Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Security Shield durch Maillink eingefangen! (https://www.trojaner-board.de/105106-security-shield-maillink-eingefangen.html)

Yasmin 15.11.2011 10:01

Security Shield durch Maillink eingefangen!
 
Hallo!

Liebe Helfer ich bin neu hier und bin gleich mal kläglich gescheitert, hier ordentlich zu beginnen.

Angefangen hat es mit einer netten Mail eines Freundes, Link angeklickt (aus blindem Vertrauen :headbang: ) und jetzt habe ich dieses "Virenprogramm" auf meinem Laptop.. :(

Hier ein bisschen gesucht, nachgelesen, registriert.

Ich wollte alle Anweisungen befolgen:
Download defogger ok, öffnen denkste - Meldung von Security Shield: Warnung! "Defogger" ist mit "Dialer.WinCE/Terdial.A" infiziert.

Das selbe mit den anderen Sachen, die ich ja installieren sollte..
und zwischen den versuchten Downloads (ich habs Win7 und mit Admin versucht zu starten) kamen auch noch andere Meldungen.
Habe hier mitgeschrieben:

"SearchProtocolHost.exe" ist mit "Spyware: Win32/WebHancer.A" infiziert.
"OTL.exe" ist mit "Net-Worm.Win32.Kido" infiziert.
"msinfo.exe" ist mit "Backdoor: Win32/Hackdef.Y" infiziert.
"dllhost.exe" ist mit "Worm: Win32/Brontok" infiziert.
"avwsc.exe" ist mit "Rogue: Win32/Defmid infiziert.
usw... anschließend natürlich immer gleich die Frage, ob ich nun kaufen will.

Ich kann Security Shield weder beenden, schließen, deinstallieren - ich finde es erst gar nicht.

Also egal was ich öffnen will, kommt wieder so eine Meldung, mit was es nicht alles infiziert sei und mich das Programm deshalb "schützt". Auch Taskmanager ist nicht zu öffnen. Und meinen Avira hat er gleich mal abgedreht.

Was kann ich nun tun?
Ich werde dieses Programm nicht los, ich komm nicht zu die Daten, die hier wichtig sind und ja.. komme ich noch irgendwie anders an die wichtigen Daten ran?

Ich hoffe, ich habe gegen keine Regel verstoßen und vorallem, dass sich doch jemand bereit erklärt, mir zu helfen! :(

markusg 15.11.2011 11:46

hi,
Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden)
  • Doppelklick auf die
    OTL.exe

    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal
    Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan
    links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.
bitte versuch es im abgesicherten modus auszuführen, erreicht man meist bei pc start mit f8.

Yasmin 15.11.2011 20:59

OTL Logfile:
Code:

OTL Extras logfile created on: 15.11.2011 20:11:30 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Yasmin\Downloads
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,53 Gb Available Physical Memory | 76,77% Memory free
3,98 Gb Paging File | 3,59 Gb Available in Paging File | 90,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 33,26 Gb Free Space | 29,78% Space Free | Partition Type: NTFS
 
Computer Name: YASMIN-LAPTOP | User Name: Yasmin | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 29
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1" = Auslogics BoostSpeed
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}" = Nero BurnLite 10
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_ENTERPRISE_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-0044-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_ENTERPRISE_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}_ENTERPRISE_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}" = Nero BurnLite 10
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Deutsch
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B8F28542-1668-4D61-ACE1-BC32894F5612}" = Badoo Desktop
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0FF219A-6233-440A-BC76-5CC144CDCDB6}" = Nitro PDF Reader 2
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{WIDELANDS-WIN32-IS}_is1" = Widelands
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Audacity_is1" = Audacity 1.2.6
"Audiograbber" = Audiograbber 1.83 SE
"Audiograbber-Lame" = Audiograbber MP3-Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"DivX Setup.divx.com" = DivX-Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free Studio_is1" = Free Studio version 5.1.4
"Free YouTube Download 3_is1" = Free YouTube Download 3 version 3.0.10.722
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.40.602
"Glary Utilities_is1" = Glary Utilities 2.39.0.1310
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"Karaoke Anything!1.0" = Karaoke Anything!
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.6.6 (Standard)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Mozilla Firefox 8.0 (x86 de)" = Mozilla Firefox 8.0 (x86 de)
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 02.08.2011 23:35:02 | Computer Name = Yasmin-Laptop | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: KiesPDLR.exe, Version: 1.0.0.0, Zeitstempel:
 0x4de37890  Name des fehlerhaften Moduls: CliSecureRT.dll, Version: 5.2.0.2, Zeitstempel:
 0x4c492bfd  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00001296  ID des fehlerhaften Prozesses:
 0xab4  Startzeit der fehlerhaften Anwendung: 0x01cc50ba321bc2a9  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe  Pfad
 des fehlerhaften Moduls: C:\Users\Yasmin\AppData\Local\Temp\b01d42a6-0948-4bd0-8dea-54d68f50a791\CliSecureRT.dll
Berichtskennung:
 91eedd3b-bd81-11e0-a2d1-0016d4ae0c6f
 
Error - 04.08.2011 10:14:57 | Computer Name = Yasmin-Laptop | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: audacity.exe, Version: 0.0.0.0, Zeitstempel:
 0x455814e4  Name des fehlerhaften Moduls: audacity.exe, Version: 0.0.0.0, Zeitstempel:
 0x455814e4  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000c17da  ID des fehlerhaften Prozesses:
 0xcdc  Startzeit der fehlerhaften Anwendung: 0x01cc52a6ed170ef3  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Audacity\audacity.exe  Pfad des fehlerhaften Moduls:
C:\Program Files\Audacity\audacity.exe  Berichtskennung: 211b58ce-bea4-11e0-a2e6-0016d4ae0c6f
 
Error - 12.08.2011 15:01:45 | Computer Name = Yasmin-Laptop | Source = Application Hang | ID = 1002
Description = Programm OIS.EXE, Version 12.0.6413.1000 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: da0    Startzeit:
01cc59215a44279d    Endzeit: 60000    Anwendungspfad: C:\PROGRA~1\MICROS~3\Office12\OIS.EXE

Berichts-ID:
 2c6e6843-c515-11e0-835f-0016d4ae0c6f 
 
Error - 13.09.2011 03:56:03 | Computer Name = Yasmin-Laptop | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 6.0.0.4240 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 3e4    Startzeit:
01cc6697c68a9a28    Endzeit: 8128    Anwendungspfad: C:\Program Files\Mozilla Firefox\firefox.exe

Berichts-ID:
 c6bb585f-dddd-11e0-ac73-0016d4ae0c6f 
 
Error - 22.09.2011 17:41:43 | Computer Name = Yasmin-Laptop | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567,
 Zeitstempel: 0x4d6727a7  Name des fehlerhaften Moduls: stobject.dll_unloaded, Version:
 0.0.0.0, Zeitstempel: 0x4ce7ba05  Ausnahmecode: 0xc0000005  Fehleroffset: 0x73912298
ID
 des fehlerhaften Prozesses: 0x12e0  Startzeit der fehlerhaften Anwendung: 0x01cc79705ea96003
Pfad
 der fehlerhaften Anwendung: C:\Windows\explorer.exe  Pfad des fehlerhaften Moduls:
 stobject.dll  Berichtskennung: a970d0bb-e563-11e0-be48-0016d4ae0c6f
 
Error - 30.09.2011 16:23:38 | Computer Name = Yasmin-Laptop | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: Skype.exe, Version: 5.0.0.156, Zeitstempel:
 0x4cf901f4  Name des fehlerhaften Moduls: Skype.exe, Version: 5.0.0.156, Zeitstempel:
 0x4cf901f4  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0057d84e  ID des fehlerhaften Prozesses:
 0xe74  Startzeit der fehlerhaften Anwendung: 0x01cc7faebd08d40b  Pfad der fehlerhaften
 Anwendung: C:\Program Files\Skype\Phone\Skype.exe  Pfad des fehlerhaften Moduls:
C:\Program Files\Skype\Phone\Skype.exe  Berichtskennung: 13d90ab0-eba2-11e0-9da6-0016d4ae0c6f
 
Error - 22.10.2011 16:05:42 | Computer Name = Yasmin-Laptop | Source = Wudf01000 | ID = 921877
Description =
 
Error - 27.10.2011 18:30:53 | Computer Name = Yasmin-Laptop | Source = Application Hang | ID = 1002
Description = Programm Skype.exe, Version 5.5.0.124 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 1014    Startzeit:
 01cc94ed199f9485    Endzeit: 549    Anwendungspfad: C:\Program Files\Skype\Phone\Skype.exe

Berichts-ID:
 4f499524-00eb-11e1-b9bf-0016d4ae0c6f 
 
Error - 11.11.2011 15:43:24 | Computer Name = Yasmin-Laptop | Source = System Restore | ID = 8193
Description =
 
Error - 13.11.2011 10:22:55 | Computer Name = Yasmin-Laptop | Source = Application Hang | ID = 1002
Description = Programm gimp-2.6.exe, Version 0.0.0.0 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 9a0    Startzeit:
01cca20f9cffbda9    Endzeit: 11    Anwendungspfad: C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe

Berichts-ID:
 f29a07d5-0e02-11e1-bef0-0016d4ae0c6f 
 
[ System Events ]
Error - 26.07.2011 08:37:38 | Computer Name = Yasmin-Laptop | Source = Service Control Manager | ID = 7000
Description = Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund
 folgenden Fehlers nicht gestartet:  %%1053
 
Error - 26.07.2011 12:16:51 | Computer Name = Yasmin-Laptop | Source = DCOM | ID = 10010
Description =
 
Error - 26.07.2011 14:23:35 | Computer Name = Yasmin-Laptop | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
 Firmware verfügbar ist.
 
Error - 26.07.2011 15:17:06 | Computer Name = Yasmin-Laptop | Source = DCOM | ID = 10010
Description =
 
Error - 27.07.2011 13:58:06 | Computer Name = Yasmin-Laptop | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
 Firmware verfügbar ist.
 
Error - 27.07.2011 18:59:43 | Computer Name = Yasmin-Laptop | Source = DCOM | ID = 10010
Description =
 
Error - 28.07.2011 04:15:33 | Computer Name = Yasmin-Laptop | Source = DCOM | ID = 10010
Description =
 
Error - 28.07.2011 04:02:14 | Computer Name = Yasmin-Laptop | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
 Firmware verfügbar ist.
 
Error - 28.07.2011 04:25:24 | Computer Name = Yasmin-Laptop | Source = Microsoft-Windows-HAL | ID = 12
Description = Der Speicher wurde beim letzten Leistungsübergang des Systems von
der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte
 Firmware verfügbar ist.
 
Error - 28.07.2011 10:25:24 | Computer Name = Yasmin-Laptop | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
 von Dienst ShellHWDetection erreicht.
 
 
< End of report >

--- --- ---
OTL Logfile:
Code:

OTL logfile created on: 15.11.2011 20:11:30 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Yasmin\Downloads
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,53 Gb Available Physical Memory | 76,77% Memory free
3,98 Gb Paging File | 3,59 Gb Available in Paging File | 90,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 33,26 Gb Free Space | 29,78% Space Free | Partition Type: NTFS
 
Computer Name: YASMIN-LAPTOP | User Name: Yasmin | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Yasmin\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Programme\WinRAR\RarExt.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (NitroReaderDriverReadSpool2) -- C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (NAUpdate) -- C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (ssadmdm) -- C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) -- C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) -- C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (vmbus) -- C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (VX3000) -- C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (ESDCR) -- C:\Windows\System32\drivers\ESD7SK.sys (ENE Technology Inc.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (ESMCR) -- C:\Windows\System32\drivers\ESM7SK.sys (ENE Technology Inc.)
DRV - (EMSCR) -- C:\Windows\System32\drivers\EMS7SK.sys (ENE Technology Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = Hotmail, Messenger, Unterhaltung, Nachrichten, Sport, Jobs, Immobilien und mehr bei MSN AT
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BF 5A E0 EC B7 4B CC 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.3.15590
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.05.17 20:57:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.05.17 20:57:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.09 00:25:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.10.27 23:33:38 | 000,000,000 | ---D | M]
 
[2010.12.28 16:04:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Extensions
[2011.11.11 20:46:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions
[2011.06.27 14:14:33 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.11.11 20:46:09 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.11.01 23:28:43 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions\foxyproxy@eric.h.jung
[2011.11.09 22:00:39 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions\toolbar@ask.com
[2011.11.09 00:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.10.27 22:13:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.10.24 21:40:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.11.05 08:10:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.11.05 04:38:54 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.05 04:32:18 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.05 04:38:54 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.05 04:38:54 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.11.05 04:38:54 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.05 04:38:54 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Badoo Desktop] C:\ProgramData\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe (Badoo)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Programme\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\RunOnce: [ihfkm] C:\Users\Yasmin\AppData\Local\ihfkm.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: Free YouTube Download - C:\Users\Yasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Yasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{399EEDD0-53C7-4BBE-A2DD-0EA90752B05A}: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F9409E1A-9082-428E-8A50-60C07BE96587}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{cf345d4d-13fc-11e0-99ed-0016d4ae0c6f}\Shell - "" = AutoRun
O33 - MountPoints2\{cf345d4d-13fc-11e0-99ed-0016d4ae0c6f}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.11.15 08:40:19 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{D9923919-E27A-45AA-A09D-DE99822A49DD}
[2011.11.15 08:40:04 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{82C61277-ECF5-4434-BA92-0773FC8737CA}
[2011.11.14 23:32:12 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011.11.14 21:21:42 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\.widelands
[2011.11.13 19:50:22 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\GlarySoft
[2011.11.13 15:22:12 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\.gimp-2.6
[2011.11.13 15:22:10 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\Documents\gegl-0.0
[2011.11.13 15:12:06 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{28B6B963-9D38-4795-AC65-61594BA551E6}
[2011.11.12 10:21:37 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{45BFD6B9-7878-40E6-A371-E343A7EBDDDB}
[2011.11.12 10:20:48 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{FBFBF729-46D7-44D6-ADD3-2C88537FD61A}
[2011.11.11 20:44:21 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{1B89CD0E-141C-487F-AF24-36C01B149E41}
[2011.11.09 22:03:45 | 002,341,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.11.09 21:59:50 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{D72D5CE5-6E09-4EB0-8E49-72680F345CE9}
[2011.11.09 21:59:38 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{F2B04E13-F77D-49A8-B2EF-4312C47B8A31}
[2011.11.09 01:01:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities
[2011.11.09 01:01:02 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities
[2011.11.09 01:00:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Widelands
[2011.11.09 00:44:16 | 000,000,000 | ---D | C] -- C:\Program Files\Widelands
[2011.11.09 00:43:09 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\Auslogics
[2011.11.09 00:42:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[2011.11.09 00:42:14 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2011.11.09 00:40:14 | 000,026,408 | ---- | C] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalmon2.dll
[2011.11.09 00:40:14 | 000,017,704 | ---- | C] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalui2.dll
[2011.11.09 00:39:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro PDF
[2011.11.09 00:39:31 | 000,000,000 | ---D | C] -- C:\Program Files\Nitro PDF
[2011.11.09 00:39:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro PDF
[2011.11.09 00:37:22 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\Downloaded Installations
[2011.11.09 00:16:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2011.11.09 00:13:44 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2011.11.08 23:40:26 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{09BC3EB7-8FF0-450F-9B5F-E47272C110A7}
[2011.11.08 23:40:10 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{8CB72E96-E2F4-43A8-96B7-BA7C2545C9FA}
[2011.11.07 01:44:53 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E0A9A437-AB01-45C1-87A6-C8EEE58A7DBE}
[2011.11.06 02:24:34 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{EAC04218-5275-4838-B60E-E857FABDD1A8}
[2011.11.06 02:24:21 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{3C267BEF-805A-448F-BD59-FB88F5BF87FB}
[2011.11.03 16:53:24 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{8396744F-8C46-457D-95DD-FB4E72AC9855}
[2011.11.03 16:53:02 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{6B67746F-042F-48EA-B013-60E352188417}
[2011.11.01 22:29:58 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E5F7470A-DB8B-4784-9620-78D0DB45CC78}
[2011.11.01 22:29:46 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{5739A0E8-C370-453A-940A-C323F71FAA09}
[2011.10.31 12:13:23 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2C6B679E-A650-4174-8F70-2E1543F027EA}
[2011.10.31 12:13:05 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{CCC76930-11D8-4FBD-B586-48422951B662}
[2011.10.31 00:23:51 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{CFDEE39F-15D8-4D3F-B512-6C9B31DD096A}
[2011.10.31 00:23:40 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{ECD6433E-C9EF-4193-8D92-93BBE39C2400}
[2011.10.29 08:54:40 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2D311157-AD14-4404-8FFD-7D3BA512CAE8}
[2011.10.29 08:54:17 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2800E545-AEAA-41D5-8164-D72EB800EDE6}
[2011.10.28 20:44:07 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{F3F7CFF0-A510-4EEF-866F-6DC2C17CE39D}
[2011.10.28 07:37:19 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{AFD6AD38-E2C9-4556-84DF-07A75B83EA12}
[2011.10.28 07:37:04 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{DD65C528-6FCF-409B-B036-402CB0F7C130}
[2011.10.28 07:36:24 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\Apple Computer
[2011.10.27 23:33:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011.10.27 23:32:50 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011.10.27 23:32:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011.10.27 22:12:57 | 000,000,000 | ---D | C] -- C:\Temp
[2011.10.27 13:52:07 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{6D019BAE-8C22-4FAF-BC56-4823B861F41F}
[2011.10.27 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{7BA56048-CA29-4083-864A-4700C28B557A}
[2011.10.26 13:17:05 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{A62BA51B-E3C7-4058-A0E1-7A5A3C323EF1}
[2011.10.26 07:17:26 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{D5E90797-D4C4-42B9-9490-8A12688947D8}
[2011.10.25 12:32:02 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{0527C41B-13E7-4BE4-A077-E121CCA580D3}
[2011.10.25 12:31:48 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{1FBB4F63-F7D8-46A2-8CE3-BB29A50493C8}
[2011.10.24 21:41:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011.10.24 21:40:33 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.10.24 21:40:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.10.24 21:40:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.10.24 21:34:56 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2EC8AF40-AD24-4EF7-928E-320A8A564072}
[2011.10.24 21:34:31 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{B42FA9E7-87C5-4DE2-B051-C44FBD2BFA4B}
[2011.10.24 13:29:02 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx
[2011.10.24 13:29:02 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts
[2011.10.24 09:01:52 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{05C7A2EB-44F4-45A4-B2FE-CB1E4F5D6B4E}
[2011.10.24 09:01:34 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{3B5115CE-EBDB-4C26-BAB8-03D85AD2B562}
[2011.10.22 13:21:54 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{360C2E55-AA19-4A5F-8C86-A16BE4F0B442}
[2011.10.22 13:21:31 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{639E63A8-19C4-4BB5-A3C3-C0C09A2CAA81}
[2011.10.22 09:14:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Badoo
[2011.10.21 23:52:33 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{262C5049-B4A4-494A-98E3-4B98B78858DD}
[2011.10.21 11:51:53 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{B56FDB0D-37D2-4E72-8EB8-79BD858601C7}
[2011.10.21 11:51:36 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{782A2428-2AE3-4AD9-AFAB-558700B41D28}
[2011.10.19 12:59:08 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{867AEA63-F708-4CF3-82AA-6438E867B59E}
[2011.10.18 17:10:18 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E2269986-862A-4364-B8D1-FD4F9EE10658}
[2011.10.18 17:09:07 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{F043BE4C-C693-44DD-BD44-B1953693C78D}
[2011.10.18 14:55:59 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{0BF2709F-07D6-4159-8253-DC85442AE9DD}
[2011.10.18 08:56:03 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E94D4C3C-6B4F-43C5-8377-231A589011AB}
 
========== Files - Modified Within 30 Days ==========
 
[2011.11.15 20:00:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.15 20:00:12 | 1602,838,528 | -HS- | M] () -- C:\hiberfil.sys
[2011.11.15 19:45:55 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2011.11.15 10:48:44 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.11.15 10:48:44 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.11.15 08:49:12 | 000,361,472 | ---- | M] () -- C:\Users\Yasmin\AppData\Local\ihfkm.exe
[2011.11.15 08:40:01 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.11.14 23:32:05 | 000,001,197 | ---- | M] () -- C:\Users\Yasmin\Desktop\Auslogics BoostSpeed.lnk
[2011.11.11 21:52:52 | 000,409,384 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.11.09 01:01:20 | 000,001,024 | ---- | M] () -- C:\Users\Yasmin\Desktop\Glary Utilities.lnk
[2011.11.09 01:00:16 | 000,001,941 | ---- | M] () -- C:\Users\Yasmin\Desktop\Widelands - Mapeditor.lnk
[2011.11.09 01:00:16 | 000,001,847 | ---- | M] () -- C:\Users\Yasmin\Desktop\Widelands.lnk
[2011.11.09 00:42:24 | 000,001,204 | ---- | M] () -- C:\Users\Yasmin\Desktop\Auslogics Disk Defrag.lnk
[2011.11.09 00:40:07 | 000,001,993 | ---- | M] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
[2011.11.09 00:25:03 | 000,001,092 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.11.09 00:16:07 | 000,001,065 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2011.11.06 02:26:24 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.06 02:26:24 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.06 02:26:24 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.06 02:26:24 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.10.27 23:33:19 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011.10.27 23:13:36 | 001,046,659 | ---- | M] () -- C:\Users\Yasmin\Desktop\Unbenannt (13).wma
[2011.10.27 23:05:05 | 002,878,579 | ---- | M] () -- C:\Users\Yasmin\Desktop\Unbenannt (12).wma
[2011.10.27 22:49:46 | 001,742,609 | ---- | M] () -- C:\Users\Yasmin\Desktop\Unbenannt (10).wma
[2011.10.27 22:04:27 | 000,098,619 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_fertig.png
[2011.10.27 15:27:52 | 000,232,774 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer2.png
[2011.10.27 15:05:07 | 000,129,674 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke2.png
[2011.10.27 14:47:27 | 000,128,541 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke.png
[2011.10.27 14:39:33 | 000,128,033 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer.png
[2011.10.25 16:13:44 | 000,017,704 | ---- | M] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalui2.dll
[2011.10.25 16:13:42 | 000,026,408 | ---- | M] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalmon2.dll
[2011.10.24 13:29:02 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx
[2011.10.24 13:29:02 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts
[2011.10.22 09:14:15 | 000,000,984 | ---- | M] () -- C:\Users\Yasmin\Desktop\Badoo.Desktop.lnk
 
========== Files Created - No Company Name ==========
 
[2011.11.15 08:49:12 | 000,361,472 | ---- | C] () -- C:\Users\Yasmin\AppData\Local\ihfkm.exe
[2011.11.14 23:32:05 | 000,001,197 | ---- | C] () -- C:\Users\Yasmin\Desktop\Auslogics BoostSpeed.lnk
[2011.11.09 01:01:29 | 000,000,316 | ---- | C] () -- C:\Windows\tasks\GlaryInitialize.job
[2011.11.09 01:01:20 | 000,001,024 | ---- | C] () -- C:\Users\Yasmin\Desktop\Glary Utilities.lnk
[2011.11.09 01:00:16 | 000,001,941 | ---- | C] () -- C:\Users\Yasmin\Desktop\Widelands - Mapeditor.lnk
[2011.11.09 01:00:16 | 000,001,847 | ---- | C] () -- C:\Users\Yasmin\Desktop\Widelands.lnk
[2011.11.09 00:42:24 | 000,001,204 | ---- | C] () -- C:\Users\Yasmin\Desktop\Auslogics Disk Defrag.lnk
[2011.11.09 00:40:07 | 000,002,495 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro PDF Reader 2.lnk
[2011.11.09 00:40:07 | 000,001,993 | ---- | C] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
[2011.11.09 00:16:07 | 000,001,065 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2011.10.27 23:33:19 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011.10.27 23:13:35 | 001,046,659 | ---- | C] () -- C:\Users\Yasmin\Desktop\Unbenannt (13).wma
[2011.10.27 23:05:05 | 002,878,579 | ---- | C] () -- C:\Users\Yasmin\Desktop\Unbenannt (12).wma
[2011.10.27 22:49:46 | 001,742,609 | ---- | C] () -- C:\Users\Yasmin\Desktop\Unbenannt (10).wma
[2011.10.27 15:44:45 | 000,098,619 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_fertig.png
[2011.10.27 15:27:50 | 000,232,774 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer2.png
[2011.10.27 15:05:05 | 000,129,674 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke2.png
[2011.10.27 14:47:26 | 000,128,541 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke.png
[2011.10.27 14:39:33 | 000,128,033 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer.png
[2011.10.22 09:14:15 | 000,000,984 | ---- | C] () -- C:\Users\Yasmin\Desktop\Badoo.Desktop.lnk
[2011.10.22 09:14:14 | 000,001,138 | ---- | C] () -- C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Badoo Desktop.lnk
[2011.07.13 08:50:31 | 000,004,608 | ---- | C] () -- C:\Users\Yasmin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.06.27 16:08:53 | 000,007,605 | ---- | C] () -- C:\Users\Yasmin\AppData\Local\Resmon.ResmonCfg
[2011.05.08 04:03:33 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.05.08 04:00:05 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.04.27 13:19:32 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011.04.27 13:19:30 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011.04.27 13:19:30 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011.04.27 13:19:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011.04.27 13:19:30 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011.01.03 22:52:08 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.01.03 22:52:08 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010.12.28 16:28:05 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010.12.28 16:22:38 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010.12.28 15:50:36 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.07.14 09:47:43 | 000,654,166 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 09:47:43 | 000,130,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 000,409,384 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,616,008 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.26 16:21:02 | 000,015,498 | ---- | C] () -- C:\Windows\VX3000.ini
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:07BF512B

< End of report >

--- --- ---

...ich hoffe, ich habe das nun richtig gemacht!
Danke auf jeden Fall schonmal für die erste Reaktion und Hilfe! :)

markusg 15.11.2011 21:09

hiho
achtung!
dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
O4 - HKCU..\RunOnce: [ihfkm] C:\Users\Yasmin\AppData\Local\ihfkm.exe ()
:Files
C:\Users\Yasmin\AppData\Local\ihfkm.exe
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.

start in den normalen modus sollte klappen
schau mal ob du die mail noch hast und sende die mir als private nachicht

öffne computer, öffne C: dann _OTL
dort rechtsklick auf moved files
wähle zu moved files.rar oder zip hinzufügen.
folge dem link, und lade das archiv im upload channel hoch
http://www.trojaner-board.de/54791-a...ner-board.html

Yasmin 15.11.2011 21:29

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ihfkm deleted successfully.
C:\Users\Yasmin\AppData\Local\ihfkm.exe moved successfully.
========== FILES ==========
File\Folder C:\Users\Yasmin\AppData\Local\ihfkm.exe not found.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Yasmin
->Flash cache emptied: 17043855 bytes

Total Flash Files Cleaned = 16,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Yasmin
->Temp folder emptied: 12868765 bytes
->Temporary Internet Files folder emptied: 151834617 bytes
->Java cache emptied: 57047450 bytes
->FireFox cache emptied: 45679869 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8672336 bytes
RecycleBin emptied: 792074 bytes

Total Files Cleaned = 264,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 11152011_211503

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...



Und die .rar Datei habe ich auch schon hochgeladen!

Übrigens toll! Der Sercurity Shield hat sich bisher nicht mehr geöffnet! :daumenhoch:
Langsam ist er immer noch, aber ich warte natürlich auch weitere Anweisungen! Danke, Danke trotzdem schonmal!!

markusg 15.11.2011 21:35

das ist doch schon mal was
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.

Bitte downloade dir Combofix.exe und speichere es unbedingt auf deinem Desktop.
  • Besuche folgende Seite für Downloadlinks und Anweisungen für dieses
    Tool

    http://www.bleepingcomputer.com/comb...x-benutzt-wird
  • Hinweis:
    Gehe sicher das all deine Anti Virus und Anti Malware Programme abgeschalten sind, damit diese Combofix nicht bei der Arbeit stören.
  • Poste bitte die C:\Combofix.txt in deiner nächsten Antwort.

markusg 15.11.2011 21:40

vergiss nicht, ich wollte bitte den link aus der mail als private nachicht falls möglich.

Yasmin 15.11.2011 22:14

Private Nachricht habe ich schon geschickt!

Tut mir Leid, dass es jetzt so lange dauerte.. musste danach nochmal neu starten, da ich plötzlich kein Internet mehr starten konnte.
Hier nun die Daten:

Combofix Logfile:
Code:

ComboFix 11-11-15.03 - Yasmin 15.11.2011  21:47:49.1.1 - x86
Microsoft Windows 7 Ultimate  6.1.7601.1.1252.43.1031.18.2038.1390 [GMT 1:00]
ausgeführt von:: c:\users\Yasmin\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Yasmin\AppData\Local\Temp\ae201572-4813-4010-9ed2-ee29ddec066a\CliSecureRT.dll
c:\windows\iun6002.exe
c:\windows\system32\muzapp.exe
c:\windows\system32\system32
c:\windows\system32\system32\3DAudio.ax
c:\windows\system32\system32\avrt.dll
c:\windows\system32\system32\cis-2.4.dll
c:\windows\system32\system32\issacapi_bs-2.3.dll
c:\windows\system32\system32\issacapi_pe-2.3.dll
c:\windows\system32\system32\issacapi_se-2.3.dll
c:\windows\system32\system32\MACXMLProto.dll
c:\windows\system32\system32\MaDRM.dll
c:\windows\system32\system32\MaJGUILib.dll
c:\windows\system32\system32\MAMACExtract.dll
c:\windows\system32\system32\MASetupCleaner.exe
c:\windows\system32\system32\MaXMLProto.dll
c:\windows\system32\system32\mfplat.dll
c:\windows\system32\system32\MK_Lyric.dll
c:\windows\system32\system32\MSCLib.dll
c:\windows\system32\system32\MSFLib.dll
c:\windows\system32\system32\MSLUR71.dll
c:\windows\system32\system32\msvcp60.dll
c:\windows\system32\system32\MTTELECHIP.dll
c:\windows\system32\system32\MTXSYNCICON.dll
c:\windows\system32\system32\muzaf1.dll
c:\windows\system32\system32\muzapp.dll
c:\windows\system32\system32\muzapp.exe
c:\windows\system32\system32\muzdecode.ax
c:\windows\system32\system32\muzeffect.ax
c:\windows\system32\system32\muzmp4sp.ax
c:\windows\system32\system32\muzmpgsp.ax
c:\windows\system32\system32\muzoggsp.ax
c:\windows\system32\system32\muzwmts.dll
c:\windows\system32\system32\psapi.dll
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-10-15 bis 2011-11-15  ))))))))))))))))))))))))))))))
.
.
2011-11-15 20:55 . 2011-11-15 20:59        --------        d-----w-        c:\users\Yasmin\AppData\Local\temp
2011-11-15 20:55 . 2011-11-15 20:55        --------        d-----w-        c:\users\Default\AppData\Local\temp
2011-11-15 20:22 . 2011-11-15 20:22        56200        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{85C1E40A-D036-4236-A08B-C0F4AA325E34}\offreg.dll
2011-11-15 20:15 . 2011-11-15 20:23        --------        d-----w-        C:\_OTL
2011-11-14 20:21 . 2011-11-14 21:58        --------        d-----w-        c:\users\Yasmin\.widelands
2011-11-13 18:50 . 2011-11-13 18:50        --------        d-----w-        c:\users\Yasmin\AppData\Roaming\GlarySoft
2011-11-13 14:22 . 2011-11-13 14:22        --------        d-----w-        c:\users\Yasmin\.gimp-2.6
2011-11-11 19:53 . 2011-10-07 03:48        6668624        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{85C1E40A-D036-4236-A08B-C0F4AA325E34}\mpengine.dll
2011-11-09 21:03 . 2011-09-29 16:03        1290608        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2011-11-09 21:03 . 2011-10-01 04:37        708608        ----a-w-        c:\program files\Common Files\System\wab32.dll
2011-11-09 21:03 . 2011-09-29 03:37        2341888        ----a-w-        c:\windows\system32\win32k.sys
2011-11-09 00:01 . 2011-11-09 00:01        --------        d-----w-        c:\program files\Glary Utilities
2011-11-08 23:44 . 2011-11-14 21:58        --------        d-----w-        c:\program files\Widelands
2011-11-08 23:43 . 2011-11-14 22:37        --------        d-----w-        c:\users\Yasmin\AppData\Roaming\Auslogics
2011-11-08 23:42 . 2011-11-14 22:31        --------        d-----w-        c:\program files\Auslogics
2011-11-08 23:40 . 2011-10-25 15:13        17704        ----a-w-        c:\windows\system32\nitrolocalui2.dll
2011-11-08 23:40 . 2011-10-25 15:13        26408        ----a-w-        c:\windows\system32\nitrolocalmon2.dll
2011-11-08 23:39 . 2011-11-08 23:39        --------        d-----w-        c:\programdata\Nitro PDF
2011-11-08 23:39 . 2011-11-08 23:39        --------        d-----w-        c:\program files\Nitro PDF
2011-11-08 23:39 . 2011-11-08 23:39        --------        d-----w-        c:\program files\Common Files\Nitro PDF
2011-11-08 23:37 . 2011-11-08 23:37        --------        d-----w-        c:\users\Yasmin\AppData\Roaming\Downloaded Installations
2011-11-08 23:13 . 2011-11-08 23:14        --------        d-----w-        c:\program files\GIMP-2.0
2011-10-28 06:36 . 2011-10-28 06:36        --------        d-----w-        c:\users\Yasmin\AppData\Roaming\Apple Computer
2011-10-27 22:32 . 2011-10-27 22:32        --------        d-----w-        c:\programdata\Apple Computer
2011-10-27 21:12 . 2011-10-27 21:12        --------        d-----w-        C:\Temp
2011-10-26 12:08 . 2011-08-13 04:18        6144        ----a-w-        c:\program files\Internet Explorer\iecompat.dll
2011-10-24 20:41 . 2011-10-24 20:41        --------        d-----w-        c:\program files\Common Files\Java
2011-10-24 12:29 . 2011-10-24 12:29        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2011-10-24 12:29 . 2011-10-24 12:29        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2011-10-22 08:14 . 2011-10-22 08:14        --------        d-----w-        c:\programdata\Badoo
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 07:40 . 2011-05-19 21:44        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 03:06 . 2010-12-28 15:20        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2011-10-01 02:42 . 2011-10-11 17:37        1638912        ----a-w-        c:\windows\system32\mshtml.tlb
2011-08-27 04:26 . 2011-10-11 17:37        233472        ----a-w-        c:\windows\system32\oleacc.dll
2011-08-27 04:26 . 2011-10-11 17:37        571904        ----a-w-        c:\windows\system32\oleaut32.dll
2011-08-20 04:31 . 2011-10-11 17:37        981504        ----a-w-        c:\windows\system32\wininet.dll
2011-11-05 07:10 . 2011-05-01 04:05        134104        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-08-23 19:20        1515688        ----a-w-        c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-23 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-23 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2011-09-29 929680]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2011-09-29 3508112]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-09-29 20880]
"Badoo Desktop"="c:\programdata\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe" [2011-08-04 1042944]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-08-23 887976]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserChoice]
2010-02-11 07:10        293376        ----a-w-        c:\windows\System32\browserchoice.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-07-20 121064]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-07-20 12776]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-07-20 136808]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-28 1343400]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-30 136360]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-10-25 217088]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe [2011-10-25 196904]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-10-25 36640]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
Inhalt des "geplante Tasks" Ordners
.
2011-11-15 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-11-09 12:08]
.
.
------- Zusätzlicher Suchlauf -------
.
IE: Free YouTube Download - c:\users\Yasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\users\Yasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.at/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-Karaoke Anything!1.0 - c:\windows\iun6002.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
AddRemove-26_VIA_driver2 - c:\program files\Samsung\USB Drivers\26_VIA_driver2\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\program files\Auslogics\Auslogics BoostSpeed\BoostSpeed.exe
c:\windows\system32\conhost.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2011-11-15  22:06:03 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2011-11-15 21:06
.
Vor Suchlauf: 8 Verzeichnis(se), 35.746.037.760 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 35.282.317.312 Bytes frei
.
- - End Of File - - 878E1E4DFAB7694F47048F90199E5159

--- --- ---

markusg 16.11.2011 13:15

nehme dir einfach so viel zeit wie es benötigt :-)

malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

Yasmin 16.11.2011 17:43

Musste keine Dateien löschen, hatte nichts gefunden...


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Datenbank Version: 8176

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

16.11.2011 17:38:05
mbam-log-2011-11-16 (17-38-05).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Durchsuchte Objekte: 278400
Laufzeit: 1 Stunde(n), 7 Minute(n), 59 Sekunde(n)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 0
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 0

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
(Keine bösartigen Objekte gefunden)

markusg 16.11.2011 17:46

hi.
1. läuft er noch langsam?
lade den CCleaner standard:
CCleaner Download - CCleaner 3.12.1572
falls der CCleaner
bereits instaliert, überspringen.
instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

Yasmin 16.11.2011 19:01

Naja wirklich flink ist er irgendwie noch nicht... aber schon viiel besser!

Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 18.05.2011 6,00MB 10.3.181.14 notwenig
Adobe Flash Player 11 Plugin Adobe Systems Incorporated 14.11.2011 6,00MB 11.1.102.55 notwenig
Adobe Reader X (10.1.1) - Deutsch Adobe Systems Incorporated 16.09.2011 165,9MB 10.1.1 notwenig
Apple Application Support Apple Inc. 27.10.2011 61,1MB 2.1.5 unbekannt
Apple Software Update Apple Inc. 24.07.2011 2,38MB 2.1.3.127 unbekannt
Ask Toolbar Ask.com 11.10.2011 4,18MB 1.13.1.0 unnötig
Audacity 1.2.6 25.07.2011 notwenig
Audiograbber 1.83 SE Audiograbber 28.12.2010 1.83 SE nötig glaub ich
Audiograbber MP3-Plugin AG 27.12.2010 1.0 nötig glaub ich
Auslogics BoostSpeed Auslogics Software Pty Ltd 13.11.2011 42,0MB 5.2 neu und noch nicht getestet
Auslogics Disk Defrag Auslogics Software Pty Ltd 08.11.2011 9,37MB version 3.3 neu und noch nicht getestet
Avira AntiVir Personal - Free Antivirus Avira GmbH 13.10.2011 76,9MB 10.2.0.704 notwenig
Badoo Desktop Badoo 21.10.2011 1,80MB 1.6.38.1042 notwenig
CCleaner Piriform 15.11.2011 3.12 notwenig
DivX-Setup DivX, LLC 09.10.2011 2.5.0.8 notwenig
Free Studio version 5.1.4 DVDVideoSoft Limited. 25.07.2011 346MB notwenig
Free YouTube Download 3 version 3.0.10.722 DVDVideoSoft Limited. 25.07.2011 44,8MB notwenig
Free YouTube to MP3 Converter version 3.9.40.602 DVDVideoSoft Limited. 26.06.2011 35,5MB notwenig
GIMP 2.6.11 The GIMP Team 08.11.2011 107,7MB 2.6.11 neu und noch nicht getestet
Glary Utilities 2.39.0.1310 Glarysoft Ltd 08.11.2011 18,6MB 2.39.0.1310 notwenig
HDAUDIO Soft Data Fax Modem with SmartCP 27.12.2010 unbekannt
Intel(R) Graphics Media Accelerator Driver Intel Corporation 27.12.2010 54,3MB 8.15.10.1930 unbekannt
Java(TM) 6 Update 29 Oracle 27.12.2010 97,1MB 6.0.290 notwenig
K-Lite Codec Pack 6.6.6 (Standard) 27.12.2010 36,3MB 6.6.6 unbekannt
Malwarebytes' Anti-Malware Version 1.51.2.1300 Malwarebytes Corporation 15.11.2011 13,8MB 1.51.2.1300 notwenig
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 12.07.2011 38,8MB 4.0.30320 unbekannt
Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 12.07.2011 2,94MB 4.0.30320 unbekannt
Microsoft LifeCam Microsoft Corporation 27.07.2011 50,0MB 3.22.270.0 notwendig
Microsoft Office Enterprise 2007 Microsoft Corporation 27.12.2010 12.0.6425.1000 unbekannt
Microsoft Office File Validation Add-In Microsoft Corporation 15.09.2011 7,95MB 14.0.5130.5003 unbekannt
Microsoft Silverlight Microsoft Corporation 10.10.2011 140,1MB 4.0.60831.0 unbekannt
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 15.06.2011 0,29MB 8.0.61001 unbekannt
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Corporation 12.04.2011 0,58MB 9.0.30729.5570 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 27.12.2010 0,58MB 9.0.30729.4148 unbekannt
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 15.06.2011 0,59MB 9.0.30729.6161 unbekannt
Mozilla Firefox 8.0 (x86 de) Mozilla 08.11.2011 41,0MB 8.0 notwenig
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 27.12.2010 35,00KB 4.20.9870.0 unbekannt
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 27.12.2010 1,33MB 4.20.9876.0 unbekannt
Nero BurnLite 10 Nero AG 27.12.2010 57,6MB 10.0.10600 notwenig
Nero Update Nero AG 27.12.2010 1,44MB 1.0.0018 notwenig
Nitro PDF Reader 2 Nitro PDF Software 08.11.2011 88,6MB 2.1.0.13 notwenig
PDFCreator Frank Heindörfer, Philip Chinery 27.12.2010 1.1.0 notwenig
QuickTime Apple Inc. 27.10.2011 73,3MB 7.71.80.42 notwenig
Samsung Kies Samsung Electronics Co., Ltd. 06.05.2011 181,3MB 2.0.0.11044_11 notwenig
SAMSUNG USB Driver for Mobile Phones SAMSUNG Electronics Co., Ltd. 14.11.2011 48,8MB 1.4.4.0 notwenig
Skype Click to Call Skype Technologies S.A. 26.10.2011 20,9MB 5.6.8442 notwenig
Skype™ 5.5 Skype Technologies S.A. 26.10.2011 17,0MB 5.5.124 notwenig
Widelands Widelands Development Team 08.11.2011 166,3MB Widelands notwenig
Windows Live Essentials Microsoft Corporation 04.08.2011 15.4.3538.0513 denke das ist msn? wenn ja notwenig, wenn nein unbekannt
WinRAR 27.12.2010 unbekannt

markusg 16.11.2011 19:15

deinstaliere:
Apple beide
Ask
Audiograbber wenn du es nicht nutzt kann es weg und zwar beide.

Auslogics beide weg, solche tuning tools nützen meist nichts
K-Lite
Microsoft Office schreibzeug, falls nicht genutzt alle weg..
Windows Live Essentials

bereinige mit dem ccleaner. sag mir was genau langsamer ist.

Yasmin 16.11.2011 20:34

gelöscht...

Langsamer ist noch teilweise der Aufbau von Homepages (auch diese hier), bzw. Anwendungen wie MSN, Skype..

markusg 16.11.2011 20:36

ok poste mir erst mal ein frisches otl logfile.

Yasmin 16.11.2011 20:52

OTL Logfile:
Code:

OTL logfile created on: 16.11.2011 20:40:12 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\Yasmin\Downloads
 Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000c07 | Country: Österreich | Language: DEA | Date Format: dd.MM.yyyy
 
1,99 Gb Total Physical Memory | 1,21 Gb Available Physical Memory | 60,95% Memory free
3,98 Gb Paging File | 2,83 Gb Available in Paging File | 70,98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 33,65 Gb Free Space | 30,13% Space Free | Partition Type: NTFS
 
Computer Name: YASMIN-LAPTOP | User Name: Yasmin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Yasmin\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Programme\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)
PRC - C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Programme\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\ProgramData\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe (Badoo)
PRC - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Programme\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
PRC - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\FsUsbExService.Exe (Teruten)
PRC - C:\Windows\vVX3000.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Programme\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Programme\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Users\Yasmin\AppData\Local\Temp\ae201572-4813-4010-9ed2-ee29ddec066a\CliSecureRT.dll ()
MOD - C:\Programme\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\adc6081b96ada807b858bd7dd6c44b08\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\3c0633ebbeacf2d66ef3952b50568479\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\b8f8841931a97c3ab2b652f13cfeb295\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\9db16bf8a565eaa6bbb182dcd147cfb6\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\945868a5fd952dcfe3fa4904cbab936a\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\1020c111f6b4ffeafa3055475e8df7de\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\2250dfa714756e8a58db82433c1ae275\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\11a64ded5d210891688bdef1c54c26e4\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\7306f4ac763fc6264804397bc22226e8\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\968981974b267a245b7b78393836df5a\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\18ec39f6cef17c8576736b60e0be5131\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\34b8c9534065b074e4e5228f40310e13\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\404a37992b5c2de07993795fb48dfc65\mscorlib.ni.dll ()
MOD - C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Programme\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Programme\DivX\DivX Update\DivXUpdate.exe ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (NitroReaderDriverReadSpool2) -- C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (Nitro PDF Software)
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (FsUsbExService) -- C:\Windows\System32\FsUsbExService.Exe (Teruten)
SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (NAUpdate) -- C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (ssadmdm) -- C:\Windows\System32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) -- C:\Windows\System32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) -- C:\Windows\System32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (vmbus) -- C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) -- C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (FsUsbExDisk) -- C:\Windows\System32\FsUsbExDisk.Sys ()
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (VX3000) -- C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (bcm4sbxp) -- C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (ESDCR) -- C:\Windows\System32\drivers\ESD7SK.sys (ENE Technology Inc.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (ESMCR) -- C:\Windows\System32\drivers\ESM7SK.sys (ENE Technology Inc.)
DRV - (EMSCR) -- C:\Windows\System32\drivers\EMS7SK.sys (ENE Technology Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2F 8F 01 C3 CF A3 CC 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.at/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.3.15590
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.05.17 20:57:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.05.17 20:57:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.09 00:25:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.10.27 23:33:38 | 000,000,000 | ---D | M]
 
[2010.12.28 16:04:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Extensions
[2011.11.16 20:38:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions
[2011.06.27 14:14:33 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.11.11 20:46:09 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.11.01 23:28:43 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Yasmin\AppData\Roaming\mozilla\Firefox\Profiles\zcqwj0dp.default\extensions\foxyproxy@eric.h.jung
[2011.11.09 00:25:01 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.10.27 22:13:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.10.24 21:40:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011.11.05 08:10:35 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.11.05 04:38:54 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.11.05 04:32:18 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011.11.05 04:38:54 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2011.11.05 04:38:54 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.11.05 04:38:54 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.11.05 04:38:54 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2011.11.15 21:57:56 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Programme\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Badoo Desktop] C:\ProgramData\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe (Badoo)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Programme\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\Yasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Yasmin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{399EEDD0-53C7-4BBE-A2DD-0EA90752B05A}: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F9409E1A-9082-428E-8A50-60C07BE96587}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011.11.16 20:25:38 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.11.16 18:12:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.11.16 18:12:14 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.11.16 16:28:39 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\Malwarebytes
[2011.11.16 16:28:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.11.16 16:28:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.11.16 16:28:11 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.11.16 16:28:11 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.11.16 16:02:42 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{B7869F11-F5A4-4888-94E0-0BE19A03E141}
[2011.11.16 16:02:17 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{AFCF0E60-482E-41F2-970A-6DFE6B1496C4}
[2011.11.15 22:06:05 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.11.15 21:58:04 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2011.11.15 21:55:57 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\temp
[2011.11.15 21:45:26 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.11.15 21:45:26 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.11.15 21:45:26 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.11.15 21:45:19 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.11.15 21:45:14 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.11.15 21:15:03 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.11.15 20:42:03 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{28725DB6-D932-4B0E-8C7A-7CEC1AFC72BC}
[2011.11.15 20:41:34 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{43C72884-C11A-4B50-A3E6-9992177549A4}
[2011.11.15 08:40:19 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{D9923919-E27A-45AA-A09D-DE99822A49DD}
[2011.11.15 08:40:04 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{82C61277-ECF5-4434-BA92-0773FC8737CA}
[2011.11.14 23:32:12 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011.11.14 21:21:42 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\.widelands
[2011.11.13 19:50:22 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\GlarySoft
[2011.11.13 15:22:12 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\.gimp-2.6
[2011.11.13 15:22:10 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\Documents\gegl-0.0
[2011.11.13 15:12:06 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{28B6B963-9D38-4795-AC65-61594BA551E6}
[2011.11.12 10:21:37 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{45BFD6B9-7878-40E6-A371-E343A7EBDDDB}
[2011.11.12 10:20:48 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{FBFBF729-46D7-44D6-ADD3-2C88537FD61A}
[2011.11.11 20:44:21 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{1B89CD0E-141C-487F-AF24-36C01B149E41}
[2011.11.09 22:03:45 | 002,341,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011.11.09 21:59:50 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{D72D5CE5-6E09-4EB0-8E49-72680F345CE9}
[2011.11.09 21:59:38 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{F2B04E13-F77D-49A8-B2EF-4312C47B8A31}
[2011.11.09 01:01:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities
[2011.11.09 01:01:02 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities
[2011.11.09 01:00:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Widelands
[2011.11.09 00:44:16 | 000,000,000 | ---D | C] -- C:\Program Files\Widelands
[2011.11.09 00:43:09 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\Auslogics
[2011.11.09 00:42:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[2011.11.09 00:42:14 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2011.11.09 00:40:14 | 000,026,408 | ---- | C] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalmon2.dll
[2011.11.09 00:40:14 | 000,017,704 | ---- | C] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalui2.dll
[2011.11.09 00:39:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro PDF
[2011.11.09 00:39:31 | 000,000,000 | ---D | C] -- C:\Program Files\Nitro PDF
[2011.11.09 00:39:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro PDF
[2011.11.09 00:37:22 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\Downloaded Installations
[2011.11.09 00:16:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2011.11.09 00:13:44 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2011.11.08 23:40:26 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{09BC3EB7-8FF0-450F-9B5F-E47272C110A7}
[2011.11.08 23:40:10 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{8CB72E96-E2F4-43A8-96B7-BA7C2545C9FA}
[2011.11.07 01:44:53 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E0A9A437-AB01-45C1-87A6-C8EEE58A7DBE}
[2011.11.06 02:24:34 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{EAC04218-5275-4838-B60E-E857FABDD1A8}
[2011.11.06 02:24:21 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{3C267BEF-805A-448F-BD59-FB88F5BF87FB}
[2011.11.03 16:53:24 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{8396744F-8C46-457D-95DD-FB4E72AC9855}
[2011.11.03 16:53:02 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{6B67746F-042F-48EA-B013-60E352188417}
[2011.11.01 22:29:58 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E5F7470A-DB8B-4784-9620-78D0DB45CC78}
[2011.11.01 22:29:46 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{5739A0E8-C370-453A-940A-C323F71FAA09}
[2011.10.31 12:13:23 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2C6B679E-A650-4174-8F70-2E1543F027EA}
[2011.10.31 12:13:05 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{CCC76930-11D8-4FBD-B586-48422951B662}
[2011.10.31 00:23:51 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{CFDEE39F-15D8-4D3F-B512-6C9B31DD096A}
[2011.10.31 00:23:40 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{ECD6433E-C9EF-4193-8D92-93BBE39C2400}
[2011.10.29 08:54:40 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2D311157-AD14-4404-8FFD-7D3BA512CAE8}
[2011.10.29 08:54:17 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2800E545-AEAA-41D5-8164-D72EB800EDE6}
[2011.10.28 20:44:07 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{F3F7CFF0-A510-4EEF-866F-6DC2C17CE39D}
[2011.10.28 07:37:19 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{AFD6AD38-E2C9-4556-84DF-07A75B83EA12}
[2011.10.28 07:37:04 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{DD65C528-6FCF-409B-B036-402CB0F7C130}
[2011.10.28 07:36:24 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Roaming\Apple Computer
[2011.10.27 23:33:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011.10.27 23:32:50 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011.10.27 23:32:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011.10.27 22:12:57 | 000,000,000 | ---D | C] -- C:\Temp
[2011.10.27 13:52:07 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{6D019BAE-8C22-4FAF-BC56-4823B861F41F}
[2011.10.27 13:51:01 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{7BA56048-CA29-4083-864A-4700C28B557A}
[2011.10.26 13:17:05 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{A62BA51B-E3C7-4058-A0E1-7A5A3C323EF1}
[2011.10.26 07:17:26 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{D5E90797-D4C4-42B9-9490-8A12688947D8}
[2011.10.25 12:32:02 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{0527C41B-13E7-4BE4-A077-E121CCA580D3}
[2011.10.25 12:31:48 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{1FBB4F63-F7D8-46A2-8CE3-BB29A50493C8}
[2011.10.24 21:41:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011.10.24 21:40:33 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011.10.24 21:40:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011.10.24 21:40:33 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011.10.24 21:34:56 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{2EC8AF40-AD24-4EF7-928E-320A8A564072}
[2011.10.24 21:34:31 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{B42FA9E7-87C5-4DE2-B051-C44FBD2BFA4B}
[2011.10.24 13:29:02 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx
[2011.10.24 13:29:02 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts
[2011.10.24 09:01:52 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{05C7A2EB-44F4-45A4-B2FE-CB1E4F5D6B4E}
[2011.10.24 09:01:34 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{3B5115CE-EBDB-4C26-BAB8-03D85AD2B562}
[2011.10.22 13:21:54 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{360C2E55-AA19-4A5F-8C86-A16BE4F0B442}
[2011.10.22 13:21:31 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{639E63A8-19C4-4BB5-A3C3-C0C09A2CAA81}
[2011.10.22 09:14:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Badoo
[2011.10.21 23:52:33 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{262C5049-B4A4-494A-98E3-4B98B78858DD}
[2011.10.21 11:51:53 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{B56FDB0D-37D2-4E72-8EB8-79BD858601C7}
[2011.10.21 11:51:36 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{782A2428-2AE3-4AD9-AFAB-558700B41D28}
[2011.10.19 12:59:08 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{867AEA63-F708-4CF3-82AA-6438E867B59E}
[2011.10.18 17:10:18 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E2269986-862A-4364-B8D1-FD4F9EE10658}
[2011.10.18 17:09:07 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{F043BE4C-C693-44DD-BD44-B1953693C78D}
[2011.10.18 14:55:59 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{0BF2709F-07D6-4159-8253-DC85442AE9DD}
[2011.10.18 08:56:03 | 000,000,000 | ---D | C] -- C:\Users\Yasmin\AppData\Local\{E94D4C3C-6B4F-43C5-8377-231A589011AB}
 
========== Files - Modified Within 30 Days ==========
 
[2011.11.16 18:12:16 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.11.16 16:50:44 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.11.16 16:50:44 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.11.16 16:28:17 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.16 16:00:06 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2011.11.16 15:59:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.11.16 15:59:36 | 1602,838,528 | -HS- | M] () -- C:\hiberfil.sys
[2011.11.15 21:57:56 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.11.15 08:40:01 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.11.14 23:32:05 | 000,001,197 | ---- | M] () -- C:\Users\Yasmin\Desktop\Auslogics BoostSpeed.lnk
[2011.11.11 21:52:52 | 000,409,384 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.11.09 01:01:20 | 000,001,024 | ---- | M] () -- C:\Users\Yasmin\Desktop\Glary Utilities.lnk
[2011.11.09 01:00:16 | 000,001,941 | ---- | M] () -- C:\Users\Yasmin\Desktop\Widelands - Mapeditor.lnk
[2011.11.09 01:00:16 | 000,001,847 | ---- | M] () -- C:\Users\Yasmin\Desktop\Widelands.lnk
[2011.11.09 00:42:24 | 000,001,204 | ---- | M] () -- C:\Users\Yasmin\Desktop\Auslogics Disk Defrag.lnk
[2011.11.09 00:40:07 | 000,001,993 | ---- | M] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
[2011.11.09 00:25:03 | 000,001,092 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.11.09 00:16:07 | 000,001,065 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2011.11.06 02:26:24 | 000,654,166 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.11.06 02:26:24 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.06 02:26:24 | 000,130,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.11.06 02:26:24 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.10.27 23:33:19 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011.10.27 23:13:36 | 001,046,659 | ---- | M] () -- C:\Users\Yasmin\Desktop\Unbenannt (13).wma
[2011.10.27 23:05:05 | 002,878,579 | ---- | M] () -- C:\Users\Yasmin\Desktop\Unbenannt (12).wma
[2011.10.27 22:49:46 | 001,742,609 | ---- | M] () -- C:\Users\Yasmin\Desktop\Unbenannt (10).wma
[2011.10.27 22:04:27 | 000,098,619 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_fertig.png
[2011.10.27 15:27:52 | 000,232,774 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer2.png
[2011.10.27 15:05:07 | 000,129,674 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke2.png
[2011.10.27 14:47:27 | 000,128,541 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke.png
[2011.10.27 14:39:33 | 000,128,033 | ---- | M] () -- C:\Users\Yasmin\Desktop\Wohnzimmer.png
[2011.10.25 16:13:44 | 000,017,704 | ---- | M] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalui2.dll
[2011.10.25 16:13:42 | 000,026,408 | ---- | M] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalmon2.dll
[2011.10.24 13:29:02 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTimeVR.qtx
[2011.10.24 13:29:02 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\Windows\System32\QuickTime.qts
[2011.10.22 09:14:15 | 000,000,984 | ---- | M] () -- C:\Users\Yasmin\Desktop\Badoo.Desktop.lnk
 
========== Files Created - No Company Name ==========
 
[2011.11.16 18:12:16 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.11.16 16:28:17 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.11.15 21:45:26 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.11.15 21:45:26 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.11.15 21:45:26 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.11.15 21:45:26 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.11.15 21:45:26 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.11.14 23:32:05 | 000,001,197 | ---- | C] () -- C:\Users\Yasmin\Desktop\Auslogics BoostSpeed.lnk
[2011.11.09 01:01:29 | 000,000,316 | ---- | C] () -- C:\Windows\tasks\GlaryInitialize.job
[2011.11.09 01:01:20 | 000,001,024 | ---- | C] () -- C:\Users\Yasmin\Desktop\Glary Utilities.lnk
[2011.11.09 01:00:16 | 000,001,941 | ---- | C] () -- C:\Users\Yasmin\Desktop\Widelands - Mapeditor.lnk
[2011.11.09 01:00:16 | 000,001,847 | ---- | C] () -- C:\Users\Yasmin\Desktop\Widelands.lnk
[2011.11.09 00:42:24 | 000,001,204 | ---- | C] () -- C:\Users\Yasmin\Desktop\Auslogics Disk Defrag.lnk
[2011.11.09 00:40:07 | 000,002,495 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro PDF Reader 2.lnk
[2011.11.09 00:40:07 | 000,001,993 | ---- | C] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
[2011.11.09 00:16:07 | 000,001,065 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2011.10.27 23:33:19 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011.10.27 23:13:35 | 001,046,659 | ---- | C] () -- C:\Users\Yasmin\Desktop\Unbenannt (13).wma
[2011.10.27 23:05:05 | 002,878,579 | ---- | C] () -- C:\Users\Yasmin\Desktop\Unbenannt (12).wma
[2011.10.27 22:49:46 | 001,742,609 | ---- | C] () -- C:\Users\Yasmin\Desktop\Unbenannt (10).wma
[2011.10.27 15:44:45 | 000,098,619 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_fertig.png
[2011.10.27 15:27:50 | 000,232,774 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer2.png
[2011.10.27 15:05:05 | 000,129,674 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke2.png
[2011.10.27 14:47:26 | 000,128,541 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer_decke.png
[2011.10.27 14:39:33 | 000,128,033 | ---- | C] () -- C:\Users\Yasmin\Desktop\Wohnzimmer.png
[2011.10.22 09:14:15 | 000,000,984 | ---- | C] () -- C:\Users\Yasmin\Desktop\Badoo.Desktop.lnk
[2011.10.22 09:14:14 | 000,001,138 | ---- | C] () -- C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Badoo Desktop.lnk
[2011.07.13 08:50:31 | 000,004,608 | ---- | C] () -- C:\Users\Yasmin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.06.27 16:08:53 | 000,007,605 | ---- | C] () -- C:\Users\Yasmin\AppData\Local\Resmon.ResmonCfg
[2011.05.08 04:03:33 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011.05.08 04:00:05 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.04.27 13:19:32 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011.04.27 13:19:30 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011.04.27 13:19:30 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011.04.27 13:19:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011.04.27 13:19:30 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011.01.03 22:52:08 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011.01.03 22:52:08 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010.12.28 16:28:05 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010.12.28 16:22:38 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010.12.28 15:50:36 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.07.14 09:47:43 | 000,654,166 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 09:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 09:47:43 | 000,130,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 09:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 05:33:53 | 000,409,384 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,616,008 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,106,388 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.26 16:21:02 | 000,015,498 | ---- | C] () -- C:\Windows\VX3000.ini
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:07BF512B

< End of report >

--- --- ---



brauchst du das extra auch wieder?

markusg 16.11.2011 20:56

hiho
achtung!
dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

:Files
ipconfig /flushdns /c


:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
ipconfig /flushdns /c


[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.

Yasmin 16.11.2011 21:21

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Yasmin\Downloads\cmd.bat deleted successfully.
C:\Users\Yasmin\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Yasmin
->Flash cache emptied: 1360 bytes

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Yasmin
->Temp folder emptied: 2416001 bytes
->Temporary Internet Files folder emptied: 53727 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 207745840 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 69255 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 201,00 mb

Error: Unable to interpret <ipconfig /flushdns /c> in the current context!

OTL by OldTimer - Version 3.2.31.0 log created on 11162011_205945

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

markusg 17.11.2011 11:46

öffne mal start ausführen tippe:
msconfig
enter
systemstart
überall haken raus, außer avira und malwarebytes.
übernehmen /ok neustart
wir beschrenken damit den start von programmen auf das wichtigste, wenn dir was fehlt kann man den haken wieder setzen.

Yasmin 17.11.2011 22:37

Ok, hab ich gemacht.

Nun fällt mir auch kein wesentlicher Unterschied auf eigentlich.. und endlich startet nicht mehr alles durcheinander! :lach:

Also dann denke ich, das wars??

Wenn ja... viiiiiiiiiielen, viiielen Dank nochmal!!
:dankeschoen:

markusg 18.11.2011 12:57

also läuft alles wieder wies soll? internet in normaler geschwindigkeit?
dann können wir, falls du magst, das system noch absichern

Yasmin 18.11.2011 14:40

Wieso sollte ich etwas dagegen haben, mein System zu sichern?? ;-)

Was sichere ich da genau? Also wie kann ich mir das vorstellen, was ändert sich dann?

markusg 18.11.2011 15:52

hi, einige programme werden wir austauschen, wie zum beispiel avira.
wir werden programme instalieren die dir helfen das system, heißt also programme, auf dem aktuellen stand zu halten usw.
ist einiges an arbeit aber lohnt sich denke ich.

Yasmin 18.11.2011 17:47

Ja bitte gerne :)

markusg 18.11.2011 17:51

falls dir der von mir gewählte browser nicht zusagt, musst du mir das bitte sagen, dann passe ich die anleitung an.
wenn du ein neues antimalware programm, wie empfoheln instalierst, deinstaliere das alte.
ich weis, viel arbeit, bitte frage mich bei problemen und unklarheiten

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
Als nächstes kommen wir zu dem Antimalware Programm.
Dieses ist ein wichtiger Bestandteil des Sicherheitskonzeptes, deswegen sollte man sich gut überlegen, welche Wahl man trifft.
Bei den kostenlosen Scannern halte ich Persönlich Avast! für die beste Wahl.
Als kostenpflichtiges würde ich Emsisoft empfehlen
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware
Weitere Vertreter .
kaspersky:
Kaspersky Lab: Antivirus software
Symantec (Norton)
Symantec - AntiVirus, Anti-Spyware, Endpoint Security, Backup, Storage Solutions

Browserwahl:
Da wir häufig mit dem Browser arbeiten, ist diese Wahl natürlich ebenfalls wichtig, die wichtigen Vertreter befinden sich in dem Verlinktem Thema.
ich persönlich rate dir zum opera
Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
http://filepony.de/download-sandboxie/
anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
http://filepony.de/download-sandboxie/

Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
Anleitung: Backup mit Windows 7-Bordmitteln - NETZWELT
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

Yasmin 19.11.2011 14:07

Bevor ich das noch mache.. mein Firefox hängt jetzt total oft... (das war vorher nicht)..
Warum? Kann/Soll ich da noch was machen vorher?
Ich spreche von der Meldung (Keine Rückmeldung)..

markusg 19.11.2011 15:54

gibts noch andere probleme? öffnet sich der internet explorer zb ungefragt? siehst du im taskmanager, prozesse iexplore.exe

Yasmin 19.11.2011 20:00

nein weder noch.. nur explorer.exe rennt...

Yasmin 20.11.2011 09:55

Dinge werden einfach angeklickt, obwohl ich gar nix mache bzw. etwas anderes angeklickt habe..
Bin aber großtenteils im Facebook, gestern dachte ich mir es hängt nur, jetzt schon wieder.
Vorfall eins, ist ein Spiel.. wo man auf der Karte verschiedene Wildnisse und Städte anklicken kann um anzugreifen.. öffnen sich willkürlich Fenster.
Zweites jetzt gerade, öffnen sich Chatfenster die ich weder angeklickt habe, noch hat mich derjenige angeschrieben, wo ich schreiben will, schließt sich einfach..
Was da jetzt los?? (Meine Mouse hat nix...)

markusg 20.11.2011 15:38

folgendes log bitte posten, nichts löschen:
http://www.trojaner-board.de/82358-t...entfernen.html

Yasmin 20.11.2011 23:03

22:21:47.0216 1924 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
22:21:47.0418 1924 ============================================================
22:21:47.0418 1924 Current date / time: 2011/11/20 22:21:47.0418
22:21:47.0418 1924 SystemInfo:
22:21:47.0418 1924
22:21:47.0418 1924 OS Version: 6.1.7601 ServicePack: 1.0
22:21:47.0418 1924 Product type: Workstation
22:21:47.0419 1924 ComputerName: YASMIN-LAPTOP
22:21:47.0419 1924 UserName: Yasmin
22:21:47.0419 1924 Windows directory: C:\Windows
22:21:47.0419 1924 System windows directory: C:\Windows
22:21:47.0419 1924 Processor architecture: Intel x86
22:21:47.0419 1924 Number of processors: 1
22:21:47.0419 1924 Page size: 0x1000
22:21:47.0419 1924 Boot type: Normal boot
22:21:47.0419 1924 ============================================================
22:21:49.0330 1924 Initialize success
22:21:53.0503 0100 ============================================================
22:21:53.0503 0100 Scan started
22:21:53.0503 0100 Mode: Manual;
22:21:53.0503 0100 ============================================================
22:21:55.0576 0100 Scan interrupted by user!
22:21:55.0576 0100 Scan interrupted by user!
22:21:55.0576 0100 Scan interrupted by user!
22:21:55.0576 0100 ============================================================
22:21:55.0576 0100 Scan finished
22:21:55.0576 0100 ============================================================
22:21:55.0598 2344 Detected object count: 0
22:21:55.0598 2344 Actual detected object count: 0
22:22:14.0363 3932 ============================================================
22:22:14.0363 3932 Scan started
22:22:14.0363 3932 Mode: Manual;
22:22:14.0363 3932 ============================================================
22:22:15.0012 3932 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
22:22:15.0046 3932 1394ohci - ok
22:22:15.0130 3932 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
22:22:15.0134 3932 ACPI - ok
22:22:15.0353 3932 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
22:22:15.0370 3932 AcpiPmi - ok
22:22:15.0524 3932 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
22:22:15.0597 3932 adp94xx - ok
22:22:15.0751 3932 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
22:22:15.0830 3932 adpahci - ok
22:22:15.0915 3932 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
22:22:15.0973 3932 adpu320 - ok
22:22:16.0184 3932 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
22:22:16.0189 3932 AFD - ok
22:22:16.0245 3932 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
22:22:16.0269 3932 agp440 - ok
22:22:16.0347 3932 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
22:22:16.0357 3932 aic78xx - ok
22:22:16.0548 3932 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
22:22:16.0571 3932 aliide - ok
22:22:16.0620 3932 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
22:22:16.0648 3932 amdagp - ok
22:22:16.0704 3932 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
22:22:16.0721 3932 amdide - ok
22:22:16.0871 3932 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
22:22:16.0893 3932 AmdK8 - ok
22:22:16.0921 3932 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
22:22:16.0948 3932 AmdPPM - ok
22:22:17.0016 3932 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
22:22:17.0043 3932 amdsata - ok
22:22:17.0188 3932 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
22:22:17.0211 3932 amdsbs - ok
22:22:17.0271 3932 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
22:22:17.0295 3932 amdxata - ok
22:22:17.0506 3932 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
22:22:17.0532 3932 AppID - ok
22:22:17.0652 3932 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
22:22:17.0675 3932 arc - ok
22:22:17.0799 3932 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
22:22:17.0825 3932 arcsas - ok
22:22:17.0915 3932 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
22:22:17.0934 3932 AsyncMac - ok
22:22:18.0067 3932 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
22:22:18.0068 3932 atapi - ok
22:22:18.0203 3932 athr (b01751cc563aecac09bbe36aaa21fbef) C:\Windows\system32\DRIVERS\athr.sys
22:22:18.0261 3932 athr - ok
22:22:18.0434 3932 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
22:22:18.0470 3932 avgntflt - ok
22:22:18.0546 3932 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
22:22:18.0574 3932 avipbb - ok
22:22:18.0743 3932 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
22:22:18.0761 3932 b06bdrv - ok
22:22:18.0954 3932 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
22:22:18.0993 3932 b57nd60x - ok
22:22:19.0085 3932 bcm4sbxp (82dd21bfa8bbe0a3a3833a1bd8e86158) C:\Windows\system32\DRIVERS\bcm4sbxp.sys
22:22:19.0106 3932 bcm4sbxp - ok
22:22:19.0261 3932 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
22:22:19.0270 3932 Beep - ok
22:22:19.0352 3932 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
22:22:19.0368 3932 blbdrive - ok
22:22:19.0423 3932 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
22:22:19.0443 3932 bowser - ok
22:22:19.0570 3932 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:22:19.0575 3932 BrFiltLo - ok
22:22:19.0602 3932 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:22:19.0625 3932 BrFiltUp - ok
22:22:19.0679 3932 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
22:22:19.0711 3932 Brserid - ok
22:22:19.0746 3932 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
22:22:19.0770 3932 BrSerWdm - ok
22:22:19.0797 3932 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:22:19.0814 3932 BrUsbMdm - ok
22:22:19.0940 3932 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
22:22:19.0946 3932 BrUsbSer - ok
22:22:19.0973 3932 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
22:22:19.0993 3932 BTHMODEM - ok
22:22:20.0157 3932 catchme - ok
22:22:20.0300 3932 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
22:22:20.0325 3932 cdfs - ok
22:22:20.0427 3932 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys
22:22:20.0458 3932 cdrom - ok
22:22:20.0687 3932 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
22:22:20.0711 3932 circlass - ok
22:22:20.0835 3932 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
22:22:20.0863 3932 CLFS - ok
22:22:20.0991 3932 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
22:22:21.0014 3932 CmBatt - ok
22:22:21.0149 3932 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
22:22:21.0173 3932 cmdide - ok
22:22:21.0227 3932 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
22:22:21.0265 3932 CNG - ok
22:22:21.0417 3932 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
22:22:21.0430 3932 Compbatt - ok
22:22:21.0513 3932 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
22:22:21.0532 3932 CompositeBus - ok
22:22:21.0692 3932 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
22:22:21.0714 3932 crcdisk - ok
22:22:21.0907 3932 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
22:22:21.0936 3932 CSC - ok
22:22:22.0130 3932 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
22:22:22.0154 3932 DfsC - ok
22:22:22.0179 3932 dgderdrv - ok
22:22:22.0258 3932 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
22:22:22.0259 3932 discache - ok
22:22:22.0426 3932 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
22:22:22.0436 3932 Disk - ok
22:22:22.0542 3932 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
22:22:22.0547 3932 drmkaud - ok
22:22:22.0618 3932 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
22:22:22.0648 3932 DXGKrnl - ok
22:22:22.0927 3932 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
22:22:23.0084 3932 ebdrv - ok
22:22:23.0283 3932 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
22:22:23.0302 3932 elxstor - ok
22:22:23.0386 3932 EMSCR (8efd7f0094b2015d836d9dd87f77dc44) C:\Windows\system32\DRIVERS\EMS7SK.sys
22:22:23.0404 3932 EMSCR - ok
22:22:23.0530 3932 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
22:22:23.0552 3932 ErrDev - ok
22:22:23.0621 3932 ESDCR (9c7487253aad6bf61f9bc83d50e32ccc) C:\Windows\system32\DRIVERS\ESD7SK.sys
22:22:23.0639 3932 ESDCR - ok
22:22:23.0820 3932 ESMCR (a18ad596fc91a05ea61945d856dd86dc) C:\Windows\system32\DRIVERS\ESM7SK.sys
22:22:23.0834 3932 ESMCR - ok
22:22:24.0100 3932 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
22:22:24.0171 3932 exfat - ok
22:22:24.0219 3932 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
22:22:24.0258 3932 fastfat - ok
22:22:24.0407 3932 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
22:22:24.0439 3932 fdc - ok
22:22:24.0488 3932 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
22:22:24.0519 3932 FileInfo - ok
22:22:24.0557 3932 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
22:22:24.0587 3932 Filetrace - ok
22:22:24.0702 3932 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
22:22:24.0720 3932 flpydisk - ok
22:22:24.0797 3932 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
22:22:24.0832 3932 FltMgr - ok
22:22:24.0892 3932 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
22:22:24.0905 3932 FsDepends - ok
22:22:25.0057 3932 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\Windows\system32\FsUsbExDisk.SYS
22:22:25.0076 3932 FsUsbExDisk - ok
22:22:25.0142 3932 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
22:22:25.0176 3932 Fs_Rec - ok
22:22:25.0392 3932 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
22:22:25.0395 3932 fvevol - ok
22:22:25.0481 3932 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:22:25.0499 3932 gagp30kx - ok
22:22:25.0547 3932 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
22:22:25.0563 3932 hcw85cir - ok
22:22:25.0760 3932 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
22:22:25.0796 3932 HdAudAddService - ok
22:22:25.0858 3932 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
22:22:25.0859 3932 HDAudBus - ok
22:22:25.0974 3932 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
22:22:25.0985 3932 HidBatt - ok
22:22:26.0017 3932 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
22:22:26.0039 3932 HidBth - ok
22:22:26.0080 3932 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
22:22:26.0106 3932 HidIr - ok
22:22:26.0273 3932 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
22:22:26.0274 3932 HidUsb - ok
22:22:26.0433 3932 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
22:22:26.0473 3932 HpSAMD - ok
22:22:26.0598 3932 HSF_DPV (53229dcf431d76434816cd29251168a0) C:\Windows\system32\DRIVERS\HSX_DPV.sys
22:22:26.0650 3932 HSF_DPV - ok
22:22:26.0775 3932 HSXHWAZL (31f949d452201f2f0af0c88d7db512cd) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
22:22:26.0807 3932 HSXHWAZL - ok
22:22:26.0908 3932 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
22:22:26.0916 3932 HTTP - ok
22:22:27.0033 3932 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
22:22:27.0034 3932 hwpolicy - ok
22:22:27.0129 3932 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
22:22:27.0154 3932 i8042prt - ok
22:22:27.0305 3932 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
22:22:27.0343 3932 iaStorV - ok
22:22:27.0636 3932 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
22:22:27.0857 3932 igfx - ok
22:22:28.0020 3932 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
22:22:28.0045 3932 iirsp - ok
22:22:28.0126 3932 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
22:22:28.0148 3932 intelide - ok
22:22:28.0304 3932 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
22:22:28.0305 3932 intelppm - ok
22:22:28.0357 3932 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:22:28.0385 3932 IpFilterDriver - ok
22:22:28.0460 3932 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
22:22:28.0475 3932 IPMIDRV - ok
22:22:28.0597 3932 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
22:22:28.0623 3932 IPNAT - ok
22:22:28.0682 3932 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
22:22:28.0702 3932 IRENUM - ok
22:22:28.0761 3932 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
22:22:28.0770 3932 isapnp - ok
22:22:28.0908 3932 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
22:22:28.0946 3932 iScsiPrt - ok
22:22:29.0028 3932 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
22:22:29.0047 3932 kbdclass - ok
22:22:29.0267 3932 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
22:22:29.0298 3932 kbdhid - ok
22:22:29.0384 3932 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
22:22:29.0408 3932 KSecDD - ok
22:22:29.0530 3932 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
22:22:29.0555 3932 KSecPkg - ok
22:22:29.0653 3932 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
22:22:29.0675 3932 lltdio - ok
22:22:29.0846 3932 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:22:29.0876 3932 LSI_FC - ok
22:22:29.0974 3932 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:22:30.0002 3932 LSI_SAS - ok
22:22:30.0149 3932 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:22:30.0175 3932 LSI_SAS2 - ok
22:22:30.0222 3932 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:22:30.0243 3932 LSI_SCSI - ok
22:22:30.0308 3932 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
22:22:30.0343 3932 luafv - ok
22:22:30.0508 3932 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys
22:22:30.0509 3932 MBAMProtector - ok
22:22:30.0605 3932 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
22:22:30.0625 3932 mdmxsdk - ok
22:22:30.0742 3932 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
22:22:30.0761 3932 megasas - ok
22:22:30.0828 3932 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
22:22:30.0858 3932 MegaSR - ok
22:22:30.0898 3932 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
22:22:30.0900 3932 Modem - ok
22:22:31.0043 3932 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
22:22:31.0044 3932 monitor - ok
22:22:31.0113 3932 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
22:22:31.0131 3932 mouclass - ok
22:22:31.0180 3932 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
22:22:31.0204 3932 mouhid - ok
22:22:31.0344 3932 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
22:22:31.0346 3932 mountmgr - ok
22:22:31.0410 3932 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
22:22:31.0447 3932 mpio - ok
22:22:31.0500 3932 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
22:22:31.0526 3932 mpsdrv - ok
22:22:31.0667 3932 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
22:22:31.0696 3932 MRxDAV - ok
22:22:31.0775 3932 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:22:31.0786 3932 mrxsmb - ok
22:22:31.0870 3932 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:22:31.0905 3932 mrxsmb10 - ok
22:22:32.0046 3932 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:22:32.0069 3932 mrxsmb20 - ok
22:22:32.0136 3932 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
22:22:32.0159 3932 msahci - ok
22:22:32.0238 3932 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
22:22:32.0253 3932 msdsm - ok
22:22:32.0413 3932 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
22:22:32.0437 3932 Msfs - ok
22:22:32.0473 3932 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
22:22:32.0481 3932 mshidkmdf - ok
22:22:32.0538 3932 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
22:22:32.0546 3932 msisadrv - ok
22:22:32.0730 3932 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
22:22:32.0746 3932 MSKSSRV - ok
22:22:32.0794 3932 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
22:22:32.0819 3932 MSPCLOCK - ok
22:22:32.0846 3932 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
22:22:32.0864 3932 MSPQM - ok
22:22:32.0918 3932 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
22:22:32.0930 3932 MsRPC - ok
22:22:33.0075 3932 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
22:22:33.0076 3932 mssmbios - ok
22:22:33.0140 3932 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
22:22:33.0156 3932 MSTEE - ok
22:22:33.0183 3932 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
22:22:33.0203 3932 MTConfig - ok
22:22:33.0246 3932 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
22:22:33.0274 3932 Mup - ok
22:22:33.0436 3932 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
22:22:33.0462 3932 NativeWifiP - ok
22:22:33.0572 3932 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
22:22:33.0579 3932 NDIS - ok
22:22:33.0726 3932 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
22:22:33.0751 3932 NdisCap - ok
22:22:33.0803 3932 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
22:22:33.0828 3932 NdisTapi - ok
22:22:33.0956 3932 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
22:22:33.0975 3932 Ndisuio - ok
22:22:34.0076 3932 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
22:22:34.0106 3932 NdisWan - ok
22:22:34.0216 3932 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
22:22:34.0238 3932 NDProxy - ok
22:22:34.0349 3932 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
22:22:34.0375 3932 NetBIOS - ok
22:22:34.0494 3932 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
22:22:34.0497 3932 NetBT - ok
22:22:34.0639 3932 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
22:22:34.0666 3932 nfrd960 - ok
22:22:34.0877 3932 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
22:22:34.0900 3932 Npfs - ok
22:22:34.0950 3932 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
22:22:34.0951 3932 nsiproxy - ok
22:22:35.0072 3932 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
22:22:35.0130 3932 Ntfs - ok
22:22:35.0242 3932 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
22:22:35.0260 3932 Null - ok
22:22:35.0319 3932 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
22:22:35.0330 3932 nvraid - ok
22:22:35.0375 3932 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
22:22:35.0410 3932 nvstor - ok
22:22:35.0552 3932 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
22:22:35.0587 3932 nv_agp - ok
22:22:35.0636 3932 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
22:22:35.0660 3932 ohci1394 - ok
22:22:35.0785 3932 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
22:22:35.0803 3932 Parport - ok
22:22:35.0954 3932 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
22:22:35.0989 3932 partmgr - ok
22:22:36.0038 3932 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
22:22:36.0044 3932 Parvdm - ok
22:22:36.0122 3932 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
22:22:36.0146 3932 pci - ok
22:22:36.0293 3932 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
22:22:36.0314 3932 pciide - ok
22:22:36.0362 3932 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
22:22:36.0377 3932 pcmcia - ok
22:22:36.0412 3932 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
22:22:36.0435 3932 pcw - ok
22:22:36.0580 3932 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
22:22:36.0623 3932 PEAUTH - ok
22:22:36.0859 3932 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
22:22:36.0868 3932 PptpMiniport - ok
22:22:36.0890 3932 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
22:22:36.0913 3932 Processor - ok
22:22:37.0092 3932 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
22:22:37.0094 3932 Psched - ok
22:22:37.0165 3932 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
22:22:37.0214 3932 ql2300 - ok
22:22:37.0342 3932 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
22:22:37.0370 3932 ql40xx - ok
22:22:37.0412 3932 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
22:22:37.0423 3932 QWAVEdrv - ok
22:22:37.0456 3932 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
22:22:37.0474 3932 RasAcd - ok
22:22:37.0531 3932 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:22:37.0549 3932 RasAgileVpn - ok
22:22:37.0689 3932 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:22:37.0715 3932 Rasl2tp - ok
22:22:37.0799 3932 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
22:22:37.0821 3932 RasPppoe - ok
22:22:37.0866 3932 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
22:22:37.0891 3932 RasSstp - ok
22:22:38.0214 3932 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
22:22:38.0252 3932 rdbss - ok
22:22:38.0313 3932 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
22:22:38.0319 3932 rdpbus - ok
22:22:38.0399 3932 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:22:38.0400 3932 RDPCDD - ok
22:22:38.0545 3932 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
22:22:38.0566 3932 RDPDR - ok
22:22:38.0633 3932 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
22:22:38.0634 3932 RDPENCDD - ok
22:22:38.0681 3932 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
22:22:38.0683 3932 RDPREFMP - ok
22:22:39.0165 3932 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys
22:22:39.0190 3932 RdpVideoMiniport - ok
22:22:39.0237 3932 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
22:22:39.0248 3932 RDPWD - ok
22:22:39.0329 3932 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
22:22:39.0358 3932 rdyboost - ok
22:22:39.0546 3932 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
22:22:39.0565 3932 rspndr - ok
22:22:39.0628 3932 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
22:22:39.0647 3932 s3cap - ok
22:22:39.0717 3932 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
22:22:39.0752 3932 sbp2port - ok
22:22:39.0896 3932 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
22:22:39.0904 3932 scfilter - ok
22:22:40.0006 3932 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys
22:22:40.0031 3932 sdbus - ok
22:22:40.0194 3932 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
22:22:40.0201 3932 secdrv - ok
22:22:40.0289 3932 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
22:22:40.0295 3932 Serenum - ok
22:22:40.0334 3932 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
22:22:40.0356 3932 Serial - ok
22:22:40.0416 3932 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
22:22:40.0422 3932 sermouse - ok
22:22:40.0586 3932 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
22:22:40.0611 3932 sffdisk - ok
22:22:40.0651 3932 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
22:22:40.0667 3932 sffp_mmc - ok
22:22:40.0711 3932 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
22:22:40.0727 3932 sffp_sd - ok
22:22:40.0778 3932 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
22:22:40.0797 3932 sfloppy - ok
22:22:40.0964 3932 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
22:22:40.0973 3932 sisagp - ok
22:22:41.0048 3932 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:22:41.0067 3932 SiSRaid2 - ok
22:22:41.0113 3932 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
22:22:41.0136 3932 SiSRaid4 - ok
22:22:41.0297 3932 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
22:22:41.0321 3932 Smb - ok
22:22:41.0420 3932 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
22:22:41.0427 3932 spldr - ok
22:22:41.0585 3932 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
22:22:41.0622 3932 srv - ok
22:22:41.0680 3932 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
22:22:41.0712 3932 srv2 - ok
22:22:41.0858 3932 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
22:22:41.0891 3932 SrvHsfHDA - ok
22:22:41.0973 3932 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
22:22:42.0019 3932 SrvHsfV92 - ok
22:22:42.0175 3932 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
22:22:42.0216 3932 SrvHsfWinac - ok
22:22:42.0365 3932 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
22:22:42.0387 3932 srvnet - ok
22:22:42.0486 3932 ssadbus (64e44acd8c238fcbbb78f0ba4bdc4b05) C:\Windows\system32\DRIVERS\ssadbus.sys
22:22:42.0516 3932 ssadbus - ok
22:22:42.0683 3932 ssadmdfl (bb2c84a15c765da89fd832b0e73f26ce) C:\Windows\system32\DRIVERS\ssadmdfl.sys
22:22:42.0710 3932 ssadmdfl - ok
22:22:42.0791 3932 ssadmdm (6d0d132ddc6f43eda00dced6d8b1ca31) C:\Windows\system32\DRIVERS\ssadmdm.sys
22:22:42.0809 3932 ssadmdm - ok
22:22:42.0971 3932 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
22:22:42.0998 3932 ssmdrv - ok
22:22:43.0066 3932 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
22:22:43.0087 3932 stexstor - ok
22:22:43.0258 3932 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
22:22:43.0267 3932 storflt - ok
22:22:43.0308 3932 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
22:22:43.0334 3932 storvsc - ok
22:22:43.0374 3932 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
22:22:43.0381 3932 swenum - ok
22:22:43.0522 3932 Synth3dVsc - ok
22:22:43.0687 3932 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
22:22:43.0742 3932 Tcpip - ok
22:22:43.0931 3932 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
22:22:43.0943 3932 TCPIP6 - ok
22:22:44.0091 3932 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
22:22:44.0116 3932 tcpipreg - ok
22:22:44.0181 3932 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
22:22:44.0261 3932 TDPIPE - ok
22:22:44.0309 3932 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
22:22:44.0316 3932 TDTCP - ok
22:22:44.0469 3932 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
22:22:44.0496 3932 tdx - ok
22:22:44.0551 3932 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
22:22:44.0560 3932 TermDD - ok
22:22:44.0674 3932 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:22:44.0692 3932 tssecsrv - ok
22:22:44.0878 3932 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
22:22:44.0887 3932 TsUsbFlt - ok
22:22:44.0937 3932 tsusbhub - ok
22:22:45.0022 3932 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
22:22:45.0033 3932 tunnel - ok
22:22:45.0160 3932 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
22:22:45.0178 3932 uagp35 - ok
22:22:45.0254 3932 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
22:22:45.0270 3932 udfs - ok
22:22:45.0345 3932 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
22:22:45.0355 3932 uliagpkx - ok
22:22:45.0504 3932 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
22:22:45.0522 3932 umbus - ok
22:22:45.0656 3932 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
22:22:45.0717 3932 UmPass - ok
22:22:45.0920 3932 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
22:22:45.0952 3932 usbaudio - ok
22:22:46.0020 3932 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
22:22:46.0029 3932 usbccgp - ok
22:22:46.0094 3932 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
22:22:46.0128 3932 usbcir - ok
22:22:46.0289 3932 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
22:22:46.0297 3932 usbehci - ok
22:22:46.0380 3932 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
22:22:46.0412 3932 usbhub - ok
22:22:46.0542 3932 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
22:22:46.0551 3932 usbohci - ok
22:22:46.0600 3932 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
22:22:46.0618 3932 usbprint - ok
22:22:46.0683 3932 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:22:46.0705 3932 USBSTOR - ok
22:22:46.0863 3932 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:22:46.0887 3932 usbuhci - ok
22:22:46.0979 3932 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys
22:22:47.0001 3932 usb_rndisx - ok
22:22:47.0181 3932 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
22:22:47.0189 3932 vdrvroot - ok
22:22:47.0278 3932 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
22:22:47.0295 3932 vga - ok
22:22:47.0362 3932 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
22:22:47.0368 3932 VgaSave - ok
22:22:47.0515 3932 VGPU - ok
22:22:47.0586 3932 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
22:22:47.0627 3932 vhdmp - ok
22:22:47.0725 3932 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
22:22:47.0734 3932 viaagp - ok
22:22:47.0791 3932 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
22:22:47.0801 3932 ViaC7 - ok
22:22:47.0937 3932 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
22:22:47.0954 3932 viaide - ok
22:22:48.0017 3932 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
22:22:48.0046 3932 vmbus - ok
22:22:48.0097 3932 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
22:22:48.0121 3932 VMBusHID - ok
22:22:48.0264 3932 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
22:22:48.0290 3932 volmgr - ok
22:22:48.0356 3932 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
22:22:48.0361 3932 volmgrx - ok
22:22:48.0410 3932 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
22:22:48.0446 3932 volsnap - ok
22:22:48.0612 3932 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
22:22:48.0644 3932 vsmraid - ok
22:22:48.0689 3932 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
22:22:48.0709 3932 vwifibus - ok
22:22:48.0785 3932 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
22:22:48.0797 3932 vwififlt - ok
22:22:48.0946 3932 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys
22:22:48.0966 3932 vwifimp - ok
22:22:49.0133 3932 VX3000 (e26744e5dd71a16e80d4dd5a286b8423) C:\Windows\system32\DRIVERS\VX3000.sys
22:22:49.0219 3932 VX3000 - ok
22:22:49.0692 3932 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
22:22:49.0767 3932 WacomPen - ok
22:22:49.0939 3932 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
22:22:49.0961 3932 WANARP - ok
22:22:49.0974 3932 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
22:22:49.0976 3932 Wanarpv6 - ok
22:22:50.0120 3932 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
22:22:50.0144 3932 Wd - ok
22:22:50.0287 3932 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
22:22:50.0338 3932 Wdf01000 - ok
22:22:50.0565 3932 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
22:22:50.0587 3932 WfpLwf - ok
22:22:50.0623 3932 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
22:22:50.0634 3932 WIMMount - ok
22:22:50.0718 3932 winachsf (6d2350bb6e77e800fc4be4e5b7a2e89a) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
22:22:50.0754 3932 winachsf - ok
22:22:51.0000 3932 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
22:22:51.0026 3932 WinUsb - ok
22:22:51.0126 3932 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
22:22:51.0127 3932 WmiAcpi - ok
22:22:51.0226 3932 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
22:22:51.0247 3932 ws2ifsl - ok
22:22:51.0424 3932 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
22:22:51.0449 3932 WudfPf - ok
22:22:51.0494 3932 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:22:51.0518 3932 WUDFRd - ok
22:22:51.0720 3932 XAudio (5a7ff9a18ff6d7e0527fe3abf9204ef8) C:\Windows\system32\DRIVERS\xaudio.sys
22:22:51.0739 3932 XAudio - ok
22:22:51.0850 3932 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:22:51.0864 3932 \Device\Harddisk0\DR0 - ok
22:22:51.0874 3932 Boot (0x1200) (b64aab151913743bf9f6e88f5fd786c5) \Device\Harddisk0\DR0\Partition0
22:22:51.0875 3932 \Device\Harddisk0\DR0\Partition0 - ok
22:22:51.0900 3932 Boot (0x1200) (3441fbf2082141e50f767df1d4254a66) \Device\Harddisk0\DR0\Partition1
22:22:51.0902 3932 \Device\Harddisk0\DR0\Partition1 - ok
22:22:51.0908 3932 ============================================================
22:22:51.0908 3932 Scan finished
22:22:51.0908 3932 ============================================================
22:22:51.0936 3476 Detected object count: 0
22:22:51.0936 3476 Actual detected object count: 0
22:24:30.0141 3108 ============================================================
22:24:30.0141 3108 Scan started
22:24:30.0141 3108 Mode: Manual; SigCheck; TDLFS;
22:24:30.0141 3108 ============================================================
22:24:30.0554 3108 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
22:24:30.0757 3108 1394ohci - ok
22:24:30.0907 3108 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
22:24:30.0929 3108 ACPI - ok
22:24:30.0987 3108 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
22:24:31.0089 3108 AcpiPmi - ok
22:24:31.0237 3108 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
22:24:31.0263 3108 adp94xx - ok
22:24:31.0319 3108 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
22:24:31.0341 3108 adpahci - ok
22:24:31.0483 3108 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
22:24:31.0502 3108 adpu320 - ok
22:24:31.0607 3108 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
22:24:31.0697 3108 AFD - ok
22:24:31.0823 3108 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
22:24:31.0839 3108 agp440 - ok
22:24:31.0903 3108 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
22:24:31.0920 3108 aic78xx - ok
22:24:31.0971 3108 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
22:24:31.0986 3108 aliide - ok
22:24:32.0012 3108 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
22:24:32.0033 3108 amdagp - ok
22:24:32.0072 3108 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
22:24:32.0087 3108 amdide - ok
22:24:32.0223 3108 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
22:24:32.0280 3108 AmdK8 - ok
22:24:32.0307 3108 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
22:24:32.0353 3108 AmdPPM - ok
22:24:32.0407 3108 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
22:24:32.0423 3108 amdsata - ok
22:24:32.0563 3108 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
22:24:32.0581 3108 amdsbs - ok
22:24:32.0639 3108 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
22:24:32.0654 3108 amdxata - ok
22:24:32.0721 3108 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
22:24:32.0909 3108 AppID - ok
22:24:33.0064 3108 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
22:24:33.0080 3108 arc - ok
22:24:33.0122 3108 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
22:24:33.0139 3108 arcsas - ok
22:24:33.0172 3108 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
22:24:33.0359 3108 AsyncMac - ok
22:24:33.0505 3108 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
22:24:33.0520 3108 atapi - ok
22:24:33.0604 3108 athr (b01751cc563aecac09bbe36aaa21fbef) C:\Windows\system32\DRIVERS\athr.sys
22:24:33.0717 3108 athr - ok
22:24:33.0858 3108 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
22:24:33.0917 3108 avgntflt - ok
22:24:33.0959 3108 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
22:24:33.0973 3108 avipbb - ok
22:24:34.0055 3108 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
22:24:34.0135 3108 b06bdrv - ok
22:24:34.0269 3108 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
22:24:34.0320 3108 b57nd60x - ok
22:24:34.0385 3108 bcm4sbxp (82dd21bfa8bbe0a3a3833a1bd8e86158) C:\Windows\system32\DRIVERS\bcm4sbxp.sys
22:24:34.0426 3108 bcm4sbxp - ok
22:24:34.0575 3108 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
22:24:34.0641 3108 Beep - ok
22:24:34.0707 3108 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
22:24:34.0747 3108 blbdrive - ok
22:24:34.0813 3108 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
22:24:34.0869 3108 bowser - ok
22:24:34.0993 3108 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:24:35.0015 3108 BrFiltLo - ok
22:24:35.0050 3108 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:24:35.0096 3108 BrFiltUp - ok
22:24:35.0158 3108 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
22:24:35.0261 3108 Brserid - ok
22:24:35.0297 3108 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
22:24:35.0336 3108 BrSerWdm - ok
22:24:35.0471 3108 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:24:35.0519 3108 BrUsbMdm - ok
22:24:35.0547 3108 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
22:24:35.0598 3108 BrUsbSer - ok
22:24:35.0627 3108 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
22:24:35.0655 3108 BTHMODEM - ok
22:24:35.0758 3108 catchme - ok
22:24:35.0879 3108 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
22:24:35.0944 3108 cdfs - ok
22:24:36.0017 3108 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys
22:24:36.0064 3108 cdrom - ok
22:24:36.0198 3108 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
22:24:36.0221 3108 circlass - ok
22:24:36.0281 3108 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
22:24:36.0301 3108 CLFS - ok
22:24:36.0361 3108 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
22:24:36.0404 3108 CmBatt - ok
22:24:36.0539 3108 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
22:24:36.0554 3108 cmdide - ok
22:24:36.0639 3108 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
22:24:36.0669 3108 CNG - ok
22:24:36.0707 3108 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
22:24:36.0726 3108 Compbatt - ok
22:24:36.0836 3108 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
22:24:36.0878 3108 CompositeBus - ok
22:24:36.0949 3108 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
22:24:36.0965 3108 crcdisk - ok
22:24:37.0053 3108 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
22:24:37.0143 3108 CSC - ok
22:24:37.0309 3108 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
22:24:37.0347 3108 DfsC - ok
22:24:37.0389 3108 dgderdrv - ok
22:24:37.0448 3108 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
22:24:37.0515 3108 discache - ok
22:24:37.0561 3108 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
22:24:37.0576 3108 Disk - ok
22:24:37.0706 3108 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
22:24:37.0747 3108 drmkaud - ok
22:24:37.0841 3108 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
22:24:37.0880 3108 DXGKrnl - ok
22:24:38.0106 3108 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
22:24:38.0212 3108 ebdrv - ok
22:24:38.0384 3108 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
22:24:38.0409 3108 elxstor - ok
22:24:38.0543 3108 EMSCR (8efd7f0094b2015d836d9dd87f77dc44) C:\Windows\system32\DRIVERS\EMS7SK.sys
22:24:38.0619 3108 EMSCR - ok
22:24:38.0753 3108 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
22:24:38.0786 3108 ErrDev - ok
22:24:38.0833 3108 ESDCR (9c7487253aad6bf61f9bc83d50e32ccc) C:\Windows\system32\DRIVERS\ESD7SK.sys
22:24:38.0905 3108 ESDCR - ok
22:24:38.0977 3108 ESMCR (a18ad596fc91a05ea61945d856dd86dc) C:\Windows\system32\DRIVERS\ESM7SK.sys
22:24:39.0042 3108 ESMCR - ok
22:24:39.0178 3108 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
22:24:39.0251 3108 exfat - ok
22:24:39.0298 3108 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
22:24:39.0378 3108 fastfat - ok
22:24:39.0508 3108 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
22:24:39.0547 3108 fdc - ok
22:24:39.0611 3108 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
22:24:39.0628 3108 FileInfo - ok
22:24:39.0669 3108 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
22:24:39.0743 3108 Filetrace - ok
22:24:39.0858 3108 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
22:24:39.0897 3108 flpydisk - ok
22:24:39.0960 3108 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
22:24:39.0985 3108 FltMgr - ok
22:24:40.0037 3108 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
22:24:40.0053 3108 FsDepends - ok
22:24:40.0114 3108 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\Windows\system32\FsUsbExDisk.SYS
22:24:40.0156 3108 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
22:24:40.0156 3108 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
22:24:40.0288 3108 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
22:24:40.0303 3108 Fs_Rec - ok
22:24:40.0371 3108 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
22:24:40.0394 3108 fvevol - ok
22:24:40.0524 3108 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:24:40.0542 3108 gagp30kx - ok
22:24:40.0680 3108 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
22:24:40.0770 3108 hcw85cir - ok
22:24:40.0916 3108 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
22:24:40.0962 3108 HdAudAddService - ok
22:24:41.0014 3108 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
22:24:41.0061 3108 HDAudBus - ok
22:24:41.0188 3108 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
22:24:41.0215 3108 HidBatt - ok
22:24:41.0249 3108 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
22:24:41.0293 3108 HidBth - ok
22:24:41.0320 3108 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
22:24:41.0358 3108 HidIr - ok
22:24:41.0430 3108 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
22:24:41.0449 3108 HidUsb - ok
22:24:41.0598 3108 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
22:24:41.0615 3108 HpSAMD - ok
22:24:41.0699 3108 HSF_DPV (53229dcf431d76434816cd29251168a0) C:\Windows\system32\DRIVERS\HSX_DPV.sys
22:24:41.0782 3108 HSF_DPV - ok
22:24:41.0909 3108 HSXHWAZL (31f949d452201f2f0af0c88d7db512cd) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
22:24:41.0964 3108 HSXHWAZL - ok
22:24:42.0042 3108 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
22:24:42.0110 3108 HTTP - ok
22:24:42.0259 3108 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
22:24:42.0279 3108 hwpolicy - ok
22:24:42.0340 3108 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
22:24:42.0361 3108 i8042prt - ok
22:24:42.0427 3108 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
22:24:42.0450 3108 iaStorV - ok
22:24:42.0699 3108 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
22:24:42.0898 3108 igfx - ok
22:24:43.0009 3108 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
22:24:43.0025 3108 iirsp - ok
22:24:43.0104 3108 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
22:24:43.0123 3108 intelide - ok
22:24:43.0159 3108 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
22:24:43.0179 3108 intelppm - ok
22:24:43.0226 3108 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:24:43.0286 3108 IpFilterDriver - ok
22:24:43.0427 3108 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
22:24:43.0464 3108 IPMIDRV - ok
22:24:43.0520 3108 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
22:24:43.0565 3108 IPNAT - ok
22:24:43.0638 3108 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
22:24:43.0705 3108 IRENUM - ok
22:24:43.0850 3108 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
22:24:43.0866 3108 isapnp - ok
22:24:43.0919 3108 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
22:24:43.0939 3108 iScsiPrt - ok
22:24:43.0995 3108 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
22:24:44.0010 3108 kbdclass - ok
22:24:44.0074 3108 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
22:24:44.0122 3108 kbdhid - ok
22:24:44.0284 3108 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
22:24:44.0300 3108 KSecDD - ok
22:24:44.0362 3108 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
22:24:44.0380 3108 KSecPkg - ok
22:24:44.0453 3108 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
22:24:44.0516 3108 lltdio - ok
22:24:44.0668 3108 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:24:44.0685 3108 LSI_FC - ok
22:24:44.0729 3108 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:24:44.0746 3108 LSI_SAS - ok
22:24:44.0783 3108 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:24:44.0798 3108 LSI_SAS2 - ok
22:24:44.0844 3108 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:24:44.0861 3108 LSI_SCSI - ok
22:24:44.0907 3108 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
22:24:44.0971 3108 luafv - ok
22:24:45.0112 3108 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys
22:24:45.0156 3108 MBAMProtector - ok
22:24:45.0229 3108 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
22:24:45.0264 3108 mdmxsdk - ok
22:24:45.0319 3108 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
22:24:45.0337 3108 megasas - ok
22:24:45.0464 3108 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
22:24:45.0484 3108 MegaSR - ok
22:24:45.0543 3108 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
22:24:45.0619 3108 Modem - ok
22:24:45.0677 3108 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
22:24:45.0765 3108 monitor - ok
22:24:45.0902 3108 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
22:24:45.0918 3108 mouclass - ok
22:24:45.0955 3108 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
22:24:45.0993 3108 mouhid - ok
22:24:46.0055 3108 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
22:24:46.0072 3108 mountmgr - ok
22:24:46.0132 3108 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
22:24:46.0150 3108 mpio - ok
22:24:46.0281 3108 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
22:24:46.0338 3108 mpsdrv - ok
22:24:46.0423 3108 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
22:24:46.0475 3108 MRxDAV - ok
22:24:46.0732 3108 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:24:46.0840 3108 mrxsmb - ok
22:24:46.0905 3108 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:24:46.0945 3108 mrxsmb10 - ok
22:24:47.0091 3108 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:24:47.0128 3108 mrxsmb20 - ok
22:24:47.0184 3108 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
22:24:47.0200 3108 msahci - ok
22:24:47.0272 3108 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
22:24:47.0290 3108 msdsm - ok
22:24:47.0451 3108 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
22:24:47.0504 3108 Msfs - ok
22:24:47.0540 3108 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
22:24:47.0604 3108 mshidkmdf - ok
22:24:47.0659 3108 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
22:24:47.0674 3108 msisadrv - ok
22:24:47.0735 3108 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
22:24:47.0801 3108 MSKSSRV - ok
22:24:47.0921 3108 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
22:24:47.0981 3108 MSPCLOCK - ok
22:24:48.0014 3108 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
22:24:48.0068 3108 MSPQM - ok
22:24:48.0131 3108 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
22:24:48.0149 3108 MsRPC - ok
22:24:48.0221 3108 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
22:24:48.0236 3108 mssmbios - ok
22:24:48.0353 3108 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
22:24:48.0415 3108 MSTEE - ok
22:24:48.0444 3108 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
22:24:48.0473 3108 MTConfig - ok
22:24:48.0523 3108 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
22:24:48.0544 3108 Mup - ok
22:24:48.0603 3108 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
22:24:48.0631 3108 NativeWifiP - ok
22:24:48.0797 3108 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
22:24:48.0830 3108 NDIS - ok
22:24:48.0954 3108 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
22:24:48.0996 3108 NdisCap - ok
22:24:49.0039 3108 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
22:24:49.0099 3108 NdisTapi - ok
22:24:49.0157 3108 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
22:24:49.0211 3108 Ndisuio - ok
22:24:49.0366 3108 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
22:24:49.0430 3108 NdisWan - ok
22:24:49.0506 3108 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
22:24:49.0568 3108 NDProxy - ok
22:24:49.0691 3108 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
22:24:49.0755 3108 NetBIOS - ok
22:24:49.0817 3108 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
22:24:49.0881 3108 NetBT - ok
22:24:50.0041 3108 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
22:24:50.0057 3108 nfrd960 - ok
22:24:50.0123 3108 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
22:24:50.0189 3108 Npfs - ok
22:24:50.0239 3108 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
22:24:50.0303 3108 nsiproxy - ok
22:24:50.0496 3108 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
22:24:50.0541 3108 Ntfs - ok
22:24:50.0656 3108 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
22:24:50.0714 3108 Null - ok
22:24:50.0776 3108 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
22:24:50.0793 3108 nvraid - ok
22:24:50.0843 3108 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
22:24:50.0860 3108 nvstor - ok
22:24:51.0007 3108 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
22:24:51.0025 3108 nv_agp - ok
22:24:51.0070 3108 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
22:24:51.0114 3108 ohci1394 - ok
22:24:51.0208 3108 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
22:24:51.0247 3108 Parport - ok
22:24:51.0411 3108 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
22:24:51.0431 3108 partmgr - ok
22:24:51.0484 3108 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
22:24:51.0521 3108 Parvdm - ok
22:24:51.0590 3108 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
22:24:51.0608 3108 pci - ok
22:24:51.0750 3108 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
22:24:51.0765 3108 pciide - ok
22:24:51.0819 3108 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
22:24:51.0838 3108 pcmcia - ok
22:24:51.0879 3108 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
22:24:51.0895 3108 pcw - ok
22:24:51.0959 3108 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
22:24:52.0045 3108 PEAUTH - ok
22:24:52.0271 3108 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
22:24:52.0316 3108 PptpMiniport - ok
22:24:52.0361 3108 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
22:24:52.0381 3108 Processor - ok
22:24:52.0438 3108 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
22:24:52.0503 3108 Psched - ok
22:24:52.0600 3108 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
22:24:52.0648 3108 ql2300 - ok
22:24:52.0779 3108 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
22:24:52.0796 3108 ql40xx - ok
22:24:52.0835 3108 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
22:24:52.0881 3108 QWAVEdrv - ok
22:24:52.0924 3108 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
22:24:52.0983 3108 RasAcd - ok
22:24:53.0121 3108 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:24:53.0179 3108 RasAgileVpn - ok
22:24:53.0245 3108 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:24:53.0305 3108 Rasl2tp - ok
22:24:53.0355 3108 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
22:24:53.0421 3108 RasPppoe - ok
22:24:53.0556 3108 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
22:24:53.0618 3108 RasSstp - ok
22:24:53.0693 3108 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
22:24:53.0756 3108 rdbss - ok
22:24:53.0881 3108 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
22:24:53.0903 3108 rdpbus - ok
22:24:53.0969 3108 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:24:54.0029 3108 RDPCDD - ok
22:24:54.0101 3108 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
22:24:54.0140 3108 RDPDR - ok
22:24:54.0256 3108 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
22:24:54.0322 3108 RDPENCDD - ok
22:24:54.0382 3108 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
22:24:54.0420 3108 RDPREFMP - ok
22:24:54.0488 3108 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys
22:24:54.0566 3108 RdpVideoMiniport - ok
22:24:54.0849 3108 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
22:24:54.0890 3108 RDPWD - ok
22:24:54.0952 3108 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
22:24:54.0972 3108 rdyboost - ok
22:24:55.0070 3108 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
22:24:55.0128 3108 rspndr - ok
22:24:55.0273 3108 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
22:24:55.0350 3108 s3cap - ok
22:24:55.0396 3108 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
22:24:55.0416 3108 sbp2port - ok
22:24:55.0475 3108 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
22:24:55.0536 3108 scfilter - ok
22:24:55.0808 3108 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys
22:24:55.0941 3108 sdbus - ok
22:24:56.0025 3108 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
22:24:56.0097 3108 secdrv - ok
22:24:56.0179 3108 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
22:24:56.0198 3108 Serenum - ok
22:24:56.0305 3108 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
22:24:56.0349 3108 Serial - ok
22:24:56.0406 3108 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
22:24:56.0425 3108 sermouse - ok
22:24:56.0510 3108 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
22:24:56.0530 3108 sffdisk - ok
22:24:56.0674 3108 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
22:24:56.0721 3108 sffp_mmc - ok
22:24:56.0768 3108 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
22:24:56.0814 3108 sffp_sd - ok
22:24:56.0865 3108 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
22:24:56.0921 3108 sfloppy - ok
22:24:57.0087 3108 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
22:24:57.0103 3108 sisagp - ok
22:24:57.0160 3108 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:24:57.0180 3108 SiSRaid2 - ok
22:24:57.0223 3108 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
22:24:57.0239 3108 SiSRaid4 - ok
22:24:57.0276 3108 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
22:24:57.0320 3108 Smb - ok
22:24:57.0476 3108 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
22:24:57.0491 3108 spldr - ok
22:24:57.0608 3108 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
22:24:57.0682 3108 srv - ok
22:24:57.0837 3108 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
22:24:57.0886 3108 srv2 - ok
22:24:57.0948 3108 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
22:24:57.0970 3108 SrvHsfHDA - ok
22:24:58.0129 3108 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
22:24:58.0184 3108 SrvHsfV92 - ok
22:24:58.0343 3108 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
22:24:58.0373 3108 SrvHsfWinac - ok
22:24:58.0522 3108 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
22:24:58.0564 3108 srvnet - ok
22:24:58.0624 3108 ssadbus (64e44acd8c238fcbbb78f0ba4bdc4b05) C:\Windows\system32\DRIVERS\ssadbus.sys
22:24:58.0639 3108 ssadbus - ok
22:24:58.0696 3108 ssadmdfl (bb2c84a15c765da89fd832b0e73f26ce) C:\Windows\system32\DRIVERS\ssadmdfl.sys
22:24:58.0709 3108 ssadmdfl - ok
22:24:58.0825 3108 ssadmdm (6d0d132ddc6f43eda00dced6d8b1ca31) C:\Windows\system32\DRIVERS\ssadmdm.sys
22:24:58.0839 3108 ssadmdm - ok
22:24:58.0895 3108 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
22:24:58.0909 3108 ssmdrv - ok
22:24:58.0967 3108 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
22:24:58.0982 3108 stexstor - ok
22:24:59.0126 3108 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
22:24:59.0142 3108 storflt - ok
22:24:59.0187 3108 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
22:24:59.0202 3108 storvsc - ok
22:24:59.0242 3108 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
22:24:59.0257 3108 swenum - ok
22:24:59.0300 3108 Synth3dVsc - ok
22:24:59.0455 3108 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
22:24:59.0502 3108 Tcpip - ok
22:24:59.0688 3108 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
22:24:59.0734 3108 TCPIP6 - ok
22:24:59.0892 3108 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
22:24:59.0958 3108 tcpipreg - ok
22:25:00.0014 3108 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
22:25:00.0067 3108 TDPIPE - ok
22:25:00.0165 3108 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
22:25:00.0219 3108 TDTCP - ok
22:25:00.0326 3108 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
22:25:00.0394 3108 tdx - ok
22:25:00.0507 3108 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
22:25:00.0522 3108 TermDD - ok
22:25:00.0619 3108 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:25:00.0678 3108 tssecsrv - ok
22:25:00.0789 3108 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
22:25:00.0851 3108 TsUsbFlt - ok
22:25:00.0921 3108 tsusbhub - ok
22:25:00.0988 3108 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
22:25:01.0106 3108 tunnel - ok
22:25:01.0205 3108 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
22:25:01.0225 3108 uagp35 - ok
22:25:01.0332 3108 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
22:25:01.0388 3108 udfs - ok
22:25:01.0468 3108 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
22:25:01.0484 3108 uliagpkx - ok
22:25:01.0593 3108 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
22:25:01.0614 3108 umbus - ok
22:25:01.0689 3108 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
22:25:01.0732 3108 UmPass - ok
22:25:01.0832 3108 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
22:25:01.0881 3108 usbaudio - ok
22:25:01.0987 3108 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
22:25:02.0036 3108 usbccgp - ok
22:25:02.0139 3108 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
22:25:02.0166 3108 usbcir - ok
22:25:02.0265 3108 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
22:25:02.0304 3108 usbehci - ok
22:25:02.0403 3108 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
22:25:02.0454 3108 usbhub - ok
22:25:02.0561 3108 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
22:25:02.0596 3108 usbohci - ok
22:25:02.0681 3108 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
22:25:02.0726 3108 usbprint - ok
22:25:02.0872 3108 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:25:02.0932 3108 USBSTOR - ok
22:25:03.0065 3108 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys
22:25:03.0084 3108 usbuhci - ok
22:25:03.0146 3108 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys
22:25:03.0191 3108 usb_rndisx - ok
22:25:03.0349 3108 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
22:25:03.0365 3108 vdrvroot - ok
22:25:03.0433 3108 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
22:25:03.0476 3108 vga - ok
22:25:03.0529 3108 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
22:25:03.0571 3108 VgaSave - ok
22:25:03.0668 3108 VGPU - ok
22:25:03.0719 3108 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
22:25:03.0739 3108 vhdmp - ok
22:25:03.0791 3108 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
22:25:03.0807 3108 viaagp - ok
22:25:03.0869 3108 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
22:25:03.0915 3108 ViaC7 - ok
22:25:04.0060 3108 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
22:25:04.0075 3108 viaide - ok
22:25:04.0126 3108 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
22:25:04.0146 3108 vmbus - ok
22:25:04.0187 3108 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
22:25:04.0225 3108 VMBusHID - ok
22:25:04.0277 3108 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
22:25:04.0297 3108 volmgr - ok
22:25:04.0425 3108 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
22:25:04.0447 3108 volmgrx - ok
22:25:04.0511 3108 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
22:25:04.0531 3108 volsnap - ok
22:25:04.0591 3108 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
22:25:04.0609 3108 vsmraid - ok
22:25:04.0656 3108 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
22:25:04.0703 3108 vwifibus - ok
22:25:04.0853 3108 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
22:25:04.0878 3108 vwififlt - ok
22:25:04.0914 3108 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys
22:25:04.0942 3108 vwifimp - ok
22:25:05.0083 3108 VX3000 (e26744e5dd71a16e80d4dd5a286b8423) C:\Windows\system32\DRIVERS\VX3000.sys
22:25:05.0143 3108 VX3000 - ok
22:25:05.0293 3108 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
22:25:05.0336 3108 WacomPen - ok
22:25:05.0395 3108 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
22:25:05.0460 3108 WANARP - ok
22:25:05.0479 3108 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
22:25:05.0522 3108 Wanarpv6 - ok
22:25:05.0621 3108 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
22:25:05.0637 3108 Wd - ok
22:25:05.0777 3108 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
22:25:05.0814 3108 Wdf01000 - ok
22:25:05.0910 3108 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
22:25:05.0973 3108 WfpLwf - ok
22:25:06.0105 3108 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
22:25:06.0122 3108 WIMMount - ok
22:25:06.0208 3108 winachsf (6d2350bb6e77e800fc4be4e5b7a2e89a) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
22:25:06.0255 3108 winachsf - ok
22:25:06.0468 3108 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
22:25:06.0508 3108 WinUsb - ok
22:25:06.0572 3108 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
22:25:06.0617 3108 WmiAcpi - ok
22:25:06.0738 3108 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
22:25:06.0798 3108 ws2ifsl - ok
22:25:06.0981 3108 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
22:25:07.0045 3108 WudfPf - ok
22:25:07.0096 3108 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:25:07.0135 3108 WUDFRd - ok
22:25:07.0210 3108 XAudio (5a7ff9a18ff6d7e0527fe3abf9204ef8) C:\Windows\system32\DRIVERS\xaudio.sys
22:25:07.0247 3108 XAudio - ok
22:25:07.0327 3108 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:25:07.0389 3108 \Device\Harddisk0\DR0 - ok
22:25:07.0400 3108 Boot (0x1200) (b64aab151913743bf9f6e88f5fd786c5) \Device\Harddisk0\DR0\Partition0
22:25:07.0401 3108 \Device\Harddisk0\DR0\Partition0 - ok
22:25:07.0443 3108 Boot (0x1200) (3441fbf2082141e50f767df1d4254a66) \Device\Harddisk0\DR0\Partition1
22:25:07.0444 3108 \Device\Harddisk0\DR0\Partition1 - ok
22:25:07.0449 3108 ============================================================
22:25:07.0449 3108 Scan finished
22:25:07.0449 3108 ============================================================
22:25:07.0478 3152 Detected object count: 1
22:25:07.0478 3152 Actual detected object count: 1
23:02:02.0507 3152 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
23:02:02.0507 3152 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip


ich bin mir zwar nicht sicher, ob du das von mir wolltest, aber ich hab dir auch noch einen screenshot in die box geladen...

markusg 21.11.2011 11:57

hast du nen brenner und rolinge zur hand?

Yasmin 21.11.2011 20:32

Nein leider nicht, wieso? Was ist los??
Roling hätte ich gleich besorgt...

markusg 21.11.2011 20:38

gehe mal auf start ausführen (suchen)
tippe oder kopiere rein:
diskmgmt.msc
enter
dann mache mir mal nen screenshot
und sag mir was auf der rechten seite als boot partition angegeben ist + die infos dazu

Yasmin 21.11.2011 22:08

Screenshot ist in der box!

markusg 22.11.2011 12:02

hänge den mal bitte hier im thema an, hab ihn da ausversehen gelöscht weil er da eig nicht reingehört, der upload channel ist nur für infizierte dateien, screenshots ins thema

Yasmin 23.11.2011 08:34

Liste der Anhänge anzeigen (Anzahl: 1)
Oh, tut mir Leid! Anhang 24595

markusg 23.11.2011 12:56

nutze hitmanpro:
http://www.trojaner-board.de/99424-c...o-scannen.html
quarantäne auswählen log posten

Yasmin 23.11.2011 14:13

Quarantäne habe ich leider nichts gefunden.. konnte immer nur auf weiter klicken..
habe aber das hier kopiert..

- <Log computer="YASMIN-LAPTOP" scan="Normal" version="3.5.9.131" date="2011-11-23T14:05:09" timeSpentInSecs="305" filesProcessed="39492">
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Cookies\PD8LEP1U.txt" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:2o7.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ad.360yield.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ad.ad-srv.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ad.adserver01.de" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ad.yieldmanager.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ad.zanox.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ads.clicmanager.fr" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ads.kampfkunst-board.info" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ads.quartermedia.de" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:adtech.de" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:advertising.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:adviva.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:apmebf.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:atdmt.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:bs.serving-sys.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:casalemedia.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:collective-media.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:conrad.122.2o7.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:de.sitestat.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:doubleclick.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:eas.apm.emediate.eu" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:fastclick.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:guj.122.2o7.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:invitemedia.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:media6degrees.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:mediaplex.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:neckermannde.122.2o7.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:revsci.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:serving-sys.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:smartadserver.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:specificclick.net" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:stat.dealtime.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:statcounter.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:track.effiliation.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:tradedoubler.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:ww251.smartadserver.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:www.burstnet.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:www.etracker.de" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:www.googleadservices.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:xiti.com" />
</Item>
- <Item type="Repair" score="0.0" status="Deleted">
<File path="C:\Users\Yasmin\AppData\Roaming\Mozilla\Firefox\Profiles\zcqwj0dp.default\cookies.sqlite:xxxlutz.at" />
</Item>
</Log>

markusg 23.11.2011 15:19

hi, kannst du mir mal noch mal genau beschreiben worin die noch vorliegenden probleme bestehen?

Yasmin 24.11.2011 00:31

Firefox hängt jetzt sehr häufig und bringt mir (Keine Rückmeldung)..
zusätzlich öffneten sich im Facebook sowohl beim Spiel Dinge obwohl ich nichts anklickte und Chatfenster öffneten und schließten sich von allein.
Vl hing ja der Laptop auch nur auf seltsame Weise.. Keine Rückmeldung bekomme ich noch immer häufiger.. Im Chat war ich bisher nicht mehr.

markusg 24.11.2011 12:46

hi, wir können halt noch weiter nach dem fehler suchen aber malware kann das system beschädigen, weswegen vllt auch ein formatieren und dann neu aufsetzen das beste und sicherste sein könnte, dann die sicherheits tipps abarbeiten die ich dir gebe

Yasmin 24.06.2012 11:58

Hallo markusg! und liebe Kenner/Könner!

Nun ist ja eine Zeit vergangen, alles war gut.. und nun.. mitten im Surfen... Virusmeldung!
Und zwar von... tadaaa Security Shield!

Wie geht denn das??
Ich habe seither nichts unbekanntes mehr angeklickt!

Seit paar Tagen hab ich auch so ne komische Meldung, wenn der Laptop im Standby-Modus war, dass ein IP-Adressenkonflikt besteht.
Kann das zusammenhängen??

Muss ich nun alles nochmal machen, was ich damals gemacht hatte??

Lieben Gruß,
und hoffe auf schnelle Hilfe, da der Laptop derzeit noch funktioniert.. das letzte Mal ging er dann ja nicht mehr..


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:16 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131