startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

Servus zusammen,

bin einer der vielen, die sich dummerweise das startfenster.com Problem zugezogen haben.

Hab mich durch 2 threads hier gelesen und schon mal die Anweisungen aus nem ähnlichen thread befolgt und würd mich sehr freuen, wenn mir jemand helfen könnte/ die Ergebnisse für mich analysieren könnte....

logfile von ADWcleaner
# AdwCleaner v2.113 - Datei am 04/03/2013 um 19:05:21 erstellt
# Aktualisiert am 23/02/2013 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzer : juerg_000 - ***
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\juerg_000\Downloads\adwcleaner.exe
# Option [Löschen]

**** [Dienste] ****

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16384

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v19.0.1 (en-US)

Datei : C:\Users\juerg_000\AppData\Roaming\Mozilla\Firefox\Profiles\rnxhzc2u.default\prefs.js

[OK] Die Datei ist sauber.


AdwCleaner[S1].txt - [903 octets] - [04/03/2013 19:05:21]

########## EOF - C:\AdwCleaner[S1].txt - [962 octets] ##########
Ergebnis von SecurityCheck:
Results of screen317's Security Check version 0.99.59
x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
McAfee Anti-Virus und Anti-Spyware
Windows Defender
Avira Desktop
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version
Adobe Flash Player 11.6.602.171
Adobe Reader XI
Mozilla Firefox (19.0.1)
````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
mcafee VIRUSS~1 mcvsshld.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````

/// Winkelfunktion
/// TB-Süch-Tiger™
startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

Hallo und

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen, die ich im Laufe dieses Strangs hier posten werde, aufmerksam durch. Frag umgehend nach, wenn dir irgendetwas unklar sein sollte, bevor du anfängst meine Anleitungen umzusetzen.

  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.

  • Bitte nur Scans durchführen zu denen du von einem Helfer aufgefordert wurdest! Installiere / Deinstalliere keine Software ohne Aufforderung!

  • Poste die Logfiles direkt in deinen Thread (bitte in CODE-Tags) und nicht als Anhang, ausser du wurdest dazu aufgefordert. Logs in Anhängen erschweren mir das Auswerten!

  • Beachte bitte auch => Löschen von Logfiles und andere Anfragen

Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread.
Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards.

JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

Danach eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles in CODE-Tags hier in den Thread.


startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

Hey cosinus,

vielen Dank dir schonmal!

JRT scan:
Junkware Removal Tool (JRT) by Thisisu
Version: 4.6.7 (03.03.2013:1)
OS: Windows 8 x64
Ran by juerg_000 on 04/03/2013 at 19:53:26.99

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ FireFox

Emptied folder: C:\Users\juerg_000\AppData\Roaming\mozilla\firefox\profiles\rnxhzc2u.default\minidumps [1 files]

~~~ Event Viewer Logs were cleared

Scan was completed on 04/03/2013 at 20:00:37.60
End of JRT log
OTL log:
OTL logfile created on: 04/03/2013 20:05:08 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\juerg_000\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16420)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.89 Gb Total Physical Memory | 2.57 Gb Available Physical Memory | 66.00% Memory free
7.39 Gb Paging File | 5.64 Gb Available in Paging File | 76.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186.30 Gb Total Space | 133.56 Gb Free Space | 71.69% Space Free | Partition Type: NTFS
Drive D: | 258.15 Gb Total Space | 258.03 Gb Free Space | 99.95% Space Free | Partition Type: NTFS
Drive F: | 275.41 Gb Total Space | 53.54 Gb Free Space | 19.44% Space Free | Partition Type: NTFS
Drive G: | 22.66 Gb Total Space | 13.73 Gb Free Space | 60.57% Space Free | Partition Type: FAT32
Computer Name: *** | User Name: juerg_000 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\juerg_000\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
PRC - C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTeK)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (ASUS)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (mfevtp) -- C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (VIAKaraokeService) -- C:\Windows\SysNative\ViakaraokeSrv.exe (VIA Technologies, Inc.)
SRV:64bit: - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (MSK80Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McOobeSv) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (AllUserInstallAgent) -- C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (McODS) -- C:\Program Files\mcafee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (0123871362419113mcinstcleanup) -- C:\Windows\Temp\0123871362419113mcinst.exe (McAfee, Inc.)
SRV - (PrintNotify) -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUSTek Computer Inc.)
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (ASUS InstantOn) -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (ASUS)
SRV - (McAWFwk) -- c:\PROGRA~1\mcafee\msc\mcawfwk.exe (McAfee, Inc.)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
========== Driver Services (SafeList) ==========
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\Drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\Drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\Drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (cfwids) -- C:\Windows\SysNative\Drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) -- C:\Windows\SysNative\Drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) -- C:\Windows\SysNative\Drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\Drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfeelamk) -- C:\Windows\SysNative\Drivers\mfeelamk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) -- C:\Windows\SysNative\Drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) -- C:\Windows\SysNative\Drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) -- C:\Windows\SysNative\Drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (ATP) -- C:\Windows\SysNative\Drivers\AsusTP.sys (ASUS Corporation)
DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\Drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (pdc) -- C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) -- C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (USBXHCI) -- C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (UCX01000) -- C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) -- C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) -- C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (msgpiowin32) -- C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (dam) -- C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) -- C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (AiCharger) -- C:\Windows\SysNative\Drivers\AiCharger.sys (ASUSTek Computer Inc.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\Drivers\athw8x.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\Drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\Drivers\kbfiltr.sys ( )
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (condrv) -- C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (VSTXRAID) -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (VerifierExt) -- C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (UASPStor) -- C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) -- C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (spaceport) -- C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (storahci) -- C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) -- C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) -- C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (EhStorTcgDrv) -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) -- C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) -- C:\Windows\SysNative\Drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CLFS) -- C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) -- C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (vpci) -- C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) -- C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) -- C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) -- C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) -- C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) -- C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) -- C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) -- C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) -- C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) -- C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) -- C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) -- C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) -- C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) -- C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) -- C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) -- C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) -- C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) -- C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) -- C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) -- C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) -- C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\Drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (L1C) -- C:\Windows\SysNative\Drivers\L1C63x64.sys (Qualcomm Atheros Co., Ltd.)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\Drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\Drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\Drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (RTL8168) -- C:\Windows\SysNative\Drivers\Rt630x64.sys (Realtek                                            )
DRV:64bit: - (NETwNs64) -- C:\Windows\SysNative\Drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (e1iexpress) -- C:\Windows\SysNative\Drivers\e1i63x64.sys (Intel Corporation)
DRV:64bit: - (HIDSwitch) -- C:\Windows\SysNative\Drivers\AsHIDSwitch64.sys (ASUS)
DRV:64bit: - (HipShieldK) -- C:\Windows\SysNative\Drivers\HipShieldK.sys (McAfee, Inc.)
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = 
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-3435455976-2761992232-2573730619-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-3435455976-2761992232-2573730619-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-3435455976-2761992232-2573730619-1001\..\SearchScopes,DefaultScope = 
IE - HKU\S-1-5-21-3435455976-2761992232-2573730619-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://de-de.facebook.com/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.1
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/04 11:46:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/03/04 18:50:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013/03/04 11:04:36 | 000,000,000 | ---D | M]
[2013/03/04 11:47:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\juerg_000\AppData\Roaming\mozilla\Extensions
[2013/03/04 13:02:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\juerg_000\AppData\Roaming\mozilla\Firefox\Profiles\rnxhzc2u.default\extensions
[2013/03/04 13:02:30 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\juerg_000\AppData\Roaming\mozilla\firefox\profiles\rnxhzc2u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/03/04 11:46:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013/02/27 06:10:14 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/20 17:14:20 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2013/02/27 06:09:34 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/02/27 06:09:34 | 000,002,086 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/07/26 06:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\\AsusWSPanel.exe (ASUS Cloud Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DF84F21-D7C0-4CAD-B46D-D41FFD5FDD3E}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8E7A823-7114-4CD8-B198-C7D8D85E3B2B}: DhcpNameServer =
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - F:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/03/04 19:53:25 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/03/04 19:52:39 | 000,000,000 | ---D | C] -- C:\JRT
[2013/03/04 19:36:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013/03/04 19:13:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/03/04 18:50:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2013/03/04 18:50:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2013/03/04 18:21:40 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Malwarebytes
[2013/03/04 18:21:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/03/04 18:21:22 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/03/04 18:21:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/03/04 18:20:55 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\Programs
[2013/03/04 18:02:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2013/03/04 17:01:45 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll
[2013/03/04 17:01:45 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_42.dll
[2013/03/04 17:01:38 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
[2013/03/04 17:01:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp Detect
[2013/03/04 17:01:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2013/03/04 17:01:29 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Winamp
[2013/03/04 17:01:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp
[2013/03/04 16:53:34 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\Desktop\pixx
[2013/03/04 16:44:27 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\Desktop\SILVER LININGS DVDRIP EDAW2013
[2013/03/04 16:43:44 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\Desktop\momentane fav`s
[2013/03/04 16:42:44 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\Desktop\Word
[2013/03/04 14:19:20 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\Macromedia
[2013/03/04 13:38:52 | 000,000,000 | ---D | C] -- C:\Program Files\Paint.NET
[2013/03/04 13:38:18 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\Paint.NET
[2013/03/04 12:41:25 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\uTorrent
[2013/03/04 12:40:14 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\BitTorrent
[2013/03/04 12:19:49 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Avira
[2013/03/04 12:11:05 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Macromedia
[2013/03/04 12:01:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013/03/04 12:01:25 | 000,129,216 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013/03/04 12:01:25 | 000,099,912 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013/03/04 12:01:25 | 000,027,800 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013/03/04 12:01:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013/03/04 12:01:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2013/03/04 11:57:55 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\Desktop\fav programme
[2013/03/04 11:46:48 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Mozilla
[2013/03/04 11:46:48 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\Mozilla
[2013/03/04 11:46:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2013/03/04 11:46:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2013/03/04 11:46:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/03/04 11:29:33 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\Documents\ASUS
[2013/03/04 11:29:27 | 000,000,000 | ---D | C] -- C:\ProgramData\ASUS
[2013/03/04 11:08:08 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\ASUS WebStorage
[2013/03/04 11:07:24 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/03/04 11:07:24 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Searches
[2013/03/04 11:07:24 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Contacts
[2013/03/04 11:07:24 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/03/04 11:06:38 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Adobe
[2013/03/04 11:06:26 | 000,000,000 | ---D | C] -- C:\ProgramData\FolderView
[2013/03/04 11:04:29 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\VirtualStore
[2013/03/04 11:04:18 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\Packages
[2013/03/04 11:04:15 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\ASUS
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Vorlagen
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\AppData\Local\Verlauf
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\AppData\Local\Temporary Internet Files
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Startmenü
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\SendTo
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Recent
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Netzwerkumgebung
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Lokale Einstellungen
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Documents\Eigene Videos
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Documents\Eigene Musik
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Eigene Dateien
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Documents\Eigene Bilder
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Druckumgebung
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Cookies
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\AppData\Local\Anwendungsdaten
[2013/03/04 11:03:59 | 000,000,000 | -HSD | C] -- C:\Users\juerg_000\Anwendungsdaten
[2013/03/04 11:03:58 | 000,000,000 | --SD | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Videos
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Saved Games
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Pictures
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Music
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Links
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Favorites
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Downloads
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Documents
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\Desktop
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/03/04 11:03:58 | 000,000,000 | R--D | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2013/03/04 11:03:58 | 000,000,000 | -H-D | C] -- C:\Users\juerg_000\AppData
[2013/03/04 11:03:58 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\Temp
[2013/03/04 11:03:58 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Local\Microsoft
[2013/03/04 11:03:58 | 000,000,000 | ---D | C] -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
========== Files - Modified Within 30 Days ==========
[2013/03/04 19:39:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/04 19:13:41 | 000,881,935 | ---- | M] () -- C:\Users\juerg_000\Desktop\SecurityCheck(1).exe
[2013/03/04 19:09:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/03/04 19:08:55 | 000,000,401 | ---- | M] () -- C:\Users\juerg_000\AppData\Roaming\sp_data.sys
[2013/03/04 19:07:35 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013/03/04 19:07:32 | 3338,391,552 | -HS- | M] () -- C:\hiberfil.sys
[2013/03/04 18:21:29 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013/03/04 17:53:56 | 000,281,088 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/03/04 16:43:21 | 004,568,320 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/04 16:43:21 | 000,790,022 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2013/03/04 16:43:21 | 000,785,550 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
[2013/03/04 16:43:21 | 000,780,976 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat
[2013/03/04 16:43:21 | 000,753,134 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013/03/04 16:43:21 | 000,710,244 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/03/04 16:43:21 | 000,158,586 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
[2013/03/04 16:43:21 | 000,155,826 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013/03/04 16:43:21 | 000,155,084 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2013/03/04 16:43:21 | 000,152,608 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat
[2013/03/04 16:43:21 | 000,132,614 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/03/04 16:41:22 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2013/03/04 12:00:21 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013/03/04 12:00:21 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013/03/04 12:00:21 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013/02/15 18:51:48 | 009,808,492 | ---- | M] () -- C:\Users\juerg_000\Desktop\Anlagen Jürgen Haberzett.pdf
[2013/02/03 15:09:00 | 000,009,075 | ---- | M] () -- C:\Users\juerg_000\Desktop\to do or think of (or not anymore;).odt
========== Files Created - No Company Name ==========
[2013/03/04 19:13:40 | 000,881,935 | ---- | C] () -- C:\Users\juerg_000\Desktop\SecurityCheck(1).exe
[2013/03/04 18:50:53 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/03/04 18:21:29 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013/03/04 17:53:46 | 000,281,088 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/03/04 16:57:49 | 000,009,075 | ---- | C] () -- C:\Users\juerg_000\Desktop\to do or think of (or not anymore;).odt
[2013/03/04 16:45:18 | 009,808,492 | ---- | C] () -- C:\Users\juerg_000\Desktop\Anlagen Jürgen Haberzett.pdf
[2013/03/04 16:41:22 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2013/03/04 14:18:57 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/04 13:39:42 | 000,001,302 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2013/03/04 11:46:41 | 000,001,165 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/03/04 11:08:00 | 000,000,401 | ---- | C] () -- C:\Users\juerg_000\AppData\Roaming\sp_data.sys
[2013/03/04 11:06:38 | 000,001,444 | ---- | C] () -- C:\Users\juerg_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/01/08 02:22:28 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2012/11/20 11:01:21 | 000,272,928 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng600.bin
[2012/11/20 11:00:59 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/11/20 11:00:54 | 000,963,388 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng600.bin
[2012/08/17 01:52:29 | 000,024,576 | ---- | C] () -- C:\ProgramData\SetStretch.exe
[2012/08/17 01:52:28 | 000,000,217 | ---- | C] () -- C:\ProgramData\SetStretch.cmd
[2012/07/26 09:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2012/07/26 09:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 08:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2012/07/26 02:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 21:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012/07/25 21:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2012/06/02 15:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2012/04/20 14:59:44 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/09/20 07:32:51 | 019,775,488 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %SystemRoot%\system32\shell32.dll -- [2012/09/20 06:54:47 | 017,559,552 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/26 04:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/26 04:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/26 04:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
extras log:
OTL Extras logfile created on: 04/03/2013 20:05:08 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\juerg_000\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16420)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.89 Gb Total Physical Memory | 2.57 Gb Available Physical Memory | 66.00% Memory free
7.39 Gb Paging File | 5.64 Gb Available in Paging File | 76.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186.30 Gb Total Space | 133.56 Gb Free Space | 71.69% Space Free | Partition Type: NTFS
Drive D: | 258.15 Gb Total Space | 258.03 Gb Free Space | 99.95% Space Free | Partition Type: NTFS
Drive F: | 275.41 Gb Total Space | 53.54 Gb Free Space | 19.44% Space Free | Partition Type: NTFS
Drive G: | 22.66 Gb Total Space | 13.73 Gb Free Space | 60.57% Space Free | Partition Type: FAT32
Computer Name: *** | User Name: juerg_000 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
"{05B3CACB-AE81-4952-88AD-2F9A6AAF1C2C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{171A8D83-DE4E-467A-858B-CF9262C2033F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{1DD7A109-AA81-4605-81F5-757B10A4A942}" = rport=137 | protocol=17 | dir=out | app=system | 
"{2A9F92BC-BC08-47AB-A0BA-D1B7D607E11B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{32AD0ED7-6020-4B5B-94E2-DF23637048B6}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{365E73B6-EAF5-40CD-B80B-94736574301A}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{380AE527-6E53-4141-A57E-D7B6D66B47E6}" = rport=139 | protocol=6 | dir=out | app=system | 
"{4ADEBB8E-4DAB-4D33-9299-DA2609F8EE1B}" = rport=445 | protocol=6 | dir=out | app=system | 
"{593C6697-A1E5-4459-BC31-AA072A5B80D9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{6AE593F5-D13B-4371-A496-8EA0E2CA964C}" = lport=137 | protocol=17 | dir=in | app=system | 
"{7E4C71B7-50B0-49FB-A9EB-F47F1955B785}" = rport=138 | protocol=17 | dir=out | app=system | 
"{8746CAB6-9CFC-44A6-9847-48761CFA3318}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{8E6A0F74-98CE-43F8-9D09-D4573CB9AB6C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{991A54D4-39C6-46BC-B84A-8A3FD27F2E94}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{9BC61B2C-868E-4BD4-9339-7C7527E7C567}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{A8BDD9E4-36C9-428A-A7EC-28BECDFD6F5A}" = lport=138 | protocol=17 | dir=in | app=system | 
"{AA7900C5-27B6-4F11-A532-0D0A90E49159}" = lport=445 | protocol=6 | dir=in | app=system | 
"{B42565A7-D24A-4A2C-A0E0-BFE2E24890E3}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{D4BD7778-E439-4A3C-A875-056035527348}" = lport=139 | protocol=6 | dir=in | app=system | 
"{EA296D4F-F717-4AD7-9D7A-4E1AD319132A}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{ECAB1CF0-995C-4810-8AB4-8AEA7817A8B0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
========== Vista Active Application Exception List ==========
"{0101C7F2-27FF-44BD-9C20-F3661EC351B2}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | 
"{0316779F-9120-436F-9697-C8CAE00ABB4F}" = dir=out | name=fresh paint | 
"{07D088F5-0DE1-4936-9C51-E18FEC45D90A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{0FA1BEBF-1D69-4431-9597-2C77A39B631B}" = protocol=6 | dir=out | app=system | 
"{17F605DA-83DD-4418-912A-666D62F36140}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} | 
"{18A23013-6DE7-4529-9E49-4B69B9B3A3C7}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | 
"{1BB53BB9-9C39-4D0C-B092-3BD764320193}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{1D7876A6-B641-4B7C-9751-16B651392115}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} | 
"{2385AB9F-471A-4F81-8A03-72C9FDD292B4}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | 
"{28B55B69-8861-4957-B834-D78D96440926}" = dir=in | name=skype | 
"{2DF4F3C0-F263-475D-BEE0-FAB18BCBC44E}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{311AAF25-6FA9-49D3-A26A-FDABAA901DE6}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | 
"{3D32ACCB-9242-49EF-B10F-7EDC84A1CE1A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{426C781B-8732-4CF9-BEF0-6C49C59987F4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{49ECF422-BBDD-4135-BF16-35E1C3F5CDCC}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} | 
"{5243CE6A-49C0-45A8-A96A-1D60A95A6F9E}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{59D1251B-F7B0-4002-9533-67D4E3F32DA4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{5D2DA09A-38C7-43FB-B3B4-84C7E7B235AF}" = protocol=6 | dir=in | app=c:\users\juerg_000\appdata\roaming\utorrent\utorrent.exe | 
"{5DEEDAB3-D39D-4494-BFE3-ACDAFC614631}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{64C35042-3087-4371-A832-F80C2568091F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{65D8CB08-9F33-4C96-81F1-A484912979CE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{66F92256-6BCE-442A-A599-976AA735F60A}" = dir=out | name=taptiles | 
"{77F63092-00A9-432C-A949-4D28CE3CCF1E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{7C836E75-49A0-42FD-BBBF-0EFB2E20121A}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{7E968864-3F53-4805-B18F-BA4D6CE3F226}" = protocol=17 | dir=in | app=c:\users\juerg_000\appdata\roaming\utorrent\utorrent.exe | 
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{8094E3E9-6767-453A-B33E-448BDB8CAC4B}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{81AF5E57-FB24-4213-81A4-73D3F42929BC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{89477E4A-807C-4213-9B20-1A2093F417C5}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{8FB06FA1-66B6-4A2B-9900-A9C7EC4ED927}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | 
"{8FEEE7F3-3E43-42B1-AFC5-8C37B0C77520}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{99E19A73-8E57-4B15-84D8-91182892DF90}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{9C64FBDE-E582-4A0D-8A7A-786073DB463A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{9DE533CB-D42F-4891-BE96-6956D4B97C35}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{A0BEB4B6-6138-4E07-BE57-BFE0E95B8169}" = dir=out | name=windows_ie_ac_001 | 
"{A60C517B-B392-4EBC-ABF4-3BCFAB10AACD}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{AD97A3AC-A81F-4BF9-8463-3C83949A79B5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{AF244168-5CAD-4AE8-AA0F-CF7078A00C3F}" = dir=out | name=wordament | 
"{B6BAA601-0FEE-4859-8113-E1CCCA171C5E}" = dir=out | name=skype | 
"{C36D5AF6-C0BF-46EE-99C4-B51388B91752}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe | 
"{C9BB49B8-95C5-4055-B4B9-69A3FBCA4E8A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{CFBDE754-F8E2-41AE-9831-85456D7B1270}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{D7E89D3A-4AAD-4931-B64D-66A149FE6386}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{D7FA004F-15EA-40B9-BF88-1C5E17B93623}" = dir=out | name=adera | 
"{DFF40C64-5898-4605-82C6-023481B9B0AD}" = dir=out | name=microsoft solitaire collection | 
"{E2F9527E-5BC6-4A14-B824-59E5FC46BC68}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{EB6DEE6B-E0A2-4AF6-85D8-97706E4296B0}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | 
"{F0C8D715-119A-4B96-863D-99518AF92B1F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe | 
"{F22BD3BC-15A5-4871-AB6A-D39888B39859}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | 
"{F3A05029-E637-4FF3-A5E0-127163E18237}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{FAFA0F3D-BD79-4EAF-8A45-DCE966E22D14}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{FB27EE7C-6A8C-43A1-A31A-F9D870CE64A8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{FCF3071B-D02B-486D-B30E-1F1A7B0EEB91}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client
"C01F56FBD9B141017E63E2A1A141E59934D4DC67" = Windows Driver Package - ASUS (ATP) Mouse  (10/29/2012
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{4D3286A6-F6AB-498A-82A4-E4F040529F3D}" = ASUS Smart Gesture
"{58172D66-2F69-4215-9AEC-ED8196023736}" = ASUS Tutor
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{69CC4B1E-0ADB-48E7-83D5-B45DA8CD1320}" = Alcor Micro USB Card Reader
"{749F674B-2674-47E8-879C-5626A06B2A91}" = ASUS InstantOn
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}" = ASUS Instant Connect
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office
"{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}" = ASUS USB Charger Plus
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.02)
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = ASUSDVD
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AmUStor" = Alcor Micro USB Card Reader
"ASUS WebStorage" = ASUS WebStorage Sync Agent
"Avira AntiVir Desktop" = Avira Free Antivirus
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = ASUSDVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version
"Mozilla Firefox 19.0.1 (x86 en-US)" = Mozilla Firefox 19.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSC" = McAfee Internet Security
"uTorrent" = µTorrent
"Winamp" = Winamp
========== HKEY_USERS Uninstall List ==========
"Winamp Detect" = Winamp Erkennungs-Plug-in
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 04/03/2013 15:04:21 | Computer Name = raxfei | Source = SideBySide | ID = 16842830
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\juerg_000\Downloads\esetsmartinstaller_enu.exe".
 Fehler in Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f.manifest.
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985.manifest.
< End of report >

/// Winkelfunktion
/// TB-Süch-Tiger™
startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

Bitte nun Logs mit GMER (<<< klick für Anleitung) und MBAR (Anleitung etwas weiter unten) erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim zweiten Mal nicht will, lass es einfach weg und führ nur MBAR aus.

Anleitung MBAR:

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
Logfiles bitte immer in CODE-Tags posten

startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

GMER wollte wirklich nich so recht ohne zu haken.
Bei MBAR stand nach dem Scan: No malware found, no clean Up necessary=)

Malwarebytes Anti-Rootkit BETA

Database version: v2013.03.04.09

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16384
juerg_000 :: *** [administrator]

04/03/2013 20:57:14
mbar-log-2013-03-04 (20-57-14).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled: 
Objects scanned: 6900
Time elapsed: 15 minute(s), 48 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)


Alt 04.03.2013, 21:13   #6
/// Winkelfunktion
/// TB-Süch-Tiger™
startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download


Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
--> startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

startfenster.com Windows 8 vcl player download

awsMBR txt:

aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2013-03-04 21:17:59
21:17:59.293    OS Version: Windows x64 6.2.9200 
21:17:59.293    Number of processors: 4 586 0x2A07
21:17:59.308    ComputerName: ***  UserName: 
21:17:59.371    Initialze error 1 
21:22:08.856    AVAST engine defs: 13030400
21:24:16.753    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000038
21:24:16.753    Disk 0 Vendor: TOSHIBA_MQ01ABD050 AX002J Size: 476940MB BusType: 11
21:24:16.784    Disk 0 MBR read successfully
21:24:16.784    Disk 0 MBR scan
21:24:16.784    Disk 0 unknown MBR code
21:24:16.784    Disk 0 Partition 1 00     EE          GPT            476940 MB offset 1
21:24:16.800    Disk 0 scanning C:\Windows\system32\drivers
21:24:16.800    Service scanning
21:24:17.409    Modules scanning
21:24:17.409    Disk 0 trace - called modules:
21:24:17.409    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys 
21:24:17.409    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005cba060]
21:24:17.425    3 CLASSPNP.SYS[fffff88001a578aa] -> nt!IofCallDriver -> [0xfffffa8004405320]
21:24:17.425    5 ACPI.sys[fffff88001159a91] -> nt!IofCallDriver -> \Device\00000038[0xfffffa80044057f0]
21:24:17.425    AVAST engine scan C:\Windows
21:24:17.425    AVAST engine scan C:\Windows\system32
21:24:17.441    AVAST engine scan C:\Windows\system32\drivers
21:24:17.441    AVAST engine scan C:\Users\juerg_000
21:24:17.441    AVAST engine scan C:\ProgramData
21:24:17.441    Scan finished successfully
21:24:38.395    Disk 0 MBR has been saved successfully to "C:\Users\juerg_000\Desktop\MBR.dat"
21:24:38.411    The log file has been saved successfully to "C:\Users\juerg_000\Desktop\aswMBR.txt"
TDSS Killer (hat soweit nichts gefunden laut Endtext) :

21:27:10.0736 3332  TDSS rootkit removing tool Feb 11 2013 18:50:42
21:27:10.0736 3332  UEFI system
21:27:10.0939 3332  ============================================================
21:27:10.0939 3332  Current date / time: 2013/03/04 21:27:10.0939
21:27:10.0939 3332  SystemInfo:
21:27:10.0939 3332  
21:27:10.0939 3332  OS Version: 6.2.9200 ServicePack: 0.0
21:27:10.0939 3332  Product type: Workstation
21:27:10.0939 3332  ComputerName: ***
21:27:10.0939 3332  UserName: juerg_000
21:27:10.0939 3332  Windows directory: C:\Windows
21:27:10.0939 3332  System windows directory: C:\Windows
21:27:10.0939 3332  Running under WOW64
21:27:10.0939 3332  Processor architecture: Intel x64
21:27:10.0939 3332  Number of processors: 4
21:27:10.0939 3332  Page size: 0x1000
21:27:10.0939 3332  Boot type: Normal boot
21:27:10.0939 3332  ============================================================
21:27:11.0596 3332  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:27:11.0596 3332  ============================================================
21:27:11.0596 3332  \Device\Harddisk0\DR0:
21:27:11.0596 3332  GPT partitions:
21:27:11.0596 3332  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {2825BE3C-A830-413A-B913-334F17389C83}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x96000
21:27:11.0596 3332  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {5975917D-3891-4E85-83F2-FC6400BC7ED7}, Name: Basic data partition, StartLBA 0x96800, BlocksNum 0x1C2000
21:27:11.0596 3332  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {AA7229B7-5630-4FE3-8774-19B93251FF33}, Name: Microsoft reserved partition, StartLBA 0x258800, BlocksNum 0x40000
21:27:11.0596 3332  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {89794D6E-B731-4E38-A031-27B0734916FC}, Name: Basic data partition, StartLBA 0x298800, BlocksNum 0x1749C000
21:27:11.0596 3332  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {52B90836-DC99-4C81-911A-540B85A280FD}, Name: Basic data partition, StartLBA 0x17734800, BlocksNum 0x2044C800
21:27:11.0596 3332  \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {3E8FC2A2-1158-442D-BC49-1EF339F1F09C}, Name: Basic data partition, StartLBA 0x37B81000, BlocksNum 0x2805000
21:27:11.0596 3332  MBR partitions:
21:27:11.0596 3332  ============================================================
21:27:11.0611 3332  C: <-> \Device\Harddisk0\DR0\Partition4
21:27:11.0643 3332  D: <-> \Device\Harddisk0\DR0\Partition5
21:27:11.0643 3332  ============================================================
21:27:11.0643 3332  Initialize success
21:27:11.0643 3332  ============================================================
21:27:29.0628 5272  ============================================================
21:27:29.0628 5272  Scan started
21:27:29.0628 5272  Mode: Manual; SigCheck; TDLFS; 
21:27:29.0628 5272  ============================================================
21:27:30.0315 5272  ================ Scan system memory ========================
21:27:30.0315 5272  System memory - ok
21:27:30.0315 5272  ================ Scan services =============================
21:27:30.0378 5272  0123871362419113mcinstcleanup - ok
21:27:30.0456 5272  [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci        C:\Windows\System32\drivers\1394ohci.sys
21:27:30.0612 5272  1394ohci - ok
21:27:30.0612 5272  [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware           C:\Windows\system32\drivers\3ware.sys
21:27:30.0628 5272  3ware - ok
21:27:30.0659 5272  [ 975AABEB243B800C23626D6B652C5A9C ] ACPI            C:\Windows\system32\drivers\ACPI.sys
21:27:30.0690 5272  ACPI - ok
21:27:30.0706 5272  [ DC968C37822117E576B933F34A2D130C ] acpiex          C:\Windows\system32\Drivers\acpiex.sys
21:27:30.0722 5272  acpiex - ok
21:27:30.0722 5272  [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr        C:\Windows\System32\drivers\acpipagr.sys
21:27:30.0753 5272  acpipagr - ok
21:27:30.0753 5272  [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi         C:\Windows\System32\drivers\acpipmi.sys
21:27:30.0815 5272  AcpiPmi - ok
21:27:30.0815 5272  [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime        C:\Windows\System32\drivers\acpitime.sys
21:27:30.0847 5272  acpitime - ok
21:27:30.0894 5272  [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:27:30.0909 5272  AdobeARMservice - ok
21:27:31.0003 5272  [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:27:31.0019 5272  AdobeFlashPlayerUpdateSvc - ok
21:27:31.0034 5272  [ 93C6388592B99925C1D1576E465BC80F ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
21:27:31.0065 5272  adp94xx - ok
21:27:31.0081 5272  [ D27763E0247292654E7F7D16444C7C72 ] adpahci         C:\Windows\system32\drivers\adpahci.sys
21:27:31.0112 5272  adpahci - ok
21:27:31.0112 5272  [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
21:27:31.0128 5272  adpu320 - ok
21:27:31.0159 5272  [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
21:27:31.0206 5272  AeLookupSvc - ok
21:27:31.0237 5272  [ 9E975BDC89C83900B2C534C4E1B018F8 ] AFD             C:\Windows\system32\drivers\afd.sys
21:27:31.0300 5272  AFD - ok
21:27:31.0331 5272  [ 98022774D9930ECBB292E70DB7601DF6 ] AgereSoftModem  C:\Windows\system32\DRIVERS\agrsm64.sys
21:27:31.0394 5272  AgereSoftModem - ok
21:27:31.0409 5272  [ 01590377A5AB19E792528C628A2A68F9 ] agp440          C:\Windows\system32\drivers\agp440.sys
21:27:31.0425 5272  agp440 - ok
21:27:31.0456 5272  [ 16F6F6B7903B913AB41AB848C8BB5658 ] AiCharger       C:\Windows\system32\DRIVERS\AiCharger.sys
21:27:31.0472 5272  AiCharger - ok
21:27:31.0487 5272  [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG             C:\Windows\System32\alg.exe
21:27:31.0612 5272  ALG - ok
21:27:31.0644 5272  [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
21:27:31.0706 5272  AllUserInstallAgent - ok
21:27:31.0737 5272  [ FB88D16B55F788EEB7590584FE2D8F1A ] AmdK8           C:\Windows\System32\drivers\amdk8.sys
21:27:31.0784 5272  AmdK8 - ok
21:27:31.0784 5272  [ 81402FF3373CE4DF77D5C874E369A985 ] AmdPPM          C:\Windows\System32\drivers\amdppm.sys
21:27:31.0816 5272  AmdPPM - ok
21:27:31.0831 5272  [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
21:27:31.0831 5272  amdsata - ok
21:27:31.0862 5272  [ 00452671904F5EE94B50BF0219C97164 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
21:27:31.0878 5272  amdsbs - ok
21:27:31.0878 5272  [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
21:27:31.0894 5272  amdxata - ok
21:27:32.0034 5272  [ 459465DA28E49B358ECFE0D788F328F4 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
21:27:32.0050 5272  AntiVirSchedulerService - ok
21:27:32.0066 5272  [ BCDD17E8469D647A71B347C4B6F86685 ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
21:27:32.0081 5272  AntiVirService - ok
21:27:32.0097 5272  [ 83B3682CE922FB0F415734B26D9D6233 ] AppID           C:\Windows\system32\drivers\appid.sys
21:27:32.0175 5272  AppID - ok
21:27:32.0222 5272  [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
21:27:32.0253 5272  AppIDSvc - ok
21:27:32.0253 5272  [ D64C4AFEE8277F35EF729A2B924666B0 ] Appinfo         C:\Windows\System32\appinfo.dll
21:27:32.0284 5272  Appinfo - ok
21:27:32.0300 5272  [ E933401B392387F4BE34DE8BAF1722A7 ] arc             C:\Windows\system32\drivers\arc.sys
21:27:32.0316 5272  arc - ok
21:27:32.0316 5272  [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
21:27:32.0331 5272  arcsas - ok
21:27:32.0394 5272  [ D01D1B40EEF27F64B45165CE0ACDE6CD ] ASLDRService    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
21:27:32.0409 5272  ASLDRService - ok
21:27:32.0409 5272  [ 4C016FD76ED5C05E84CA8CAB77993961 ] ASMMAP64        C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
21:27:32.0425 5272  ASMMAP64 - ok
21:27:32.0456 5272  [ 6A122B4F0E5293CACFA8A5F2CBA9B356 ] ASUS InstantOn  C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
21:27:32.0456 5272  ASUS InstantOn - ok
21:27:32.0472 5272  [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
21:27:32.0519 5272  AsyncMac - ok
21:27:32.0519 5272  [ A721FF570C2387E383BDDEA9632863C9 ] atapi           C:\Windows\system32\drivers\atapi.sys
21:27:32.0534 5272  atapi - ok
21:27:32.0675 5272  [ D55EBCD80CA519020338F75E420FDF3F ] athr            C:\Windows\system32\DRIVERS\athw8x.sys
21:27:32.0831 5272  athr - ok
21:27:32.0847 5272  [ DBC598E47E7A382E60E2A4745D41FEF9 ] ATKGFNEXSrv     C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
21:27:32.0847 5272  ATKGFNEXSrv - ok
21:27:32.0878 5272  [ 41CEAFFCF3550785E59E3EC9BEE8D97A ] ATKWMIACPIIO    C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
21:27:32.0894 5272  ATKWMIACPIIO - ok
21:27:32.0925 5272  [ 437EB91CB20144375DDE145149778405 ] ATP             C:\Windows\System32\drivers\AsusTP.sys
21:27:32.0925 5272  ATP - ok
21:27:32.0956 5272  [ 8A814F4CBF6AA28A8F0212592824C927 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
21:27:33.0003 5272  AudioEndpointBuilder - ok
21:27:33.0034 5272  [ 01E8E96251900BCEFAB34FBC1FCEB552 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
21:27:33.0081 5272  Audiosrv - ok
21:27:33.0097 5272  [ BFE9598EBC3934CF8D876A303849C896 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
21:27:33.0112 5272  avgntflt - ok
21:27:33.0144 5272  [ F74D86A9FB35FA5F24627B8DBBF3A9A4 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
21:27:33.0159 5272  avipbb - ok
21:27:33.0175 5272  [ CD0E732347BF09717E0BDDC0C66699AB ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
21:27:33.0175 5272  avkmgr - ok
21:27:33.0222 5272  [ 89491EF71D5EA011127832C588002853 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
21:27:33.0284 5272  AxInstSV - ok
21:27:33.0300 5272  [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
21:27:33.0347 5272  b06bdrv - ok
21:27:33.0378 5272  [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay    C:\Windows\System32\drivers\BasicDisplay.sys
21:27:33.0456 5272  BasicDisplay - ok
21:27:33.0456 5272  [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender     C:\Windows\System32\drivers\BasicRender.sys
21:27:33.0487 5272  BasicRender - ok
21:27:33.0519 5272  [ 558F6EEF46EC2642C8F72D34CBB5612E ] BDESVC          C:\Windows\System32\bdesvc.dll
21:27:33.0581 5272  BDESVC - ok
21:27:33.0613 5272  [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep            C:\Windows\system32\drivers\Beep.sys
21:27:33.0675 5272  Beep - ok
21:27:33.0722 5272  [ 407F85D5387EDBB665A7969DF4D4712B ] BFE             C:\Windows\System32\bfe.dll
21:27:33.0769 5272  BFE - ok
21:27:33.0800 5272  [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS            C:\Windows\System32\qmgr.dll
21:27:33.0894 5272  BITS - ok
21:27:33.0909 5272  [ B17AC10B47C7FCB44D22A1F06415840E ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
21:27:33.0988 5272  bowser - ok
21:27:34.0034 5272  [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
21:27:34.0097 5272  BrokerInfrastructure - ok
21:27:34.0128 5272  [ 310068BDA80B1D55C36580FD8A873FAF ] Browser         C:\Windows\System32\browser.dll
21:27:34.0191 5272  Browser - ok
21:27:34.0206 5272  [ FC79BE6D8FBC8699E9980F657D281BE9 ] BthAvrcpTg      C:\Windows\System32\drivers\BthAvrcpTg.sys
21:27:34.0269 5272  BthAvrcpTg - ok
21:27:34.0284 5272  [ 8DE53C3B497D58C7D3E52F54D28E7D86 ] BthEnum         C:\Windows\System32\drivers\BthEnum.sys
21:27:34.0316 5272  BthEnum - ok
21:27:34.0331 5272  [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum       C:\Windows\System32\drivers\bthhfenum.sys
21:27:34.0456 5272  BthHFEnum - ok
21:27:34.0488 5272  [ 6F7368071FCDDB96C0527A6E5D7C1906 ] bthhfhid        C:\Windows\System32\drivers\BthHFHid.sys
21:27:34.0519 5272  bthhfhid - ok
21:27:34.0550 5272  [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM        C:\Windows\System32\drivers\bthmodem.sys
21:27:34.0597 5272  BTHMODEM - ok
21:27:34.0597 5272  [ 091BB978E9504D0AD14586929431A957 ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
21:27:34.0659 5272  BthPan - ok
21:27:34.0691 5272  [ 427510B95603B24A0E1DDB47EFC4BA44 ] BTHPORT         C:\Windows\System32\Drivers\BTHport.sys
21:27:34.0753 5272  BTHPORT - ok
21:27:34.0800 5272  [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv         C:\Windows\system32\bthserv.dll
21:27:34.0816 5272  bthserv - ok
21:27:34.0831 5272  [ 0BB16201253AA87015EFFECAF157225F ] BTHUSB          C:\Windows\System32\Drivers\BTHUSB.sys
21:27:34.0847 5272  BTHUSB - ok
21:27:34.0878 5272  [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
21:27:34.0941 5272  cdfs - ok
21:27:34.0941 5272  [ 339BFF85D788268752DA8C9644B188EE ] cdrom           C:\Windows\System32\drivers\cdrom.sys
21:27:34.0956 5272  cdrom - ok
21:27:34.0988 5272  [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc     C:\Windows\System32\certprop.dll
21:27:35.0019 5272  CertPropSvc - ok
21:27:35.0066 5272  [ A73276435F75025DA6E67B2470E1FE16 ] cfwids          C:\Windows\system32\drivers\cfwids.sys
21:27:35.0081 5272  cfwids - ok
21:27:35.0097 5272  [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass        C:\Windows\System32\drivers\circlass.sys
21:27:35.0144 5272  circlass - ok
21:27:35.0175 5272  [ 9905168708DB68849B879B5548F68AB3 ] CLFS            C:\Windows\system32\drivers\CLFS.sys
21:27:35.0191 5272  CLFS - ok
21:27:35.0206 5272  [ 2DC8538A2260647484A6C921CA837313 ] CmBatt          C:\Windows\System32\drivers\CmBatt.sys
21:27:35.0269 5272  CmBatt - ok
21:27:35.0300 5272  [ 1894FD2D5966A81D3B07A7C4D8724D59 ] CNG             C:\Windows\system32\Drivers\cng.sys
21:27:35.0331 5272  CNG - ok
21:27:35.0347 5272  [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus    C:\Windows\System32\drivers\CompositeBus.sys
21:27:35.0378 5272  CompositeBus - ok
21:27:35.0378 5272  COMSysApp - ok
21:27:35.0394 5272  [ D9CB0782AF819548072AA45B70F8B22D ] condrv          C:\Windows\system32\drivers\condrv.sys
21:27:35.0409 5272  condrv - ok
21:27:35.0472 5272  [ 9F5AFC3EE57412798B1A559B620386A0 ] cphs            C:\Windows\SysWow64\IntelCpHeciSvc.exe
21:27:35.0488 5272  cphs - ok
21:27:35.0519 5272  [ F0E78B119D12BA81F163D48C0FF30B9A ] CryptSvc        C:\Windows\system32\cryptsvc.dll
21:27:35.0550 5272  CryptSvc - ok
21:27:35.0581 5272  [ A4CCA7289C1A6223D61FD27BF2FC413F ] dam             C:\Windows\system32\drivers\dam.sys
21:27:35.0597 5272  dam - ok
21:27:35.0628 5272  [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch      C:\Windows\system32\rpcss.dll
21:27:35.0706 5272  DcomLaunch - ok
21:27:35.0738 5272  [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc       C:\Windows\System32\defragsvc.dll
21:27:35.0816 5272  defragsvc - ok
21:27:35.0847 5272  [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
21:27:35.0878 5272  DeviceAssociationService - ok
21:27:35.0909 5272  [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall   C:\Windows\system32\umpnpmgr.dll
21:27:35.0941 5272  DeviceInstall - ok
21:27:35.0972 5272  [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc            C:\Windows\system32\Drivers\dfsc.sys
21:27:35.0988 5272  Dfsc - ok
21:27:36.0035 5272  [ CFB72DF4B2364AF6D4D685DCD310E942 ] Dhcp            C:\Windows\system32\dhcpcore.dll
21:27:36.0113 5272  Dhcp - ok
21:27:36.0128 5272  [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache        C:\Windows\system32\drivers\discache.sys
21:27:36.0144 5272  discache - ok
21:27:36.0160 5272  [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk            C:\Windows\system32\drivers\disk.sys
21:27:36.0175 5272  disk - ok
21:27:36.0175 5272  [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc           C:\Windows\System32\drivers\dmvsc.sys
21:27:36.0238 5272  dmvsc - ok
21:27:36.0253 5272  [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
21:27:36.0300 5272  Dnscache - ok
21:27:36.0331 5272  [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc         C:\Windows\System32\dot3svc.dll
21:27:36.0363 5272  dot3svc - ok
21:27:36.0378 5272  [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS             C:\Windows\system32\dps.dll
21:27:36.0410 5272  DPS - ok
21:27:36.0425 5272  [ 84D07E4E4FBE72DA3EC1C1E77C49B53C ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
21:27:36.0488 5272  drmkaud - ok
21:27:36.0519 5272  [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc          C:\Windows\System32\DeviceSetupManager.dll
21:27:36.0613 5272  DsmSvc - ok
21:27:36.0660 5272  [ 898BF1647BBF012B38EF45C7F9F7A67E ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
21:27:36.0722 5272  DXGKrnl - ok
21:27:36.0738 5272  [ 651FBD69A9713D623D456A240F96179C ] e1iexpress      C:\Windows\system32\DRIVERS\e1i63x64.sys
21:27:36.0785 5272  e1iexpress - ok
21:27:36.0831 5272  [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost         C:\Windows\System32\eapsvc.dll
21:27:36.0863 5272  Eaphost - ok
21:27:36.0941 5272  [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
21:27:37.0050 5272  ebdrv - ok
21:27:37.0066 5272  [ F702AB6181513303AB0FC8D59E52708B ] EFS             C:\Windows\System32\lsass.exe
21:27:37.0144 5272  EFS - ok
21:27:37.0160 5272  [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass     C:\Windows\system32\drivers\EhStorClass.sys
21:27:37.0175 5272  EhStorClass - ok
21:27:37.0175 5272  [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv    C:\Windows\system32\drivers\EhStorTcgDrv.sys
21:27:37.0191 5272  EhStorTcgDrv - ok
21:27:37.0206 5272  [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev          C:\Windows\System32\drivers\errdev.sys
21:27:37.0206 5272  ErrDev - ok
21:27:37.0269 5272  [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem     C:\Windows\system32\es.dll
21:27:37.0331 5272  EventSystem - ok
21:27:37.0363 5272  [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat           C:\Windows\system32\drivers\exfat.sys
21:27:37.0394 5272  exfat - ok
21:27:37.0394 5272  [ 60996602A7111FD2D086E803F33E4282 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
21:27:37.0410 5272  fastfat - ok
21:27:37.0456 5272  [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax             C:\Windows\system32\fxssvc.exe
21:27:37.0519 5272  Fax - ok
21:27:37.0535 5272  [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc             C:\Windows\System32\drivers\fdc.sys
21:27:37.0566 5272  fdc - ok
21:27:37.0581 5272  [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost         C:\Windows\system32\fdPHost.dll
21:27:37.0613 5272  fdPHost - ok
21:27:37.0628 5272  [ 872506AAB591E8908DF4461475AF92DF ] FDResPub        C:\Windows\system32\fdrespub.dll
21:27:37.0644 5272  FDResPub - ok
21:27:37.0691 5272  [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc           C:\Windows\system32\fhsvc.dll
21:27:37.0722 5272  fhsvc - ok
21:27:37.0753 5272  [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
21:27:37.0769 5272  FileInfo - ok
21:27:37.0769 5272  [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
21:27:37.0800 5272  Filetrace - ok
21:27:37.0800 5272  [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk        C:\Windows\System32\drivers\flpydisk.sys
21:27:37.0831 5272  flpydisk - ok
21:27:37.0847 5272  [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
21:27:37.0863 5272  FltMgr - ok
21:27:37.0910 5272  [ 305CB1E16576F436BC8797E629A3D46D ] FontCache       C:\Windows\system32\FntCache.dll
21:27:38.0019 5272  FontCache - ok
21:27:38.0066 5272  [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:27:38.0081 5272  FontCache3.0.0.0 - ok
21:27:38.0113 5272  [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
21:27:38.0128 5272  FsDepends - ok
21:27:38.0128 5272  [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
21:27:38.0144 5272  Fs_Rec - ok
21:27:38.0175 5272  [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
21:27:38.0191 5272  fvevol - ok
21:27:38.0207 5272  [ 3EF3FCCC0E70EEC5C2AD996F32BBA642 ] FxPPM           C:\Windows\System32\drivers\fxppm.sys
21:27:38.0238 5272  FxPPM - ok
21:27:38.0238 5272  [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
21:27:38.0253 5272  gagp30kx - ok
21:27:38.0269 5272  [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter      C:\Windows\System32\drivers\vmgencounter.sys
21:27:38.0285 5272  gencounter - ok
21:27:38.0316 5272  [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101     C:\Windows\system32\Drivers\msgpioclx.sys
21:27:38.0331 5272  GPIOClx0101 - ok
21:27:38.0378 5272  [ 5358678C6370F2ADC5291849F6503262 ] gpsvc           C:\Windows\System32\gpsvc.dll
21:27:38.0441 5272  gpsvc - ok
21:27:38.0472 5272  [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:27:38.0519 5272  HdAudAddService - ok
21:27:38.0550 5272  [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus        C:\Windows\System32\drivers\HDAudBus.sys
21:27:38.0581 5272  HDAudBus - ok
21:27:38.0581 5272  [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt         C:\Windows\System32\drivers\HidBatt.sys
21:27:38.0597 5272  HidBatt - ok
21:27:38.0628 5272  [ A25BAE8C1F2830C8E5625EC7E4E968BE ] HidBth          C:\Windows\System32\drivers\hidbth.sys
21:27:38.0660 5272  HidBth - ok
21:27:38.0675 5272  [ AC0526C4E3A7954F750B8F8D95EFB340 ] hidi2c          C:\Windows\System32\drivers\hidi2c.sys
21:27:38.0707 5272  hidi2c - ok
21:27:38.0722 5272  [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr           C:\Windows\System32\drivers\hidir.sys
21:27:38.0753 5272  HidIr - ok
21:27:38.0832 5272  [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv         C:\Windows\system32\hidserv.dll
21:27:38.0847 5272  hidserv - ok
21:27:38.0878 5272  [ A9F2301B8D28BB4D887F5AEBB55ACB3A ] HIDSwitch       C:\Windows\System32\drivers\AsHIDSwitch64.sys
21:27:38.0894 5272  HIDSwitch - ok
21:27:38.0910 5272  [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] HidUsb          C:\Windows\System32\drivers\hidusb.sys
21:27:38.0941 5272  HidUsb - ok
21:27:38.0941 5272  [ A894FB2CAE6A29F5D9C8EDA47B074623 ] HipShieldK      C:\Windows\system32\drivers\HipShieldK.sys
21:27:38.0957 5272  HipShieldK - ok
21:27:38.0988 5272  [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc          C:\Windows\system32\kmsvc.dll
21:27:39.0019 5272  hkmsvc - ok
21:27:39.0035 5272  [ 6CC1AD7B0E071C317B7FB8FC6AEF0EDA ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:27:39.0113 5272  HomeGroupListener - ok
21:27:39.0128 5272  [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:27:39.0160 5272  HomeGroupProvider - ok
21:27:39.0175 5272  [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
21:27:39.0191 5272  HpSAMD - ok
21:27:39.0207 5272  [ 47DBBF38E00C3F7404B71F6509241EF1 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
21:27:39.0300 5272  HTTP - ok
21:27:39.0316 5272  [ 2A98301068801700906C06649860FE94 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
21:27:39.0316 5272  hwpolicy - ok
21:27:39.0332 5272  [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd        C:\Windows\System32\drivers\hyperkbd.sys
21:27:39.0363 5272  hyperkbd - ok
21:27:39.0363 5272  [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo      C:\Windows\system32\DRIVERS\HyperVideo.sys
21:27:39.0378 5272  HyperVideo - ok
21:27:39.0378 5272  [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt        C:\Windows\System32\drivers\i8042prt.sys
21:27:39.0394 5272  i8042prt - ok
21:27:39.0441 5272  [ 0FE66A51D81A25AACEAAE4C26308121D ] iaStorA         C:\Windows\system32\drivers\iaStorA.sys
21:27:39.0457 5272  iaStorA - ok
21:27:39.0535 5272  [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
21:27:39.0582 5272  iaStorV - ok
21:27:39.0847 5272  [ 11A31FC2481BFE69B0507ED8C80215F4 ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
21:27:40.0097 5272  igfx - ok
21:27:40.0128 5272  [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
21:27:40.0144 5272  iirsp - ok
21:27:40.0175 5272  [ 45EACE8D94B9CEC746A85154892C4FDC ] IKEEXT          C:\Windows\System32\ikeext.dll
21:27:40.0222 5272  IKEEXT - ok
21:27:40.0238 5272  [ F5495B38BFB9149925F54F65AB40EFBF ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
21:27:40.0285 5272  IntcDAud - ok
21:27:40.0347 5272  [ C99F8E90DE4B8F0C7FE15BB1CBCD29DC ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
21:27:40.0378 5272  Intel(R) Capability Licensing Service Interface - ok
21:27:40.0457 5272  [ 9656F8E29F6C3161A3E99BCD3A472FF9 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
21:27:40.0472 5272  Intel(R) ME Service - ok
21:27:40.0488 5272  [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide        C:\Windows\system32\drivers\intelide.sys
21:27:40.0488 5272  intelide - ok
21:27:40.0519 5272  [ F9E126AA767E2E6E3128434A43C9F713 ] intelppm        C:\Windows\System32\drivers\intelppm.sys
21:27:40.0535 5272  intelppm - ok
21:27:40.0535 5272  [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:27:40.0566 5272  IpFilterDriver - ok
21:27:40.0597 5272  [ CAC5202757EF68C4849B0DFFA75F6D3C ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
21:27:40.0660 5272  iphlpsvc - ok
21:27:40.0691 5272  [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV         C:\Windows\System32\drivers\IPMIDrv.sys
21:27:40.0738 5272  IPMIDRV - ok
21:27:40.0738 5272  [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
21:27:40.0769 5272  IPNAT - ok
21:27:40.0785 5272  [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM          C:\Windows\system32\drivers\irenum.sys
21:27:40.0832 5272  IRENUM - ok
21:27:40.0847 5272  [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
21:27:40.0863 5272  isapnp - ok
21:27:40.0894 5272  [ F5F0DE1B7F256997501EECECE9648108 ] iScsiPrt        C:\Windows\System32\drivers\msiscsi.sys
21:27:40.0910 5272  iScsiPrt - ok
21:27:40.0941 5272  [ 78ABBE558F57144047F10A0F50FE4B2F ] jhi_service     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
21:27:40.0957 5272  jhi_service - ok
21:27:40.0957 5272  [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass        C:\Windows\System32\drivers\kbdclass.sys
21:27:40.0972 5272  kbdclass - ok
21:27:40.0972 5272  [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid          C:\Windows\System32\drivers\kbdhid.sys
21:27:41.0003 5272  kbdhid - ok
21:27:41.0035 5272  [ A8080BEBCDB7A16495CE1205921DCAC5 ] kbfiltr         C:\Windows\System32\drivers\kbfiltr.sys
21:27:41.0035 5272  kbfiltr - ok
21:27:41.0066 5272  [ FB6C185092E18011EF49989425C2AA87 ] kdnic           C:\Windows\system32\DRIVERS\kdnic.sys
21:27:41.0144 5272  kdnic - ok
21:27:41.0160 5272  [ F702AB6181513303AB0FC8D59E52708B ] KeyIso          C:\Windows\system32\lsass.exe
21:27:41.0175 5272  KeyIso - ok
21:27:41.0207 5272  [ DFA480F6DED551464F3A5B959F437800 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
21:27:41.0207 5272  KSecDD - ok
21:27:41.0238 5272  [ E427D299CFE267A2465D3AAF81440ED9 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
21:27:41.0254 5272  KSecPkg - ok
21:27:41.0269 5272  [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
21:27:41.0285 5272  ksthunk - ok
21:27:41.0332 5272  [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm           C:\Windows\system32\msdtckrm.dll
21:27:41.0363 5272  KtmRm - ok
21:27:41.0394 5272  [ CBD16721541EE334F6D623CE0B4003BF ] L1C             C:\Windows\system32\DRIVERS\L1C63x64.sys
21:27:41.0394 5272  L1C - ok
21:27:41.0425 5272  [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer    C:\Windows\system32\srvsvc.dll
21:27:41.0457 5272  LanmanServer - ok
21:27:41.0472 5272  [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:27:41.0504 5272  LanmanWorkstation - ok
21:27:41.0535 5272  [ CEEFD29FC551F289810B0B9381B321DC ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
21:27:41.0550 5272  lltdio - ok
21:27:41.0582 5272  [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc         C:\Windows\System32\lltdsvc.dll
21:27:41.0644 5272  lltdsvc - ok
21:27:41.0644 5272  [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts         C:\Windows\System32\lmhsvc.dll
21:27:41.0722 5272  lmhosts - ok
21:27:41.0754 5272  [ 2C24DC448DBE8DB9BE1441B824C57E79 ] LMS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
21:27:41.0754 5272  LMS - ok
21:27:41.0785 5272  [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
21:27:41.0800 5272  LSI_SAS - ok
21:27:41.0816 5272  [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
21:27:41.0832 5272  LSI_SAS2 - ok
21:27:41.0832 5272  [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
21:27:41.0847 5272  LSI_SCSI - ok
21:27:41.0847 5272  [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS         C:\Windows\system32\drivers\lsi_sss.sys
21:27:41.0863 5272  LSI_SSS - ok
21:27:41.0894 5272  [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] LSM             C:\Windows\System32\lsm.dll
21:27:41.0941 5272  LSM - ok
21:27:41.0941 5272  [ 2BDC5D711FA61307CE6190D47C956368 ] luafv           C:\Windows\system32\drivers\luafv.sys
21:27:41.0972 5272  luafv - ok
21:27:42.0050 5272  [ 1E3AF124A3405EEE594BB9FFD4640F48 ] McAWFwk         c:\PROGRA~1\mcafee\msc\mcawfwk.exe
21:27:42.0066 5272  McAWFwk - ok
21:27:42.0129 5272  [ F928E5E72BBA15DD0CE9A26E0413D236 ] McMPFSvc        C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
21:27:42.0144 5272  McMPFSvc - ok
21:27:42.0144 5272  [ F928E5E72BBA15DD0CE9A26E0413D236 ] mcmscsvc        C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:27:42.0160 5272  mcmscsvc - ok
21:27:42.0160 5272  [ F928E5E72BBA15DD0CE9A26E0413D236 ] McNaiAnn        C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:27:42.0160 5272  McNaiAnn - ok
21:27:42.0175 5272  [ F928E5E72BBA15DD0CE9A26E0413D236 ] McNASvc         C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:27:42.0175 5272  McNASvc - ok
21:27:42.0222 5272  [ B26B99CE6218CC586B727CBA7C923233 ] McODS           C:\Program Files\mcafee\VirusScan\mcods.exe
21:27:42.0238 5272  McODS - ok
21:27:42.0238 5272  [ F928E5E72BBA15DD0CE9A26E0413D236 ] McOobeSv        C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:27:42.0254 5272  McOobeSv - ok
21:27:42.0254 5272  [ F928E5E72BBA15DD0CE9A26E0413D236 ] McProxy         C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
21:27:42.0269 5272  McProxy - ok
21:27:42.0316 5272  [ 23EA22ACADD66D7F1E18A4AA72BE6158 ] McShield        C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
21:27:42.0332 5272  McShield - ok
21:27:42.0347 5272  [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas         C:\Windows\system32\drivers\megasas.sys
21:27:42.0363 5272  megasas - ok
21:27:42.0379 5272  [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
21:27:42.0394 5272  MegaSR - ok
21:27:42.0410 5272  [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64          C:\Windows\System32\drivers\HECIx64.sys
21:27:42.0425 5272  MEIx64 - ok
21:27:42.0457 5272  [ 19323081FA4018C9C1AEBF08114BEA11 ] mfeapfk         C:\Windows\system32\drivers\mfeapfk.sys
21:27:42.0472 5272  mfeapfk - ok
21:27:42.0488 5272  [ EF1D39A70CAD1B7BEDC220480F26815C ] mfeavfk         C:\Windows\system32\drivers\mfeavfk.sys
21:27:42.0488 5272  mfeavfk - ok
21:27:42.0519 5272  mfeavfk01 - ok
21:27:42.0535 5272  [ 9DBA574C2189A32BF484F6EC2322C5CA ] mfeelamk        C:\Windows\system32\drivers\mfeelamk.sys
21:27:42.0535 5272  mfeelamk - ok
21:27:42.0566 5272  [ 3CBBB569730EFD069B4BD253DDD4AD58 ] mfefire         C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
21:27:42.0582 5272  mfefire - ok
21:27:42.0613 5272  [ 67972BFC8F23054BD23E1DE1450E40BD ] mfefirek        C:\Windows\system32\drivers\mfefirek.sys
21:27:42.0629 5272  mfefirek - ok
21:27:42.0660 5272  [ 5C0EE849C03C37071FABDAA6B58D3D94 ] mfehidk         C:\Windows\system32\drivers\mfehidk.sys
21:27:42.0691 5272  mfehidk - ok
21:27:42.0691 5272  [ 450B77CAC7384A9C1BAF476AC302CD4C ] mferkdet        C:\Windows\system32\drivers\mferkdet.sys
21:27:42.0707 5272  mferkdet - ok
21:27:42.0738 5272  [ 74CE2EBE64AB78904E33DD4C5F21611F ] mfevtp          C:\windows\system32\mfevtps.exe
21:27:42.0738 5272  mfevtp - ok
21:27:42.0769 5272  [ F55F9742BFA88D02F96516B80AB400EC ] mfewfpk         C:\Windows\system32\drivers\mfewfpk.sys
21:27:42.0769 5272  mfewfpk - ok
21:27:42.0800 5272  [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS           C:\Windows\system32\mmcss.dll
21:27:42.0832 5272  MMCSS - ok
21:27:42.0863 5272  [ 780098AD5DA8A4822E2563984C85EF7B ] Modem           C:\Windows\system32\drivers\modem.sys
21:27:42.0894 5272  Modem - ok
21:27:42.0894 5272  [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
21:27:42.0957 5272  monitor - ok
21:27:42.0957 5272  [ 618446B98C79776654340CE27C73485E ] mouclass        C:\Windows\System32\drivers\mouclass.sys
21:27:42.0972 5272  mouclass - ok
21:27:42.0972 5272  [ CB2527B8B87D83E56FBF3944BBB6F606 ] mouhid          C:\Windows\System32\drivers\mouhid.sys
21:27:43.0004 5272  mouhid - ok
21:27:43.0019 5272  [ 89D263DBF08119CE16273991C120D6DD ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
21:27:43.0019 5272  mountmgr - ok
21:27:43.0066 5272  [ 46C379299D0C831463162C473C2D5927 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:27:43.0066 5272  MozillaMaintenance - ok
21:27:43.0082 5272  [ 36BF4D86F166ACBC14F0B8B8F90CBCEA ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
21:27:43.0113 5272  mpsdrv - ok
21:27:43.0144 5272  [ 411EA973A1961C287927DF13891EB41E ] MpsSvc          C:\Windows\system32\mpssvc.dll
21:27:43.0175 5272  MpsSvc - ok
21:27:43.0207 5272  [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
21:27:43.0222 5272  MRxDAV - ok
21:27:43.0269 5272  [ 1EEAA5A62E8C49DDF58798F06F78BFFA ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
21:27:43.0300 5272  mrxsmb - ok
21:27:43.0300 5272  [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:27:43.0332 5272  mrxsmb10 - ok
21:27:43.0332 5272  [ BFBE1EA55ECC15733933D429E384BCA4 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:27:43.0363 5272  mrxsmb20 - ok
21:27:43.0394 5272  [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge        C:\Windows\system32\DRIVERS\bridge.sys
21:27:43.0425 5272  MsBridge - ok
21:27:43.0441 5272  [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC           C:\Windows\System32\msdtc.exe
21:27:43.0457 5272  MSDTC - ok
21:27:43.0472 5272  [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
21:27:43.0504 5272  Msfs - ok
21:27:43.0519 5272  [ C9BFB0353099B071E70299549C18C8AE ] msgpiowin32     C:\Windows\System32\drivers\msgpiowin32.sys
21:27:43.0535 5272  msgpiowin32 - ok
21:27:43.0551 5272  [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
21:27:43.0582 5272  mshidkmdf - ok
21:27:43.0597 5272  [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf       C:\Windows\System32\drivers\mshidumdf.sys
21:27:43.0613 5272  mshidumdf - ok
21:27:43.0613 5272  [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
21:27:43.0629 5272  msisadrv - ok
21:27:43.0676 5272  [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
21:27:43.0707 5272  MSiSCSI - ok
21:27:43.0707 5272  msiserver - ok
21:27:43.0738 5272  [ F928E5E72BBA15DD0CE9A26E0413D236 ] MSK80Service    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
21:27:43.0754 5272  MSK80Service - ok
21:27:43.0769 5272  [ 509809566E49F4411055864EA8D437CD ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
21:27:43.0785 5272  MSKSSRV - ok
21:27:43.0801 5272  [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp          C:\Windows\system32\DRIVERS\mslldp.sys
21:27:43.0816 5272  MsLldp - ok
21:27:43.0816 5272  [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
21:27:43.0847 5272  MSPCLOCK - ok
21:27:43.0863 5272  [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
21:27:43.0894 5272  MSPQM - ok
21:27:43.0910 5272  [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
21:27:43.0926 5272  MsRPC - ok
21:27:43.0926 5272  [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios        C:\Windows\System32\drivers\mssmbios.sys
21:27:43.0941 5272  mssmbios - ok
21:27:43.0941 5272  [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
21:27:43.0957 5272  MSTEE - ok
21:27:43.0957 5272  [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig        C:\Windows\System32\drivers\MTConfig.sys
21:27:43.0988 5272  MTConfig - ok
21:27:44.0004 5272  [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup             C:\Windows\system32\Drivers\mup.sys
21:27:44.0004 5272  Mup - ok
21:27:44.0019 5272  [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis          C:\Windows\system32\drivers\mvumis.sys
21:27:44.0019 5272  mvumis - ok
21:27:44.0066 5272  [ 4B18840511D720BA118D3017E8165875 ] napagent        C:\Windows\system32\qagentRT.dll
21:27:44.0097 5272  napagent - ok
21:27:44.0129 5272  [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
21:27:44.0160 5272  NativeWifiP - ok
21:27:44.0207 5272  [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc          C:\Windows\System32\ncasvc.dll
21:27:44.0238 5272  NcaSvc - ok
21:27:44.0238 5272  [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup    C:\Windows\System32\NcdAutoSetup.dll
21:27:44.0316 5272  NcdAutoSetup - ok
21:27:44.0347 5272  [ FE6463C1574610E26ED8DE2054DF59A4 ] NDIS            C:\Windows\system32\drivers\ndis.sys
21:27:44.0394 5272  NDIS - ok
21:27:44.0426 5272  [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
21:27:44.0457 5272  NdisCap - ok
21:27:44.0457 5272  [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform  C:\Windows\system32\DRIVERS\NdisImPlatform.sys
21:27:44.0472 5272  NdisImPlatform - ok
21:27:44.0504 5272  [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
21:27:44.0566 5272  NdisTapi - ok
21:27:44.0597 5272  [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
21:27:44.0629 5272  Ndisuio - ok
21:27:44.0629 5272  [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
21:27:44.0660 5272  NdisWan - ok
21:27:44.0660 5272  [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY   C:\Windows\system32\DRIVERS\ndiswan.sys
21:27:44.0691 5272  NDISWANLEGACY - ok
21:27:44.0707 5272  [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
21:27:44.0722 5272  NDProxy - ok
21:27:44.0738 5272  [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu             C:\Windows\system32\drivers\Ndu.sys
21:27:44.0754 5272  Ndu - ok
21:27:44.0769 5272  [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
21:27:44.0801 5272  NetBIOS - ok
21:27:44.0832 5272  [ 7CEC25C682D319D484630B3952C31A11 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
21:27:44.0894 5272  NetBT - ok
21:27:44.0926 5272  [ F702AB6181513303AB0FC8D59E52708B ] Netlogon        C:\Windows\system32\lsass.exe
21:27:44.0941 5272  Netlogon - ok
21:27:44.0972 5272  [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman          C:\Windows\System32\netman.dll
21:27:45.0004 5272  Netman - ok
21:27:45.0035 5272  [ 20F6FD63E6D456114BC8056D62792786 ] netprofm        C:\Windows\System32\netprofmsvc.dll
21:27:45.0066 5272  netprofm - ok
21:27:45.0129 5272  [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:27:45.0144 5272  NetTcpPortSharing - ok
21:27:45.0285 5272  [ 57B9C04D673F236D41FAB03842C8640B ] NETwNs64        C:\Windows\system32\DRIVERS\NETwNs64.sys
21:27:45.0472 5272  NETwNs64 - ok
21:27:45.0488 5272  [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
21:27:45.0504 5272  nfrd960 - ok
21:27:45.0519 5272  [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc          C:\Windows\System32\nlasvc.dll
21:27:45.0582 5272  NlaSvc - ok
21:27:45.0582 5272  [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
21:27:45.0613 5272  Npfs - ok
21:27:45.0644 5272  [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig       C:\Windows\System32\drivers\npsvctrig.sys
21:27:45.0676 5272  npsvctrig - ok
21:27:45.0707 5272  [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi             C:\Windows\system32\nsisvc.dll
21:27:45.0738 5272  nsi - ok
21:27:45.0754 5272  [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
21:27:45.0785 5272  nsiproxy - ok
21:27:45.0832 5272  [ 4A7EEA9C4AD5CBFDA3C0E5B821C99CAD ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
21:27:45.0879 5272  Ntfs - ok
21:27:45.0894 5272  [ 4163ADE07DB51843AE31F65B94F5398D ] Null            C:\Windows\system32\drivers\Null.sys
21:27:45.0910 5272  Null - ok
21:27:45.0926 5272  [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
Alt 05.03.2013, 10:21   #8
/// Winkelfunktion
/// TB-Süch-Tiger™
startfenster.com Windows 8 vcl player download - Standard

startfenster.com Windows 8 vcl player download


Eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in CODE-Tags in den Thread.
Logfiles bitte immer in CODE-Tags posten

Alt 05.03.2013, 11:29   #9
startfenster.com Windows 8 vcl player download - Standard

startfenster.com Windows 8 vcl player download

Ja schon. Es hat sich auch nichts unerwünschtes mehr geöffnet gestern und die performance war normal. hab dann mal alles gereinigt und mir den vlc-Player über ne virenfreie Quelle besorgt O.o' (sorry, aber ich musste dringend was gucken )

