Code:
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\\Update-Service-Installer-Service deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\\Update-Service deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"DisplayName"|"@%SystemRoot%\\System32\\dnsapi.dll,-101" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"Group"|"TDI" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"ImagePath"|hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"Description"|"@%SystemRoot%\\System32\\dnsapi.dll,-102" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"ObjectName"|"NT AUTHORITY\\NetworkService" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"ErrorControl"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"Start"|dword:00000002 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"Type"|dword:00000020 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"DependOnService"|hex(7):54,00,64,00,78,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"ServiceSidType"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"RequiredPrivileges"|hex(7):53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\\"FailureActions"|hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters\\"ServiceDll"|hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,6e,00,73,00,72,00,73,00,6c,00,76,00,72,00,2e,00,64,00,6c,00,6c,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Parameters\\"ServiceDllUnloadOnStop"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Dnscache\Security\\"Security"|hex:01,00,14,90,d0,00,00,00,dc,00,00,00,14,00,00,00,30,00,00,00,02,00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,00,00,02,00,a0,00,07,00,00,00,00,02,18,00,8d,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,21,02,00,00,00,02,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,02,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,12,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,02,14,00,8d,00,02,00,01,01,00,00,00,00,00,05,14,00,00,00,00,02,14,00,8d,00,02,00,01,01,00,00,00,00,00,05,13,00,00,00,00,02,18,00,cd,00,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2c,02,00,00,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"DisplayName"|"@%systemroot%\\system32\\wkssvc.dll,-100" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"Group"|"NetworkProvider" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"ImagePath"|hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"Description"|"@%systemroot%\\system32\\wkssvc.dll,-101" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"ObjectName"|"NT AUTHORITY\\LocalService" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"ErrorControl"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"Start"|dword:00000002 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"Type"|dword:00000020 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"DependOnService"|hex(7):42,00,6f,00,77,00,73,00,65,00,72,00,00,00,4d,00,52,00,78,00,53,00,6d,00,62,00,31,00,30,00,00,00,4d,00,52,00,78,00,53,00,6d,00,62,00,32,00,30,00,00,00,4e,00,53,00,49,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"ServiceSidType"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\\"FailureActions"|hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,00,01,00,00,00,60,ea,00,00,01,00,00,00,c0,d4,01,00,00,00,00,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage\\"Bind"|hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,36,00,42,00,35,00,46,00,37,00,36,00,36,00,39,00,2d,00,30,00,44,00,36,00,37,00,2d,00,34,00,34,00,45,00,41,00,2d,00,42,00,44,00,46,00,31,00,2d,00,45,00,45,00,44,00,38,00,32,00,46,00,33,00,31,00,32,00,35,00,43,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,46,00,42,00,32,00,34,00,36,00,44,00,44,00,34,00,2d,00,42,00,32,00,34,00,34,00,2d,00,34,00,44,00,37,00,30,00,2d,00,41,00,30,00,33,00,42,00,2d,00,45,00,31,00,30,00,34,00,31,00,41,00,30,00,34,00,44,00,31,00,30,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,36,00,42,00,35,00,46,00,37,00,36,00,36,00,39,00,2d,00,30,00,44,00,36,00,37,00,2d,00,34,00,34,00,45,00,41,00,2d,00,42,00,44,00,46,00,31,00,2d,00,45,00,45,00,44,00,38,00,32,00,46,00,33,00,31,00,32,00,35,00,43,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,46,00,42,00,32,00,34,00,36,00,44,00,44,00,34,00,2d,00,42,00,32,00,34,00,34,00,2d,00,34,00,44,00,37,00,30,00,2d,00,41,00,30,00,33,00,42,00,2d,00,45,00,31,00,30,00,34,00,31,00,41,00,30,00,34,00,44,00,31,00,30,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage\\"Route"|hex(7):22,00,53,00,6d,00,62,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,22,00,00,00,22,00,53,00,6d,00,62,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,36,00,22,00,20,00,22,00,7b,00,36,00,42,00,35,00,46,00,37,00,36,00,36,00,39,00,2d,00,30,00,44,00,36,00,37,00,2d,00,34,00,34,00,45,00,41,00,2d,00,42,00,44,00,46,00,31,00,2d,00,45,00,45,00,44,00,38,00,32,00,46,00,33,00,31,00,32,00,35,00,43,00,39,00,7d,00,22,00,00,00,22,00,53,00,6d,00,62,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,36,00,22,00,20,00,22,00,7b,00,46,00,42,00,32,00,34,00,36,00,44,00,44,00,34,00,2d,00,42,00,32,00,34,00,34,00,2d,00,34,00,44,00,37,00,30,00,2d,00,41,00,30,00,33,00,42,00,2d,00,45,00,31,00,30,00,34,00,31,00,41,00,30,00,34,00,44,00,31,00,30,00,39,00,7d,00,22,00,00,00,22,00,53,00,6d,00,62,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,36,00,22,00,20,00,22,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,22,00,20,00,22,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,36,00,22,00,20,00,22,00,7b,00,36,00,42,00,35,00,46,00,37,00,36,00,36,00,39,00,2d,00,30,00,44,00,36,00,37,00,2d,00,34,00,34,00,45,00,41,00,2d,00,42,00,44,00,46,00,31,00,2d,00,45,00,45,00,44,00,38,00,32,00,46,00,33,00,31,00,32,00,35,00,43,00,39,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,36,00,22,00,20,00,22,00,7b,00,46,00,42,00,32,00,34,00,36,00,44,00,44,00,34,00,2d,00,42,00,32,00,34,00,34,00,2d,00,34,00,44,00,37,00,30,00,2d,00,41,00,30,00,33,00,42,00,2d,00,45,00,31,00,30,00,34,00,31,00,41,00,30,00,34,00,44,00,31,00,30,00,39,00,7d,00,22,00,00,00,22,00,4e,00,65,00,74,00,42,00,54,00,22,00,20,00,22,00,54,00,63,00,70,00,69,00,70,00,36,00,22,00,20,00,22,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,22,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage\\"Export"|hex(7):5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,36,00,42,00,35,00,46,00,37,00,36,00,36,00,39,00,2d,00,30,00,44,00,36,00,37,00,2d,00,34,00,34,00,45,00,41,00,2d,00,42,00,44,00,46,00,31,00,2d,00,45,00,45,00,44,00,38,00,32,00,46,00,33,00,31,00,32,00,35,00,43,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,46,00,42,00,32,00,34,00,36,00,44,00,44,00,34,00,2d,00,42,00,32,00,34,00,34,00,2d,00,34,00,44,00,37,00,30,00,2d,00,41,00,30,00,33,00,42,00,2d,00,45,00,31,00,30,00,34,00,31,00,41,00,30,00,34,00,44,00,31,00,30,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,53,00,6d,00,62,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,62,00,69,00,6f,00,73,00,53,00,6d,00,62,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,36,00,42,00,35,00,46,00,37,00,36,00,36,00,39,00,2d,00,30,00,44,00,36,00,37,00,2d,00,34,00,34,00,45,00,41,00,2d,00,42,00,44,00,46,00,31,00,2d,00,45,00,45,00,44,00,38,00,32,00,46,00,33,00,31,00,32,00,35,00,43,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,46,00,42,00,32,00,34,00,36,00,44,00,44,00,34,00,2d,00,42,00,32,00,34,00,34,00,2d,00,34,00,44,00,37,00,30,00,2d,00,41,00,30,00,33,00,42,00,2d,00,45,00,31,00,30,00,34,00,31,00,41,00,30,00,34,00,44,00,31,00,30,00,39,00,7d,00,00,00,5c,00,44,00,65,00,76,00,69,00,63,00,65,00,5c,00,4c,00,61,00,6e,00,6d,00,61,00,6e,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,69,00,6f,00,6e,00,5f,00,4e,00,65,00,74,00,42,00,54,00,5f,00,54,00,63,00,70,00,69,00,70,00,36,00,5f,00,7b,00,34,00,39,00,33,00,37,00,44,00,38,00,35,00,34,00,2d,00,38,00,41,00,38,00,37,00,2d,00,34,00,46,00,32,00,36,00,2d,00,42,00,46,00,46,00,31,00,2d,00,37,00,37,00,34,00,30,00,41,00,37,00,31,00,35,00,39,00,39,00,31,00,42,00,7d,00,00,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\NetworkProvider\\"DeviceName"|"\\Device\\LanmanRedirector" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\NetworkProvider\\"Name"|"Microsoft Windows Network" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\NetworkProvider\\"DisplayName"|hex(2):40,00,25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,6b,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,31,00,30,00,32,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\NetworkProvider\\"ProviderPath"|hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,6c,00,61,00,6e,00,6d,00,61,00,6e,00,2e,00,64,00,6c,00,6c,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters\\"ServiceDll"|hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,6b,00,73,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters\\"ServiceDllUnloadOnStop"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters\\"EnablePlainTextPassword"|dword:00000000 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters\\"EnableSecuritySignature"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters\\"RequireSecuritySignature"|dword:00000000 /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Parameters\\"OtherDomains"|hex(7):00,00 /E : value set successfully!
========== COMMANDS ==========
OTL by OldTimer - Version 3.2.69.0 log created on 06022014_210932 Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-06-2014
Ran by egon at 2014-06-02 21:16:53
Running from C:\Users\egon\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
32 Bit HP CIO Components Installer (Version: 2.1.5 - Hewlett-Packard) Hidden
4660_4680_Help (Version: 1.00.0000 - Hewlett-Packard) Hidden
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.4.402.287 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version: - Agere Systems)
ASUS CopyProtect (HKLM\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0006 - ASUS)
ASUS Data Security Manager (HKLM\...\{1C8521E5-5A7B-4A4E-A9CD-AD53116EAEE0}) (Version: 1.00.0006 - ASUS)
ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.8 - ASUS)
ASUS Live Update (HKLM\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.6 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.01 - ASUS)
ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0005 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0021 - ASUS)
Asus_Camera_ScreenSaver (HKLM\...\Asus_Camera_ScreenSaver) (Version: 2.0.0008 - ASUS)
Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros)
ATI Catalyst Install Manager (HKLM\...\{03ECA42B-5AF3-AFE7-7AC2-DD8465A39FE5}) (Version: 3.0.664.0 - ATI Technologies, Inc.)
ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK)
ATK Hotkey (HKLM\...\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}) (Version: 1.00.0034 - ATK)
ATKOSD2 (HKLM\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0001 - ASUS)
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira)
BPD_HPSU (Version: 1.00.0000 - Hewlett-Packard) Hidden
bpd_scan (Version: 3.00.0000 - Hewlett-Packard) Hidden
BPDSoftware (Version: 50.0.165.000 - Hewlett-Packard) Hidden
BPDSoftware_Ini (Version: 1.00.0000 - Hewlett-Packard) Hidden
BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Catalyst Control Center Core Implementation (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Graphics Full New (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Graphics Light (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Chinese Standard (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Chinese Traditional (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Czech (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Danish (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Dutch (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Finnish (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization French (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization German (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Greek (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Hungarian (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Italian (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Japanese (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Korean (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Norwegian (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Polish (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Portuguese (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Russian (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Spanish (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Swedish (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Thai (Version: 2008.0429.2146.37034 - ATI) Hidden
Catalyst Control Center Localization Turkish (Version: 2008.0429.2146.37034 - ATI) Hidden
CCC Help Chinese Standard (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Chinese Traditional (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Czech (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Danish (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Dutch (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help English (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Finnish (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help French (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help German (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Greek (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Hungarian (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Italian (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Japanese (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Korean (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Norwegian (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Polish (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Portuguese (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Russian (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Spanish (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Swedish (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Thai (Version: 2008.0429.2145.37034 - ATI) Hidden
CCC Help Turkish (Version: 2008.0429.2145.37034 - ATI) Hidden
ccc-core-static (Version: 2008.0429.2146.37034 - ATI) Hidden
ccc-utility (Version: 2008.0429.2146.37034 - ATI) Hidden
Cisco EAP-FAST Module (HKLM\...\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Destination Component (Version: 100.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 110.0.180.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DHTML Editing Component (HKLM\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
DocMgr (Version: 100.0.201.000 - Hewlett-Packard) Hidden
DocProc (Version: 11.0.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Dolby Control Center (HKLM\...\{DE66EFAD-B9CC-4FD4-9157-6C18E5100161}) (Version: 1.1.0503 - Dolby)
easyFly 4 (HKCU\...\{09696666-CB70-4056-A504-D916D92933E2}) (Version: 4.0.1.3 - IPACS)
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Express Gate (HKLM\...\{27D51A76-371D-48B6-B06E-4137A15B7583}) (Version: 0.8.0.3 - devicevm)
Fax (Version: 120.0.194.000 - Hewlett-Packard) Hidden
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
Google Updater (HKLM\...\Google Updater) (Version: 2.4.2432.1652 - Google Inc.)
GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden
HP Document Manager 1.0 (HKLM\...\HP Document Manager) (Version: 1.0 - HP)
HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP)
HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 10.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 10.0 - HP)
HP Update (HKLM\...\{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}) (Version: 5.002.007.004 - Hewlett-Packard)
HP_Network_UserGuide (Version: 1.00.0000 - Hewlett-Packard) Hidden
HPDiagnosticAlert (Version: 1.00.0000 - Microsoft) Hidden
HPProductAssistant (Version: 100.0.170.000 - Hewlett-Packard) Hidden
J4680 (Version: 50.0.165.000 - Ihr Firmenname) Hidden
Lager (Version: 1.0.0.0 - Hewlett-Packard) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 1.1 German Language Pack (HKLM\...\{E78BFA60-5393-4C38-82AB-E8019E464EB4}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - )
Microsoft .NET Framework 3.5 Language Pack - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack - deu) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack - deu (Version: 3.5.21022 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Basic 2007 (HKLM\...\BASICR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Basic 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual J# .NET Redistributable Package 1.1 (HKLM\...\{1A655D51-1423-48A3-B748-8F5A0BE294C8}) (Version: 1.1.4322 - Microsoft)
MSVCSetup (Version: 1.00.0000 - HP) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NB Probe (HKLM\...\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}) (Version: - )
Network (Version: 110.0.180.000 - Hewlett-Packard) Hidden
OCR Software by I.R.I.S. 10.0 (HKLM\...\HPOCR) (Version: 10.0 - HP)
ProductContext (Version: 50.0.165.000 - Hewlett-Packard) Hidden
Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5645 - Realtek Semiconductor Corp.)
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.01 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.55.01 - )
Safely Remove Disk Drive (HKLM\...\InstallShield_{0F97342A-56FA-4E9B-9F58-87DBD9DE9D9A}) (Version: 1.0.1540.3 - AMD)
Safely Remove Disk Drive (Version: 1.0.1540.3 - AMD) Hidden
Scan (Version: 10.1.0.0 - Hewlett-Packard) Hidden
Skins (Version: 2008.0429.2146.37034 - ATI) Hidden
SmartWebPrinting (Version: 140.0.186.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 100.0.175.000 - Hewlett-Packard) Hidden
Status (Version: 110.0.180.000 - Hewlett-Packard) Hidden
Suite (Version: 1.00.0000 - CyberLink Corp.) Hidden
Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden
TrayApp (Version: 110.0.180.000 - Hewlett-Packard) Hidden
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (HKLM\...\{3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2836939v3) (Version: 3 - Microsoft Corporation)
USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version: - )
WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden
WinFlash (HKLM\...\{DE10AB76-4756-4913-BE25-55D1C1051F9A}) (Version: - )
Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.10 - ATK)
==================== Restore Points =========================
17-05-2014 19:22:27 Geplanter Prüfpunkt
18-05-2014 20:38:31 Geplanter Prüfpunkt
21-05-2014 18:04:38 Windows Update
26-05-2014 16:24:46 Geplanter Prüfpunkt
27-05-2014 16:16:23 Geplanter Prüfpunkt
30-05-2014 16:12:03 Windows Update
31-05-2014 12:09:15 Removed Avira SearchFree Toolbar plus Web Protection.
31-05-2014 12:16:51 Removed Avira SearchFree Toolbar plus Web Protection.
31-05-2014 17:27:52 Wiederherstellungsvorgang
31-05-2014 18:40:18 Wiederherstellungsvorgang
31-05-2014 18:49:55 Wiederherstellungsvorgang
01-06-2014 10:55:56 Windows Update
02-06-2014 16:41:11 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {12B58683-C5B9-4A41-A27D-DD99299668ED} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - egon => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {350B4B60-6E3D-4DE1-8E63-3B0157FF3E0A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-19] (Google Inc.)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3EB8A74D-6CD6-467B-B244-6A647B72A47E} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {54A8E72B-9795-4A47-9265-9797A4027845} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-19] (Google Inc.)
Task: {65410507-DAB8-48F8-8ECA-575CF3EA65D2} - System32\Tasks\ASUS Live Update => C:\Program Files\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()
Task: {774D5AD6-AB4B-45C6-B4BC-BB282EE77AA1} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2008-06-18] (ASUS)
Task: {9296E7A1-9B23-4FA1-A78B-75FD0FFC79BF} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06] (Adobe Systems Incorporated)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {FF8F6342-6737-4B66-9ACF-9C44CE227793} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{B5651F0E-2EE9-4B34-8DEB-ED7D2B7F25BD}.job => C:\Windows\system32\msfeedssync.exe
==================== Loaded Modules (whitelisted) =============
2008-10-15 22:41 - 2007-05-18 11:31 - 00073728 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
2008-10-15 22:19 - 2007-10-03 06:53 - 00094208 _____ () C:\Program Files\ATK Hotkey\ASLDRSrv.exe
2008-10-15 22:42 - 2007-08-08 09:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe
2008-10-15 22:46 - 2007-08-03 21:24 - 00125496 _____ () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
2008-10-15 22:46 - 2007-09-14 19:00 - 00147456 _____ () C:\Program Files\ASUS\NB Probe\SPM\spdiskex.dll
2008-10-15 22:46 - 2003-11-28 11:11 - 00135168 _____ () C:\Program Files\ASUS\NB Probe\SPM\spos.dll
2008-10-15 22:46 - 2005-08-30 00:24 - 00081920 _____ () C:\Program Files\ASUS\NB Probe\SPM\spnbacpi.dll
2008-10-15 22:46 - 2003-09-10 01:08 - 00049152 _____ () C:\Program Files\ASUS\NB Probe\SPM\spdmi.dll
2008-10-15 22:46 - 2006-04-04 19:24 - 00036864 _____ () C:\Program Files\ASUS\NB Probe\SPM\ghadmi.dll
2008-10-15 22:46 - 2005-04-08 04:25 - 00077824 _____ () C:\Program Files\ASUS\NB Probe\SPM\spmemory.dll
2008-04-30 00:00 - 2008-04-30 00:00 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2008-10-15 22:41 - 2007-06-15 19:28 - 00147456 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
2008-10-15 22:41 - 2007-06-02 02:08 - 00143360 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
2008-02-04 22:29 - 2008-02-04 22:29 - 00688128 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
2008-10-15 22:41 - 2007-08-08 11:52 - 00331776 _____ () C:\Program Files\ASUS\ASUS Data Security Manager\AdsmendecExt.dll
2008-10-15 22:43 - 2007-11-30 20:20 - 00051768 _____ () C:\Program Files\ASUS\ASUS Live Update\ALU.exe
2008-10-15 22:19 - 2008-01-12 07:40 - 00098304 _____ () C:\Program Files\ATK Hotkey\HControlUser.exe
2008-10-15 22:19 - 2007-11-13 00:41 - 00106496 _____ () C:\Program Files\ATK Hotkey\MsgTran.dll
2008-10-15 22:49 - 2008-10-15 22:49 - 00033136 _____ () C:\Windows\ASScrPro.exe
2008-10-15 22:19 - 2004-05-28 03:13 - 00057344 _____ () C:\Program Files\ATK Hotkey\CMSSC.dll
2008-10-15 22:19 - 2007-11-05 04:48 - 00106496 _____ () C:\Program Files\ATK Hotkey\MsgTranAgt.exe
2008-10-15 22:27 - 2007-07-06 01:53 - 01040384 _____ () C:\Program Files\Wireless Console 2\wcourier.exe
2008-07-12 01:34 - 2008-07-12 01:34 - 00010240 _____ () C:\Program Files\P4G\DevMng.dll
2008-07-18 05:56 - 2008-07-18 05:56 - 00015360 _____ () C:\Program Files\P4G\OvrClk.dll
2008-10-15 22:42 - 2007-03-10 01:16 - 00106496 _____ () C:\Program Files\ATKGFNEX\AGFNEX.dll
2007-07-10 07:48 - 2007-07-10 07:48 - 00009216 _____ () C:\Program Files\ASUS\Splendid\GLCDdll.dll
2008-10-15 22:19 - 2007-12-04 19:57 - 02486272 _____ () C:\Program Files\ATK Hotkey\ATKOSD.exe
2008-10-15 22:19 - 2007-08-15 20:20 - 00106496 _____ () C:\Program Files\ATK Hotkey\KBFiltr.exe
2008-10-15 22:19 - 2008-01-23 19:51 - 00151552 _____ () C:\Program Files\ATK Hotkey\WDC.exe
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name: HP Officejet J4680
Description: HP Officejet J4680
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Hewlett-Packard
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Officejet J4680 series
Description: Officejet J4680 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Officejet J4680 series
Description: Officejet J4680 series
Class Guid: {4d36e979-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/02/2014 09:12:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/02/2014 09:05:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/02/2014 06:12:04 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/02/2014 05:26:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/01/2014 02:27:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (06/02/2014 09:15:52 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (06/02/2014 09:14:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service
Error: (06/02/2014 09:13:15 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (06/02/2014 09:11:04 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 412) (User: NT-AUTORITÄT)
Description: 2147942402
Error: (06/02/2014 09:08:14 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (06/02/2014 09:06:09 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: ComputerbrowserLanmanWorkstation
Error: (06/02/2014 09:06:02 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service
Error: (06/02/2014 09:06:01 PM) (Source: DCOM) (EventID: 10000) (User: )
Description: C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe -Embedding2{73C9DFA0-750D-11E1-B0C4-0800200C9A66}
Error: (06/02/2014 09:05:28 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: ComputerbrowserLanmanWorkstation
Error: (06/02/2014 09:05:28 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: DNS-Client%%2
Microsoft Office Sessions:
=========================
Error: (03/10/2014 08:27:12 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1439 seconds with 660 seconds of active time. This session ended with a crash.
Error: (11/18/2013 09:31:48 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 25 seconds with 0 seconds of active time. This session ended with a crash.
Error: (04/19/2012 07:59:18 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 34 seconds with 0 seconds of active time. This session ended with a crash.
Error: (03/17/2012 06:46:28 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 50 seconds with 0 seconds of active time. This session ended with a crash.
CodeIntegrity Errors:
===================================
Date: 2014-06-02 21:16:46.847
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:46.239
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:45.646
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:45.069
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:44.507
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:43.868
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:43.290
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:42.713
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:41.964
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-06-02 21:16:41.403
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\mbamchameleon.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 32%
Total physical RAM: 3326.2 MB
Available physical RAM: 2253.55 MB
Total Pagefile: 6848.9 MB
Available Pagefile: 5850.09 MB
Total Virtual: 2047.88 MB
Available Virtual: 1919.91 MB
==================== Drives ================================
Drive c: (VistaOS) (Fixed) (Total:116.44 GB) (Free:65.27 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:106.68 GB) (Free:94.75 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 233 GB) (Disk ID: 97646C29)
Partition 1: (Not Active) - (Size=10 GB) - (Type=1C)
Partition 2: (Active) - (Size=116 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=107 GB) - (Type=OF Extended)
==================== End Of Log ============================ [/CODE]
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-06-2014
Ran by egon (administrator) on EGON-PC on 02-06-2014 21:16:04
Running from C:\Users\egon\Desktop
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
() C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
() C:\Program Files\ATK Hotkey\AsLdrSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(AMD) C:\Program Files\AMD\Safely Remove Disk\SafeRemoveService.exe
() C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
(AMD) C:\Windows\System32\SafeRemoveDialog.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
() C:\Program Files\ASUS\ASUS Live Update\ALU.exe
(ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
() C:\Program Files\ATK Hotkey\HControlUser.exe
() C:\Windows\ASScrPro.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(ATK0100) C:\Program Files\ATK Hotkey\HControl.exe
() C:\Program Files\ATK Hotkey\MsgTranAgt.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ASUS) C:\Program Files\ASUS\ASUS CopyProtect\ASPG.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ATK) C:\Program Files\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\System32\ACEngSvr.exe
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files\ATK Hotkey\KBFiltr.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
() C:\Program Files\ATK Hotkey\WDC.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [ATKOSD2] => C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [7651328 2008-07-15] (ASUS)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-27] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6183456 2008-06-13] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [HControlUser] => C:\Program Files\ATK Hotkey\HcontrolUser.exe [98304 2008-01-12] ()
HKLM\...\Run: [ASUS Screen Saver Protector] => C:\Windows\ASScrPro.exe [33136 2008-10-15] ()
HKLM\...\Run: [ASUS Camera ScreenSaver] => C:\Windows\AsScrProlog.exe [47672 2008-10-15] ()
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKU\S-1-5-21-99956060-2673457517-1827905997-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-99956060-2673457517-1827905997-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-99956060-2673457517-1827905997-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2008-11-28] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
SearchScopes: HKLM - DefaultScope value is missing.
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-03-09]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-03-09]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchURL: {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR Extension: (YouTube) - C:\Users\egon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-25]
CHR Extension: (Google-Suche) - C:\Users\egon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-25]
CHR Extension: (Google Mail) - C:\Users\egon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-25]
========================== Services (Whitelisted) =================
R2 ADSMService; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [73728 2007-05-18] ()
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-05-27] (Avira Operations GmbH & Co. KG)
R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-03] ()
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] ()
R2 SafeRemove; C:\Program Files\AMD\Safely Remove Disk\SafeRemoveService.exe [147456 2008-07-07] (AMD)
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] ()
==================== Drivers (Whitelisted) ====================
R0 ahcix86s; C:\Windows\System32\DRIVERS\ahcix86s.sys [173576 2008-05-27] (AMD Technologies Inc.)
R0 AsDsm; C:\Windows\system32\Drivers\AsDsm.sys [29752 2007-08-11] (Windows (R) Codename Longhorn DDK provider)
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-05] (Avira Operations GmbH & Co. KG)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15416 2008-05-29] (Windows (R) Codename Longhorn DDK provider)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-15] (ATK0100)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-02] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-23] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-02 21:15 - 2014-06-02 21:09 - 00036398 _____ () C:\Users\egon\Desktop\06022014_210932.log
2014-06-02 21:09 - 2014-06-02 21:09 - 00000000 ____D () C:\_OTL
2014-06-02 17:46 - 2014-06-02 17:46 - 00125566 _____ () C:\Users\egon\Desktop\OTL.Txt
2014-06-02 17:46 - 2014-06-02 17:46 - 00053174 _____ () C:\Users\egon\Desktop\Extras.Txt
2014-06-02 17:31 - 2014-06-02 17:31 - 00602112 _____ (OldTimer Tools) C:\Users\egon\Desktop\OTL.exe
2014-06-01 14:32 - 2014-06-01 14:32 - 00001468 _____ () C:\Users\egon\Desktop\mbam.txt
2014-06-01 14:04 - 2014-06-01 14:30 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-01 14:04 - 2014-06-01 14:04 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-01 14:04 - 2014-06-01 14:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-01 14:04 - 2014-06-01 14:04 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-01 14:04 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-01 14:04 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-01 14:04 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-01 14:03 - 2014-06-01 14:03 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\egon\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-01 13:58 - 2014-06-01 13:58 - 00000977 _____ () C:\Users\egon\Desktop\JRT.txt
2014-06-01 13:53 - 2014-06-01 14:25 - 00000000 ____D () C:\Windows\ERUNT
2014-06-01 13:52 - 2014-06-01 13:52 - 01016261 _____ (Thisisu) C:\Users\egon\Desktop\JRT.exe
2014-06-01 13:46 - 2014-06-01 13:46 - 00008660 _____ () C:\Users\egon\Desktop\AdwCleaner[S0].txt
2014-06-01 13:42 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-06-01 13:41 - 2014-06-01 13:42 - 00000000 ____D () C:\AdwCleaner
2014-06-01 13:39 - 2014-06-01 13:39 - 01327971 _____ () C:\Users\egon\Desktop\adwcleaner_3.211.exe
2014-06-01 12:58 - 2014-06-02 21:15 - 00000000 ____D () C:\Users\egon\Desktop\FRST-OlderVersion
2014-05-31 21:31 - 2014-05-31 21:31 - 00000000 ___SD () C:\ComboFix
2014-05-31 19:24 - 2014-05-31 19:24 - 00000000 ____D () C:\Qoobox
2014-05-31 19:24 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-31 19:24 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-31 19:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-31 19:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-31 19:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-31 19:24 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-31 19:24 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-31 19:24 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-31 19:22 - 2014-05-31 21:31 - 00000000 ___SD () C:\32788R22FWJFW
2014-05-31 19:22 - 2014-05-31 19:22 - 05203398 ____R (Swearware) C:\Users\egon\Desktop\ComboFix.exe
2014-05-31 19:22 - 2014-05-31 19:22 - 00000000 ____D () C:\Windows\erdnt
2014-05-31 19:01 - 2014-05-31 19:01 - 00000554 _____ () C:\Users\egon\Desktop\Problemsignatur.txt
2014-05-31 18:35 - 2014-05-31 18:35 - 291155312 _____ () C:\Windows\MEMORY.DMP
2014-05-31 18:35 - 2014-05-31 18:35 - 00143544 _____ () C:\Windows\Minidump\Mini053114-01.dmp
2014-05-31 18:35 - 2014-05-31 18:35 - 00000000 ____D () C:\Windows\Minidump
2014-05-31 15:50 - 2014-05-31 15:50 - 00380416 _____ () C:\Users\egon\Desktop\fz6jr33b.exe
2014-05-31 14:36 - 2014-06-01 14:36 - 00029919 _____ () C:\Users\egon\Desktop\Addition.txt
2014-05-31 14:34 - 2014-06-02 21:16 - 00012046 _____ () C:\Users\egon\Desktop\FRST.txt
2014-05-31 14:34 - 2014-06-02 21:16 - 00000000 ____D () C:\FRST
2014-05-31 14:33 - 2014-06-02 21:15 - 01059840 _____ (Farbar) C:\Users\egon\Desktop\FRST.exe
2014-05-31 14:31 - 2014-05-31 14:32 - 00000470 _____ () C:\Users\egon\Desktop\defogger_disable.log
2014-05-31 14:31 - 2014-05-31 14:31 - 00000000 _____ () C:\Users\egon\defogger_reenable
2014-05-31 14:29 - 2014-05-31 14:29 - 00050477 _____ () C:\Users\egon\Desktop\Defogger.exe
2014-05-15 20:21 - 2014-03-25 15:26 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 20:17 - 2014-05-05 21:31 - 06021120 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 20:17 - 2014-05-05 21:31 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 20:17 - 2014-05-05 20:47 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
==================== One Month Modified Files and Folders =======
2014-06-02 21:16 - 2014-05-31 14:34 - 00012046 _____ () C:\Users\egon\Desktop\FRST.txt
2014-06-02 21:16 - 2014-05-31 14:34 - 00000000 ____D () C:\FRST
2014-06-02 21:16 - 2008-11-14 16:59 - 00000000 ____D () C:\Users\egon\AppData\Local\Temp
2014-06-02 21:15 - 2014-06-01 12:58 - 00000000 ____D () C:\Users\egon\Desktop\FRST-OlderVersion
2014-06-02 21:15 - 2014-05-31 14:33 - 01059840 _____ (Farbar) C:\Users\egon\Desktop\FRST.exe
2014-06-02 21:15 - 2009-12-19 14:18 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-02 21:15 - 2009-12-19 14:18 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-02 21:11 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-02 21:11 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-02 21:11 - 2006-11-02 14:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-02 21:09 - 2014-06-02 21:15 - 00036398 _____ () C:\Users\egon\Desktop\06022014_210932.log
2014-06-02 21:09 - 2014-06-02 21:09 - 00000000 ____D () C:\_OTL
2014-06-02 21:09 - 2008-10-15 20:38 - 01608634 _____ () C:\Windows\WindowsUpdate.log
2014-06-02 21:09 - 2006-11-02 15:01 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-02 21:04 - 2008-10-15 22:53 - 00045056 _____ () C:\Windows\system32\acovcnt.exe
2014-06-02 17:46 - 2014-06-02 17:46 - 00125566 _____ () C:\Users\egon\Desktop\OTL.Txt
2014-06-02 17:46 - 2014-06-02 17:46 - 00053174 _____ () C:\Users\egon\Desktop\Extras.Txt
2014-06-02 17:31 - 2014-06-02 17:31 - 00602112 _____ (OldTimer Tools) C:\Users\egon\Desktop\OTL.exe
2014-06-02 17:27 - 2008-11-14 17:21 - 00000416 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{B5651F0E-2EE9-4B34-8DEB-ED7D2B7F25BD}.job
2014-06-02 17:25 - 2008-01-21 04:47 - 00303168 _____ () C:\Windows\PFRO.log
2014-06-01 14:36 - 2014-05-31 14:36 - 00029919 _____ () C:\Users\egon\Desktop\Addition.txt
2014-06-01 14:32 - 2014-06-01 14:32 - 00001468 _____ () C:\Users\egon\Desktop\mbam.txt
2014-06-01 14:30 - 2014-06-01 14:04 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-01 14:25 - 2014-06-01 13:53 - 00000000 ____D () C:\Windows\ERUNT
2014-06-01 14:17 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-06-01 14:04 - 2014-06-01 14:04 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-01 14:04 - 2014-06-01 14:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-01 14:04 - 2014-06-01 14:04 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-01 14:03 - 2014-06-01 14:03 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\egon\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-01 13:58 - 2014-06-01 13:58 - 00000977 _____ () C:\Users\egon\Desktop\JRT.txt
2014-06-01 13:52 - 2014-06-01 13:52 - 01016261 _____ (Thisisu) C:\Users\egon\Desktop\JRT.exe
2014-06-01 13:50 - 2006-11-02 12:33 - 01568228 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-01 13:46 - 2014-06-01 13:46 - 00008660 _____ () C:\Users\egon\Desktop\AdwCleaner[S0].txt
2014-06-01 13:42 - 2014-06-01 13:41 - 00000000 ____D () C:\AdwCleaner
2014-06-01 13:39 - 2014-06-01 13:39 - 01327971 _____ () C:\Users\egon\Desktop\adwcleaner_3.211.exe
2014-05-31 21:31 - 2014-05-31 21:31 - 00000000 ___SD () C:\ComboFix
2014-05-31 21:31 - 2014-05-31 19:22 - 00000000 ___SD () C:\32788R22FWJFW
2014-05-31 19:24 - 2014-05-31 19:24 - 00000000 ____D () C:\Qoobox
2014-05-31 19:22 - 2014-05-31 19:22 - 05203398 ____R (Swearware) C:\Users\egon\Desktop\ComboFix.exe
2014-05-31 19:22 - 2014-05-31 19:22 - 00000000 ____D () C:\Windows\erdnt
2014-05-31 19:01 - 2014-05-31 19:01 - 00000554 _____ () C:\Users\egon\Desktop\Problemsignatur.txt
2014-05-31 19:01 - 2008-12-25 16:08 - 00002631 _____ () C:\Users\egon\Desktop\Microsoft Office Word 2007.lnk
2014-05-31 18:35 - 2014-05-31 18:35 - 291155312 _____ () C:\Windows\MEMORY.DMP
2014-05-31 18:35 - 2014-05-31 18:35 - 00143544 _____ () C:\Windows\Minidump\Mini053114-01.dmp
2014-05-31 18:35 - 2014-05-31 18:35 - 00000000 ____D () C:\Windows\Minidump
2014-05-31 18:22 - 2008-11-14 16:59 - 00000000 ____D () C:\Users\egon
2014-05-31 16:34 - 2008-11-15 15:24 - 00000000 ____D () C:\ProgramData\HP
2014-05-31 15:50 - 2014-05-31 15:50 - 00380416 _____ () C:\Users\egon\Desktop\fz6jr33b.exe
2014-05-31 14:32 - 2014-05-31 14:31 - 00000470 _____ () C:\Users\egon\Desktop\defogger_disable.log
2014-05-31 14:31 - 2014-05-31 14:31 - 00000000 _____ () C:\Users\egon\defogger_reenable
2014-05-31 14:29 - 2014-05-31 14:29 - 00050477 _____ () C:\Users\egon\Desktop\Defogger.exe
2014-05-31 14:26 - 2008-12-25 16:07 - 00002735 _____ () C:\Users\egon\Desktop\Microsoft Office Outlook 2007.lnk
2014-05-30 19:29 - 2012-10-20 14:17 - 00000000 ____D () C:\Windows\pss
2014-05-30 19:23 - 2013-02-23 21:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-30 19:23 - 2013-02-23 21:22 - 00000000 ____D () C:\Program Files\Avira
2014-05-30 19:20 - 2013-02-23 21:22 - 00000000 ____D () C:\ProgramData\Avira
2014-05-30 19:19 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE
2014-05-30 19:14 - 2008-12-25 16:02 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-05-30 18:56 - 2013-05-12 16:21 - 00000000 ____D () C:\Users\egon\AppData\Roaming\IrfanView
2014-05-27 15:38 - 2013-02-23 21:22 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-27 15:38 - 2013-02-23 21:22 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-26 10:44 - 2009-03-24 18:29 - 00001052 _____ () C:\Windows\Tasks\Google Software Updater.job
2014-05-22 17:04 - 2010-07-10 17:26 - 00000000 ____D () C:\Users\egon\Documents\freewayprogramm
2014-05-20 20:03 - 2009-01-08 20:22 - 00012350 _____ () C:\Users\egon\Desktop\Volksmusik Musik Radio Webradio Internetradio Netradio.url
2014-05-15 20:32 - 2013-08-14 21:18 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 20:28 - 2006-11-02 12:24 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-05-12 07:26 - 2014-06-01 14:04 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-01 14:04 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:25 - 2014-06-01 14:04 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-08 20:17 - 2009-05-07 18:15 - 00000162 _____ () C:\Users\egon\Desktop\eBay Neue und gebrauchte Elektronikartikel, Autos, Kleidung, Sammlerstücke, Sportartikel und mehr – alles zu günstigen Preisen.url
2014-05-05 21:31 - 2014-05-15 20:17 - 06021120 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-05 21:31 - 2014-05-15 20:17 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-05 20:47 - 2014-05-15 20:17 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
Some content of TEMP:
====================
C:\Users\egon\AppData\Local\Temp\avgnt.exe
C:\Users\egon\AppData\Local\Temp\iv_uninstall.exe
C:\Users\egon\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-06-02 18:18
==================== End Of Log ============================ --- --- --- |