxxp://www.holasearch.com/?q={searchTerms}&affID=121962&tt=gc_&babsrc=SP_ss&mnt[...]
Gelöscht [l.1118] : homepage = "hxxp://www.holasearch.com/?affID=121962&tt=gc_&babsrc=HP_ss&mntrId=CE1390F652BE8D6D"[...]
Gelöscht [l.2221] : urls_to_restore_on_startup = [ "hxxp://www.holasearch.com/?affID=121962&tt=gc_&babsrc=HP_ss&m[...]

*************************

AdwCleaner[S1].txt - [8629 octets] - [12/05/2013 02:02:43]

########## EOF - C:\AdwCleaner[S1].txt - [8689 octets] ##########

markusg 13.05.2013 12:40

Hi,
HitmanPro - Download - Filepony
Hitmanpro laden, doppelklicken,
Auf scan.
Nichts löschen, auf weiter, Log als XML speichern und posten, bzw packen und anhängen

JannikLR 13.05.2013 19:55

Code:

HitmanPro 3.7.3.194
www.hitmanpro.com

  Computer name . . . . : ROHR-PC
  Windows . . . . . . . : 6.1.1.7601.X64/4
  User name . . . . . . : Rohr-PC\Rohr
  UAC . . . . . . . . . : Disabled
  License . . . . . . . : Free

  Scan date . . . . . . : 2013-05-13 20:49:13
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 3m 2s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 2
  Traces  . . . . . . . : 34

  Objects scanned . . . : 1.149.747
  Files scanned . . . . : 22.513
  Remnants scanned  . . : 311.001 files / 816.233 keys

Malware _____________________________________________________________________

  C:\Users\Rohr\Desktop\Spiele\MW2 MP FoV Changer.exe
      Size . . . . . . . : 83.456 bytes
      Age  . . . . . . . : 191.0 days (2012-11-03 21:23:12)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : AE8081CD9F3B7738BA9B4CED8FB7C96094BDC6CAC98BD25DD263532E14D02847
      Needs elevation  . : Yes
      Product  . . . . . : MW2_mp_fov
      Description  . . . : MW2_mp_fov
      Version  . . . . . : 1.0.0.0
      Copyright  . . . . : Copyright ©  2012
    > Ikarus . . . . . . : Trojan-Dropper!IK
      Fuzzy  . . . . . . : 101.0

  C:\Users\Rohr\Desktop\Spiele\Neuer Ordner\Self-Activator_Gamekeys_biz\Self-Activator_Gamekeys_biz\START_INTERFACE.exe
      Size . . . . . . . : 1.887.744 bytes
      Age  . . . . . . . : 106.9 days (2013-01-27 00:16:48)
      Entropy  . . . . . : 6.8
      SHA-256  . . . . . : 0A121328638C61084C531838F4D64A00504219F6ABD3E6207673FEED2D2F3C0C
      Publisher  . . . . : Gamekeys.biz
      Description  . . . : Self-Activator
      Version  . . . . . : 1.0.0.0
      Copyright  . . . . : Adam Pox
    > G Data . . . . . . : Trojan.Generic.8429085 (Engine A)
    > Ikarus . . . . . . : Trojan-Dropper.Delf!IK
      Fuzzy  . . . . . . : 100.0


Suspicious files ____________________________________________________________

  C:\Users\Rohr\AppData\Local\PunkBuster\APB\pb\pbcl.dll
      Size . . . . . . . : 953.905 bytes
      Age  . . . . . . . : 260.0 days (2012-08-26 19:51:10)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 9A5BDD44D0817FE21A154412B5989E157455BC24ADBCB238376F73FCEFB14696
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\APB\pb\PnkBstrK.sys
      Size . . . . . . . : 138.992 bytes
      Age  . . . . . . . : 260.0 days (2012-08-26 19:51:24)
      Entropy  . . . . . : 7.7
      SHA-256  . . . . . : 17E604316606C999C87C896508B3525E4897DFA1522FEE01B86524F46B3D9B3D
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\dll\wc002317.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 72.9 days (2013-03-01 23:22:47)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 72.9 days (2013-03-01 23:22:47)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 75.1 days (2013-02-27 17:34:13)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\pbcls.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 75.1 days (2013-02-27 17:51:57)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
      Size . . . . . . . : 137.992 bytes
      Age  . . . . . . . : 75.1 days (2013-02-27 17:34:44)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 21A3D2E3A063EA2F986EF1BAFD1A71F7FC9EDB3F69E0265E51A18DBC111084F1
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\dll\wc002304.dll
      Size . . . . . . . : 954.496 bytes
      Age  . . . . . . . : 269.4 days (2012-08-17 11:53:19)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\pbcl.dll
      Size . . . . . . . : 954.496 bytes
      Age  . . . . . . . : 269.4 days (2012-08-17 11:53:19)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\pbclold.dll
      Size . . . . . . . : 915.149 bytes
      Age  . . . . . . . : 269.4 days (2012-08-17 11:48:20)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : E189EF452F559BFAC0C0A91EFADC78EAA569B915985A213F99666BE56FC86165
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\PnkBstrK.sys
      Size . . . . . . . : 139.424 bytes
      Age  . . . . . . . : 269.4 days (2012-08-17 11:49:33)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 2A97BC40220EE7B5383991EDB238A70B2D6A7881E54E465999E2EADD6A396029
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\dll\wc002293.dll
      Size . . . . . . . : 949.190 bytes
      Age  . . . . . . . : 272.0 days (2012-08-14 20:34:06)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\pbcl.dll
      Size . . . . . . . : 949.190 bytes
      Age  . . . . . . . : 214.9 days (2012-10-10 22:32:47)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\pbclold.dll
      Size . . . . . . . : 949.190 bytes
      Age  . . . . . . . : 272.0 days (2012-08-14 20:13:14)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\PnkBstrK.sys
      Size . . . . . . . : 140.360 bytes
      Age  . . . . . . . : 272.0 days (2012-08-14 20:13:31)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 0F41B3843E2D2D1BB1ACF8B7CAA293309CC1CF8CF478B1AC86DD6BB214928DC4
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BR\pb\pbcl.dll
      Size . . . . . . . : 951.922 bytes
      Age  . . . . . . . : 277.9 days (2012-08-08 22:57:29)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 556FB516EF1C1A23F6C976C7624709744E53FCB1E6521CA6ABBDE9969C40F532
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BR\pb\pbcls.dll
      Size . . . . . . . : 951.922 bytes
      Age  . . . . . . . : 277.9 days (2012-08-08 22:57:29)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 556FB516EF1C1A23F6C976C7624709744E53FCB1E6521CA6ABBDE9969C40F532
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BR\pb\PnkBstrK.sys
      Size . . . . . . . : 140.072 bytes
      Age  . . . . . . . : 277.1 days (2012-08-09 17:56:29)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : E4F5F27A3E0EFCC2701C2F9BAB3BDCDD01CA7D3580B0A344A453EEC7CA33505A
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\wc002323.dll
      Size . . . . . . . : 956.648 bytes
      Age  . . . . . . . : 22.1 days (2013-04-21 18:00:06)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : E88505208F2EA9F150F451C73EEFE57D54A7F50E9D24CB9E647D95A1E826A052
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
        -0.2s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\htm\wc002323.htm
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\wc002323.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.dll
        11.5s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrA.exe

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.dll
      Size . . . . . . . : 956.648 bytes
      Age  . . . . . . . : 22.1 days (2013-04-21 18:00:06)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : E88505208F2EA9F150F451C73EEFE57D54A7F50E9D24CB9E647D95A1E826A052
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
        -0.2s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\htm\wc002323.htm
        -0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\wc002323.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.dll
        11.5s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrA.exe

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbclold.dll
      Size . . . . . . . : 947.283 bytes
      Age  . . . . . . . : 22.1 days (2013-04-21 17:47:52)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 26898E20DB3E20E2986684F1726D3421B0EA9D381F4BD56D6370AAE63973F5B8
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
      Forensic Cluster
        -3.1s C:\Program Files (x86)\EA Games\Battlefield Heroes\mods\bfheroes\mugshot.png
        -0.2s C:\Program Files (x86)\EA Games\Battlefield Heroes\pbcl.log
        -0.1s C:\Program Files (x86)\EA Games\Battlefield Heroes\pb\pbcl.db
        -0.1s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\
        -0.1s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\
        -0.1s C:\Program Files (x86)\EA Games\Battlefield Heroes\pb\pbcl.log
        -0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbclgame.cfg
        -0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.db
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbclold.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbag.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\scrnshot\
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\htm\
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.log
          0.7s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrB.exe
          1.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbase.cfx
          1.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbaselightmap.cfx
          1.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetail.cfx
          1.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetaillightmap.cfx
          1.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbaseshadow.cfx
          1.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbaselightmapshadow.cfx
          1.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailshadow.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetaillightmapshadow.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasepointlight.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailpointlight.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatest.cfx
          1.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestlightmap.cfx
          1.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatest.cfx
          1.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestlightmap.cfx
          1.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestshadow.cfx
          1.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestlightmapshadow.cfx
          1.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestshadow.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestlightmapshadow.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestpointlight.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestpointlight.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafpointlight.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmdetailshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmbaseshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafpointlightshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmdetail.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmbase.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafdir.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderspriteleaf.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderroad.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderroaddetailnoblend.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderroaddetail.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwater.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothing.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimation.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimap.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimap.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimap.cfx
          2.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimap.cfx
          2.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothinghasrimeffect.cfx
          2.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationhasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimaphasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimaphasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimaphasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimaphasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothingpointlighthasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationpointlighthasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimappointlighthasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimappointlighthasrimeffect.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimappointlighthasrimeffect.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimappointlighthasrimeffect.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothinghasrimeffectlow.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationhasrimeffectlow.cfx
          2.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimaphasrimeffectlow.cfx
          2.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimaphasrimeffectlow.cfx
          2.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimaphasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimaphasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothingpointlighthasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationpointlighthasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothinghasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationhasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimaphasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimaphasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimaphasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimaphasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothingpointlighthasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationpointlighthasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimappointlighthasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimappointlighthasrimeffectsuperlow.cfx
          3.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimappointlighthasrimeffectsuperlow.cfx
          3.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimappointlighthasrimeffectsuperlow.cfx
          3.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmzonly.cfx
        13.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwater2d.cfx
        13.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwaterdistant2d.cfx
        13.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwatersurrounding2d.cfx
        13.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwaterhighend3d.cfx
        13.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwaterdistant3d.cfx
        13.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwatersurrounding3d.cfx

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrK.sys
      Size . . . . . . . : 139.648 bytes
      Age  . . . . . . . : 22.1 days (2013-04-21 17:52:15)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 164A5F0B9153B75F8955C44BFAE12B594B8D53922AE090132695FF2DAD191C8A
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
        -37.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafdirog.cfx
        -37.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkog.cfx
        -34.8s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbns_c.dat
        -23.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadersmactivecamo.cfx
        -2.2s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4
        -2.2s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrK.sys

  C:\Users\Rohr\Desktop\Spiele\Neuer Ordner\Self-Activator_Gamekeys_biz\Self-Activator_Gamekeys_biz\vpn_pl.exe
      Size . . . . . . . : 31.744 bytes
      Age  . . . . . . . : 106.9 days (2013-01-27 00:16:48)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : ADE6CD3F8F8B38B7925F6787B0A7494441D783E7FBCC40ECC78B3EE1AB2E4229
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 22.0
        Program has no publisher information but prompts the user for permission elevation.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.

  C:\Users\Rohr\Desktop\Spiele\Neuer Ordner\Self-Activator_Gamekeys_biz\Self-Activator_Gamekeys_biz\vpn_ru.exe
      Size . . . . . . . : 31.744 bytes
      Age  . . . . . . . : 106.9 days (2013-01-27 00:16:48)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : 94E9AB74C36245BBC9E6C606B0E02A0DFC3EF58FD0BFFA9A786BB3791D820DA1
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 22.0
        Program has no publisher information but prompts the user for permission elevation.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.


Potential Unwanted Programs _________________________________________________

  HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Blabbers      \ (Blabbers)
  HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)
  HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro)

Cookies _____________________________________________________________________

  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
  C:\Users\Rohr\AppData\Roaming\Microsoft\Windows\Cookies\XFD20J5Y.txt


markusg 13.05.2013 20:05

hi
sagen dir die ersten Beiden Funde etwas?

JannikLR 13.05.2013 21:18

Ja , MW2 MP FoV Changer ist dazu da um seine Sicht etwas zu verändern in einem Spiel , kann aber gelöscht werden.
Bei dem zweiten bin ich mir nicht sicher. Es gibt da so ne Seite wo man Spiele günstig kaufen kann .. ( Gamekeys.biz ) Sieht schwer danach aus das es daher kommt.

markusg 14.05.2013 12:13

dann lösche mit Hitmanpro
Potential Unwanted Programs _________________________________________________

HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Blabbers \ (Blabbers)
HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)
HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro)

und kookies.
danach neustarten, neues otl log

JannikLR 14.05.2013 13:17

Code:

HitmanPro 3.7.3.194
www.hitmanpro.com

  Computer name . . . . : ROHR-PC
  Windows . . . . . . . : 6.1.1.7601.X64/4
  User name . . . . . . : Rohr-PC\Rohr
  UAC . . . . . . . . . : Disabled
  License . . . . . . . : Trial (30 days left)

  Scan date . . . . . . : 2013-05-14 14:10:22
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 5m 47s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No

  Threats . . . . . . . : 0
  Traces  . . . . . . . : 29

  Objects scanned . . . : 1.144.820
  Files scanned . . . . : 22.319
  Remnants scanned  . . : 306.150 files / 816.351 keys

Suspicious files ____________________________________________________________

  C:\Users\Rohr\AppData\Local\PunkBuster\APB\pb\pbcl.dll
      Size . . . . . . . : 953.905 bytes
      Age  . . . . . . . : 260.8 days (2012-08-26 19:51:10)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 9A5BDD44D0817FE21A154412B5989E157455BC24ADBCB238376F73FCEFB14696
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\APB\pb\PnkBstrK.sys
      Size . . . . . . . : 138.992 bytes
      Age  . . . . . . . : 260.8 days (2012-08-26 19:51:24)
      Entropy  . . . . . : 7.7
      SHA-256  . . . . . : 17E604316606C999C87C896508B3525E4897DFA1522FEE01B86524F46B3D9B3D
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\dll\wc002317.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 73.6 days (2013-03-01 23:22:47)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
      Size . . . . . . . : 949.613 bytes
      Age  . . . . . . . : 73.6 days (2013-03-01 23:22:47)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 15059F09B1D62DEA6B5D22EF9E0D062411C167378D870AE339AAB50B0BDC7FC0
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 75.9 days (2013-02-27 17:34:13)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\pbcls.dll
      Size . . . . . . . : 959.376 bytes
      Age  . . . . . . . : 75.8 days (2013-02-27 17:51:57)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A85592ACDCFDA7C0293504A5F5279C2654ACC0E6D2398ED8958F6E03F05DCEB5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
      Size . . . . . . . : 137.992 bytes
      Age  . . . . . . . : 75.9 days (2013-02-27 17:34:44)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 21A3D2E3A063EA2F986EF1BAFD1A71F7FC9EDB3F69E0265E51A18DBC111084F1
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\dll\wc002304.dll
      Size . . . . . . . : 954.496 bytes
      Age  . . . . . . . : 270.1 days (2012-08-17 11:53:19)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\pbcl.dll
      Size . . . . . . . : 954.496 bytes
      Age  . . . . . . . : 270.1 days (2012-08-17 11:53:19)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : EEBDAC091729B0B80A21E14B2CE0392E4584205BA06F5ED1B846C51D034A2177
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\pbclold.dll
      Size . . . . . . . : 915.149 bytes
      Age  . . . . . . . : 270.1 days (2012-08-17 11:48:20)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : E189EF452F559BFAC0C0A91EFADC78EAA569B915985A213F99666BE56FC86165
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BFP4F\pb\PnkBstrK.sys
      Size . . . . . . . : 139.424 bytes
      Age  . . . . . . . : 270.1 days (2012-08-17 11:49:33)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 2A97BC40220EE7B5383991EDB238A70B2D6A7881E54E465999E2EADD6A396029
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\dll\wc002293.dll
      Size . . . . . . . : 949.190 bytes
      Age  . . . . . . . : 272.7 days (2012-08-14 20:34:06)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\pbcl.dll
      Size . . . . . . . : 949.190 bytes
      Age  . . . . . . . : 215.7 days (2012-10-10 22:32:47)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\pbclold.dll
      Size . . . . . . . : 949.190 bytes
      Age  . . . . . . . : 272.7 days (2012-08-14 20:13:14)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BLR\pb\PnkBstrK.sys
      Size . . . . . . . : 140.360 bytes
      Age  . . . . . . . : 272.7 days (2012-08-14 20:13:31)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 0F41B3843E2D2D1BB1ACF8B7CAA293309CC1CF8CF478B1AC86DD6BB214928DC4
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\BR\pb\pbcl.dll
      Size . . . . . . . : 951.922 bytes
      Age  . . . . . . . : 278.6 days (2012-08-08 22:57:29)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 556FB516EF1C1A23F6C976C7624709744E53FCB1E6521CA6ABBDE9969C40F532
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BR\pb\pbcls.dll
      Size . . . . . . . : 951.922 bytes
      Age  . . . . . . . : 278.6 days (2012-08-08 22:57:29)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 556FB516EF1C1A23F6C976C7624709744E53FCB1E6521CA6ABBDE9969C40F532
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.

  C:\Users\Rohr\AppData\Local\PunkBuster\BR\pb\PnkBstrK.sys
      Size . . . . . . . : 140.072 bytes
      Age  . . . . . . . : 277.8 days (2012-08-09 17:56:29)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : E4F5F27A3E0EFCC2701C2F9BAB3BDCDD01CA7D3580B0A344A453EEC7CA33505A
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\wc002323.dll
      Size . . . . . . . : 956.648 bytes
      Age  . . . . . . . : 22.8 days (2013-04-21 18:00:06)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : E88505208F2EA9F150F451C73EEFE57D54A7F50E9D24CB9E647D95A1E826A052
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
        -0.2s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\htm\wc002323.htm
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\wc002323.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.dll
        11.5s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrA.exe

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.dll
      Size . . . . . . . : 956.648 bytes
      Age  . . . . . . . : 22.8 days (2013-04-21 18:00:06)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : E88505208F2EA9F150F451C73EEFE57D54A7F50E9D24CB9E647D95A1E826A052
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
        -0.2s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\htm\wc002323.htm
        -0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\wc002323.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.dll
        11.5s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrA.exe

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbclold.dll
      Size . . . . . . . : 947.283 bytes
      Age  . . . . . . . : 22.8 days (2013-04-21 17:47:52)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 26898E20DB3E20E2986684F1726D3421B0EA9D381F4BD56D6370AAE63973F5B8
      Fuzzy  . . . . . . : 29.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
      Forensic Cluster
        -3.1s C:\Program Files (x86)\EA Games\Battlefield Heroes\mods\bfheroes\mugshot.png
        -0.2s C:\Program Files (x86)\EA Games\Battlefield Heroes\pbcl.log
        -0.1s C:\Program Files (x86)\EA Games\Battlefield Heroes\pb\pbcl.db
        -0.1s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\
        -0.1s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\
        -0.1s C:\Program Files (x86)\EA Games\Battlefield Heroes\pb\pbcl.log
        -0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbclgame.cfg
        -0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.db
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbclold.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbag.dll
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\scrnshot\
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\dll\
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\htm\
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbcl.log
          0.7s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrB.exe
          1.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbase.cfx
          1.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbaselightmap.cfx
          1.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetail.cfx
          1.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetaillightmap.cfx
          1.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbaseshadow.cfx
          1.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbaselightmapshadow.cfx
          1.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailshadow.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetaillightmapshadow.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasepointlight.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailpointlight.cfx
          1.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatest.cfx
          1.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestlightmap.cfx
          1.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatest.cfx
          1.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestlightmap.cfx
          1.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestshadow.cfx
          1.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestlightmapshadow.cfx
          1.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestshadow.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestlightmapshadow.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasealphatestpointlight.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderstmbasedetailalphatestpointlight.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafpointlight.cfx
          1.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmdetailshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmbaseshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafpointlightshadowed.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmdetail.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkstmbase.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafdir.cfx
          1.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderspriteleaf.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderroad.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderroaddetailnoblend.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderroaddetail.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwater.cfx
          1.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothing.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimation.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimap.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimap.cfx
          2.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimap.cfx
          2.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimap.cfx
          2.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothinghasrimeffect.cfx
          2.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationhasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimaphasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimaphasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimaphasrimeffect.cfx
          2.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimaphasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothingpointlighthasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationpointlighthasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimappointlighthasrimeffect.cfx
          2.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimappointlighthasrimeffect.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimappointlighthasrimeffect.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimappointlighthasrimeffect.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothinghasrimeffectlow.cfx
          2.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationhasrimeffectlow.cfx
          2.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimaphasrimeffectlow.cfx
          2.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimaphasrimeffectlow.cfx
          2.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimaphasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimaphasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothingpointlighthasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationpointlighthasrimeffectlow.cfx
          2.6s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimappointlighthasrimeffectlow.cfx
          2.7s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothinghasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationhasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimaphasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimaphasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimaphasrimeffectsuperlow.cfx
          2.8s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimaphasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmnothingpointlighthasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationpointlighthasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimappointlighthasrimeffectsuperlow.cfx
          2.9s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmusehemimappointlighthasrimeffectsuperlow.cfx
          3.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasuvanimationusehemimappointlighthasrimeffectsuperlow.cfx
          3.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmhasgimapusehemimappointlighthasrimeffectsuperlow.cfx
          3.0s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderbmzonly.cfx
        13.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwater2d.cfx
        13.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwaterdistant2d.cfx
        13.1s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwatersurrounding2d.cfx
        13.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwaterhighend3d.cfx
        13.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwaterdistant3d.cfx
        13.5s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderwatersurrounding3d.cfx

  C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrK.sys
      Size . . . . . . . : 139.648 bytes
      Age  . . . . . . . : 22.8 days (2013-04-21 17:52:15)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : 164A5F0B9153B75F8955C44BFAE12B594B8D53922AE090132695FF2DAD191C8A
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 22.0
        The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.
        Program contains PE structure anomalies. This is not typical for most programs.
        The file is a device driver. Device drivers run as trusted (highly privileged) code.
        Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
        -37.3s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashaderleafdirog.cfx
        -37.2s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadertrunkog.cfx
        -34.8s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\pbns_c.dat
        -23.4s C:\Users\Rohr\Documents\Battlefield Heroes\mods\bfheroes\cache\{D7B71EE2-2B7D-11CF-A370-1303BEC2C535}_246917_4\rashadersmactivecamo.cfx
        -2.2s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4
        -2.2s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4
          0.0s C:\Users\Rohr\AppData\Local\PunkBuster\HEROES\pb\PnkBstrK.sys

  C:\Users\Rohr\Desktop\Spiele\Neuer Ordner\Self-Activator_Gamekeys_biz\Self-Activator_Gamekeys_biz\vpn_pl.exe
      Size . . . . . . . : 31.744 bytes
      Age  . . . . . . . : 107.6 days (2013-01-27 00:16:48)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : ADE6CD3F8F8B38B7925F6787B0A7494441D783E7FBCC40ECC78B3EE1AB2E4229
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 22.0
        Program has no publisher information but prompts the user for permission elevation.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.

  C:\Users\Rohr\Desktop\Spiele\Neuer Ordner\Self-Activator_Gamekeys_biz\Self-Activator_Gamekeys_biz\vpn_ru.exe
      Size . . . . . . . : 31.744 bytes
      Age  . . . . . . . : 107.6 days (2013-01-27 00:16:48)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : 94E9AB74C36245BBC9E6C606B0E02A0DFC3EF58FD0BFFA9A786BB3791D820DA1
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 22.0
        Program has no publisher information but prompts the user for permission elevation.
        Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
        Authors name is missing in version info. This is not common to most programs.
        Version control is missing. This file is probably created by an individual. This is not typical for most programs.


Cookies _____________________________________________________________________

  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
  C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.etracker.de

Cookies konnten nicht gelöscht werden.

markusg 14.05.2013 13:18

ok passt.
bitte neues OTL Log.

JannikLR 14.05.2013 13:30

Sorry , was meinst du mit OTL ?

markusg 14.05.2013 13:32

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

JannikLR 14.05.2013 13:45

OTL Logfile:
Code:

OTL logfile created on: 14.05.2013 14:41:11 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Rohr\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,98 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 57,34% Memory free
7,96 Gb Paging File | 5,88 Gb Available in Paging File | 73,80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,66 Gb Total Space | 255,56 Gb Free Space | 54,88% Space Free | Partition Type: NTFS
 
Computer Name: ROHR-PC | User Name: Rohr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Rohr\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\puush\puush.exe ()
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\puush\puush.exe ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\wincfi39.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (VIAKaraokeService) -- C:\Windows\SysNative\ViakaraokeSrv.exe (VIA Technologies, Inc.)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (BEService) -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe ()
SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\ccSvcHst.exe (Symantec Corporation)
SRV - (npggsvc) -- C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (HiPatchService) -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1403010.016\symnets.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1403010.016\SymEFA64.sys (Symantec Corporation)
DRV:64bit: - (Point64) -- C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1403010.016\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\NISx64\1403010.016\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1403010.016\SymDS64.sys (Symantec Corporation)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (dc3d) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1403010.016\Ironx64.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NIS) -- C:\Windows\SysNative\drivers\NISx64\1403010.016\ccSetx64.sys (Symantec Corporation)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK1708) -- C:\Windows\SysNative\drivers\SaiK1708.sys (Saitek)
DRV:64bit: - (SaiU1708) -- C:\Windows\SysNative\drivers\SaiU1708.sys (Saitek)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (asmtxhci) -- C:\Windows\SysNative\drivers\asmtxhci.sys (ASMedia Technology Inc)
DRV:64bit: - (asmthub3) -- C:\Windows\SysNative\drivers\asmthub3.sys (ASMedia Technology Inc)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiPcie) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.1.22\Definitions\IPSDefs\20130511.001\IDSviA64.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.1.22\Definitions\VirusDefs\20130513.022\ex64.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.1.22\Definitions\VirusDefs\20130513.022\eng64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.1.22\Definitions\BASHDefs\20130502.001\BHDrvx64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (AODDriver4.2) -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV - (AODDriver4.01) -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV - (WinRing0_1_2_0) -- C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys (OpenLibSys.org)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_deDE496
IE - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..browser.search.selectedEngine: "Hola Search"
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.3: C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.1.22\coFFPlgn\ [2013.05.14 14:07:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.1.22\IPSFFPlgn\ [2013.04.19 22:01:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.10 13:06:35 | 000,000,000 | ---D | M]
 
[2013.03.10 13:08:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rohr\AppData\Roaming\mozilla\Extensions
[2013.05.12 02:02:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rohr\AppData\Roaming\mozilla\Firefox\Profiles\xtanz4ff.default\extensions
[2013.05.10 16:43:07 | 000,001,304 | ---- | M] () -- C:\Users\Rohr\AppData\Roaming\mozilla\firefox\profiles\xtanz4ff.default\searchplugins\holasearch.xml
[2013.03.10 13:06:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013.03.07 16:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013.03.07 17:45:15 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013.03.07 17:45:15 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013.03.07 17:45:15 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2013.03.07 17:45:15 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2013.03.07 17:45:15 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2013.03.07 17:45:15 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Hola Search (Enabled)
CHR - default_search_provider: search_url = hxxp://www.holasearch.com/?q={searchTerms}&affID=121962&tt=gc_&babsrc=SP_ss&mntrId=CE1390F652BE8D6D
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonEU\NGM\npNxGameeu.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - Extension: AdBlock = C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.63_0\
CHR - Extension: Norton Identity Protection = C:\Users\Rohr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.3.3.19_0\
 
O1 HOSTS File: ([2013.03.17 01:14:10 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\IPS\IPSBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Programme\SmartTechnology\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Programme\SmartTechnology\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe (Dxtory Software)
O4 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000..\Run: [puush] C:\Program Files (x86)\puush\puush.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5556E540-02B6-4492-B8D3-A3DD9D832D22}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EA5C435D-AF6C-4C26-A640-4E7C72DE713D}: DhcpNameServer = 217.0.43.193 217.0.43.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.05.14 13:47:19 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2013.05.14 13:37:48 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2013.05.13 20:42:12 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2013.05.13 20:41:48 | 009,741,664 | ---- | C] (SurfRight B.V.) -- C:\Users\Rohr\Desktop\HitmanPro_x64.exe
[2013.05.12 01:53:57 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.05.12 01:50:30 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.05.10 21:15:30 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\searchplugins
[2013.05.10 21:15:30 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Extensions
[2013.05.10 16:36:04 | 000,000,000 | ---D | C] -- C:\Users\Rohr\AppData\Roaming\Wise Disk Cleaner
[2013.05.10 16:35:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wise
[2013.05.10 16:33:03 | 000,000,000 | ---D | C] -- C:\Users\Rohr\AppData\Roaming\Auslogics
[2013.05.10 16:21:01 | 000,019,632 | ---- | C] (PerformerSoft LLC) -- C:\Windows\SysNative\roboot64.exe
[2013.05.10 16:14:05 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013.05.10 13:41:24 | 007,859,160 | ---- | C] (Auslogics Software Pty Ltd                                  ) -- C:\Users\Rohr\Desktop\disk3610-defrag-setup.exe
[2013.05.07 21:14:35 | 000,000,000 | ---D | C] -- C:\Users\Rohr\Documents\Square Enix
[2013.05.04 17:55:12 | 000,000,000 | ---D | C] -- C:\gravity
[2013.05.04 17:51:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2013.05.04 17:51:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2013.04.30 15:59:02 | 000,000,000 | ---D | C] -- C:\Users\Rohr\AppData\Roaming\NetSpeedMonitor
[2013.04.30 15:45:22 | 000,000,000 | ---D | C] -- C:\Users\Rohr\Desktop\LaunchComponent (1)
[2013.04.30 15:16:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3
[2013.04.30 15:16:04 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2013.04.30 15:16:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2013.04.24 14:05:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft-Maus- und Tastatur-Center
[2013.04.24 14:04:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Mouse and Keyboard Center
[2013.04.23 21:59:41 | 000,000,000 | ---D | C] -- C:\Users\Rohr\AppData\Roaming\Audacity
[2013.04.23 21:59:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
[2013.04.23 21:59:12 | 021,281,052 | ---- | C] (Audacity Team                                              ) -- C:\Users\Rohr\Desktop\audacity-win-2.0.3.exe
[2013.04.21 17:31:21 | 000,000,000 | ---D | C] -- C:\Users\Rohr\Documents\Battlefield Heroes
[2013.04.21 17:30:10 | 000,000,000 | ---D | C] -- C:\Users\Rohr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games
[2013.04.21 17:22:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EA Games
[2013.04.20 15:49:54 | 000,000,000 | ---D | C] -- C:\Dxtory Aufnahmen
[2013.04.20 15:47:26 | 000,000,000 | ---D | C] -- C:\Users\Rohr\AppData\Local\Dxtory Software
[2013.04.20 15:47:19 | 003,673,600 | ---- | C] (Dxtory Software) -- C:\Windows\SysNative\DxtoryCodec64.dll
[2013.04.20 15:47:19 | 003,166,720 | ---- | C] (Dxtory Software) -- C:\Windows\SysWow64\DxtoryCodec.dll
[2013.04.20 15:47:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
[2013.04.20 15:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dxtory Software
[2013.04.20 15:44:50 | 000,000,000 | ---D | C] -- C:\Users\Rohr\Desktop\Dxtory + Crack, by eXiR
[2013.04.19 21:59:45 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.05.14 14:13:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.05.14 14:12:50 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.05.14 14:12:50 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.05.14 14:06:42 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.05.14 14:05:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.05.14 14:05:12 | 3207,159,808 | -HS- | M] () -- C:\hiberfil.sys
[2013.05.14 13:47:19 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2013.05.14 13:47:03 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.05.14 13:37:49 | 000,001,905 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013.05.13 20:41:55 | 009,741,664 | ---- | M] (SurfRight B.V.) -- C:\Users\Rohr\Desktop\HitmanPro_x64.exe
[2013.05.12 01:53:57 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.05.10 16:35:39 | 000,001,204 | ---- | M] () -- C:\Users\Public\Desktop\Wise Disk Cleaner.lnk
[2013.05.10 13:41:06 | 007,859,160 | ---- | M] (Auslogics Software Pty Ltd                                  ) -- C:\Users\Rohr\Desktop\disk3610-defrag-setup.exe
[2013.05.06 19:14:21 | 000,291,088 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.05.06 19:14:21 | 000,291,088 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.04.30 15:16:06 | 000,001,182 | ---- | M] () -- C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2013.04.30 15:16:06 | 000,001,170 | ---- | M] () -- C:\Users\Public\Desktop\Game Booster 3.lnk
[2013.04.24 16:36:03 | 001,776,473 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1403010.016\Cat.DB
[2013.04.24 14:05:09 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_NuidFltr_01011.Wdf
[2013.04.23 21:59:33 | 000,001,007 | ---- | M] () -- C:\Users\Rohr\Desktop\Audacity.lnk
[2013.04.23 21:55:47 | 021,281,052 | ---- | M] (Audacity Team                                              ) -- C:\Users\Rohr\Desktop\audacity-win-2.0.3.exe
[2013.04.21 18:00:18 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.04.21 18:00:10 | 000,282,296 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2013.04.20 15:47:22 | 000,001,182 | ---- | M] () -- C:\Users\Rohr\Desktop\Dxtory.lnk
[2013.04.19 21:59:46 | 000,002,501 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013.04.19 21:59:10 | 000,014,818 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1403010.016\VT20130115.021
[2013.04.19 19:36:52 | 000,177,312 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013.04.19 19:36:52 | 000,007,466 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013.04.19 19:36:52 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013.05.14 13:37:49 | 000,001,905 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2013.05.12 01:53:57 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013.05.10 16:35:39 | 000,001,204 | ---- | C] () -- C:\Users\Public\Desktop\Wise Disk Cleaner.lnk
[2013.04.30 15:16:06 | 000,001,182 | ---- | C] () -- C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2013.04.30 15:16:06 | 000,001,170 | ---- | C] () -- C:\Users\Public\Desktop\Game Booster 3.lnk
[2013.04.24 14:05:09 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_NuidFltr_01011.Wdf
[2013.04.23 21:59:33 | 000,001,007 | ---- | C] () -- C:\Users\Rohr\Desktop\Audacity.lnk
[2013.04.23 21:59:32 | 000,001,019 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013.04.20 15:47:22 | 000,001,182 | ---- | C] () -- C:\Users\Rohr\Desktop\Dxtory.lnk
[2013.04.19 21:59:46 | 000,002,501 | ---- | C] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013.04.05 17:24:54 | 000,001,410 | ---- | C] () -- C:\Users\Rohr\AppData\Roaming\.minecraft - Verknüpfung.lnk
[2013.03.17 01:03:50 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.03.17 01:03:50 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.03.17 01:03:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.03.17 01:03:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.03.17 01:03:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.12.09 18:38:48 | 000,000,025 | ---- | C] () -- C:\Windows\CDE DX3800EFGIPSD.ini
[2012.11.18 01:05:44 | 000,004,608 | ---- | C] () -- C:\Users\Rohr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.11.10 19:20:44 | 000,088,280 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012.08.14 20:08:07 | 001,589,442 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.08.14 20:05:10 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2012.08.08 22:44:15 | 000,291,088 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.08.08 22:44:13 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.08.06 14:27:10 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.08.06 14:25:41 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012.08.06 14:19:04 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2012.08.06 14:19:04 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2012.08.06 14:15:08 | 000,048,481 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2012.08.06 14:08:33 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012.08.06 14:08:30 | 000,037,967 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2012.07.28 03:39:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.07.28 03:39:50 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.05.02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.05.12 19:26:37 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\.minecraft
[2012.12.23 03:29:19 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\.Spoutcraft
[2013.04.23 22:08:37 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Audacity
[2013.05.10 16:33:03 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Auslogics
[2012.10.31 22:40:43 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Awesomium
[2013.01.04 17:36:14 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Carbon
[2012.09.06 21:44:10 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\DVDVideoSoft
[2012.11.09 18:54:25 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\GarenaPlus
[2012.08.08 01:11:17 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\LolClient
[2012.08.06 16:34:33 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\MAXON
[2012.11.03 21:23:36 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\MW2 FoV Changer
[2013.02.16 00:04:21 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\MW3 FoV Changer
[2013.05.01 01:25:12 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\NetSpeedMonitor
[2013.02.26 22:49:40 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Origin
[2013.01.27 15:03:44 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Play withSIX
[2013.04.10 16:50:37 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\puush
[2012.08.25 18:10:25 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\six-zsync
[2012.10.21 13:27:58 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Sony
[2012.11.18 00:59:24 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\TechSmith
[2012.09.22 23:43:51 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Teeworlds
[2013.05.12 17:54:05 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\TS3Client
[2013.03.10 13:11:23 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\TuneUp Software
[2013.05.10 16:41:43 | 000,000,000 | ---D | M] -- C:\Users\Rohr\AppData\Roaming\Wise Disk Cleaner
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:07BF512B

< End of report >

--- --- ---


OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 14.05.2013 14:41:11 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Rohr\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,98 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 57,34% Memory free
7,96 Gb Paging File | 5,88 Gb Available in Paging File | 73,80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,66 Gb Total Space | 255,56 Gb Free Space | 54,88% Space Free | Partition Type: NTFS
 
Computer Name: ROHR-PC | User Name: Rohr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-330010271-3606213368-2544051051-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027BADAE-E4B7-4D36-A0F9-32ED12A6107D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{02A3D18B-F865-495F-A4EC-1A0265CE9A60}" = rport=138 | protocol=17 | dir=out | app=system |
"{114D0E4E-5129-4C59-86AA-FA253DFBA9F0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1550A4B9-DDC5-4DEE-BFA2-1F7B67C98E56}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1DC2179B-3A44-4212-85F7-01853AF14466}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{63F0504C-5DAC-4BEB-84E8-59582F1117CB}" = lport=10243 | protocol=6 | dir=in | app=system |
"{6418169C-7CC8-4E02-8EF5-112422DECE53}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7470A873-F5BE-423F-B393-3263718F39B5}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{805E2186-4A5C-4CC7-9932-5227B6EF3452}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{827B7564-A060-4179-805E-C99B6547B7FD}" = rport=139 | protocol=6 | dir=out | app=system |
"{87AC528D-E384-479A-B428-EE8222B015AF}" = lport=138 | protocol=17 | dir=in | app=system |
"{914CDDD9-AC9E-412F-9E62-41C6BE600D58}" = rport=10243 | protocol=6 | dir=out | app=system |
"{97A6429D-0BD4-47CA-B6D8-81484854356C}" = lport=137 | protocol=17 | dir=in | app=system |
"{9D9E834A-9449-4454-931E-5C09D5E9FDA5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A39175D3-02B9-44E3-9CDC-4E21B1B96B55}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AF027CCC-4618-4AD9-8B46-CC9B44979CDF}" = rport=137 | protocol=17 | dir=out | app=system |
"{B29BD134-4040-45B7-8C35-0F0440452687}" = lport=445 | protocol=6 | dir=in | app=system |
"{BF72FD4B-401E-4E9E-98D7-ADDB9CD1239B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E90F2527-C2E3-4CC8-9984-B0A715DAA10B}" = rport=445 | protocol=6 | dir=out | app=system |
"{F12C4A9C-466A-47CE-B2B2-283991AF48BD}" = lport=139 | protocol=6 | dir=in | app=system |
"{F99BC8DB-D4CE-41AA-BD81-62CBA840849C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05C4883D-222A-4C26-89A4-6C8D622BC82F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pblauncher.exe |
"{065C3C86-6282-4A8C-A61D-A558B5E168F3}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{0981295E-42C6-4D63-9D19-6F362794DB47}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{0A81DB20-08AC-4F3E-8F33-8B7019CEAB4A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{0F4A3563-75A2-4EEA-9485-332453C320F9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pblauncher.exe |
"{0FC3CFBD-D5F4-480E-A091-6C64C9A33F1B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trialspc\datapack\trialsfmx.exe |
"{193A502A-1CC9-4CA2-B2B2-B83DBFD147D3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pbclient.exe |
"{1F4886C7-EA9A-487B-AD0D-A7E774961D8A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{1FE58BF3-2D63-4D63-9C36-15D38F3B1774}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\launchpad.exe |
"{20C2CF8D-82DD-42C3-BC2D-4DD58016DB4B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{2331868E-CF69-4775-B47B-41141FF8B81A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{27FBD392-0D2A-4078-99E7-0782C3FD1C90}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{2A84BF2B-22C4-4A93-8C2B-33A74F7C940A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{2A92393F-9D82-4CC6-9823-0CF5A6A69EAF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{2C46EECB-AD53-44B5-BB68-4DEAA44AF359}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors f2p\engine.exe |
"{33F80D9F-A71C-4B40-8735-299D9BA468CA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{34376670-0550-4663-ACC0-D0D67EB01DA9}" = protocol=6 | dir=in | app=c:\users\rohr\appdata\roaming\spotify\spotify.exe |
"{34A7A37A-2CD5-42E3-9E55-365FB3C1FFD4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3AB47FBC-D6B1-4F67-AE7A-9DB766D5806A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{40C6EBF0-9E71-4F34-B579-6B42D2DFC60B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{40FB7B60-2E50-443D-9D28-5352F3C10265}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{42DF4006-6341-47A8-8BC4-7B0DDC68BC7F}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{47FA7EBE-077C-4450-A353-3C3EE8376629}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{48F64B26-7227-4EC1-B295-03481604B99D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{49E3405F-A00E-47AA-ABEB-85D3A57FBFDA}" = protocol=17 | dir=in | app=c:\users\rohr\downloads\blackshot_garenaplus_installer.exe |
"{4BBE4024-4DE8-4085-B425-0B00F1A51BEA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{4BC1742A-084F-4A8B-9DCB-A4EAC375F5F7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4DA532E9-C51D-4E23-97E3-AD921C81D7FE}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4F6DCA1B-5947-4B2C-B99F-FE2DC8FA4587}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{4F98DE89-0A44-46FF-BC69-6401036F7322}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{5124E2FE-6B88-4582-9036-AD90FD9A99CF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{52505BC9-B127-4BDE-8E8D-EF1175567A60}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{60AD4E64-C67B-4F85-BB58-46AF6977E41E}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{60F9AE52-16BD-4FD0-8E87-730801A677DC}" = protocol=6 | dir=out | app=system |
"{61707B84-2752-479B-A3A7-0C0F817EE854}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{61B4DDAD-E548-4D0F-A7D3-1B64CB35CE0A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{6302364B-8781-4A8F-8213-ABFF82ECD079}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{6335E121-676D-418F-9A00-5954D4F7788F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6380400C-5288-46EC-89ED-EF8DDA869032}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{64A2E12A-DE42-4A3F-9367-E621F615F423}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{65862933-19EA-4B4D-8F67-2FF68D1DE048}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\besetup\setup_battleyearma2oa.exe |
"{699C32AA-4208-4D94-B1D4-0AC48C332435}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{69D9F237-0810-447A-84D5-D0A7AF7CFFE7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{6B16CA70-8B81-49F8-9EEC-19EECBED0F5C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6D4FD8F1-6EE9-4855-A13A-725F803D80DF}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{6E3294B0-2A3E-4560-A2B7-FBE801BB8F16}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{713294BA-CF54-4B1D-B62F-1A130C2AF4B3}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{74357F61-0F3C-414C-9B5F-9348DBD72828}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\apb.exe |
"{75510EE5-0EF0-464A-A888-C2E04FBBE239}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{75F10379-11C1-4AA0-B699-DF273A678299}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{77C97928-CE1B-433E-8A22-66041CA60C2D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{7A86C5C6-8FBC-4BCB-9E66-A3096B6CCEDB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{7E27934A-77FA-466E-B09C-647D9CD6D620}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\vivoxvoiceservice.exe |
"{7F18138B-F512-49EC-AAA6-67C1A8A343C2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{7F5A66C8-C42A-4311-A0E1-B803CD12804C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\_runa2co.cmd |
"{82213B9B-94F4-4904-B314-C48B64FD429F}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{8286DFD1-D39D-4B06-96B1-DBAEDD63D6E6}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{8AFACFD3-EF86-468E-A1B9-A13490FCD41A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\launchpad.exe |
"{95BCD7E2-EC2F-41BD-B005-2F1F028C029D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{95F876B6-B23B-45E0-B4B4-0F366C7AADAF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ragnarok online 2\wplauncher.exe |
"{962E84A4-DB0B-4C44-A01D-F9E179171486}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{9C6E88FE-FEBD-4085-9F1B-9A708CC576B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{A2F6F082-BB84-46AA-8FBB-1D531FC172E2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{A3BE29FF-28E7-4C85-88EC-5B629CE076CA}" = protocol=6 | dir=in | app=c:\program files (x86)\gameforge4d\elsword_de\data\x2.exe |
"{A585731D-F1E4-4130-8838-C39609DE32EC}" = protocol=6 | dir=in | app=c:\users\rohr\downloads\blackshot_garenaplus_installer.exe |
"{A5A13250-0ED2-4932-8A5A-5D1822720A15}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A6DB9646-2CEE-4D2C-A523-759D54097BAE}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A78D28E4-0385-4C97-B2A1-5483D81E3507}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A8A75986-21A1-4B01-8AB7-11EDD8D9DB48}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{AAC526F4-CF8D-4830-A7A9-C495538C2CB3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
"{ABDF932C-8B4C-405D-AFC8-1ED727F5B541}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AC3A52AF-1E3D-425C-BE6D-A7EBADDEFA93}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AD0D0D5A-23F0-4DB9-A929-79B9B4E0631B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brawl busters\bin\pbclient.exe |
"{AD939C13-028E-44E4-A5BC-B761130DFA17}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{AF06F65B-1024-4F0F-806B-567F93473F1D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{AFDBD153-3678-48DB-8F13-9940972EB133}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{B4A01520-E650-4305-A3F8-09EE50A94121}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B89778BE-BC83-42A8-BFB2-9D10266AAD06}" = protocol=6 | dir=in | app=c:\users\rohr\appdata\roaming\spotify\spotify.exe |
"{C06ABB01-51D2-4AE3-A7C7-F8A7E7A47828}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
"{C072B9F4-6D59-4995-914D-BE6A1FB18C5D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{C12E432E-D6E3-4CAB-9F55-BE6E7E0F31E5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arcticcombat\gamelauncher_gp\mappingaccount.exe |
"{C221F92F-F8B9-4E5E-93C6-F14D58A63D08}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arcticcombat\gamelauncher_gp\mappingaccount.exe |
"{C318003F-295B-4D42-8EC1-E557542843CC}" = protocol=17 | dir=in | app=c:\users\rohr\appdata\roaming\spotify\spotify.exe |
"{C453F2A5-5DF6-47A2-ACF6-CD239C77F9F9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{C5551AC8-1798-4F91-97FE-683AE9E0AF8B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C5926E96-EB9D-4BBD-8278-F6906679E9B7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{C6087E5F-A1F8-4488-BFF0-0C9ABF3FF673}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ragnarok online 2\wplauncher.exe |
"{C71E6D64-EEBE-47F6-8084-DE60713507D3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe |
"{C8559D38-268C-44D6-8B77-270E448789CE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{CDFF9F81-384C-46A9-8553-80E81942C11D}" = protocol=17 | dir=in | app=c:\program files (x86)\gameforge4d\elsword_de\data\x2.exe |
"{CFE499C8-8646-417D-B00F-C9A070FC6224}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CFED1CC1-FE06-4B72-9715-671664CF6402}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\apb reloaded\binaries\apb.exe |
"{D017525B-BF20-4C87-BA55-5C53769BC226}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
"{D2B5E112-2B83-44E6-982F-16C618446A0D}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{D4F334CA-3226-43D9-88C1-1CFC774B3C0A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
"{D6AE01C9-5A18-4A7C-B92B-4FD93DFBADD4}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{D702A72C-E897-4B52-A43A-8451E3656739}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\gotham city impostors f2p\engine.exe |
"{D7E9F8BC-E2FE-44C1-89DD-24D9521A598F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe |
"{D9550433-BF2B-4B95-9F69-566DA21E30AB}" = protocol=17 | dir=in | app=c:\users\rohr\appdata\roaming\spotify\spotify.exe |
"{DA647BC5-EFB4-4218-9470-AB2867F2F09E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win32\udk.exe |
"{DB946137-F2D7-4883-9AE6-41524EFB3B2C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{DC373E34-1D52-432C-9819-852B8868E13E}" = protocol=6 | dir=in | app=c:\program files (x86)\efusion\blackshot\system\blackshot.exe |
"{DC3F6C38-DD52-416A-93E9-1AD5A9189370}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{DD6BCFB5-B7A4-415F-B1F5-1BD386516152}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DD8BF246-3B27-4870-A7EF-D82E7E5A8D36}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe |
"{DDAD8EA4-042E-4492-919E-0E417DCCB6FD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{DFC0D45C-98E4-4463-A8AD-313C997168DD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E6789382-7C89-4CF0-B047-9F169F3B7ADF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{EAD47EF0-8045-4121-A43F-B10BACB6C8EB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EC034EF0-1305-4213-99AF-F611E0EAC902}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe |
"{EF375E4C-F4D0-414C-AF17-71F430D24B98}" = protocol=17 | dir=in | app=c:\program files (x86)\efusion\blackshot\system\blackshot.exe |
"{F08E7CB7-BB37-4D9E-9A21-B15141F78B96}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trialspc\datapack\trialsfmx.exe |
"{F817C2B7-2C4C-4D23-90BE-4897B2B34485}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F9067107-C66F-4BBC-8E06-8833B7EF0622}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe |
"{FB50481C-3694-4126-9369-36A43E129CEA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{068F0C39-9496-4068-8A5B-B489F2B6D8D5}C:\program files (x86)\lolreplay\lolreplay.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lolreplay\lolreplay.exe |
"TCP Query User{18EF24A2-3D30-40C5-B9D0-809076CECCB2}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe |
"TCP Query User{61B6D0F5-5FBF-43BA-B9A2-779EFCD530BB}C:\users\rohr\documents\arma 2\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=c:\users\rohr\documents\arma 2\expansion\beta\arma2oa.exe |
"TCP Query User{640ACBE2-378F-4382-A003-34D540E712FB}C:\windows\syswow64\rundll32.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\rundll32.exe |
"TCP Query User{A2361BC2-C675-43CD-A835-03F328A4D6C4}C:\program files (x86)\steam\steamapps\janniklr1\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\janniklr1\team fortress 2\hl2.exe |
"TCP Query User{A65906C5-9F65-4C7E-AF11-89AD34E2CA0C}C:\program files (x86)\steam\steamapps\common\bullet run\binaries\win32\bulletrun.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bullet run\binaries\win32\bulletrun.exe |
"TCP Query User{C5CC72F8-D784-4755-82C2-4A59124EA887}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"TCP Query User{DA5A837B-D96D-4A73-B7F1-A046F29E4B5A}C:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"TCP Query User{E9B8E509-3166-4379-B1C5-3AF1AE898462}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"TCP Query User{EBE49F57-D283-47EA-983A-FE97D1874F05}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe" = protocol=6 | dir=in | app=c:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"TCP Query User{F65BC433-D698-4782-A31D-2E84B1EF65F5}C:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"TCP Query User{F86D6790-7175-4046-9558-9711AEEE5F1F}C:\users\rohr\desktop\mw3_modernadmin_host_tool\mw3_modernadmin_host_tool\modernadmin.exe" = protocol=6 | dir=in | app=c:\users\rohr\desktop\mw3_modernadmin_host_tool\mw3_modernadmin_host_tool\modernadmin.exe |
"TCP Query User{FAB7E65D-C0BE-4E00-863B-375DAFD24527}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{121B2DFA-C435-45E2-8148-79354C2489C5}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{12836FE7-4E70-4637-A7D1-5DC15BE5FA1D}C:\users\rohr\desktop\mw3_modernadmin_host_tool\mw3_modernadmin_host_tool\modernadmin.exe" = protocol=17 | dir=in | app=c:\users\rohr\desktop\mw3_modernadmin_host_tool\mw3_modernadmin_host_tool\modernadmin.exe |
"UDP Query User{3765ACA0-F235-40D5-9A2C-370ADC8D0A60}C:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
"UDP Query User{522C368B-EBA9-4F82-8186-66108F922E8A}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{5544D4A3-C0B9-414D-963F-A6FD33A20553}C:\program files (x86)\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield play4free\bfp4f.exe |
"UDP Query User{72CDD3CC-3752-44E5-A177-4CDB4FCB831F}C:\program files (x86)\steam\steamapps\common\bullet run\binaries\win32\bulletrun.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bullet run\binaries\win32\bulletrun.exe |
"UDP Query User{7832494D-A796-4186-B4F7-469BD885F5C2}C:\program files (x86)\lolreplay\lolreplay.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lolreplay\lolreplay.exe |
"UDP Query User{803550D5-ADD9-45E2-9B33-7DF77691138D}C:\windows\syswow64\rundll32.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\rundll32.exe |
"UDP Query User{BB35024F-EF2A-46D4-B25F-2212FA613A7A}C:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\tribesascend.exe |
"UDP Query User{D142063F-86EF-45CB-8126-02D759C20D8D}C:\users\rohr\documents\arma 2\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=c:\users\rohr\documents\arma 2\expansion\beta\arma2oa.exe |
"UDP Query User{D966686E-2E72-4C70-9F99-848E89B2E790}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe" = protocol=17 | dir=in | app=c:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe |
"UDP Query User{DAAD5D53-B21D-4952-B697-19E10620B652}C:\program files (x86)\steam\steamapps\janniklr1\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\janniklr1\team fortress 2\hl2.exe |
"UDP Query User{FF9F0E0F-2525-48F1-8182-800BE3464A61}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{24F93B56-61F5-415F-85B9-AA444DA34AFC}" = Microsoft-Maus- und Tastatur-Center
"{26A24AE4-039D-4CA4-87B4-2F86417021FF}" = Java 7 Update 21 (64-bit)
"{3145731D-C578-70ED-899F-7A670D2A6662}" = AMD Fuel
"{4975DE61-6BF6-B9BC-1FDE-C04C5EC78E4C}" = AMD Media Foundation Decoders
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5E03A267-415E-5383-FA8F-3CE4145663B9}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{89EE4A30-080F-2C95-6F78-C98D18FBD74D}" = AMD Accelerated Video Transcoding
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{9CF11D16-ECEB-90A5-A028-CA9E068D848B}" = ccc-utility64
"{AB085680-FE98-11E1-A232-F04DA23A5C58}" = MSVCRT Redists
"{F1525BFE-6D58-4E7A-9B17-C563B7EAADC5}" = Smart Technology Programming Software 7.0.23.0
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F74FF821-AD39-B6B4-3738-C68B5E179C8E}" = AMD Drag and Drop Transcoding
"CCleaner" = CCleaner
"HitmanPro37" = HitmanPro 3.7
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Mouse and Keyboard Center" = Microsoft-Maus- und Tastatur-Center
"WinRAR archiver" = WinRAR 4.20 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{017F8447-2A1D-0DDB-B5D7-CA2BFACE2886}" = CCC Help French
"{03AC8F6C-B522-4DA3-9B50-9EBEF444A4E4}" = DayZ Commander
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{054E9A1C-3EA2-C657-E787-FD8DCF5C3D3B}" = CCC Help Czech
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}" = Cool & Quiet
"{1DE2BD51-0300-772D-5E18-F337D95D5687}" = CCC Help German
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{224E8FEB-5C1F-077F-6FC5-602AC1AE644D}" = CCC Help Danish
"{275E9C49-C72F-D754-DEB7-77F10A9C00D8}" = CCC Help Japanese
"{289AC7E0-0AEE-4a7b-913C-709D9803D23E}" = Nexon Game Manager
"{30049739-BE95-6591-B504-E6D7057D49CC}" = CCC Help Spanish
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3F1EB155-F96E-EB7B-2EF2-7375490E0FA9}" = CCC Help English
"{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX
"{4B023D7B-9E67-795D-FB31-B5E1F6DCA451}" = CCC Help Italian
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{55F6C486-8C75-2A72-DAFE-CE78A624C9F7}" = CCC Help Russian
"{5AF23993-7152-1620-E43F-1B4542FB4F84}" = CCC Help Thai
"{63326924-3CAF-C858-3A8F-8598C87019D7}" = AMD VISION Engine Control Center
"{63822E89-11AA-F8EC-D433-F72A85799EC0}" = CCC Help Greek
"{66361420-4905-AEB8-17AE-172FDD164A7E}" = CCC Help Polish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{769F2A4B-84A3-9486-ADD2-9E5AB4B4E1E3}" = Catalyst Control Center InstallProxy
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8773DD1C-5FB2-95B5-5A93-0EFEAC900A4D}" = CCC Help Norwegian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8CCBB0BF-9CC1-1A65-BB93-56012A460EE6}" = CCC Help Portuguese
"{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}" = EPU-4 Engine
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0A3CE05-96CB-52E9-434E-074F3BB7807E}" = CCC Help Turkish
"{A2S166A0-F031-4E27-A057-C69733219434}_is1" = TERA
"{A407FC22-36BF-4C82-A516-59D94BC505A9}" = System Requirements Lab Detection
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9C64319-932F-D02B-B14C-FFFC3EC49E77}" = CCC Help Chinese Standard
"{C09DB932-7619-7B56-30E3-C0454811D6D7}" = CCC Help Korean
"{C22A4697-BD77-ACB1-744F-1FD0A0BFF798}" = CCC Help Swedish
"{C3592426-531E-4110-911D-BFECE2CE284B}" = puush
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.11 Game
"{D4B457B2-260F-C561-CA87-703BD3B724CA}" = Catalyst Control Center Graphics Previews Common
"{D6CDB506-297D-AE70-0EF6-DE5185F961BE}" = CCC Help Chinese Traditional
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI
"{ECFD508E-68A2-91B2-46DD-1D03D783D94B}" = Catalyst Control Center Localization All
"{EDE361D5-35A5-DA7D-3462-C3DABD24029B}" = CCC Help Hungarian
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F1E7DD6A-AE2D-D706-BEB3-937F76CA6AE9}" = CCC Help Finnish
"{F56F54DD-BCB2-1221-2CB7-E983A5CF9D15}" = CCC Help Dutch
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Audacity_is1" = Audacity 2.0.3
"Battlelog Web Plugins" = Battlelog Web Plugins
"BattlEye for A2" = BattlEye Uninstall
"BattlEye for OA" = BattlEye for OA Uninstall
"Dxtory2.0_is1" = Dxtory 2.0.104
"Fraps" = Fraps (remove only)
"Game Booster_is1" = Game Booster 3
"Google Chrome" = Google Chrome
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Plattform-Geräte-Manager
"LOLReplay" = LOLReplay
"Mozilla Firefox 19.0.2 (x86 de)" = Mozilla Firefox 19.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NIS" = Norton Internet Security
"OpenAL" = OpenAL
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"Steam App 113200" = The Binding of Isaac
"Steam App 202970" = Call of Duty: Black Ops II
"Steam App 202990" = Call of Duty: Black Ops II - Multiplayer
"Steam App 212910" = Call of Duty: Black Ops II - Zombies
"Steam App 220160" = Trials Evolution Gold Edition
"Steam App 222880" = Insurgency
"Steam App 231060" = Ragnarok Online 2
"Steam App 33910" = ARMA 2
"Steam App 33930" = ARMA 2: Operation Arrowhead
"Steam App 42680" = Call of Duty: Modern Warfare 3
"Steam App 42690" = Call of Duty: Modern Warfare 3 - Multiplayer
"Steam App 440" = Team Fortress 2
"Steam App 730" = Counter-Strike: Global Offensive
"Steam App 8190" = Just Cause 2
"Uplay" = Uplay
"Winamp" = Winamp
"Wise Disk Cleaner_is1" = Wise Disk Cleaner 7.61
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-330010271-3606213368-2544051051-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes (Rohr)
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 10.05.2013 10:50:00 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 11.05.2013 06:43:44 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 11.05.2013 11:14:35 | Computer Name = Rohr-PC | Source = Application Hang | ID = 1002
Description = Programm chrome.exe, Version 26.0.1410.64 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 12d4    Startzeit:
 01ce4e4b837523b1    Endzeit: 121    Anwendungspfad: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Berichts-ID:
 78d16a22-ba4d-11e2-8e1d-10bf4876115f 
 
Error - 11.05.2013 20:01:03 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 11.05.2013 20:06:59 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 12.05.2013 07:19:10 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 13.05.2013 08:01:09 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 14.05.2013 07:04:54 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 14.05.2013 07:37:13 | Computer Name = Rohr-PC | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\Rohr\Downloads\SoftonicDownloader_fuer_diskmax.exe".
 Fehler in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
 
Error - 14.05.2013 08:06:41 | Computer Name = Rohr-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 08.02.2013 08:50:33 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 09.02.2013 08:38:26 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 09.02.2013 08:38:29 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 10.02.2013 07:04:28 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 10.02.2013 07:04:31 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 10.02.2013 17:02:12 | Computer Name = Rohr-PC | Source = EventLog | ID = 6008
Description = Das System wurde zuvor am ?10.?02.?2013 um 21:59:27 unerwartet heruntergefahren.
 
Error - 10.02.2013 17:02:13 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 10.02.2013 17:02:21 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 11.02.2013 07:47:33 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 11.02.2013 07:47:36 | Computer Name = Rohr-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
 
< End of report >

--- --- ---

markusg 14.05.2013 13:52

bHi,
du musst aufpassen, von wo du dein Zeug läds..

du hast dir am 10.05 noch holasearch instaliert.

otl fix

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.

Code:

:OTL
FF - prefs.js..browser.search.selectedEngine: "Hola Search"
[2013.05.10 16:43:07 | 000,001,304 | ---- | M] () -- C:\Users\Rohr\AppData\Roaming\mozilla\firefox\profiles\xtanz4ff.default\searchplugins\holasearch.xml
O3 - HKU\S-1-5-21-330010271-3606213368-2544051051-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
:files
:Commands
[emptytemp]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread

Suchmaschinen verwalten - Google Chrome-Hilfe
alle suchmaschinen außer google löschen
bitte teste, ob es im Firefox, internet explorer, und sonstigen
evtl. instalierte Browser, irgendwelche ungewollten toolbars, umleitungen oder sonstigen Probleme gibt.
Teste wie pc und programme allgemein laufen.

JannikLR 14.05.2013 14:10

All processes killed
========== OTL ==========
Prefs.js: "Hola Search" removed from browser.search.selectedEngine
C:\Users\Rohr\AppData\Roaming\mozilla\firefox\profiles\xtanz4ff.default\searchplugins\holasearch.xml moved successfully.
Registry value HKEY_USERS\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Rohr
->Temp folder emptied: 2855091 bytes
->Temporary Internet Files folder emptied: 9963741 bytes
->Java cache emptied: 725628 bytes
->FireFox cache emptied: 3317130 bytes
->Google Chrome cache emptied: 355304317 bytes
->Flash cache emptied: 840 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 200704 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3648 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36081758 bytes
RecycleBin emptied: 162652 bytes

Total Files Cleaned = 390,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 05142013_150051

Files\Folders moved on Reboot...
C:\Users\Rohr\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

markusg 14.05.2013 14:13

frage noch beantworten

JannikLR 14.05.2013 14:25

Suchmaschinen gelöscht.
PC läuft höchstens ein kleines bisschen schneller. Große Veränderungen bemerke ich nicht.

markusg 14.05.2013 14:31

wie die Browser laufen auch testen, Umleitungen etc.

JannikLR 14.05.2013 14:35

Fühlt sich leicht flüssiger an.

markusg 14.05.2013 14:36

Hi,
öffne OTL, berienigen, PC startet neu, Remover werden gelöscht.
Lösche übrig gebliebene Setups, Logs, und von uns verwendete Programme.
Dann mal den PC absichern:
als antimalware programm würde ich emsisoft empfehlen.
diese haben für mich den besten schutz kostet aber etwas.
Computeractive Software Store - Emsisoft Anti-Malware 7 [1-PC] - 63% off RRP
testversion:
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware
insbesondere wenn du onlinebanking, einkäufe, sonstige zahlungsabwicklungen oder ähnlich wichtiges, wie zb berufliches machst, also sensible daten zu schützen sind, solltest du in sicherheitssoftware investieren.
vor dem aktivieren der lizenz die 30 tage testzeitraum ausnutzen.

kostenlos, aber eben nicht ganz so gut währe avast zu empfehlen.
http://www.trojaner-board.de/110895-...antivirus.html

sag mir welches du nutzt, dann gebe ich konfigurationshinweise.
bitte dein bisheriges av deinstalieren
die folgende anleitung ist umfangreich, dass ist mir klar, sie sollte aber umgesetzt werden, da nur dann dein pc sicher ist. stelle so viele fragen wie nötig, ich arbeite gern alles mit dir durch!

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
als browser rate ich dir zu chrome:
Installation von Google Chrome für mehrere Nutzerkonten - Google Chrome-Hilfe
anleitung lesen bitte
falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung anpassen.


Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
Sandboxie - Download - Filepony

anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
Sandbox Einstellungen |

bitte folgende zusatz konfiguration machen:
sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen.
dort klicke auf sandbox einstellungen.
beschrenkungen, bei programm start und internet zugriff schreibe:
chrome.exe
dann gehe auf anwendungen, webbrowser, chrome.
dort aktiviere alles außer gesammten profil ordner freigeben.
Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
anmerkung zu file hippo.
in den settings zusätzlich auswählen:
hide beta updates.
Run updateChecker when Windows starts

Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
http://www.trojaner-board.de/82962-w...en-backup.html
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
bitte auch lesen, wie mache ich programme für alle sichtbar:
Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

passwort sicherheit:
jeder dienst benötigt ein eigenes, mindestens 12-stelliges passwort
bei der passwort verwaltung und erstellung hilft roboform
Passwort Manager, Formular Ausfueller, Passwort Management | RoboForm Passwort Manager
anleitung:
RoboForm-Bedienungsanleitung: Passwort-Manager, Verwalten von Passwörtern und persönlichen Daten


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:36 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131