| reddi007 |  16.07.2011 10:04 |        Trojaner  C:\install\winupd.exe ?    Hallo Leute, ich habe seit ein paar Tagen immer wieder eine auftauchende Meldung meines Antivir Programms.   
Ein TR/Dropper.Gen wurde gefunden.   
Habe leider null plan wie ich den weg bekomme. Leider kann ich auch nicht sagen wie der drauf gekommen ist. Das Notebook hatte ein Kumpel für 2 Wochen er konnte es mir auch nicht sagen.   
Habe schon ein bisschen in den Foren rumgelesen aber bei solchen sachen denke ich mal ist das jedesmal Individuell.     
habe mal nen Hijack gemacht wenns denn weiter hilft.       
HiJackthis Logfile:   Code:  
 Logfile of Trend Micro HijackThis v2.0.4 
Scan saved at 10:45:02, on 16.07.2011 
Platform: Windows 7 SP1 (WinNT 6.00.3505) 
MSIE: Internet Explorer v8.00 (8.00.7601.17514) 
Boot mode: Normal   
Running processes: 
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe 
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 
C:\Windows\SysWOW64\explorer.exe 
C:\Windows\SysWOW64\explorer.exe 
C:\Windows\SysWOW64\explorer.exe 
C:\Windows\SysWOW64\explorer.exe 
C:\Windows\SysWOW64\explorer.exe 
C:\Windows\SysWOW64\explorer.exe 
D:\Firefox\win7\firefox.exe 
D:\Firefox\win7\plugin-container.exe     
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =  
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =  
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =  
F2 - REG:system.ini: UserInit=userinit.exe 
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll 
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) 
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll 
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll 
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min 
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"  O4 - HKLM\..\Run: [HKLM] C:\install\winupd.exe 
O4 - HKCU\..\Run: [ccleaner] "D:\ccleaner\CCleaner.exe" /AUTO  O4 - HKCU\..\Run: [HKCU] C:\install\winupd.exe  O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\install\winupd.exe 
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\install\winupd.exe 
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') 
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') 
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') 
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') 
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\wowa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm 
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\OFFICE~1\win7\OFFICE11\EXCEL.EXE/3000 
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE~1\win7\OFFICE11\REFIEBAR.DLL 
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~3\COMMON~1\Skype\SKYPE4~1.DLL 
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) 
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing) 
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) 
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) 
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) 
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) 
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) 
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) 
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) 
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) 
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) 
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) 
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) 
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) 
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) 
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) 
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) 
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) 
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) 
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)   
-- 
End of file - 6410 bytes   --- --- ---    
Hier noch was von OTL:   
nummer 1:OTL Logfile:   Code:  
 OTL logfile created on: 16.07.2011 11:08:13 - Run 1 
OTL by OldTimer - Version 3.2.26.1     Folder = D:\rootkitscan 
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7601.17514) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
2,50 Gb Total Physical Memory | 1,60 Gb Available Physical Memory | 63,98% Memory free 
4,99 Gb Paging File | 3,82 Gb Available in Paging File | 76,40% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 48,83 Gb Total Space | 15,38 Gb Free Space | 31,51% Space Free | Partition Type: NTFS 
Drive D: | 48,83 Gb Total Space | 8,49 Gb Free Space | 17,38% Space Free | Partition Type: NTFS 
Drive E: | 97,65 Gb Total Space | 75,51 Gb Free Space | 77,32% Space Free | Partition Type: NTFS 
Drive F: | 97,65 Gb Total Space | 73,07 Gb Free Space | 74,82% Space Free | Partition Type: NTFS 
Drive G: | 172,80 Gb Total Space | 52,25 Gb Free Space | 30,24% Space Free | Partition Type: NTFS 
  
Computer Name: WALLE | User Name: wowa | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - D:\rootkitscan\OTL.exe (OldTimer Tools) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
PRC - D:\Firefox\win7\plugin-container.exe (Mozilla Corporation) 
PRC - D:\Firefox\win7\firefox.exe (Mozilla Corporation) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
PRC - C:\Windows\SysWOW64\explorer.exe (Microsoft Corporation) 
  
   ========== Modules (SafeList) ========== 
  
MOD - D:\rootkitscan\OTL.exe (OldTimer Tools) 
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation) 
  
   ========== Win32 Services (SafeList) ========== 
  
SRV:64bit: - (dgdersvc) -- C:\Windows\SysNative\dgdersvc.exe (Devguru Co., Ltd.) 
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) 
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SRV:64bit: - (Ati External Event Utility) -- C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.) 
SRV:64bit: - (XAudioService) -- C:\Windows\SysNative\drivers\XAudio64.exe (Conexant Systems, Inc.) 
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) 
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH) 
SRV - (dgdersvc) -- C:\Windows\SysWOW64\dgdersvc.exe (Devguru Co., Ltd.) 
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) 
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) 
SRV - (StarWindServiceAE) -- D:\alcohol120brennprogr\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) 
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) 
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys () 
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) 
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) 
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) 
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation) 
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation) 
DRV:64bit: - (dgderdrv) -- C:\Windows\SysNative\drivers\dgderdrv.sys (Devguru Co., Ltd) 
DRV:64bit: - (TFsExDisk) -- C:\Windows\SysNative\drivers\TFsExDisk.sys (Teruten Inc) 
DRV:64bit: - (ss_bmdm) -- C:\Windows\SysNative\drivers\ss_bmdm.sys (MCCI Corporation) 
DRV:64bit: - (ss_bserd) -- C:\Windows\SysNative\drivers\ss_bserd.sys (MCCI Corporation) 
DRV:64bit: - (ss_bbus) SAMSUNG USB Mobile Device (WDM) -- C:\Windows\SysNative\drivers\ss_bbus.sys (MCCI) 
DRV:64bit: - (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) -- C:\Windows\SysNative\drivers\ss_bmdfl.sys (MCCI Corporation) 
DRV:64bit: - (vmm) -- C:\Windows\SysNative\Treiber\VMM.sys (Microsoft Corporation) 
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) 
DRV:64bit: - (NSHE) -- C:\Windows\SysNative\drivers\nshe.sys (T0r0) 
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) 
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) 
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) 
DRV:64bit: - (irda) -- C:\Windows\SysNative\drivers\irda.sys (Microsoft Corporation) 
DRV:64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.) 
DRV:64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.) 
DRV:64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.) 
DRV:64bit: - (Ntfs) -- C:\Windows\SysNative\wbem\ntfs.mof () 
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) 
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) 
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) 
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) 
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation                                            ) 
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) 
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.) 
DRV:64bit: - (SiFilter) -- C:\Windows\SysNative\drivers\SiWinAcc.sys (Silicon Image, Inc) 
DRV:64bit: - (SI3112) -- C:\Windows\SysNative\drivers\SI3112.sys (Silicon Image, Inc) 
DRV:64bit: - (SMSCIRDA) -- C:\Windows\SysNative\drivers\smscir64.sys (SMSC) 
DRV:64bit: - (VPCNetS2) -- C:\Windows\SysNative\drivers\VMNetSrv.sys (Microsoft Corporation) 
DRV:64bit: - (Cam5603D) -- C:\Windows\SysNative\drivers\BisonCam.sys (Bison Electronics. Inc. ) 
DRV:64bit: - (aksdf) -- C:\Windows\SysNative\drivers\aksdf.sys (Aladdin Knowledge Systems Ltd.) 
DRV:64bit: - (Hardlock) -- C:\Windows\SysNative\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.) 
DRV:64bit: - (HSF_DPV) -- C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.) 
DRV:64bit: - (CAXHWAZL) -- C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.) 
DRV:64bit: - (winachsf) -- C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.) 
DRV:64bit: - (XAudio) -- C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.) 
DRV:64bit: - (mdmxsdk) -- C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant) 
DRV:64bit: - (ESDCR) -- C:\Windows\SysNative\drivers\ESD7SK.sys (ENE Technology Inc.) 
DRV:64bit: - (ESMCR) -- C:\Windows\SysNative\drivers\ESM7SK.sys (ENE Technology Inc.) 
DRV:64bit: - (EMSCR) -- C:\Windows\SysNative\drivers\EMS7SK.sys (ENE Technology Inc.) 
DRV - (dgderdrv) -- C:\Windows\SysWOW64\drivers\dgderdrv.sys (Devguru Co., Ltd) 
DRV - (TFsExDisk) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys (Teruten Inc) 
DRV - (NSHE) -- C:\Windows\SysWOW64\drivers\NSHE.SYS (T0r0) 
DRV - (Hardlock) -- C:\Windows\SysWOW64\drivers\hardlock.sys (Aladdin Knowledge Systems) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
  
  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
  
  
IE - HKU\S-1-5-21-2785384167-962072550-2642694341-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ 
IE - HKU\S-1-5-21-2785384167-962072550-2642694341-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp 
IE - HKU\S-1-5-21-2785384167-962072550-2642694341-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de 
IE - HKU\S-1-5-21-2785384167-962072550-2642694341-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BE 76 79 CC 01 71 CA 01  [binary data] 
IE - HKU\S-1-5-21-2785384167-962072550-2642694341-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.update: false 
FF - prefs.js..browser.startup.homepage: "www.t-online.de" 
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8 
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6 
FF - prefs.js..extensions.enabledItems: youtube2mp3@mondayx.de:1.0.7 
FF - prefs.js..extensions.enabledItems: illimitux@illimitux.net:4.1 
  
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () 
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) 
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) 
FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\adobeReader\win7\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
  
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: D:\Firefox\win7\components [2011.06.28 17:40:33 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: D:\Firefox\win7\plugins [2011.06.24 16:51:25 | 000,000,000 | ---D | M] 
  
[2009.11.29 17:08:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wowa\AppData\Roaming\mozilla\Extensions 
[2011.06.24 16:52:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\wowa\AppData\Roaming\mozilla\Firefox\Profiles\wwkq882s.default\extensions 
[2011.04.15 17:26:09 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\wowa\AppData\Roaming\mozilla\Firefox\Profiles\wwkq882s.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} 
[2011.04.12 20:49:12 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\wowa\AppData\Roaming\mozilla\Firefox\Profiles\wwkq882s.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} 
[2011.04.25 18:11:22 | 000,000,000 | ---D | M] (Illimitux) -- C:\Users\wowa\AppData\Roaming\mozilla\Firefox\Profiles\wwkq882s.default\extensions\illimitux@illimitux.net 
[2011.04.15 17:26:08 | 000,000,000 | ---D | M] (YouTube to MP3) -- C:\Users\wowa\AppData\Roaming\mozilla\Firefox\Profiles\wwkq882s.default\extensions\youtube2mp3@mondayx.de 
[2011.04.12 20:53:10 | 000,000,000 | ---D | M] (Java Console) -- D:\FIREFOX\WIN7\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} 
[2011.04.12 21:50:19 | 000,000,000 | ---D | M] (Java Console) -- D:\FIREFOX\WIN7\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} 
  
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. 
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) 
O4 - HKLM..\Run: [HKLM] C:\install\winupd.exe () 
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) 
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) 
O4 - HKU\S-1-5-21-2785384167-962072550-2642694341-1001..\Run: [ccleaner] D:\ccleaner\CCleaner.exe (Piriform Ltd) 
O4 - HKU\S-1-5-21-2785384167-962072550-2642694341-1001..\Run: [HKCU] C:\install\winupd.exe () 
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin]  File not found 
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin]  File not found 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\install\winupd.exe () 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 
O7 - HKU\S-1-5-21-2785384167-962072550-2642694341-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 
O7 - HKU\S-1-5-21-2785384167-962072550-2642694341-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\install\winupd.exe () 
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\wowa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () 
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - D:\office 2003\win7\OFFICE11\EXCEL.EXE (Microsoft Corporation) 
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\wowa\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () 
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - D:\office 2003\win7\OFFICE11\EXCEL.EXE (Microsoft Corporation) 
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\office 2003\win7\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) 
O13 - gopher Prefix: missing 
O13 - gopher Prefix: missing 
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found 
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found 
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found 
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~3\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) 
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~3\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~3\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) 
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~3\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) 
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found 
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2008.12.19 17:45:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] 
O32 - AutoRun File - [2010.01.14 16:30:48 | 000,012,379 | ---- | M] () - G:\autoscan.pdf -- [ NTFS ] 
O33 - MountPoints2\{04ffc475-23aa-11df-bca1-0016d4193543}\Shell - "" = AutoRun 
O33 - MountPoints2\{04ffc475-23aa-11df-bca1-0016d4193543}\Shell\AutoRun\command - "" = I:\AutoRun.exe 
O33 - MountPoints2\{04ffc4cc-23aa-11df-bca1-0016d4193543}\Shell - "" = AutoRun 
O33 - MountPoints2\{04ffc4cc-23aa-11df-bca1-0016d4193543}\Shell\AutoRun\command - "" = I:\AutoRun.exe 
O33 - MountPoints2\{9c92fd0c-1d79-11df-8824-806e6f6e6963}\Shell - "" = AutoRun 
O33 - MountPoints2\{9c92fd0c-1d79-11df-8824-806e6f6e6963}\Shell\AutoRun\command - "" = I:\AutoRun.exe 
O33 - MountPoints2\{bdf41d37-13c5-11df-8649-0016d4193543}\Shell - "" = AutoRun 
O33 - MountPoints2\{bdf41d37-13c5-11df-8649-0016d4193543}\Shell\AutoRun\command - "" = I:\AutoRun.exe 
O33 - MountPoints2\{bdf41d4c-13c5-11df-8649-0016d4193543}\Shell - "" = AutoRun 
O33 - MountPoints2\{bdf41d4c-13c5-11df-8649-0016d4193543}\Shell\AutoRun\command - "" = I:\AutoRun.exe 
O33 - MountPoints2\{ca645afe-1eec-11df-b157-0016d4193543}\Shell - "" = AutoRun 
O33 - MountPoints2\{ca645afe-1eec-11df-b157-0016d4193543}\Shell\AutoRun\command - "" = I:\AutoRun.exe 
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = comfile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
  
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
  
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - D:\adobeReader\win7\Reader\Reader_sl.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: AdobeCS5ServiceManager - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) 
MsConfig:64bit - StartUpReg: AlcoholAutomount - hkey= - key= - D:\alcohol120brennprogr\Alcohol 120\axcmd.exe (Alcohol Soft Development Team) 
MsConfig:64bit - StartUpReg: HKCU - hkey= - key= - Reg Error: Value error. File not found 
MsConfig:64bit - StartUpReg: HKLM - hkey= - key= - C:\install\winupd.exe () 
MsConfig:64bit - StartUpReg: msnmsgr - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) 
MsConfig:64bit - StartUpReg: SwitchBoard - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) 
MsConfig:64bit - State: "bootini" - Reg Error: Key error. 
MsConfig:64bit - State: "startup" - Reg Error: Key error. 
MsConfig:64bit - State: "services" - Reg Error: Key error. 
  
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SafeBootMin:64bit: Base - Driver Group 
SafeBootMin:64bit: Boot Bus Extender - Driver Group 
SafeBootMin:64bit: Boot file system - Driver Group 
SafeBootMin:64bit: File system - Driver Group 
SafeBootMin:64bit: Filter - Driver Group 
SafeBootMin:64bit: HelpSvc - Service 
SafeBootMin:64bit: PCI Configuration - Driver Group 
SafeBootMin:64bit: PNP Filter - Driver Group 
SafeBootMin:64bit: Primary disk - Driver Group 
SafeBootMin:64bit: sacsvr - Service 
SafeBootMin:64bit: SCSI Class - Driver Group 
SafeBootMin:64bit: System Bus Extender - Driver Group 
SafeBootMin:64bit: vmms - Service 
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) 
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
SafeBootMin: Base - Driver Group 
SafeBootMin: Boot Bus Extender - Driver Group 
SafeBootMin: Boot file system - Driver Group 
SafeBootMin: File system - Driver Group 
SafeBootMin: Filter - Driver Group 
SafeBootMin: HelpSvc - Service 
SafeBootMin: PCI Configuration - Driver Group 
SafeBootMin: PNP Filter - Driver Group 
SafeBootMin: Primary disk - Driver Group 
SafeBootMin: sacsvr - Service 
SafeBootMin: SCSI Class - Driver Group 
SafeBootMin: System Bus Extender - Driver Group 
SafeBootMin: vmms - Service 
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
  
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SafeBootNet:64bit: Base - Driver Group 
SafeBootNet:64bit: Boot Bus Extender - Driver Group 
SafeBootNet:64bit: Boot file system - Driver Group 
SafeBootNet:64bit: File system - Driver Group 
SafeBootNet:64bit: Filter - Driver Group 
SafeBootNet:64bit: HelpSvc - Service 
SafeBootNet:64bit: Messenger - Service 
SafeBootNet:64bit: NDIS Wrapper - Driver Group 
SafeBootNet:64bit: NetBIOSGroup - Driver Group 
SafeBootNet:64bit: NetDDEGroup - Driver Group 
SafeBootNet:64bit: Network - Driver Group 
SafeBootNet:64bit: NetworkProvider - Driver Group 
SafeBootNet:64bit: PCI Configuration - Driver Group 
SafeBootNet:64bit: PNP Filter - Driver Group 
SafeBootNet:64bit: PNP_TDI - Driver Group 
SafeBootNet:64bit: Primary disk - Driver Group 
SafeBootNet:64bit: rdsessmgr - Service 
SafeBootNet:64bit: sacsvr - Service 
SafeBootNet:64bit: SCSI Class - Driver Group 
SafeBootNet:64bit: Streams Drivers - Driver Group 
SafeBootNet:64bit: System Bus Extender - Driver Group 
SafeBootNet:64bit: TDI - Driver Group 
SafeBootNet:64bit: vmms - Service 
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) 
SafeBootNet:64bit: WudfUsbccidDriver - Driver 
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net 
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient 
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService 
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans 
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers 
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
SafeBootNet: Base - Driver Group 
SafeBootNet: Boot Bus Extender - Driver Group 
SafeBootNet: Boot file system - Driver Group 
SafeBootNet: File system - Driver Group 
SafeBootNet: Filter - Driver Group 
SafeBootNet: HelpSvc - Service 
SafeBootNet: Messenger - Service 
SafeBootNet: NDIS Wrapper - Driver Group 
SafeBootNet: NetBIOSGroup - Driver Group 
SafeBootNet: NetDDEGroup - Driver Group 
SafeBootNet: Network - Driver Group 
SafeBootNet: NetworkProvider - Driver Group 
SafeBootNet: PCI Configuration - Driver Group 
SafeBootNet: PNP Filter - Driver Group 
SafeBootNet: PNP_TDI - Driver Group 
SafeBootNet: Primary disk - Driver Group 
SafeBootNet: rdsessmgr - Service 
SafeBootNet: sacsvr - Service 
SafeBootNet: SCSI Class - Driver Group 
SafeBootNet: Streams Drivers - Driver Group 
SafeBootNet: System Bus Extender - Driver Group 
SafeBootNet: TDI - Driver Group 
SafeBootNet: vmms - Service 
SafeBootNet: WudfUsbccidDriver - Driver 
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers 
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive 
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive 
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller 
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc 
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard 
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse 
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net 
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient 
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService 
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans 
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters 
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter 
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System 
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive 
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers 
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy 
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers 
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume 
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices 
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices 
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices 
  
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings 
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install 
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework 
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig 
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) 
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework 
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll 
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack 
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE 
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx 
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help 
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools 
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements 
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player 
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access 
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner 
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll 
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings 
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install 
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding 
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts 
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player 
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help 
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface 
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP 
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig 
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP 
  
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) 
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) 
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) 
  
CREATERESTOREPOINT 
Restore point Set: OTL Restore Point 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2011.07.16 11:10:16 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan 
[2011.07.03 21:45:31 | 000,000,000 | ---D | C] -- C:\install 
[2011.06.23 21:35:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Alcohol Soft 
[2011.06.23 21:04:15 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt 
[2011.06.23 21:02:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120% 
   ========== Files - Modified Within 30 Days ========== 
  
[2011.07.16 11:08:19 | 000,037,218 | -H-- | M] () -- C:\Users\wowa\AppData\Roaming\wowalog.dat 
[2011.07.16 10:34:33 | 001,480,600 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI 
[2011.07.16 10:34:33 | 000,649,042 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat 
[2011.07.16 10:34:33 | 000,610,768 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat 
[2011.07.16 10:34:33 | 000,128,128 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat 
[2011.07.16 10:34:33 | 000,105,086 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat 
[2011.07.16 10:32:41 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2011.07.16 10:32:41 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2011.07.16 10:27:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2011.07.16 10:27:00 | 2011,779,072 | -HS- | M] () -- C:\hiberfil.sys 
[2011.06.28 17:38:02 | 000,123,784 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys 
[2011.06.28 17:38:02 | 000,088,288 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys 
[2011.06.23 21:53:18 | 000,001,905 | ---- | M] () -- C:\Windows\diagwrn.xml 
[2011.06.23 21:53:18 | 000,001,905 | ---- | M] () -- C:\Windows\diagerr.xml 
[2011.06.23 20:48:38 | 000,868,848 | ---- | M] () -- C:\Windows\SysNative\drivers\sptd.sys 
[2011.06.21 22:36:33 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 
   ========== Files Created - No Company Name ========== 
  
[2011.06.23 21:52:56 | 000,001,905 | ---- | C] () -- C:\Windows\diagwrn.xml 
[2011.06.23 21:52:56 | 000,001,905 | ---- | C] () -- C:\Windows\diagerr.xml 
[2011.06.23 20:48:38 | 000,868,848 | ---- | C] () -- C:\Windows\SysNative\drivers\sptd.sys 
[2011.06.13 14:07:09 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat 
[2011.04.15 16:36:30 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat 
[2010.10.25 11:09:56 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll 
[2010.10.25 11:09:56 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll 
[2010.10.25 11:09:56 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll 
[2010.10.25 11:09:56 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll 
[2010.02.21 22:21:38 | 000,017,408 | ---- | C] () -- C:\Users\wowa\AppData\Local\WebpageIcons.db 
[2010.02.21 15:46:37 | 000,000,017 | ---- | C] () -- C:\Users\wowa\AppData\Local\resmon.resmoncfg 
[2010.02.19 19:23:27 | 000,356,352 | ---- | C] () -- C:\Windows\EMCRI.dll 
[2010.02.18 23:30:44 | 000,015,190 | ---- | C] () -- C:\Windows\M2000Twn.ini 
[2010.01.17 21:05:32 | 001,504,288 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI 
[2010.01.14 20:04:43 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\hlduinst.exe 
[2010.01.14 20:04:42 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNWISE.EXE 
[2010.01.14 20:04:42 | 000,006,836 | ---- | C] () -- C:\Windows\SysWow64\UNWISE.INI 
[2009.11.30 18:44:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin 
[2009.11.30 18:30:54 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI 
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat 
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT 
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat 
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin 
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll 
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll 
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat 
[2008.12.01 21:08:40 | 003,107,788 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.dat 
[2005.04.08 04:16:43 | 000,037,218 | -H-- | C] () -- C:\Users\wowa\AppData\Roaming\wowalog.dat 
[2003.02.20 18:53:42 | 000,005,702 | ---- | C] () -- C:\Windows\SysWow64\OUTLPERF.INI 
   ========== LOP Check ========== 
  
[2011.04.19 16:17:44 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\DVDVideoSoftIEHelpers 
[2011.04.16 12:41:21 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Samsung 
[2011.06.19 00:19:39 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT 
   ========== Purity Check ========== 
  
  
   ========== Custom Scans ========== 
  
   < %ALLUSERSPROFILE%\Application Data\*. > 
   < %ALLUSERSPROFILE%\Application Data\*.exe /s > 
   < %APPDATA%\*. > 
[2011.06.13 14:18:58 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Adobe 
[2011.04.19 16:17:44 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\DVDVideoSoftIEHelpers 
[2009.11.29 16:36:36 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Identities 
[2010.02.24 00:15:33 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\InstallShield 
[2009.12.02 21:39:16 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Macromedia 
[2009.07.14 20:18:19 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Media Center Programs 
[2011.04.16 13:05:27 | 000,000,000 | --SD | M] -- C:\Users\wowa\AppData\Roaming\Microsoft 
[2009.11.29 17:08:27 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Mozilla 
[2011.04.16 12:41:21 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Samsung 
[2011.06.19 00:48:13 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\Skype 
[2011.06.19 00:47:32 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\skypePM 
[2011.06.12 15:17:50 | 000,000,000 | ---D | M] -- C:\Users\wowa\AppData\Roaming\vlc 
   < %APPDATA%\*.exe /s > 
[2011.04.12 16:50:40 | 000,311,940 | R--- | M] () -- C:\Users\wowa\AppData\Roaming\Microsoft\Installer\{38E3EF60-58D7-424F-A6A3-773706D6713F}\_1D9FBF85630B112BF30C52.exe 
[2011.04.12 16:50:40 | 000,148,680 | R--- | M] () -- C:\Users\wowa\AppData\Roaming\Microsoft\Installer\{38E3EF60-58D7-424F-A6A3-773706D6713F}\_331F28BB5A3EAE0CCE1696.exe 
[2011.04.12 16:50:40 | 000,082,601 | R--- | M] () -- C:\Users\wowa\AppData\Roaming\Microsoft\Installer\{38E3EF60-58D7-424F-A6A3-773706D6713F}\_366EA8281CC7E2B7759215.exe 
[2011.04.12 16:50:40 | 000,013,942 | R--- | M] () -- C:\Users\wowa\AppData\Roaming\Microsoft\Installer\{38E3EF60-58D7-424F-A6A3-773706D6713F}\_9F74CE917636013F597EC0.exe 
   < %SYSTEMDRIVE%\*.exe > 
  
   < MD5 for: AGP440.SYS  > 
[2008.04.14 14:00:00 | 020,108,202 | ---- | M] () .cab file -- C:\WINXP\Driver Cache\i386\sp3.cab:AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys 
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys 
   < MD5 for: ATAPI.SYS  > 
[2008.04.14 14:00:00 | 020,108,202 | ---- | M] () .cab file -- C:\WINXP\Driver Cache\i386\sp3.cab:atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys 
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys 
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINXP\ERDNT\cache\atapi.sys 
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINXP\system32\drivers\atapi.sys 
   < MD5 for: CNGAUDIT.DLL  > 
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll 
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll 
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll 
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll 
   < MD5 for: EVENTLOG.DLL  > 
[2008.04.14 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINXP\ERDNT\cache\eventlog.dll 
[2008.04.14 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINXP\system32\dllcache\eventlog.dll 
[2008.04.14 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=04955AA695448C181B367D964AF158AA -- C:\WINXP\system32\eventlog.dll 
   < MD5 for: EXPLORER.EXE  > 
[2009.07.14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe 
[2009.10.31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe 
[2010.11.20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\SysWOW64\explorer.exe 
[2010.11.20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe 
[2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINXP\ERDNT\cache\explorer.exe 
[2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINXP\explorer.exe 
[2008.04.14 14:00:00 | 001,036,800 | ---- | M] (Microsoft Corporation) MD5=418045A93CD87A352098AB7DABE1B53E -- C:\WINXP\system32\dllcache\explorer.exe 
[2009.08.03 08:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe 
[2009.10.31 08:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe 
[2009.08.03 07:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe 
[2010.11.20 15:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\explorer.exe 
[2010.11.20 15:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe 
[2009.10.31 08:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe 
[2009.08.03 07:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe 
[2009.07.14 03:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe 
[2009.10.31 08:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe 
[2009.08.03 08:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe 
   < MD5 for: IASTORV.SYS  > 
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\drivers\iaStorV.sys 
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys 
[2010.11.20 15:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys 
[2009.07.14 03:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys 
   < MD5 for: NETLOGON.DLL  > 
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINXP\ERDNT\cache\netlogon.dll 
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINXP\system32\dllcache\netlogon.dll 
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=0098D35F91DEAB9C127360A877F2CF84 -- C:\WINXP\system32\netlogon.dll 
[2009.07.14 03:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll 
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll 
[2010.11.20 15:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll 
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll 
[2010.11.20 14:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll 
[2009.07.14 03:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll 
   < MD5 for: NVSTOR.SYS  > 
[2009.07.14 03:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys 
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\drivers\nvstor.sys 
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys 
[2010.11.20 15:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys 
   < MD5 for: SCECLI.DLL  > 
[2009.07.14 03:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll 
[2009.07.14 03:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll 
[2008.04.14 14:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINXP\ERDNT\cache\scecli.dll 
[2008.04.14 14:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINXP\system32\dllcache\scecli.dll 
[2008.04.14 14:00:00 | 000,187,904 | ---- | M] (Microsoft Corporation) MD5=5132443DF6FC3771A17AB4AE55DCBC28 -- C:\WINXP\system32\scecli.dll 
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll 
[2010.11.20 14:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll 
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll 
[2010.11.20 15:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll 
   < MD5 for: USER32.DLL  > 
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll 
[2010.11.20 14:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll 
[2009.07.14 03:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll 
[2008.04.14 14:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINXP\ERDNT\cache\user32.dll 
[2008.04.14 14:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINXP\system32\dllcache\user32.dll 
[2008.04.14 14:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) MD5=B0050CC5340E3A0760DD8B417FF7AEBD -- C:\WINXP\system32\user32.dll 
[2009.07.14 03:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll 
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll 
[2010.11.20 15:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll 
   < MD5 for: USERINIT.EXE  > 
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe 
[2010.11.20 14:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe 
[2009.07.14 03:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe 
[2009.07.14 03:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe 
[2008.04.14 14:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINXP\ERDNT\cache\userinit.exe 
[2008.04.14 14:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINXP\system32\dllcache\userinit.exe 
[2008.04.14 14:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=788F95312E26389D596C0FA55834E106 -- C:\WINXP\system32\userinit.exe 
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe 
[2010.11.20 15:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe 
   < MD5 for: WINLOGON.EXE  > 
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe 
[2010.11.20 15:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe 
[2009.07.14 03:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe 
[2009.10.28 09:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe 
[2009.10.28 08:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe 
[2008.04.14 14:00:00 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINXP\ERDNT\cache\winlogon.exe 
[2008.04.14 14:00:00 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINXP\system32\dllcache\winlogon.exe 
[2008.04.14 14:00:00 | 000,513,024 | ---- | M] (Microsoft Corporation) MD5=F09A527B422E25C478E38CAA0E44417A -- C:\WINXP\system32\winlogon.exe 
   < MD5 for: WS2IFSL.SYS  > 
[2008.04.14 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINXP\system32\dllcache\ws2ifsl.sys 
[2008.04.14 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) MD5=6ABE6E225ADB5A751622A9CC3BC19CE8 -- C:\WINXP\system32\drivers\ws2ifsl.sys 
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys 
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys 
   < %systemroot%\system32\drivers\*.sys /lockedfiles > 
   < %systemroot%\System32\config\*.sav > 
   < %systemroot%\*. /mp /s > 
   < %systemroot%\system32\*.dll /lockedfiles > 
[2010.11.20 14:21:37 | 011,410,432 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\wmp.dll   
< End of report >   --- --- ---    
nummer 2:OTL Logfile:   Code:  
 OTL Extras logfile created on: 16.07.2011 11:08:13 - Run 1 
OTL by OldTimer - Version 3.2.26.1     Folder = D:\rootkitscan 
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 8.0.7601.17514) 
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 
  
2,50 Gb Total Physical Memory | 1,60 Gb Available Physical Memory | 63,98% Memory free 
4,99 Gb Paging File | 3,82 Gb Available in Paging File | 76,40% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 48,83 Gb Total Space | 15,38 Gb Free Space | 31,51% Space Free | Partition Type: NTFS 
Drive D: | 48,83 Gb Total Space | 8,49 Gb Free Space | 17,38% Space Free | Partition Type: NTFS 
Drive E: | 97,65 Gb Total Space | 75,51 Gb Free Space | 77,32% Space Free | Partition Type: NTFS 
Drive F: | 97,65 Gb Total Space | 73,07 Gb Free Space | 74,82% Space Free | Partition Type: NTFS 
Drive G: | 172,80 Gb Total Space | 52,25 Gb Free Space | 30,24% Space Free | Partition Type: NTFS 
  
Computer Name: WALLE | User Name: wowa | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) 
  
[HKEY_USERS\S-1-5-21-2785384167-962072550-2642694341-1001\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- D:\Firefox\win7\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* File not found 
cmdfile [open] -- "%1" %* File not found 
comfile [open] -- "%1" %* File not found 
exefile [open] -- "%1" %* File not found 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- "D:\office 2003\win7\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "D:\office 2003\win7\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* File not found 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" File not found 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found 
scrfile [open] -- "%1" /S File not found 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found 
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () 
Directory [Bridge] -- D:\photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.) 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- "D:\office 2003\win7\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- "D:\office 2003\win7\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () 
Directory [Bridge] -- D:\photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.) 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data] 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
   ========== Firewall Settings ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 0 
   ========== Authorized Applications List ========== 
  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) 
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64 
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64 
"{4A57592C-FF92-4083-97A9-92783BD5AFB4}" = Acer OrbiCam 
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64 
"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007 
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64 
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64 
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting 
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64 
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64 
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones 
"{FB13AAF7-E2CA-0DA5-C4D6-B04EF73B81DD}" = ATI Catalyst Install Manager 
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help 
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86 
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5 
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool 
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT 
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 24 
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform 
"{38E3EF60-58D7-424F-A6A3-773706D6713F}" = SevenClean 2012 
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater 
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent 
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3 
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin 
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 
"{90110407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR 
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5 
"{AC76BA86-7AD7-1031-7B44-A94000000001}" = Adobe Reader 9.4.5 - Deutsch 
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger 
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials 
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call 
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player 
"{E9A5B341-167D-4042-8854-46F671F94049}" = Medieval CUE Splitter 
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard 
"7-Zip" = 7-Zip 4.57 
"Adobe AIR" = Adobe AIR 
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX 
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin 
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus 
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help 
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player 
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7 
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.35.324 
"Hardlock Device Driver" = Hardlock Device Driver 
"Hardlock Gerätetreiber" = Hardlock Gerätetreiber 
"IsoBuster_is1" = IsoBuster 2.7 
"JDownloader" = JDownloader 
"Mobile Partner" = Mobile Partner 
"Mozilla Firefox (3.6.18)" = Mozilla Firefox (3.6.18) 
"Uninstall_is1" = Uninstall 1.0.0.1 
"VLC media player" = VLC media player 1.1.10 
"WinLiveSuite_Wave3" = Windows Live Essentials 
   ========== Last 10 Event Log Errors ========== 
  
[ Application Events ] 
Error - 03.07.2011 15:42:41 | Computer Name = walle | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 03.07.2011 15:42:41 | Computer Name = walle | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 16.07.2011 04:11:27 | Computer Name = walle | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 16.07.2011 04:11:27 | Computer Name = walle | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 16.07.2011 04:27:37 | Computer Name = walle | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 16.07.2011 04:27:37 | Computer Name = walle | Source = Microsoft-Windows-CAPI2 | ID = 4107 
Description = Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen 
 Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. 
 Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum 
 gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. 
. 
  
Error - 16.07.2011 04:27:45 | Computer Name = walle | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, 
 Zeitstempel: 0x4ce796f3  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, 
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x10418792  ID des fehlerhaften 
 Prozesses: 0x80c  Startzeit der fehlerhaften Anwendung: 0x01cc4392376d3c76  Pfad der 
 fehlerhaften Anwendung: C:\Windows\SysWOW64\explorer.exe  Pfad des fehlerhaften Moduls: 
 unknown  Berichtskennung: 7a87c346-af85-11e0-9c9d-0016d4193543 
  
Error - 16.07.2011 04:27:45 | Computer Name = walle | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, 
 Zeitstempel: 0x4ce796f3  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, 
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x104f8792  ID des fehlerhaften 
 Prozesses: 0xa78  Startzeit der fehlerhaften Anwendung: 0x01cc439239775f74  Pfad der 
 fehlerhaften Anwendung: C:\Windows\SysWOW64\explorer.exe  Pfad des fehlerhaften Moduls: 
 unknown  Berichtskennung: 7a87ea56-af85-11e0-9c9d-0016d4193543 
  
Error - 16.07.2011 04:27:45 | Computer Name = walle | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, 
 Zeitstempel: 0x4ce796f3  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, 
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x10488792  ID des fehlerhaften 
 Prozesses: 0xb74  Startzeit der fehlerhaften Anwendung: 0x01cc439239c3aab4  Pfad der 
 fehlerhaften Anwendung: C:\Windows\SysWOW64\explorer.exe  Pfad des fehlerhaften Moduls: 
 unknown  Berichtskennung: 7abe995c-af85-11e0-9c9d-0016d4193543 
  
Error - 16.07.2011 04:27:45 | Computer Name = walle | Source = Application Error | ID = 1000 
Description = Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17514, 
 Zeitstempel: 0x4ce796f3  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, 
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x104f8792  ID des fehlerhaften 
 Prozesses: 0xa88  Startzeit der fehlerhaften Anwendung: 0x01cc439239919952  Pfad der 
 fehlerhaften Anwendung: C:\Windows\SysWOW64\explorer.exe  Pfad des fehlerhaften Moduls: 
 unknown  Berichtskennung: 7ac0fbb6-af85-11e0-9c9d-0016d4193543 
  
[ System Events ] 
Error - 02.07.2011 08:39:19 | Computer Name = walle | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "Guardant Emulator Driver" wurde aufgrund folgenden Fehlers 
 nicht gestartet:   %%1275 
  
Error - 02.07.2011 08:41:51 | Computer Name = walle | Source = Service Control Manager | ID = 7023 
Description = Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:  
  %%-2147024882 
  
Error - 02.07.2011 08:43:23 | Computer Name = walle | Source = Application Popup | ID = 1060 
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Windows\system32\Drivers\NSHE.SYS 
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version 
 des Treibers zu erhalten. 
  
Error - 02.07.2011 08:43:24 | Computer Name = walle | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "Guardant Emulator Driver" wurde aufgrund folgenden Fehlers 
 nicht gestartet:   %%1275 
  
Error - 03.07.2011 15:42:39 | Computer Name = walle | Source = Application Popup | ID = 1060 
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Windows\system32\Drivers\NSHE.SYS 
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version 
 des Treibers zu erhalten. 
  
Error - 03.07.2011 15:42:39 | Computer Name = walle | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "Guardant Emulator Driver" wurde aufgrund folgenden Fehlers 
 nicht gestartet:   %%1275 
  
Error - 16.07.2011 04:11:21 | Computer Name = walle | Source = Application Popup | ID = 1060 
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Windows\system32\Drivers\NSHE.SYS 
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version 
 des Treibers zu erhalten. 
  
Error - 16.07.2011 04:11:21 | Computer Name = walle | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "Guardant Emulator Driver" wurde aufgrund folgenden Fehlers 
 nicht gestartet:   %%1275 
  
Error - 16.07.2011 04:27:31 | Computer Name = walle | Source = Application Popup | ID = 1060 
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Windows\system32\Drivers\NSHE.SYS 
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version 
 des Treibers zu erhalten. 
  
Error - 16.07.2011 04:27:31 | Computer Name = walle | Source = Service Control Manager | ID = 7000 
Description = Der Dienst "Guardant Emulator Driver" wurde aufgrund folgenden Fehlers 
 nicht gestartet:   %%1275 
  
  
< End of report >   --- --- ---     
Ich hoffe mir kann einer dabei helfen :)   
Danke schön im Vorraus:singsing:    |