|  | 
| 
 | |||||||
| Plagegeister aller Art und deren Bekämpfung: Haeufige Abstuerze und weiterleitungen im FirefoxWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. | 
|  | 
|  | 
|  09.04.2013, 11:25 | #1 | 
|  |   Haeufige Abstuerze und weiterleitungen im Firefox Hallo, seit ca. 2 Wochen treibt mich der Firefox auf die Palme. Teilweise stuerzt der Browser in den unterschiedlichsten Situationen mehrmals am Stück ab um anschliessend wieder 1-2 Stunden stabil zu laufen, die Abstürze konnte ich nicht rekonstruieren. Zudem werde ich stets beim ersten Aufruf der pcgh.de Seite weitergeleitet, ueber pricerunner.de hin zu ihreit.de Dabei spielt es keine Rolle ob ich die URL direkt eingebe oder die Seite über google betrete. Auch eine komplette Deinstallation mit anschliessender Bereinigung der Registry brachte keinen Erfolg. Ich hoffe Ihr koennt mir helfen, Danke | 
|  09.04.2013, 13:14 | #2 | 
| /// TB-Ausbilder    |   Haeufige Abstuerze und weiterleitungen im Firefox!! Hinweis an Mitlesende !! Dieses Thema und die Anweisungen sind nur für diesen speziellen Fall gedacht. Sie könnten andere Computer schwer beschädigen. Öffnet bitte euer eigenes Thema.  Ich werde dir bei deinem Problem helfen. Die Bereinigung funktioniert nur, wenn du dich an die folgenden Regeln hälst:  Bitte lesen: Regeln für die Bereinigung 
 Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Laufwerksemulationen abschalten mit Defogger Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop und starte es:Schritt 2: Scan mit aswMBR 
 Schritt 3: Scan mit dem TDSS-Killer Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen. 
 Schritt 4: Scan mit DDS+ (mit attach) Downloade dir bitte DDS (von sUBs) und speichere die Datei auf deinem Desktop. 
				__________________ | 
|  09.04.2013, 15:02 | #3 | 
|  |   Haeufige Abstuerze und weiterleitungen im Firefox Danke fuer die Hilfe, hier alle benoetigten Logfiles.__________________ defogger_disable Code: 
  ATTFilter defogger_disable by jpshortstuff (23.02.10.1)
Log created at 15:00 on 09/04/2013 (admin)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
SPTD -> Disabled (Service running -> reboot required)
-=E.O.F=-
         aswMBR Code: 
  ATTFilter aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-04-09 15:05:56
-----------------------------
15:05:56.345    OS Version: Windows x64 6.1.7601 Service Pack 1
15:05:56.345    Number of processors: 4 586 0x1E05
15:05:56.345    ComputerName: MAURICE-PC  UserName: admin
15:05:56.486    Initialize success
15:06:04.642    AVAST engine defs: 13040900
15:06:18.517    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T1L0-7
15:06:18.533    Disk 0 Vendor: OCZ-VERTEX2 1.11 Size: 114473MB BusType: 3
15:06:18.533    Disk 0 MBR read successfully
15:06:18.533    Disk 0 MBR scan
15:06:18.548    Disk 0 Windows 7 default MBR code
15:06:18.548    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
15:06:18.580    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       114371 MB offset 206848
15:06:18.626    Disk 0 scanning C:\Windows\system32\drivers
15:06:23.517    Service scanning
15:06:36.533    Modules scanning
15:06:36.533    Disk 0 trace - called modules:
15:06:36.548    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 
15:06:36.548    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004209060]
15:06:36.548    3 CLASSPNP.SYS[fffff880018fe43f] -> nt!IofCallDriver -> [0xfffffa8003fbd670]
15:06:36.564    5 ACPI.sys[fffff88000ef97a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T1L0-7[0xfffffa8003fef060]
15:06:36.705    AVAST engine scan C:\Windows
15:06:37.486    AVAST engine scan C:\Windows\system32
15:08:36.543    AVAST engine scan C:\Windows\system32\drivers
15:08:42.184    AVAST engine scan C:\Users\admin
15:42:22.167    AVAST engine scan C:\ProgramData
15:46:41.706    Scan finished successfully
15:47:41.487    Disk 0 MBR has been saved successfully to "C:\Users\admin\Desktop\MBR.dat"
15:47:41.565    The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt"
         Code: 
  ATTFilter 15:04:44.0258 4196  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
15:04:44.0336 4196  ============================================================
15:04:44.0336 4196  Current date / time: 2013/04/09 15:04:44.0336
15:04:44.0336 4196  SystemInfo:
15:04:44.0336 4196  
15:04:44.0336 4196  OS Version: 6.1.7601 ServicePack: 1.0
15:04:44.0336 4196  Product type: Workstation
15:04:44.0336 4196  ComputerName: MAURICE-PC
15:04:44.0336 4196  UserName: admin
15:04:44.0336 4196  Windows directory: C:\Windows
15:04:44.0336 4196  System windows directory: C:\Windows
15:04:44.0336 4196  Running under WOW64
15:04:44.0336 4196  Processor architecture: Intel x64
15:04:44.0336 4196  Number of processors: 4
15:04:44.0336 4196  Page size: 0x1000
15:04:44.0336 4196  Boot type: Normal boot
15:04:44.0336 4196  ============================================================
15:04:45.0024 4196  Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:04:45.0040 4196  ============================================================
15:04:45.0040 4196  \Device\Harddisk0\DR0:
15:04:45.0040 4196  MBR partitions:
15:04:45.0040 4196  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
15:04:45.0040 4196  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xDF61800
15:04:45.0040 4196  ============================================================
15:04:45.0040 4196  C: <-> \Device\Harddisk0\DR0\Partition2
15:04:45.0040 4196  ============================================================
15:04:45.0040 4196  Initialize success
15:04:45.0040 4196  ============================================================
15:47:53.0285 3188  ============================================================
15:47:53.0285 3188  Scan started
15:47:53.0285 3188  Mode: Manual; TDLFS; 
15:47:53.0285 3188  ============================================================
15:47:53.0582 3188  ================ Scan system memory ========================
15:47:53.0582 3188  System memory - ok
15:47:53.0582 3188  ================ Scan services =============================
15:47:53.0613 3188  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
15:47:53.0613 3188  1394ohci - ok
15:47:53.0644 3188  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
15:47:53.0644 3188  ACPI - ok
15:47:53.0644 3188  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
15:47:53.0644 3188  AcpiPmi - ok
15:47:53.0707 3188  [ DBD5934D88CDD8B8C255D857DF9F689B ] AddonsHelper    C:\Users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe
15:47:53.0785 3188  AddonsHelper - ok
15:47:53.0785 3188  [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
15:47:53.0785 3188  AdobeARMservice - ok
15:47:53.0800 3188  [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
15:47:53.0816 3188  AdobeFlashPlayerUpdateSvc - ok
15:47:53.0832 3188  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
15:47:53.0847 3188  adp94xx - ok
15:47:53.0847 3188  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
15:47:53.0847 3188  adpahci - ok
15:47:53.0863 3188  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
15:47:53.0863 3188  adpu320 - ok
15:47:53.0863 3188  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
15:47:53.0863 3188  AeLookupSvc - ok
15:47:53.0878 3188  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\Windows\system32\drivers\afd.sys
15:47:53.0878 3188  AFD - ok
15:47:53.0878 3188  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
15:47:53.0878 3188  agp440 - ok
15:47:53.0878 3188  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\Windows\System32\alg.exe
15:47:53.0878 3188  ALG - ok
15:47:53.0894 3188  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
15:47:53.0894 3188  aliide - ok
15:47:53.0910 3188  ALSysIO - ok
15:47:53.0910 3188  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
15:47:53.0910 3188  amdide - ok
15:47:53.0910 3188  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
15:47:53.0910 3188  AmdK8 - ok
15:47:53.0925 3188  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
15:47:53.0925 3188  AmdPPM - ok
15:47:53.0925 3188  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
15:47:53.0925 3188  amdsata - ok
15:47:53.0925 3188  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
15:47:53.0925 3188  amdsbs - ok
15:47:53.0941 3188  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
15:47:53.0941 3188  amdxata - ok
15:47:53.0941 3188  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\Windows\system32\drivers\appid.sys
15:47:53.0941 3188  AppID - ok
15:47:53.0941 3188  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
15:47:53.0941 3188  AppIDSvc - ok
15:47:53.0941 3188  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo         C:\Windows\System32\appinfo.dll
15:47:53.0957 3188  Appinfo - ok
15:47:53.0957 3188  [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt         C:\Windows\System32\appmgmts.dll
15:47:53.0957 3188  AppMgmt - ok
15:47:53.0957 3188  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\Windows\system32\DRIVERS\arc.sys
15:47:53.0957 3188  arc - ok
15:47:53.0972 3188  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
15:47:53.0972 3188  arcsas - ok
15:47:53.0988 3188  [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
15:47:53.0988 3188  aspnet_state - ok
15:47:53.0988 3188  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
15:47:53.0988 3188  AsyncMac - ok
15:47:53.0988 3188  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\Windows\system32\drivers\atapi.sys
15:47:53.0988 3188  atapi - ok
15:47:54.0003 3188  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:47:54.0003 3188  AudioEndpointBuilder - ok
15:47:54.0019 3188  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
15:47:54.0019 3188  AudioSrv - ok
15:47:54.0019 3188  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
15:47:54.0019 3188  AxInstSV - ok
15:47:54.0035 3188  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbda.sys
15:47:54.0035 3188  b06bdrv - ok
15:47:54.0035 3188  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
15:47:54.0050 3188  b57nd60a - ok
15:47:54.0050 3188  [ 7729395761F4061A643B573BF7F19AA8 ] BackupReader    C:\Windows\system32\DRIVERS\BackupReader.sys
15:47:54.0050 3188  BackupReader - ok
15:47:54.0050 3188  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
15:47:54.0050 3188  BDESVC - ok
15:47:54.0050 3188  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
15:47:54.0050 3188  Beep - ok
15:47:54.0066 3188  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE             C:\Windows\System32\bfe.dll
15:47:54.0082 3188  BFE - ok
15:47:54.0082 3188  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
15:47:54.0097 3188  BITS - ok
15:47:54.0097 3188  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
15:47:54.0097 3188  blbdrive - ok
15:47:54.0097 3188  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
15:47:54.0113 3188  bowser - ok
15:47:54.0113 3188  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
15:47:54.0113 3188  BrFiltLo - ok
15:47:54.0113 3188  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
15:47:54.0113 3188  BrFiltUp - ok
15:47:54.0113 3188  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\Windows\System32\browser.dll
15:47:54.0113 3188  Browser - ok
15:47:54.0128 3188  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
15:47:54.0128 3188  Brserid - ok
15:47:54.0128 3188  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
15:47:54.0128 3188  BrSerWdm - ok
15:47:54.0128 3188  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
15:47:54.0128 3188  BrUsbMdm - ok
15:47:54.0128 3188  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
15:47:54.0128 3188  BrUsbSer - ok
15:47:54.0144 3188  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
15:47:54.0144 3188  BTHMODEM - ok
15:47:54.0144 3188  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\Windows\system32\bthserv.dll
15:47:54.0144 3188  bthserv - ok
15:47:54.0144 3188  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
15:47:54.0144 3188  cdfs - ok
15:47:54.0160 3188  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\Windows\system32\drivers\cdrom.sys
15:47:54.0160 3188  cdrom - ok
15:47:54.0160 3188  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\Windows\System32\certprop.dll
15:47:54.0160 3188  CertPropSvc - ok
15:47:54.0160 3188  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
15:47:54.0160 3188  circlass - ok
15:47:54.0175 3188  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
15:47:54.0175 3188  CLFS - ok
15:47:54.0175 3188  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:47:54.0191 3188  clr_optimization_v2.0.50727_32 - ok
15:47:54.0191 3188  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
15:47:54.0191 3188  clr_optimization_v2.0.50727_64 - ok
15:47:54.0191 3188  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:47:54.0207 3188  clr_optimization_v4.0.30319_32 - ok
15:47:54.0207 3188  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
15:47:54.0207 3188  clr_optimization_v4.0.30319_64 - ok
15:47:54.0207 3188  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
15:47:54.0207 3188  CmBatt - ok
15:47:54.0222 3188  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
15:47:54.0222 3188  cmdide - ok
15:47:54.0222 3188  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG             C:\Windows\system32\Drivers\cng.sys
15:47:54.0222 3188  CNG - ok
15:47:54.0238 3188  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
15:47:54.0238 3188  Compbatt - ok
15:47:54.0238 3188  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
15:47:54.0238 3188  CompositeBus - ok
15:47:54.0238 3188  COMSysApp - ok
15:47:54.0238 3188  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
15:47:54.0238 3188  crcdisk - ok
15:47:54.0253 3188  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\Windows\system32\cryptsvc.dll
15:47:54.0253 3188  CryptSvc - ok
15:47:54.0253 3188  [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC             C:\Windows\system32\drivers\csc.sys
15:47:54.0269 3188  CSC - ok
15:47:54.0269 3188  [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService      C:\Windows\System32\cscsvc.dll
15:47:54.0285 3188  CscService - ok
15:47:54.0300 3188  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
15:47:54.0300 3188  DcomLaunch - ok
15:47:54.0300 3188  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\Windows\System32\defragsvc.dll
15:47:54.0300 3188  defragsvc - ok
15:47:54.0316 3188  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
15:47:54.0316 3188  DfsC - ok
15:47:54.0316 3188  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
15:47:54.0316 3188  Dhcp - ok
15:47:54.0332 3188  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
15:47:54.0332 3188  discache - ok
15:47:54.0332 3188  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
15:47:54.0332 3188  Disk - ok
15:47:54.0332 3188  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
15:47:54.0332 3188  Dnscache - ok
15:47:54.0347 3188  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\Windows\System32\dot3svc.dll
15:47:54.0347 3188  dot3svc - ok
15:47:54.0347 3188  [ B42ED0320C6E41102FDE0005154849BB ] dot4            C:\Windows\system32\DRIVERS\Dot4.sys
15:47:54.0347 3188  dot4 - ok
15:47:54.0347 3188  [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print       C:\Windows\system32\drivers\Dot4Prt.sys
15:47:54.0347 3188  Dot4Print - ok
15:47:54.0363 3188  [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb         C:\Windows\system32\DRIVERS\dot4usb.sys
15:47:54.0363 3188  dot4usb - ok
15:47:54.0363 3188  [ B18F7E12C3967E7B855DF0FB548E54D5 ] dplazsvr        C:\Windows\system32\clbcatqd.exe
15:47:54.0394 3188  dplazsvr - ok
15:47:54.0394 3188  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\Windows\system32\dps.dll
15:47:54.0394 3188  DPS - ok
15:47:54.0394 3188  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
15:47:54.0394 3188  drmkaud - ok
15:47:54.0410 3188  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
15:47:54.0425 3188  DXGKrnl - ok
15:47:54.0425 3188  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\Windows\System32\eapsvc.dll
15:47:54.0425 3188  EapHost - ok
15:47:54.0457 3188  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\Windows\system32\DRIVERS\evbda.sys
15:47:54.0488 3188  ebdrv - ok
15:47:54.0488 3188  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\Windows\System32\lsass.exe
15:47:54.0488 3188  EFS - ok
15:47:54.0503 3188  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
15:47:54.0503 3188  ehRecvr - ok
15:47:54.0519 3188  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched         C:\Windows\ehome\ehsched.exe
15:47:54.0519 3188  ehSched - ok
15:47:54.0519 3188  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
15:47:54.0535 3188  elxstor - ok
15:47:54.0535 3188  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
15:47:54.0535 3188  ErrDev - ok
15:47:54.0535 3188  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\Windows\system32\es.dll
15:47:54.0550 3188  EventSystem - ok
15:47:54.0550 3188  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\Windows\system32\drivers\exfat.sys
15:47:54.0550 3188  exfat - ok
15:47:54.0566 3188  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\Windows\system32\drivers\fastfat.sys
15:47:54.0566 3188  fastfat - ok
15:47:54.0566 3188  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\Windows\system32\fxssvc.exe
15:47:54.0582 3188  Fax - ok
15:47:54.0582 3188  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
15:47:54.0582 3188  fdc - ok
15:47:54.0582 3188  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\Windows\system32\fdPHost.dll
15:47:54.0582 3188  fdPHost - ok
15:47:54.0582 3188  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
15:47:54.0582 3188  FDResPub - ok
15:47:54.0597 3188  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
15:47:54.0597 3188  FileInfo - ok
15:47:54.0597 3188  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
15:47:54.0597 3188  Filetrace - ok
15:47:54.0597 3188  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
15:47:54.0597 3188  flpydisk - ok
15:47:54.0597 3188  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
15:47:54.0613 3188  FltMgr - ok
15:47:54.0628 3188  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache       C:\Windows\system32\FntCache.dll
15:47:54.0628 3188  FontCache - ok
15:47:54.0628 3188  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
15:47:54.0644 3188  FontCache3.0.0.0 - ok
15:47:54.0644 3188  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
15:47:54.0644 3188  FsDepends - ok
15:47:54.0644 3188  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
15:47:54.0644 3188  Fs_Rec - ok
15:47:54.0644 3188  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
15:47:54.0660 3188  fvevol - ok
15:47:54.0660 3188  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
15:47:54.0660 3188  gagp30kx - ok
15:47:54.0660 3188  [ A37909A904A94E8201A04050548719DF ] GFilterSvc      C:\Windows\System32\GFilterSvc.exe
15:47:54.0691 3188  GFilterSvc - ok
15:47:54.0707 3188  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\Windows\System32\gpsvc.dll
15:47:54.0722 3188  gpsvc - ok
15:47:54.0722 3188  [ F02A533F517EB38333CB12A9E8963773 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:47:54.0722 3188  gupdate - ok
15:47:54.0722 3188  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:47:54.0722 3188  gupdatem - ok
15:47:54.0738 3188  [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc           C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
15:47:54.0738 3188  gusvc - ok
15:47:54.0738 3188  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
15:47:54.0738 3188  hcw85cir - ok
15:47:54.0738 3188  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
15:47:54.0738 3188  HdAudAddService - ok
15:47:54.0753 3188  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
15:47:54.0753 3188  HDAudBus - ok
15:47:54.0753 3188  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
15:47:54.0753 3188  HidBatt - ok
15:47:54.0753 3188  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
15:47:54.0753 3188  HidBth - ok
15:47:54.0769 3188  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
15:47:54.0769 3188  HidIr - ok
15:47:54.0769 3188  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\Windows\system32\hidserv.dll
15:47:54.0769 3188  hidserv - ok
15:47:54.0769 3188  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
15:47:54.0769 3188  HidUsb - ok
15:47:54.0769 3188  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
15:47:54.0769 3188  hkmsvc - ok
15:47:54.0785 3188  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
15:47:54.0785 3188  HomeGroupListener - ok
15:47:54.0785 3188  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
15:47:54.0785 3188  HomeGroupProvider - ok
15:47:54.0800 3188  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
15:47:54.0800 3188  HpSAMD - ok
15:47:54.0800 3188  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
15:47:54.0816 3188  HTTP - ok
15:47:54.0816 3188  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
15:47:54.0816 3188  hwpolicy - ok
15:47:54.0816 3188  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
15:47:54.0816 3188  i8042prt - ok
15:47:54.0832 3188  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
15:47:54.0832 3188  iaStorV - ok
15:47:54.0847 3188  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
15:47:54.0847 3188  idsvc - ok
15:47:54.0863 3188  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
15:47:54.0863 3188  iirsp - ok
15:47:54.0863 3188  [ 2F95BEF56AEEEB45DE55EC44668E2695 ] IJPLMSVC        C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
15:47:54.0894 3188  IJPLMSVC - ok
15:47:54.0894 3188  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
15:47:54.0910 3188  IKEEXT - ok
15:47:54.0910 3188  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
15:47:54.0910 3188  intelide - ok
15:47:54.0910 3188  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
15:47:54.0925 3188  intelppm - ok
15:47:54.0925 3188  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
15:47:54.0925 3188  IPBusEnum - ok
15:47:54.0925 3188  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:47:54.0925 3188  IpFilterDriver - ok
15:47:54.0941 3188  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
15:47:54.0941 3188  iphlpsvc - ok
15:47:54.0941 3188  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
15:47:54.0941 3188  IPMIDRV - ok
15:47:54.0957 3188  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
15:47:54.0957 3188  IPNAT - ok
15:47:54.0957 3188  [ 05360B1EA5A2ABF620D1D96EBD8BD8F1 ] irda            C:\Windows\system32\DRIVERS\irda.sys
15:47:54.0957 3188  irda - ok
15:47:54.0957 3188  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
15:47:54.0957 3188  IRENUM - ok
15:47:54.0957 3188  [ 3848384AB383F0A8F506C4370635C1F9 ] Irmon           C:\Windows\System32\irmon.dll
15:47:54.0957 3188  Irmon - ok
15:47:54.0972 3188  [ D2CA12736624BA636F8357DC3EF0757E ] irsir           C:\Windows\system32\DRIVERS\irsir.sys
15:47:54.0972 3188  irsir - ok
15:47:54.0972 3188  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
15:47:54.0972 3188  isapnp - ok
15:47:54.0972 3188  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
15:47:54.0988 3188  iScsiPrt - ok
15:47:54.0988 3188  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
15:47:54.0988 3188  kbdclass - ok
15:47:54.0988 3188  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
15:47:54.0988 3188  kbdhid - ok
15:47:54.0988 3188  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
15:47:54.0988 3188  KeyIso - ok
15:47:55.0003 3188  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
15:47:55.0003 3188  KSecDD - ok
15:47:55.0003 3188  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
15:47:55.0003 3188  KSecPkg - ok
15:47:55.0003 3188  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
15:47:55.0003 3188  ksthunk - ok
15:47:55.0019 3188  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\Windows\system32\msdtckrm.dll
15:47:55.0019 3188  KtmRm - ok
15:47:55.0019 3188  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
15:47:55.0035 3188  LanmanServer - ok
15:47:55.0035 3188  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:47:55.0035 3188  LanmanWorkstation - ok
15:47:55.0035 3188  [ B6552D382FF070B4ED34CBD6737277C0 ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
15:47:55.0035 3188  LHidFilt - ok
15:47:55.0050 3188  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
15:47:55.0050 3188  lltdio - ok
15:47:55.0050 3188  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
15:47:55.0050 3188  lltdsvc - ok
15:47:55.0050 3188  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\Windows\System32\lmhsvc.dll
15:47:55.0050 3188  lmhosts - ok
15:47:55.0066 3188  [ 73C1F563AB73D459DFFE682D66476558 ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
15:47:55.0066 3188  LMouFilt - ok
15:47:55.0066 3188  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
15:47:55.0066 3188  LSI_FC - ok
15:47:55.0066 3188  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
15:47:55.0066 3188  LSI_SAS - ok
15:47:55.0082 3188  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
15:47:55.0082 3188  LSI_SAS2 - ok
15:47:55.0082 3188  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
15:47:55.0082 3188  LSI_SCSI - ok
15:47:55.0082 3188  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\Windows\system32\drivers\luafv.sys
15:47:55.0097 3188  luafv - ok
15:47:55.0097 3188  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
15:47:55.0097 3188  Mcx2Svc - ok
15:47:55.0097 3188  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
15:47:55.0097 3188  megasas - ok
15:47:55.0097 3188  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
15:47:55.0113 3188  MegaSR - ok
15:47:55.0113 3188  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\Windows\system32\mmcss.dll
15:47:55.0113 3188  MMCSS - ok
15:47:55.0113 3188  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\Windows\system32\drivers\modem.sys
15:47:55.0113 3188  Modem - ok
15:47:55.0113 3188  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
15:47:55.0113 3188  monitor - ok
15:47:55.0128 3188  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
15:47:55.0128 3188  mouclass - ok
15:47:55.0128 3188  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
15:47:55.0128 3188  mouhid - ok
15:47:55.0128 3188  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
15:47:55.0128 3188  mountmgr - ok
15:47:55.0144 3188  [ 1C9B83F6A2D1F414F0ACD28D75605607 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
15:47:55.0144 3188  MozillaMaintenance - ok
15:47:55.0144 3188  [ F8A10560B35C66F9DE212F03DAD5BFA7 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
15:47:55.0144 3188  MpFilter - ok
15:47:55.0160 3188  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
15:47:55.0160 3188  mpio - ok
15:47:55.0160 3188  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
15:47:55.0160 3188  mpsdrv - ok
15:47:55.0175 3188  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
15:47:55.0191 3188  MpsSvc - ok
15:47:55.0191 3188  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
15:47:55.0191 3188  MRxDAV - ok
15:47:55.0191 3188  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
15:47:55.0191 3188  mrxsmb - ok
15:47:55.0207 3188  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:47:55.0207 3188  mrxsmb10 - ok
15:47:55.0207 3188  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:47:55.0207 3188  mrxsmb20 - ok
15:47:55.0207 3188  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
15:47:55.0222 3188  msahci - ok
15:47:55.0222 3188  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
15:47:55.0222 3188  msdsm - ok
15:47:55.0222 3188  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\Windows\System32\msdtc.exe
15:47:55.0222 3188  MSDTC - ok
15:47:55.0238 3188  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
15:47:55.0238 3188  Msfs - ok
15:47:55.0238 3188  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
15:47:55.0238 3188  mshidkmdf - ok
15:47:55.0238 3188  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
15:47:55.0238 3188  msisadrv - ok
15:47:55.0238 3188  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
15:47:55.0253 3188  MSiSCSI - ok
15:47:55.0253 3188  msiserver - ok
15:47:55.0253 3188  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
15:47:55.0253 3188  MSKSSRV - ok
15:47:55.0253 3188  [ E07DEC52FF801841BA9B6878A60304FB ] MsMpSvc         c:\Program Files\Microsoft Security Client\MsMpEng.exe
15:47:55.0253 3188  MsMpSvc - ok
15:47:55.0253 3188  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
15:47:55.0253 3188  MSPCLOCK - ok
15:47:55.0269 3188  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
15:47:55.0269 3188  MSPQM - ok
15:47:55.0269 3188  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
15:47:55.0269 3188  MsRPC - ok
15:47:55.0285 3188  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
15:47:55.0285 3188  mssmbios - ok
15:47:55.0285 3188  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
15:47:55.0285 3188  MSTEE - ok
15:47:55.0285 3188  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
15:47:55.0285 3188  MTConfig - ok
15:47:55.0285 3188  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\Windows\system32\Drivers\mup.sys
15:47:55.0285 3188  Mup - ok
15:47:55.0300 3188  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
15:47:55.0300 3188  napagent - ok
15:47:55.0300 3188  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
15:47:55.0316 3188  NativeWifiP - ok
15:47:55.0316 3188  [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS            C:\Windows\system32\drivers\ndis.sys
15:47:55.0332 3188  NDIS - ok
15:47:55.0332 3188  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
15:47:55.0332 3188  NdisCap - ok
15:47:55.0347 3188  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
15:47:55.0347 3188  NdisTapi - ok
15:47:55.0347 3188  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
15:47:55.0347 3188  Ndisuio - ok
15:47:55.0347 3188  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
15:47:55.0347 3188  NdisWan - ok
15:47:55.0347 3188  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
15:47:55.0363 3188  NDProxy - ok
15:47:55.0363 3188  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
15:47:55.0363 3188  NetBIOS - ok
15:47:55.0363 3188  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
15:47:55.0363 3188  NetBT - ok
15:47:55.0363 3188  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
15:47:55.0378 3188  Netlogon - ok
15:47:55.0378 3188  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
15:47:55.0378 3188  Netman - ok
15:47:55.0378 3188  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:47:55.0394 3188  NetMsmqActivator - ok
15:47:55.0394 3188  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:47:55.0394 3188  NetPipeActivator - ok
15:47:55.0394 3188  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
15:47:55.0410 3188  netprofm - ok
15:47:55.0410 3188  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:47:55.0410 3188  NetTcpActivator - ok
15:47:55.0410 3188  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:47:55.0410 3188  NetTcpPortSharing - ok
15:47:55.0410 3188  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
15:47:55.0410 3188  nfrd960 - ok
15:47:55.0425 3188  [ 162100E0BC8377710F9D170631921C03 ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
15:47:55.0425 3188  NisDrv - ok
15:47:55.0425 3188  [ C6E15F2F95F9C0A6098D43510B604E52 ] NisSrv          c:\Program Files\Microsoft Security Client\NisSrv.exe
15:47:55.0425 3188  NisSrv - ok
15:47:55.0441 3188  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
15:47:55.0441 3188  NlaSvc - ok
15:47:55.0441 3188  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
15:47:55.0441 3188  Npfs - ok
15:47:55.0457 3188  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\Windows\system32\nsisvc.dll
15:47:55.0457 3188  nsi - ok
15:47:55.0457 3188  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
15:47:55.0457 3188  nsiproxy - ok
15:47:55.0472 3188  [ A2F74975097F52A00745F9637451FDD8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
15:47:55.0488 3188  Ntfs - ok
15:47:55.0488 3188  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
15:47:55.0488 3188  Null - ok
15:47:55.0628 3188  [ FE2909F7DFB12B9A20AD207FE23B7E96 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
15:47:55.0738 3188  nvlddmkm - ok
15:47:55.0753 3188  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
15:47:55.0753 3188  nvraid - ok
15:47:55.0753 3188  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
15:47:55.0753 3188  nvstor - ok
15:47:55.0769 3188  [ 3341D2C91989BC87C3C0BAA97C27253B ] nvsvc           C:\Windows\system32\nvvsvc.exe
15:47:55.0785 3188  nvsvc - ok
15:47:55.0785 3188  [ 551CE34DAD2DFF0A480781E68B286E4D ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
15:47:55.0800 3188  nvUpdatusService - ok
15:47:55.0800 3188  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
15:47:55.0816 3188  nv_agp - ok
15:47:55.0816 3188  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
15:47:55.0816 3188  ohci1394 - ok
15:47:55.0816 3188  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
15:47:55.0816 3188  p2pimsvc - ok
15:47:55.0832 3188  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
15:47:55.0832 3188  p2psvc - ok
15:47:55.0847 3188  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
15:47:55.0847 3188  Parport - ok
15:47:55.0847 3188  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\Windows\system32\drivers\partmgr.sys
15:47:55.0847 3188  partmgr - ok
15:47:55.0847 3188  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
15:47:55.0847 3188  PcaSvc - ok
15:47:55.0863 3188  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\Windows\system32\drivers\pci.sys
15:47:55.0863 3188  pci - ok
15:47:55.0863 3188  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
15:47:55.0863 3188  pciide - ok
15:47:55.0863 3188  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
15:47:55.0863 3188  pcmcia - ok
15:47:55.0878 3188  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\Windows\system32\drivers\pcw.sys
15:47:55.0878 3188  pcw - ok
15:47:55.0878 3188  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
15:47:55.0894 3188  PEAUTH - ok
15:47:55.0910 3188  [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
15:47:55.0925 3188  PeerDistSvc - ok
15:47:55.0941 3188  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
15:47:55.0941 3188  PerfHost - ok
15:47:55.0957 3188  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\Windows\system32\pla.dll
15:47:55.0972 3188  pla - ok
15:47:55.0988 3188  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
15:47:55.0988 3188  PlugPlay - ok
15:47:55.0988 3188  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
15:47:55.0988 3188  PNRPAutoReg - ok
15:47:56.0003 3188  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
15:47:56.0003 3188  PNRPsvc - ok
15:47:56.0003 3188  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
15:47:56.0019 3188  PolicyAgent - ok
15:47:56.0019 3188  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\Windows\system32\umpo.dll
15:47:56.0019 3188  Power - ok
15:47:56.0035 3188  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
15:47:56.0035 3188  PptpMiniport - ok
15:47:56.0035 3188  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\Windows\system32\DRIVERS\processr.sys
15:47:56.0035 3188  Processor - ok
15:47:56.0035 3188  [ 5C78838B4D166D1A27DB3A8A820C799A ] ProfSvc         C:\Windows\system32\profsvc.dll
15:47:56.0035 3188  ProfSvc - ok
15:47:56.0050 3188  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
15:47:56.0050 3188  ProtectedStorage - ok
15:47:56.0050 3188  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
15:47:56.0050 3188  Psched - ok
15:47:56.0316 3188  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
15:47:56.0332 3188  ql2300 - ok
15:47:56.0332 3188  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
15:47:56.0332 3188  ql40xx - ok
15:47:56.0347 3188  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\Windows\system32\qwave.dll
15:47:56.0347 3188  QWAVE - ok
15:47:56.0347 3188  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
15:47:56.0347 3188  QWAVEdrv - ok
15:47:56.0347 3188  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
15:47:56.0363 3188  RasAcd - ok
15:47:56.0363 3188  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
15:47:56.0363 3188  RasAgileVpn - ok
15:47:56.0363 3188  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\Windows\System32\rasauto.dll
15:47:56.0363 3188  RasAuto - ok
15:47:56.0363 3188  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
15:47:56.0363 3188  Rasl2tp - ok
15:47:56.0378 3188  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
15:47:56.0378 3188  RasMan - ok
15:47:56.0378 3188  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
15:47:56.0378 3188  RasPppoe - ok
15:47:56.0394 3188  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
15:47:56.0394 3188  RasSstp - ok
15:47:56.0394 3188  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
15:47:56.0394 3188  rdbss - ok
15:47:56.0410 3188  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
15:47:56.0410 3188  rdpbus - ok
15:47:56.0410 3188  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
15:47:56.0410 3188  RDPCDD - ok
15:47:56.0410 3188  [ 1B6163C503398B23FF8B939C67747683 ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
15:47:56.0410 3188  RDPDR - ok
15:47:56.0410 3188  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
15:47:56.0410 3188  RDPENCDD - ok
15:47:56.0425 3188  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
15:47:56.0425 3188  RDPREFMP - ok
15:47:56.0425 3188  [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
15:47:56.0425 3188  RdpVideoMiniport - ok
15:47:56.0425 3188  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
15:47:56.0425 3188  RDPWD - ok
15:47:56.0441 3188  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
15:47:56.0441 3188  rdyboost - ok
15:47:56.0441 3188  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
15:47:56.0441 3188  RemoteAccess - ok
15:47:56.0457 3188  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
15:47:56.0457 3188  RemoteRegistry - ok
15:47:56.0457 3188  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
15:47:56.0457 3188  RpcEptMapper - ok
15:47:56.0457 3188  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
15:47:56.0457 3188  RpcLocator - ok
15:47:56.0472 3188  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs           C:\Windows\system32\rpcss.dll
15:47:56.0472 3188  RpcSs - ok
15:47:56.0472 3188  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
15:47:56.0472 3188  rspndr - ok
15:47:56.0488 3188  [ 3B01789EE4EAEE97F5EB46B711387D5E ] RTL8167         C:\Windows\system32\DRIVERS\Rt64win7.sys
15:47:56.0488 3188  RTL8167 - ok
15:47:56.0488 3188  [ E60C0A09F997826C7627B244195AB581 ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
15:47:56.0488 3188  s3cap - ok
15:47:56.0488 3188  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs           C:\Windows\system32\lsass.exe
15:47:56.0488 3188  SamSs - ok
15:47:56.0488 3188  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
15:47:56.0488 3188  sbp2port - ok
15:47:56.0503 3188  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
15:47:56.0503 3188  SCardSvr - ok
15:47:56.0503 3188  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
15:47:56.0503 3188  scfilter - ok
15:47:56.0519 3188  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
15:47:56.0535 3188  Schedule - ok
15:47:56.0535 3188  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc     C:\Windows\System32\certprop.dll
15:47:56.0535 3188  SCPolicySvc - ok
15:47:56.0582 3188  [ 3E1152BF8ADD19B3169BC8E31C29C844 ] SDFirewallService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe
15:47:56.0613 3188  SDFirewallService - ok
15:47:56.0660 3188  [ ABF83CF4BCCEA547AA285E74F89990A3 ] SDMonitorService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe
15:47:56.0691 3188  SDMonitorService - ok
15:47:56.0707 3188  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
15:47:56.0707 3188  SDRSVC - ok
15:47:56.0722 3188  [ 43D29ECB8137EEAE30B0970BBC7A5500 ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
15:47:56.0722 3188  SDScannerService - ok
15:47:56.0738 3188  [ 6B859B122E85C2C833E6D8C5DC4B07F3 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
15:47:56.0753 3188  SDUpdateService - ok
15:47:56.0753 3188  [ 59DCE6783F9ED27EB72C81466E363BF8 ] SDWSCService    C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
15:47:56.0753 3188  SDWSCService - ok
15:47:56.0769 3188  [ 0F4A80438E7286A0E623582F5F2395BD ] SearchAnonymizer C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
15:47:56.0785 3188  SearchAnonymizer - ok
15:47:56.0785 3188  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
15:47:56.0785 3188  secdrv - ok
15:47:56.0785 3188  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
15:47:56.0785 3188  seclogon - ok
15:47:56.0785 3188  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
15:47:56.0785 3188  SENS - ok
15:47:56.0800 3188  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
15:47:56.0800 3188  SensrSvc - ok
15:47:56.0800 3188  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
15:47:56.0800 3188  Serenum - ok
15:47:56.0800 3188  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
15:47:56.0800 3188  Serial - ok
15:47:56.0800 3188  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
15:47:56.0800 3188  sermouse - ok
15:47:56.0816 3188  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
15:47:56.0816 3188  SessionEnv - ok
15:47:56.0816 3188  [ A554811BCD09279536440C964AE35BBF ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
15:47:56.0816 3188  sffdisk - ok
15:47:56.0816 3188  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
15:47:56.0832 3188  sffp_mmc - ok
15:47:56.0832 3188  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
15:47:56.0832 3188  sffp_sd - ok
15:47:56.0832 3188  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
15:47:56.0832 3188  sfloppy - ok
15:47:56.0832 3188  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
15:47:56.0847 3188  SharedAccess - ok
15:47:56.0847 3188  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:47:56.0847 3188  ShellHWDetection - ok
15:47:56.0847 3188  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
15:47:56.0847 3188  SiSRaid2 - ok
15:47:56.0863 3188  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
15:47:56.0863 3188  SiSRaid4 - ok
15:47:56.0863 3188  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
15:47:56.0863 3188  Smb - ok
15:47:56.0863 3188  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
15:47:56.0863 3188  SNMPTRAP - ok
15:47:56.0878 3188  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr           C:\Windows\system32\drivers\spldr.sys
15:47:56.0878 3188  spldr - ok
15:47:56.0878 3188  [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler         C:\Windows\System32\spoolsv.exe
15:47:56.0894 3188  Spooler - ok
15:47:56.0925 3188  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
15:47:56.0972 3188  sppsvc - ok
15:47:56.0972 3188  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
15:47:56.0972 3188  sppuinotify - ok
15:47:56.0988 3188  [ 602884696850C86434530790B110E8EB ] sptd            C:\Windows\System32\Drivers\sptd.sys
15:47:57.0003 3188  sptd - ok
15:47:57.0003 3188  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv             C:\Windows\system32\DRIVERS\srv.sys
15:47:57.0003 3188  srv - ok
15:47:57.0019 3188  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
15:47:57.0019 3188  srv2 - ok
15:47:57.0019 3188  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
15:47:57.0019 3188  srvnet - ok
15:47:57.0035 3188  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
15:47:57.0035 3188  SSDPSRV - ok
15:47:57.0035 3188  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc         C:\Windows\system32\sstpsvc.dll
15:47:57.0035 3188  SstpSvc - ok
15:47:57.0035 3188  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
15:47:57.0035 3188  stexstor - ok
15:47:57.0050 3188  [ DECACB6921DED1A38642642685D77DAC ] StillCam        C:\Windows\system32\DRIVERS\serscan.sys
15:47:57.0050 3188  StillCam - ok
15:47:57.0050 3188  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
15:47:57.0066 3188  stisvc - ok
15:47:57.0066 3188  [ 7785DC213270D2FC066538DAF94087E7 ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
15:47:57.0066 3188  storflt - ok
15:47:57.0066 3188  [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc         C:\Windows\system32\drivers\storvsc.sys
15:47:57.0066 3188  storvsc - ok
15:47:57.0066 3188  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\drivers\swenum.sys
15:47:57.0066 3188  swenum - ok
15:47:57.0082 3188  [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard     C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
15:47:57.0082 3188  SwitchBoard - ok
15:47:57.0097 3188  [ E08E46FDD841B7184194011CA1955A0B ] swprv           C:\Windows\System32\swprv.dll
15:47:57.0097 3188  swprv - ok
15:47:57.0097 3188  Synth3dVsc - ok
15:47:57.0128 3188  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain         C:\Windows\system32\sysmain.dll
15:47:57.0144 3188  SysMain - ok
15:47:57.0144 3188  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
15:47:57.0144 3188  TabletInputService - ok
15:47:57.0222 3188  [ 7C7E4D7EAC200630DE8581C8B67D36AB ] TabletServicePen C:\Program Files\Tablet\Pen\Pen_Tablet.exe
15:47:57.0316 3188  TabletServicePen - ok
15:47:57.0332 3188  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv         C:\Windows\System32\tapisrv.dll
15:47:57.0332 3188  TapiSrv - ok
15:47:57.0332 3188  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS             C:\Windows\System32\tbssvc.dll
15:47:57.0332 3188  TBS - ok
15:47:57.0347 3188  [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
15:47:57.0378 3188  Tcpip - ok
15:47:57.0394 3188  [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
15:47:57.0394 3188  TCPIP6 - ok
15:47:57.0410 3188  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
15:47:57.0410 3188  tcpipreg - ok
15:47:57.0410 3188  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
15:47:57.0410 3188  TDPIPE - ok
15:47:57.0410 3188  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
15:47:57.0410 3188  TDTCP - ok
15:47:57.0410 3188  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
15:47:57.0425 3188  tdx - ok
15:47:57.0457 3188  [ 6B1B2F8D62D606B200C2072564090104 ] TeamViewer8     C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
15:47:57.0488 3188  TeamViewer8 - ok
15:47:57.0488 3188  [ F5520DBB47C60EE83024B38720ABDA24 ] teamviewervpn   C:\Windows\system32\DRIVERS\teamviewervpn.sys
15:47:57.0488 3188  teamviewervpn - ok
15:47:57.0488 3188  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\drivers\termdd.sys
15:47:57.0503 3188  TermDD - ok
15:47:57.0503 3188  [ 2E648163254233755035B46DD7B89123 ] TermService     C:\Windows\System32\termsrv.dll
15:47:57.0519 3188  TermService - ok
15:47:57.0519 3188  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
15:47:57.0519 3188  Themes - ok
15:47:57.0519 3188  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER     C:\Windows\system32\mmcss.dll
15:47:57.0519 3188  THREADORDER - ok
15:47:57.0535 3188  [ C4F3C11A5C4F413D16B09A33DCF7554C ] TouchServicePen C:\Program Files\Tablet\Pen\Pen_TouchService.exe
15:47:57.0550 3188  TouchServicePen - ok
15:47:57.0550 3188  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
15:47:57.0550 3188  TrkWks - ok
15:47:57.0550 3188  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:47:57.0566 3188  TrustedInstaller - ok
15:47:57.0566 3188  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
15:47:57.0566 3188  tssecsrv - ok
15:47:57.0566 3188  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
15:47:57.0566 3188  TsUsbFlt - ok
15:47:57.0566 3188  tsusbhub - ok
15:47:57.0582 3188  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
15:47:57.0582 3188  tunnel - ok
15:47:57.0582 3188  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
15:47:57.0582 3188  uagp35 - ok
15:47:57.0582 3188  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
15:47:57.0597 3188  udfs - ok
15:47:57.0597 3188  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
15:47:57.0597 3188  UI0Detect - ok
15:47:57.0597 3188  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
15:47:57.0597 3188  uliagpkx - ok
15:47:57.0597 3188  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
15:47:57.0613 3188  umbus - ok
15:47:57.0613 3188  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
15:47:57.0613 3188  UmPass - ok
15:47:57.0613 3188  [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService    C:\Windows\System32\umrdp.dll
15:47:57.0613 3188  UmRdpService - ok
15:47:57.0628 3188  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
15:47:57.0628 3188  upnphost - ok
15:47:57.0628 3188  [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64       C:\Windows\system32\Drivers\usbaapl64.sys
15:47:57.0644 3188  USBAAPL64 - ok
15:47:57.0644 3188  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
15:47:57.0644 3188  usbccgp - ok
15:47:57.0644 3188  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
15:47:57.0660 3188  usbcir - ok
15:47:57.0660 3188  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci         C:\Windows\system32\drivers\usbehci.sys
15:47:57.0660 3188  usbehci - ok
15:47:57.0660 3188  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
15:47:57.0660 3188  usbhub - ok
15:47:57.0675 3188  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
15:47:57.0675 3188  usbohci - ok
15:47:57.0675 3188  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
15:47:57.0675 3188  usbprint - ok
15:47:57.0675 3188  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:47:57.0675 3188  USBSTOR - ok
15:47:57.0675 3188  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
15:47:57.0675 3188  usbuhci - ok
15:47:57.0691 3188  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms           C:\Windows\System32\uxsms.dll
15:47:57.0691 3188  UxSms - ok
15:47:57.0691 3188  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
15:47:57.0691 3188  VaultSvc - ok
15:47:57.0691 3188  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
15:47:57.0691 3188  vdrvroot - ok
15:47:57.0707 3188  [ 8D6B481601D01A456E75C3210F1830BE ] vds             C:\Windows\System32\vds.exe
15:47:57.0707 3188  vds - ok
15:47:57.0707 3188  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
15:47:57.0707 3188  vga - ok
15:47:57.0707 3188  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave         C:\Windows\System32\drivers\vga.sys
15:47:57.0707 3188  VgaSave - ok
15:47:57.0707 3188  VGPU - ok
15:47:57.0753 3188  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
15:47:57.0769 3188  vhdmp - ok
15:47:57.0785 3188  [ 906A7C6B6659A650648CF21998270945 ] VIAHdAudAddService C:\Windows\system32\drivers\viahduaa.sys
15:47:57.0800 3188  VIAHdAudAddService - ok
15:47:57.0816 3188  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
15:47:57.0816 3188  viaide - ok
15:47:57.0816 3188  [ 86EA3E79AE350FEA5331A1303054005F ] vmbus           C:\Windows\system32\drivers\vmbus.sys
15:47:57.0816 3188  vmbus - ok
15:47:57.0816 3188  [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
15:47:57.0816 3188  VMBusHID - ok
15:47:57.0832 3188  [ 091E009EF749C9D65CF9ADFAD316D251 ] vmm             C:\Windows\system32\Treiber\vmm.sys
15:47:57.0832 3188  vmm - ok
15:47:57.0832 3188  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
15:47:57.0832 3188  volmgr - ok
15:47:57.0847 3188  [ A255814907C89BE58B79EF2F189B843B ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
15:47:57.0847 3188  volmgrx - ok
15:47:57.0847 3188  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
15:47:57.0863 3188  volsnap - ok
15:47:57.0863 3188  [ BC2EA40B98B5E866D9A4F98AFB66B682 ] VPCNetS2        C:\Windows\system32\DRIVERS\VMNetSrv.sys
15:47:57.0863 3188  VPCNetS2 - ok
15:47:57.0863 3188  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
15:47:57.0863 3188  vsmraid - ok
15:47:57.0894 3188  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS             C:\Windows\system32\vssvc.exe
15:47:57.0910 3188  VSS - ok
15:47:57.0910 3188  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
15:47:57.0910 3188  vwifibus - ok
15:47:57.0925 3188  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time         C:\Windows\system32\w32time.dll
15:47:57.0925 3188  W32Time - ok
15:47:57.0925 3188  [ E04D43C7D1641E95D35CAE6086C7E350 ] wacommousefilter C:\Windows\system32\DRIVERS\wacommousefilter.sys
15:47:57.0925 3188  wacommousefilter - ok
15:47:57.0941 3188  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
15:47:57.0941 3188  WacomPen - ok
15:47:57.0941 3188  [ EC1CEB237E365330C1FCFC4876AA0AC0 ] wacomvhid       C:\Windows\system32\DRIVERS\wacomvhid.sys
15:47:57.0941 3188  wacomvhid - ok
15:47:57.0941 3188  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
15:47:57.0941 3188  WANARP - ok
15:47:57.0941 3188  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
15:47:57.0941 3188  Wanarpv6 - ok
15:47:57.0972 3188  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
15:47:57.0988 3188  wbengine - ok
15:47:57.0988 3188  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
15:47:57.0988 3188  WbioSrvc - ok
15:47:58.0003 3188  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc         C:\Windows\System32\wcncsvc.dll
15:47:58.0003 3188  wcncsvc - ok
15:47:58.0003 3188  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
15:47:58.0003 3188  WcsPlugInService - ok
15:47:58.0003 3188  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
15:47:58.0003 3188  Wd - ok
15:47:58.0019 3188  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
15:47:58.0019 3188  Wdf01000 - ok
15:47:58.0035 3188  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
15:47:58.0035 3188  WdiServiceHost - ok
15:47:58.0035 3188  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost   C:\Windows\system32\wdi.dll
15:47:58.0035 3188  WdiSystemHost - ok
15:47:58.0035 3188  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient       C:\Windows\System32\webclnt.dll
15:47:58.0050 3188  WebClient - ok
15:47:58.0050 3188  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
15:47:58.0050 3188  Wecsvc - ok
15:47:58.0066 3188  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
15:47:58.0066 3188  wercplsupport - ok
15:47:58.0066 3188  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
15:47:58.0066 3188  WerSvc - ok
15:47:58.0066 3188  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
15:47:58.0066 3188  WfpLwf - ok
15:47:58.0066 3188  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
15:47:58.0066 3188  WIMMount - ok
15:47:58.0082 3188  WinDefend - ok
15:47:58.0082 3188  WinHttpAutoProxySvc - ok
15:47:58.0082 3188  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
15:47:58.0097 3188  Winmgmt - ok
15:47:58.0113 3188  [ BCB1310604AA415C4508708975B3931E ] WinRM           C:\Windows\system32\WsmSvc.dll
15:47:58.0128 3188  WinRM - ok
15:47:58.0144 3188  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
15:47:58.0144 3188  WinUsb - ok
15:47:58.0160 3188  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc         C:\Windows\System32\wlansvc.dll
15:47:58.0160 3188  Wlansvc - ok
15:47:58.0160 3188  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
15:47:58.0160 3188  WmiAcpi - ok
15:47:58.0175 3188  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
15:47:58.0175 3188  wmiApSrv - ok
15:47:58.0175 3188  WMPNetworkSvc - ok
15:47:58.0175 3188  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
15:47:58.0191 3188  WPCSvc - ok
15:47:58.0191 3188  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
15:47:58.0191 3188  WPDBusEnum - ok
15:47:58.0191 3188  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
15:47:58.0191 3188  ws2ifsl - ok
15:47:58.0191 3188  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
15:47:58.0207 3188  wscsvc - ok
15:47:58.0207 3188  [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice  C:\Windows\system32\DRIVERS\WSDPrint.sys
15:47:58.0207 3188  WSDPrintDevice - ok
15:47:58.0207 3188  WSearch - ok
15:47:58.0238 3188  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
15:47:58.0253 3188  wuauserv - ok
15:47:58.0269 3188  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
15:47:58.0269 3188  WudfPf - ok
15:47:58.0269 3188  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
15:47:58.0269 3188  WUDFRd - ok
15:47:58.0269 3188  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
15:47:58.0285 3188  wudfsvc - ok
15:47:58.0285 3188  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc         C:\Windows\System32\wwansvc.dll
15:47:58.0285 3188  WwanSvc - ok
15:47:58.0285 3188  ================ Scan global ===============================
15:47:58.0300 3188  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
15:47:58.0300 3188  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
15:47:58.0300 3188  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
15:47:58.0316 3188  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
15:47:58.0316 3188  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
15:47:58.0316 3188  [Global] - ok
15:47:58.0316 3188  ================ Scan MBR ==================================
15:47:58.0316 3188  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
15:47:58.0410 3188  \Device\Harddisk0\DR0 - ok
15:47:58.0410 3188  ================ Scan VBR ==================================
15:47:58.0425 3188  [ 9F7F1E1DE59BE7FC6D1F76367EB552EE ] \Device\Harddisk0\DR0\Partition1
15:47:58.0425 3188  \Device\Harddisk0\DR0\Partition1 - ok
15:47:58.0425 3188  [ 67A937CE03893D8730F631B97C9D4A13 ] \Device\Harddisk0\DR0\Partition2
15:47:58.0425 3188  \Device\Harddisk0\DR0\Partition2 - ok
15:47:58.0425 3188  ============================================================
15:47:58.0425 3188  Scan finished
15:47:58.0425 3188  ============================================================
15:47:58.0425 1060  Detected object count: 0
15:47:58.0425 1060  Actual detected object count: 0
         dds DDS Logfile: DDS Logfile: Code: 
  ATTFilter DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 9.0.8112.16470  BrowserJavaVersion: 10.17.2
Run by admin at 15:53:37 on 2013-04-09
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.49.1031.18.4087.1950 [GMT 2:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Spybot - Search and Destroy *Disabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\clbcatqd.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\GFilterSvc.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe
C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\PSD Temp\Acrobat 11.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\SearchIndexer.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.de/
mWinlogon: Userinit = userinit.exe,
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: DNS Error Helper: {9B6B03F1-16CF-4491-BBBB-E872802DD717} - C:\ProgramData\DNSErrorHelper\bho.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Adobe Acrobat Create PDF Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
EB: Developer Tools: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll
uRun: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [AdobeBridge] <no file>
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
mRun: [Acrobat Assistant 8.0] "C:\PSD Temp\Acrobat 11.0\Acrobat\Acrotray.exe"
mRun: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC} - C:\Program Files (x86)\Java\jre7\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab
TCP: NameServer = 192.168.178.1
TCP: Interfaces\{EC6C48CC-AACA-4FBB-8D2E-E299CA8E61B1} : DHCPNameServer = 192.168.178.1
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [Ocs_SM] C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
.
INFO: x64-HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1	www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
FF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
FF - plugin: C:\PSD Temp\Acrobat 11.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Users\admin\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-02-20 09:57; dnshelp@dnshelp.com; C:\Users\admin\AppData\Roaming\Helper
FF - ExtSQL: 2013-03-06 10:27; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: 2013-03-06 10:34; firebug@software.joehewitt.com; C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\firebug@software.joehewitt.com.xpi
FF - ExtSQL: 2013-03-15 11:37; web2pdfextension@web2pdf.adobedotcom; C:\PSD Temp\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]
R2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344]
R2 AddonsHelper;AddonsHelper;C:\Users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [2013-2-20 896512]
R2 dplazsvr;Konfiguration Machine Bluetooth;C:\Windows\System32\clbcatqd.exe [2013-2-20 114176]
R2 GFilterSvc;G-Filter Service;C:\Windows\System32\GFilterSvc.exe [2013-2-20 121856]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2010-10-24 130008]
R2 SDFirewallService;Spybot-S&D 2 Firewall Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe [2011-7-27 3585696]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-4-2 166528]
R2 SearchAnonymizer;SearchAnonymizer;C:\Users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2013-2-20 40960]
R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2013-1-7 6581624]
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-3-5 3560288]
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2013-1-7 528760]
R3 NisSrv;Microsoft-Netzwerkinspektion;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-9-28 239616]
R3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2011-2-2 35112]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2010-9-28 1250816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SDMonitorService;Spybot-S&D 2 Monitoring Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe [2011-7-27 3834456]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-4-2 1188896]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-4-2 1395736]
S3 BackupReader;BackupReader;C:\Windows\System32\drivers\BackupReader.sys [2011-3-2 63872]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-6-9 20992]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-9 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712]
.
=============== File Associations ===============
.
FileExt: .js: jsfile="C:\PSD Temp\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"
ShellExec: dreamweaver.exe: Open="C:\PSD Temp\Adobe Dreamweaver CS6\dreamweaver.exe", "%1"
.
=============== Created Last 30 ================
.
2013-04-09 13:13:29	9311288	----a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{67657373-B52E-4FEB-ACFF-90C9B74582D1}\mpengine.dll
2013-04-09 09:00:16	--------	d-----w-	C:\_OTL
2013-04-08 09:39:55	9311288	----a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-06 09:44:36	--------	d-----w-	C:\Program Files (x86)\JTL-Software
2013-04-04 09:07:13	26520	----a-w-	C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-04-03 08:53:00	--------	d-----w-	C:\Users\admin\AppData\Local\WinZip
2013-03-26 07:57:18	19968	----a-w-	C:\Windows\System32\drivers\usb8023.sys
2013-03-25 08:12:50	73432	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-25 08:12:50	693976	----a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe
2013-03-22 07:43:37	972264	------w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{01CFE287-B1EE-415B-94AF-FAF5B56EE9A5}\gapaengine.dll
2013-03-21 10:37:16	--------	d-----w-	C:\Users\admin\AppData\Roaming\SolidDocuments
2013-03-19 15:56:49	--------	d-----w-	C:\Users\admin\AppData\Roaming\PC-FAX TX
2013-03-19 12:59:01	73728	------w-	C:\Windows\SysWow64\BRCrypt.dll
2013-03-15 12:33:18	--------	d-----w-	C:\Users\admin\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2013-03-15 10:35:47	--------	d-----w-	C:\ProgramData\ALM
.
==================== Find3M  ====================
.
2013-04-02 10:34:28	282744	------w-	C:\Windows\System32\MpSigStub.exe
2013-03-05 08:05:00	95648	----a-w-	C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-05 08:04:59	861088	----a-w-	C:\Windows\SysWow64\npdeployJava1.dll
2013-03-05 08:04:58	782240	----a-w-	C:\Windows\SysWow64\deployJava1.dll
2013-02-21 08:30:12	108448	----a-w-	C:\Windows\System32\WindowsAccessBridge-64.dll
2013-02-21 08:30:10	963488	----a-w-	C:\Windows\System32\deployJava1.dll
2013-02-21 08:30:10	1085344	----a-w-	C:\Windows\System32\npDeployJava1.dll
2013-02-20 08:54:47	121856	----a-w-	C:\Windows\System32\GFilterSvc.exe
2013-02-20 08:54:46	114176	----a-w-	C:\Windows\System32\clbcatqd.exe
2013-02-02 06:57:02	2312704	----a-w-	C:\Windows\System32\jscript9.dll
2013-02-02 06:47:24	1494528	----a-w-	C:\Windows\System32\inetcpl.cpl
2013-02-02 06:47:19	1392128	----a-w-	C:\Windows\System32\wininet.dll
2013-02-02 06:42:18	173056	----a-w-	C:\Windows\System32\ieUnatt.exe
2013-02-02 06:41:51	599040	----a-w-	C:\Windows\System32\vbscript.dll
2013-02-02 06:38:01	2382848	----a-w-	C:\Windows\System32\mshtml.tlb
2013-02-02 03:38:35	1800704	----a-w-	C:\Windows\SysWow64\jscript9.dll
2013-02-02 03:30:32	1427968	----a-w-	C:\Windows\SysWow64\inetcpl.cpl
2013-02-02 03:30:21	1129472	----a-w-	C:\Windows\SysWow64\wininet.dll
2013-02-02 03:26:47	142848	----a-w-	C:\Windows\SysWow64\ieUnatt.exe
2013-02-02 03:26:21	420864	----a-w-	C:\Windows\SysWow64\vbscript.dll
2013-02-02 03:23:28	2382848	----a-w-	C:\Windows\SysWow64\mshtml.tlb
2013-01-20 14:59:04	230320	----a-w-	C:\Windows\System32\drivers\MpFilter.sys
2013-01-20 14:59:04	130008	----a-w-	C:\Windows\System32\drivers\NisDrvWFP.sys
.
============= FINISH: 15:53:47,00 ===============
         --- --- --- dds-attach Code: 
  ATTFilter . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 28.09.2010 14:14:01 System Uptime: 09.04.2013 15:01:28 (0 hours ago) . Motherboard: ASRock | | P55M Pro Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz | CPUSocket | 2668/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 112 GiB total, 19,818 GiB free. D: is CDROM () F: is Removable G: is Removable H: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP417: 26.03.2013 18:08:24 - Windows Update RP418: 02.04.2013 08:41:49 - Windows Update RP419: 06.04.2013 10:33:51 - Windows Update RP420: 09.04.2013 11:02:54 - OTL Restore Point - 09.04.2013 11:02:54 RP421: 09.04.2013 15:13:10 - Windows Update . ==== Installed Programs ====================== . 3.4.0.9271.1 ABBYY FineReader 10 Corporate Edition Adobe Acrobat XI Pro Adobe AIR Adobe Dreamweaver CS6 Adobe Flash Player 11 Plugin Adobe Help Manager Adobe Illustrator CS6 Adobe InDesign CS6 Adobe Media Player Adobe Photoshop CS6 Adobe Reader XI (11.0.02) - Deutsch Adobe Shockwave Player 12.0 Adobe Widget Browser Bamboo Bamboo Dock BenVista PhotoZoom Pro 4.1.2 Brother MFL-Pro Suite MFC-9840CDW CDBurnerXP CINEMA 4D 12.016 Crazybump (remove only) DebugMode Wink DiffDaff Version 1.0 EditPlus 3 erLT Evrsoft First Page 2006 ffdshow x64 v1.2.4422 [2012-04-09] FileZilla Client 3.6.0.2 Flash Slideshow Maker Pro 5.00 FlashSlider 4.3.1 FolderVisualizer G-Filter Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper Haali Media Splitter HD Tune Pro 5.00 HiJackThis IcoFX 1.6.4 J2SE Runtime Environment 5.0 Update 21 Java 7 Update 15 (64-bit) Java 7 Update 17 Java Auto Updater JavaFX 2.1.1 JDownloader JTL-Wawi Logitech SetPoint 5.20 Malwarebytes Anti-Malware Version 1.70.0.1100 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft .NET Framework 4 Extended Microsoft Antimalware Service DE-DE Language Pack Microsoft Security Client Microsoft Security Client DE-DE Language Pack Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server Management Studio Express Microsoft SQL Server Native Client Microsoft Virtual PC 2007 Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft_VC80_ATL_x86_x64 Microsoft_VC80_CRT_x86 Microsoft_VC80_CRT_x86_x64 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFC_x86_x64 Microsoft_VC80_MFCLOC_x86 Microsoft_VC80_MFCLOC_x86_x64 Microsoft_VC90_ATL_x86 Microsoft_VC90_ATL_x86_x64 Microsoft_VC90_CRT_x86 Microsoft_VC90_CRT_x86_x64 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFC_x86_x64 Mozilla Firefox 20.0 (x86 de) Mozilla Maintenance Service Mozilla Thunderbird 17.0.5 (x86 de) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Notepad++ NVIDIA Display Control Panel NVIDIA Grafiktreiber 310.70 NVIDIA Install Application NVIDIA Photoshop Plug-ins 64 bit NVIDIA Systemsteuerung 310.70 NVIDIA Update 1.10.8 NVIDIA Update Components Nvu 1.0 OpenOffice.org 3.2 PandoraRecovery (Remove Only) PDF-Viewer PDF Editor 3 PDF Settings CS6 PDF24 Creator 4.5.0 PDFCreator PhotoRescue PC v3.2.2.12903 PIXMA Extended Survey Program PixPlant 2.0.50 Platform PSPad editor QuickTime RAR Password Recovery Magic v6.1.1.386 Realtek Ethernet Controller Driver For Windows Vista and Later Safari SearchAnonymizer Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft .NET Framework 4 Extended (KB2736428) Security Update for Microsoft .NET Framework 4 Extended (KB2742595) Sothink SWF Quicker Spybot - Search & Destroy Spybot - Search & Destroy 2 SuperMailer 5.66 swMSM TeamViewer 8 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) User's Guides VIA Plattform-Geräte-Manager VLC media player 2.0.5 Webocton - Scriptly 0.8.95.6 WebTablet FB Plugin WebTablet IE Plugin WebTablet Netscape Plugin WinHTTrack Website Copier 3.45-3 WinMerge 2.12.4 WinRAR WinZip 17.0 . ==== End Of File =========================== | 
|  09.04.2013, 15:14 | #4 | 
| /// TB-Ausbilder    |   Haeufige Abstuerze und weiterleitungen im Firefox Also etwas sehr schlimmes ist nicht dabei. Machen wir mal weiter: Scan mit Combofix 
 
				__________________  Digitale Freibeuter gegen Malware!  Keine Hilfe per PM! | 
|  09.04.2013, 15:32 | #5 | 
|  |   Haeufige Abstuerze und weiterleitungen im Firefox Da ist sie ComboFix Code: 
  ATTFilter ComboFix 13-04-08.04 - admin 09.04.2013  16:24:21.1.4 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.49.1031.18.4087.1641 [GMT 2:00]
ausgeführt von:: c:\users\admin\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Spybot - Search and Destroy *Disabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\admin\g2mdlhlpx.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-03-09 bis 2013-04-09  ))))))))))))))))))))))))))))))
.
.
2013-04-09 14:27 . 2013-04-09 14:27	--------	d-----w-	c:\users\UpdatusUser\AppData\Local\temp
2013-04-09 14:27 . 2013-04-09 14:27	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-04-09 13:13 . 2013-03-15 06:28	9311288	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{67657373-B52E-4FEB-ACFF-90C9B74582D1}\mpengine.dll
2013-04-09 09:00 . 2013-04-09 09:00	--------	d-----w-	C:\_OTL
2013-04-08 09:39 . 2013-03-15 06:28	9311288	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-06 09:44 . 2013-04-06 09:44	--------	d-----w-	c:\program files (x86)\JTL-Software
2013-04-03 08:53 . 2013-04-03 08:53	--------	d-----w-	c:\users\admin\AppData\Local\WinZip
2013-04-03 07:47 . 2013-04-04 06:03	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2013-03-26 07:57 . 2013-02-12 04:12	19968	----a-w-	c:\windows\system32\drivers\usb8023.sys
2013-03-25 08:12 . 2013-03-25 08:12	73432	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-25 08:12 . 2013-03-25 08:12	693976	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-22 07:43 . 2012-12-03 08:51	972264	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01CFE287-B1EE-415B-94AF-FAF5B56EE9A5}\gapaengine.dll
2013-03-21 10:37 . 2013-03-21 10:37	--------	d-----w-	c:\users\admin\AppData\Roaming\SolidDocuments
2013-03-19 15:56 . 2013-03-21 08:30	--------	d-----w-	c:\users\admin\AppData\Roaming\PC-FAX TX
2013-03-19 12:59 . 2006-07-07 11:40	73728	------w-	c:\windows\SysWow64\BRCrypt.dll
2013-03-15 12:33 . 2013-03-15 12:33	--------	d-----w-	c:\users\admin\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2013-03-15 10:35 . 2013-03-15 10:35	--------	d-----w-	c:\programdata\ALM
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-02 10:34 . 2010-09-28 13:49	282744	------w-	c:\windows\system32\MpSigStub.exe
2013-03-13 16:08 . 2010-09-30 06:45	72013344	----a-w-	c:\windows\system32\MRT.exe
2013-03-05 08:05 . 2013-03-05 08:05	95648	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-05 08:04 . 2012-05-07 14:22	861088	----a-w-	c:\windows\SysWow64\npdeployJava1.dll
2013-03-05 08:04 . 2010-09-29 07:46	782240	----a-w-	c:\windows\SysWow64\deployJava1.dll
2013-02-21 08:30 . 2013-02-21 08:30	108448	----a-w-	c:\windows\system32\WindowsAccessBridge-64.dll
2013-02-21 08:30 . 2013-02-21 08:30	310688	----a-w-	c:\windows\system32\javaws.exe
2013-02-21 08:30 . 2013-02-21 08:30	188832	----a-w-	c:\windows\system32\javaw.exe
2013-02-21 08:30 . 2013-02-21 08:30	188320	----a-w-	c:\windows\system32\java.exe
2013-02-21 08:30 . 2012-06-22 08:43	963488	----a-w-	c:\windows\system32\deployJava1.dll
2013-02-21 08:30 . 2012-06-22 08:43	1085344	----a-w-	c:\windows\system32\npDeployJava1.dll
2013-02-20 08:54 . 2013-02-20 08:54	121856	----a-w-	c:\windows\system32\GFilterSvc.exe
2013-02-20 08:54 . 2013-02-20 08:54	114176	----a-w-	c:\windows\system32\clbcatqd.exe
2013-01-20 14:59 . 2013-01-20 14:59	230320	----a-w-	c:\windows\system32\drivers\MpFilter.sys
2013-01-20 14:59 . 2010-10-24 20:25	130008	----a-w-	c:\windows\system32\drivers\NisDrvWFP.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717}]
2013-02-20 08:54	138752	----a-w-	c:\programdata\DNSErrorHelper\bho.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-23 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-07-04 3921432]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2012-10-16 646744]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"Acrobat Assistant 8.0"="c:\psd temp\Acrobat 11.0\Acrobat\Acrotray.exe" [2012-12-18 3478752]
"BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 AddonsHelper;AddonsHelper;c:\users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SDMonitorService;Spybot-S&D 2 Monitoring Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDMonSvc.exe [2011-05-10 3834456]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-07-04 1188896]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-07-04 1395736]
R3 ALSysIO;ALSysIO;c:\users\admin\AppData\Local\Temp\ALSysIO64.sys [x]
R3 BackupReader;BackupReader;c:\windows\system32\DRIVERS\BackupReader.sys [2011-03-02 63872]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-29 834544]
S2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344]
S2 dplazsvr;Konfiguration Machine Bluetooth;c:\windows\system32\clbcatqd.exe [2013-02-20 114176]
S2 GFilterSvc;G-Filter Service;c:\windows\System32\GFilterSvc.exe [2013-02-20 121856]
S2 SDFirewallService;Spybot-S&D 2 Firewall Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFWSvc.exe [2011-05-10 3585696]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-03-22 166528]
S2 SearchAnonymizer;SearchAnonymizer;c:\users\admin\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2013-02-20 40960]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-07-05 6581624]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-07-05 528760]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-01-12 35112]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-09-17 1250816]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 58143583
*Deregistered* - 58143583
*Deregistered* - aswMBR
.
Inhalt des "geplante Tasks" Ordners
.
2013-04-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-25 08:12]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001Core.job
- c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001UA.job
- c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
"Ocs_SM"="c:\users\admin\AppData\Roaming\OCS\SM\SearchAnonymizer.exe" [2013-02-20 106496]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-01-24 477600]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\
FF - ExtSQL: 2013-02-20 09:57; dnshelp@dnshelp.com; c:\users\admin\AppData\Roaming\Helper
FF - ExtSQL: 2013-03-06 10:27; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: 2013-03-06 10:34; firebug@software.joehewitt.com; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\firebug@software.joehewitt.com.xpi
FF - ExtSQL: 2013-03-15 11:37; web2pdfextension@web2pdf.adobedotcom; c:\psd temp\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Notify-SDWinLogon - SDWinLogon.dll
AddRemove-PandoraRecovery - g:\pandora recovery\Uninstall.exe
AddRemove-PhotoRescue PC_is1 - g:\datenrettung\PhotoRescue PC v3.2.2.12903\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-04-09  16:29:15
ComboFix-quarantined-files.txt  2013-04-09 14:29
.
Vor Suchlauf: 21 Verzeichnis(se), 21.298.053.120 Bytes frei
Nach Suchlauf: 24 Verzeichnis(se), 21.851.488.256 Bytes frei
.
- - End Of File - - 9373DAFF21AC00FBC24974B5A7BA0643
          | 
|  09.04.2013, 15:38 | #6 | 
| /// TB-Ausbilder    |   Haeufige Abstuerze und weiterleitungen im Firefox Fein, wir machen noch den Rest weg. Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Deinstallation von Programmen 
 Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen Downloade Dir bitte  AdwCleaner auf deinen Desktop. 
 Schritt 3: AdwCleaner wiederholen Die vorliegende Version der Werbeprogramme ist ziemlich hartnäckig und kann von AdwCleaner erfahrungsgemäss nur bei zweimaliger Anwendung entfernt werden. Also wiederhole diesen Schritt bitte und poste auch das Logfile. Schritt 4: Combofix-Skript 
 
				__________________ --> Haeufige Abstuerze und weiterleitungen im Firefox | 
|  09.04.2013, 16:48 | #7 | 
|  |   Haeufige Abstuerze und weiterleitungen im Firefox Spybot & SearchAnonymizer wurden geloescht.  AdwCleaner[S1] Code: 
  ATTFilter # AdwCleaner v2.200 - Datei am 09/04/2013 um 17:25:09 erstellt
# Aktualisiert am 02/04/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : admin - MAURICE-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\admin\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
         Code: 
  ATTFilter # AdwCleaner v2.200 - Datei am 09/04/2013 um 17:25:25 erstellt
# Aktualisiert am 02/04/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : admin - MAURICE-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\admin\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
Gestoppt & Gelöscht : GFilterSvc
Gestoppt & Gelöscht : SearchAnonymizer
***** [Dateien / Ordner] *****
Ordner Gelöscht : C:\ProgramData\DeviceVM
Ordner Gelöscht : C:\Users\admin\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\admin\AppData\Roaming\OCS
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{206a7328-437f-4bd9-b53e-12bfee24d588}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16470
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v20.0 (de)
Datei : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\prefs.js
[OK] Die Datei ist sauber.
-\\ Google Chrome v26.0.1410.43
Datei : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [331 octets] - [09/04/2013 17:25:09]
AdwCleaner[S2].txt - [1839 octets] - [09/04/2013 17:25:25]
########## EOF - C:\AdwCleaner[S2].txt - [1899 octets] ##########
         AdwCleaner[S3] Code: 
  ATTFilter # AdwCleaner v2.200 - Datei am 09/04/2013 um 17:28:40 erstellt
# Aktualisiert am 02/04/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzer : admin - MAURICE-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\admin\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
***** [Registrierungsdatenbank] *****
***** [Internet Browser] *****
-\\ Internet Explorer v9.0.8112.16470
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v20.0 (de)
Datei : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\prefs.js
[OK] Die Datei ist sauber.
-\\ Google Chrome v26.0.1410.43
Datei : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [331 octets] - [09/04/2013 17:25:09]
AdwCleaner[S2].txt - [1966 octets] - [09/04/2013 17:25:25]
AdwCleaner[S3].txt - [1003 octets] - [09/04/2013 17:28:40]
########## EOF - C:\AdwCleaner[S3].txt - [1063 octets] ##########
         ComboFix Code: 
  ATTFilter ComboFix 13-04-09.01 - admin 09.04.2013  17:35:36.2.4 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.49.1031.18.4087.2401 [GMT 2:00]
ausgeführt von:: c:\users\admin\Downloads\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\admin\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\clbcatqd.exe"
"c:\windows\System32\GFilterSvc.exe"
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\clbcatqd.exe
c:\windows\System32\GFilterSvc.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Treiber/Dienste   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_dplazsvr
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-03-09 bis 2013-04-09  ))))))))))))))))))))))))))))))
.
.
2013-04-09 15:38 . 2013-04-09 15:38	--------	d-----w-	c:\users\UpdatusUser\AppData\Local\temp
2013-04-09 13:13 . 2013-03-15 06:28	9311288	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{67657373-B52E-4FEB-ACFF-90C9B74582D1}\mpengine.dll
2013-04-09 09:00 . 2013-04-09 09:00	--------	d-----w-	C:\_OTL
2013-04-08 09:39 . 2013-03-15 06:28	9311288	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-06 09:44 . 2013-04-06 09:44	--------	d-----w-	c:\program files (x86)\JTL-Software
2013-04-03 08:53 . 2013-04-03 08:53	--------	d-----w-	c:\users\admin\AppData\Local\WinZip
2013-04-03 07:47 . 2013-04-04 06:03	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2013-03-26 07:57 . 2013-02-12 04:12	19968	----a-w-	c:\windows\system32\drivers\usb8023.sys
2013-03-25 08:12 . 2013-03-25 08:12	73432	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-25 08:12 . 2013-03-25 08:12	693976	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-22 07:43 . 2012-12-03 08:51	972264	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{01CFE287-B1EE-415B-94AF-FAF5B56EE9A5}\gapaengine.dll
2013-03-21 10:37 . 2013-03-21 10:37	--------	d-----w-	c:\users\admin\AppData\Roaming\SolidDocuments
2013-03-19 15:56 . 2013-03-21 08:30	--------	d-----w-	c:\users\admin\AppData\Roaming\PC-FAX TX
2013-03-19 12:59 . 2006-07-07 11:40	73728	------w-	c:\windows\SysWow64\BRCrypt.dll
2013-03-15 12:33 . 2013-03-15 12:33	--------	d-----w-	c:\users\admin\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2013-03-15 10:35 . 2013-03-15 10:35	--------	d-----w-	c:\programdata\ALM
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-02 10:34 . 2010-09-28 13:49	282744	------w-	c:\windows\system32\MpSigStub.exe
2013-03-13 16:08 . 2010-09-30 06:45	72013344	----a-w-	c:\windows\system32\MRT.exe
2013-03-05 08:05 . 2013-03-05 08:05	95648	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-05 08:04 . 2012-05-07 14:22	861088	----a-w-	c:\windows\SysWow64\npdeployJava1.dll
2013-03-05 08:04 . 2010-09-29 07:46	782240	----a-w-	c:\windows\SysWow64\deployJava1.dll
2013-02-21 08:30 . 2013-02-21 08:30	108448	----a-w-	c:\windows\system32\WindowsAccessBridge-64.dll
2013-02-21 08:30 . 2013-02-21 08:30	310688	----a-w-	c:\windows\system32\javaws.exe
2013-02-21 08:30 . 2013-02-21 08:30	188832	----a-w-	c:\windows\system32\javaw.exe
2013-02-21 08:30 . 2013-02-21 08:30	188320	----a-w-	c:\windows\system32\java.exe
2013-02-21 08:30 . 2012-06-22 08:43	963488	----a-w-	c:\windows\system32\deployJava1.dll
2013-02-21 08:30 . 2012-06-22 08:43	1085344	----a-w-	c:\windows\system32\npDeployJava1.dll
2013-01-20 14:59 . 2013-01-20 14:59	230320	----a-w-	c:\windows\system32\drivers\MpFilter.sys
2013-01-20 14:59 . 2010-10-24 20:25	130008	----a-w-	c:\windows\system32\drivers\NisDrvWFP.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717}]
2013-02-20 08:54	138752	----a-w-	c:\programdata\DNSErrorHelper\bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-21 2583040]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2012-10-16 646744]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"Acrobat Assistant 8.0"="c:\psd temp\Acrobat 11.0\Acrobat\Acrotray.exe" [2012-12-18 3478752]
"BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
"ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 AddonsHelper;AddonsHelper;c:\users\admin\AppData\Local\Temp\OCS\Downloads\d340164aef134ca45f5d3a3a8b8d1b79\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ALSysIO;ALSysIO;c:\users\admin\AppData\Local\Temp\ALSysIO64.sys [x]
R3 BackupReader;BackupReader;c:\windows\system32\DRIVERS\BackupReader.sys [2011-03-02 63872]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-29 834544]
S2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2011-07-05 6581624]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2011-07-05 528760]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2011-01-12 35112]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-09-17 1250816]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-04-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-25 08:12]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-23 07:08]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001Core.job
- c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3181291509-3413217637-2026685076-1001UA.job
- c:\users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-28 17:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-01-24 477600]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\
FF - ExtSQL: 2013-02-20 09:57; dnshelp@dnshelp.com; c:\users\admin\AppData\Roaming\Helper
FF - ExtSQL: 2013-03-06 10:27; {e4a8a97b-f2ed-450b-b12d-ee082ba24781}; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF - ExtSQL: 2013-03-06 10:34; firebug@software.joehewitt.com; c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\mcwtkzbr.default-1362561967315\extensions\firebug@software.joehewitt.com.xpi
FF - ExtSQL: 2013-03-15 11:37; web2pdfextension@web2pdf.adobedotcom; c:\psd temp\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-Ocs_SM - c:\users\admin\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
AddRemove-PandoraRecovery - g:\pandora recovery\Uninstall.exe
AddRemove-PhotoRescue PC_is1 - g:\datenrettung\PhotoRescue PC v3.2.2.12903\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe
c:\program files (x86)\TeamViewer\Version8\tv_w32.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-04-09  17:40:49 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-04-09 15:40
ComboFix2.txt  2013-04-09 14:29
.
Vor Suchlauf: 23 Verzeichnis(se), 22.976.995.328 Bytes frei
Nach Suchlauf: 25 Verzeichnis(se), 22.413.819.904 Bytes frei
.
- - End Of File - - 3E76A0C09AB26283556D6CB25347808B
          | 
|  09.04.2013, 16:55 | #8 | 
| /// TB-Ausbilder    |   Haeufige Abstuerze und weiterleitungen im Firefox Gut!   Soweit ich das sehe haben wir damit alles Schädliche entfernt. Um sicher sein zu können müssen jetzt noch ein paar Kontrollen machen und werden dann deinen Computer noch auf einen sicheren Stand bringen. Da diese Scans jetzt sehr lange dauern können bitte ich dich mir erst wieder zu schreiben, wenn du auch wirklich alles erledigt hast oder Probleme auftreten sollten. Schritt 1: Quick-Scan mit Malwarebytes Downloade Dir bitteSchritt 2: Hinweis: Der Scan kann sehr lange (einige Stunden) dauern!  Schritt 3: Scan mit SecurityCheck Downloade Dir bitte  SecurityCheck und: 
 
				__________________  Digitale Freibeuter gegen Malware!  Keine Hilfe per PM! | 
|  10.04.2013, 09:26 | #9 | 
|  |   Haeufige Abstuerze und weiterleitungen im Firefox Moin, es scheint schon einiges gebracht zu haben, bisher keine abstuerze oder weiterleitungen  mbam-log Code: 
  ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.04.10.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 admin :: MAURICE-PC [Administrator] 10.04.2013 08:53:02 mbam-log-2013-04-10 (08-53-02).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 243058 Laufzeit: 1 Minute(n), 26 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ESET Code: 
  ATTFilter ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=afc0c8404aac814a9ba2ecd641380693
# engine=13585
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-04-10 08:15:04
# local_time=2013-04-10 10:15:04 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5892 16777213 88 94 4672757 16414932 0 0
# scanned=356854
# found=0
# cleaned=0
# scan_time=1931
         Security Check Code: 
  ATTFilter book Results of screen317's Security Check version 0.99.61 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials (On Access scanning disabled!) Error obtaining update status for antivirus! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 JavaFX 2.1.1 Java 7 Update 17 Adobe Flash Player 11.6.602.180 Adobe Reader XI Mozilla Firefox (20.0) Mozilla Thunderbird (17.0.5) Google Chrome 25.0.1364.172 Google Chrome 26.0.1410.43 Google Chrome plugins... ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` | 
|  10.04.2013, 13:33 | #10 | 
| /// TB-Ausbilder    |   Haeufige Abstuerze und weiterleitungen im Firefox Prima!   Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich. Schritt 1: Tools deinstallieren Die Reihenfolge ist hier entscheidend. 
 Schritt 2: ESET deinstallieren (Optional) 
 Abschließend noch Tipps zu folgenden Themen: 
  Lesestoff: Systemupdates Man kann es gar nicht oft genug erwähnen, wie wichtig es ist, sein System aktuell zu halten. Dein Auto bringst du ja auch regelmässig zur Inspektion in die Werkstatt. Stelle also bitte sicher, dass die Systemupdates aktiviert sind: 
  Lesestoff: Softwareupdates Ebenso wichtig wie die Systemprogramme ist auch die Software, die du täglich nutzt. Die folgende Liste gibt dir einen kleinen Überblick mit Links zu den Updates, welche Programme dringend aktuell gehalten werden müssen (falls du sie überhaupt installiert hast und nutzt), weil durch deren Sicherheitslücken oft Malware auf die Computer gelangen kann: 
  Lesestoff: Sicherheitssoftware Würde dich jemand nackt auf dem Motorrad auf der Autobahn überholen würdest du auch den Kopf schütteln. Dein Computer braucht auch einen Schutz vor den täglichen kleinen Angriffen durch Schädlinge. Neben hervorragenden kommerziellen Anti-Viren-Lösungen gibt es auch durchaus gute Schutzprogramme, die kostenfrei mit reduziertem Funktionsumfang erhältlich sind. Aber vorsicht, hier gilt nicht "je mehr desto besser". Was du brauchst ist genau einen Virenscanner mit Hintergrundwächter. Nicht mehr und nicht weniger. Es gibt hier viele Produkte auf dem Markt, die einem gute Dienste leisten. Ich persönlich empfehle dir Avast Free Antivirus. Es bietet relativ guten Schutz, bei wenig nerviger Werbung und installiert dir ein Browserplugin, das dich vor gefährlichen Webseiten warnt. 
    Lesestoff: Sicheres Surfen Zunächst muss man sagen, dass es üblicherweise immer der menschliche Faktor ist, der es Malware ermöglicht auf einen Computer zu gelangen. Kaufst du Leuten, die an deiner Haustür klingeln, auch sofort ohne nachzudenken irgendwelches Zeug ab? Gewöhne dir daher zunächst einige Verhaltensregeln beim Surfen im Internet an: 
 Aber selbst bei der peinlichen Einhaltung dieser Regeln kann es dennoch zu einer sogenannten Drive-By-Infektion kommen, bei der ein Schädling aus dem Schutzmechanismus des Webbrowsers ausbricht. Um die Sicherheit noch weiter zu erhöhen gibt es spezielle Schutzsoftware, die deinen Browser noch weiter absichert. 
 Zuletzt denke bitte über die Benutzung eines alternativen Browsers nach. Programme, die nicht so oft verwendet werden, sind auch nicht so sehr im Focus der "bösen Jungs". D.h. du bist mit einem exotischen Browser eher auf der sicheren Seite. Grundsätzlich bist du erst einmal deutlich sicherer, wenn du nicht den Internet Explorer benutzt. 
 Damit wünsche ich dir noch viel Spaß beim Surfen im Internet  ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Eine Bitte: Gib mir eine kurze Rückmeldung, wenn alles erledigt ist und keine Fragen mehr vorhanden sind, damit ich diesen Thread aus meinen Abos löschen kann. 
				__________________  Digitale Freibeuter gegen Malware!  Keine Hilfe per PM! | 
|  10.04.2013, 14:40 | #11 | 
|  |   Haeufige Abstuerze und weiterleitungen im Firefox Alles erledigt ... keine Spur mehr von irgendwelchen Probleme   Danke fuer den super support, das ist auch eine Spede wert! | 
|  10.04.2013, 16:45 | #12 | 
| /// TB-Ausbilder    |   Haeufige Abstuerze und weiterleitungen im Firefox Schön, dass wir helfen konnten   Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen Falls du noch Lob oder Kritik loswerden möchtest, dann gibt es diesen Bereich hier: http://www.trojaner-board.de/lob-kritik-wuensche/ 
				__________________  Digitale Freibeuter gegen Malware!  Keine Hilfe per PM! | 
|  | 
| Themen zu Haeufige Abstuerze und weiterleitungen im Firefox | 
| abstürze, aufruf, browser, deinstallation, direkt, eingebe, firefox, gen, google, hoffe, komplette, konnte, laufen, registry, seite, spiel, stabil, stets, stuerzt, stunde, stunden, treibt, weitergeleitet, woche, wochen |