Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Firewall wird nicht richtig ausgeführt! (https://www.trojaner-board.de/113005-firewall-richtig-ausgefuehrt.html)

KenoP 02.04.2012 23:23

Firewall wird nicht richtig ausgeführt!
 
Hallo liebe Trojaner-Board Gemeinde.
Ich hab seit ein paar(??) Tagen ein Problem mit meiner Firewall. Sie lässt sich nicht mehr aktiviren. Ich hab schon in vielen Foren nach Lösungen gesucht doch bislang habe ich keine Lösung gefunden bzw. ich hab keine Lösung richtig verstanden, die ich auch anwenden könnte.
Zur Vorgeschichte: Ich bin seit einger Zeit krank und liege im Bett, da erscheint vor etwa einer Woche ein "Bluescreen". Ich dachte es läge an einer Überhitzung, da der Laptop über viele Stunden auf einer Decke lag und (für mich) unnatürlich heiß gelaufen war.
Das eigentliche Problem ist mir erst gestern aufgefallen.
Ich hab in einem anderm Forum einen Screenshot gefunden der mein Problem 100% dalegt. (Fotos: hxxp://www.sevenforums.com/system-security/200214-window-7-firewall-error-code-0x80070424.html).
Bevor ich das Problem gemerkt hab, habe ich versucht Nero 8 und BullGuard von orginal Cds zu installieren, die ich bei mir zu Hause wiedergefunden hatte.
Daraufhin gab es eine Fehlermeldung ein Treiber sei blockiert worden. Ich dachte mir mit der Deinstallation sei dieses Problem beseitigt. Dem war anscheinend nicht so.

Als ich das Problem bemerkt hatte habe ich mich informiert und verschiedene Suchläufe durchgeführt.(Malwarebytes Anti-Malware, Antivire, SUPERAntiSpyware, cmd-Konsole) Es gab bei Antivir 3 Funde( Reoport im Anhang).
Ich löschte diese und startete mein Pc neu, doch das Problem blieb vorhanden
Ich habe keine Windos 7 Reperatur oder Wiederherstellungs-CD, deshalb hoffe ich, dass es eine Lösung ohne die Wiederherstellung oder Formatierung des System geht.

Andere Firewalls besitze ich meins Wissens nach nicht.

Die Gmerscan habe ich nicht durchgeführt da ich ein 64-bit System habe.

Hier meine Technischen Daten:
Betriebsystem:Microsoft Windows 7 Home Premium
Systemtyp:x64-basierter PC
Prozessor:Intel Core i3 Prozessor
BIOS: Insyde 1.90, 11.11.2010

Meine DDS.txt
[CODE].DDS Logfile:
Code:

DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_31
Run by Keno at 23:42:40 on 2012-04-02
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3959.2151 [GMT 2:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Windows\SysWOW64\svchost.exe -k Update-Service
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
c:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
uDefault_Page_URL = hxxp://toshiba.msn.com
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID-Anmelde-Hilfsprogramm: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [IcqUpdater] "C:\Users\Keno\AppData\Local\Temp\IcqUpdater.exe" update 4132 Global\MMutexLib_Global_AppInstance_YzpccHJvZ3JhfjJcaWNxNy41XGljcS5leGU "C:\Program Files (x86)\ICQ7.5\updates\downloaded" "C:\PROGRA~2\ICQ7.5\ICQ.exe silent loginmode=4 noupdate=1" autorun
uRun: [Facebook Update] "C:\Users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe"
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
dRun: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe
StartupFolder: C:\Users\Keno\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{DA91AA9D-A387-41A9-AE6E-1C23B8285E9B} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{DA91AA9D-A387-41A9-AE6E-1C23B8285E9B}\75C414E4D2933303931323 : DhcpNameServer = 192.168.2.1 192.168.2.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{0347C33E-8762-4905-BF09-768834316C61}
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{326E768D-4182-46FD-9C16-1449A49795F4}
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{9FDDE16B-836F-4806-AB1F-1455CBEFF289}
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{F3C88694-EFFA-4d78-B409-54B7B2535B14}
{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun-x64: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
mRun-x64: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://ssnhdn.listen2myradio.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q=
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Keno\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109989
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 8ee9dc020000000000004ceddee5aca3
FF - user.js: extensions.BabylonToolbar_i.hardId - 8ee9dc020000000000004ceddee5aca3
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15415
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:51:24
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AntiVirSchedulerService;Avira Planer;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-4-1 86224]
R2 AntiVirService;Avira Echtzeit Scanner;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-4-1 110032]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-1-28 249200]
R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-3-10 46448]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-3-17 258928]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\system32\DRIVERS\TVALZFL.sys --> C:\Windows\system32\DRIVERS\TVALZFL.sys [?]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-27 2320920]
R2 Update-Service;Update-Service;C:\Windows\System32\svchost.exe -k Update-Service [2009-7-14 20992]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;C:\Windows\system32\drivers\CHDMI64.sys --> C:\Windows\system32\drivers\CHDMI64.sys [?]
R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys --> C:\Windows\system32\DRIVERS\FwLnk.sys [?]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 PGEffect;Pangu effect driver;C:\Windows\system32\DRIVERS\pgeffect.sys --> C:\Windows\system32\DRIVERS\pgeffect.sys [?]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\system32\DRIVERS\rtl8192se.sys --> C:\Windows\system32\DRIVERS\rtl8192se.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-12-27 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-2-23 835952]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update-Dienst (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-5 136176]
S3 gupdatem;Google Update-Dienst (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-3-5 136176]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-5-11 124368]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-04-02 15:53:59        --------        d-----w-        C:\ProgramData\SUPERSetup
2012-04-02 12:18:07        --------        d-----w-        C:\Users\Keno\AppData\Roaming\Malwarebytes
2012-04-02 12:18:02        --------        d-----w-        C:\ProgramData\Malwarebytes
2012-04-02 12:18:01        23152        ----a-w-        C:\Windows\System32\drivers\mbam.sys
2012-04-02 12:18:01        --------        d-----w-        C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-04-01 15:11:47        --------        d-----w-        C:\Users\Keno\AppData\Roaming\Avira
2012-04-01 15:11:15        97312        ----a-w-        C:\Windows\System32\drivers\avgntflt.sys
2012-04-01 15:11:15        27760        ----a-w-        C:\Windows\System32\drivers\avkmgr.sys
2012-04-01 15:11:14        --------        d-----w-        C:\ProgramData\Avira
2012-04-01 15:11:14        --------        d-----w-        C:\Program Files (x86)\Avira
2012-04-01 14:25:28        --------        d-----w-        C:\ProgramData\BullGuard
2012-04-01 14:13:17        --------        d-----w-        C:\Users\Keno\AppData\Local\Ahead
2012-03-28 11:29:12        --------        d-----w-        C:\Users\Keno\AppData\Local\Spotify
2012-03-28 11:28:15        --------        d-----w-        C:\Users\Keno\AppData\Roaming\Spotify
2012-03-26 22:44:14        --------        d-----w-        C:\Users\Keno\AppData\Local\DDMSettings
2012-03-26 22:42:07        --------        d-----w-        C:\Program Files\DivX
2012-03-26 22:41:58        --------        d-----w-        C:\Program Files (x86)\Common Files\DivX Shared
2012-03-26 22:41:07        --------        d-----w-        C:\Program Files (x86)\DivX
2012-03-26 22:39:51        --------        d-----w-        C:\ProgramData\DivX
2012-03-25 19:59:24        --------        d-sh--w-        C:\ProgramData\SecuROM
2012-03-25 19:31:00        --------        d-----w-        C:\Users\Keno\AppData\Roaming\Ubisoft
2012-03-25 19:28:50        --------        d-----w-        C:\ProgramData\Tages
2012-03-25 19:27:23        43680        ----a-w-        C:\Windows\System32\drivers\lirsgt.sys
2012-03-25 19:27:23        314016        ----a-w-        C:\Windows\System32\drivers\atksgt.sys
2012-03-24 17:07:15        --------        d-----w-        C:\Users\Keno\AppData\Local\HP
2012-03-24 17:06:06        --------        d-----w-        C:\Users\Keno\AppData\Roaming\DAEMON Tools Lite
2012-03-24 17:06:04        --------        d-----w-        C:\ProgramData\DAEMON Tools Lite
2012-03-24 14:53:58        3977496        ----a-w-        C:\Windows\System32\d3dx9_31.dll
2012-03-24 14:52:47        --------        d-----w-        C:\Windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2012-03-24 13:41:00        --------        d-----w-        C:\Users\Keno\res
2012-03-24 13:41:00        --------        d-----w-        C:\Users\Keno\Readme
2012-03-24 13:40:40        --------        d-----w-        C:\Users\Keno\Prerequisites
2012-03-24 13:40:40        --------        d-----w-        C:\Users\Keno\EULA
2012-03-24 13:40:39        --------        d-----w-        C:\Users\Keno\0x0007
2012-03-24 13:10:19        --------        d-----w-        C:\Users\Keno\AppData\Local\{59CAAA9E-35F0-47AA-BBE6-67F29997E9B0}
2012-03-23 14:57:14        8669240        ----a-w-        C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{94168AFD-FEBB-45E0-AC33-918B039A07D7}\mpengine.dll
2012-03-23 14:41:04        305664        ----a-w-        C:\Windows\System32\aptwgv56x.dll
2012-03-19 22:50:31        --------        d-----w-        C:\Users\Keno\AppData\Local\{88062434-F90A-4E12-94DB-F4C651E9CBF6}
2012-03-19 22:37:18        --------        d-----w-        C:\Users\Keno\AppData\Local\{92F9B859-A904-4878-967D-582420951EB6}
2012-03-19 22:33:34        --------        d-----w-        C:\Users\Keno\AppData\Local\{C8E5DD37-666A-406F-BBD9-42EDE137943B}
2012-03-19 22:31:31        --------        d-----w-        C:\Users\Keno\AppData\Local\{73CE502F-B735-4396-A4A5-8E56BEEDB9FC}
2012-03-19 22:30:13        --------        d-----w-        C:\Users\Keno\AppData\Local\{40BD12F0-4DFF-4BF0-808D-A62EA4DA128B}
2012-03-19 22:28:49        --------        d-----w-        C:\Users\Keno\AppData\Local\{81C29D9D-E641-420D-B29F-EF5F7331DAE7}
2012-03-19 22:26:22        --------        d-----w-        C:\Users\Keno\AppData\Local\{4DF4D427-D0C2-4D45-B6AB-390E829139F5}
2012-03-19 22:22:38        --------        d-----w-        C:\Users\Keno\AppData\Local\{4D36FC9A-5630-4E2A-9142-812C34B703B4}
2012-03-19 22:19:26        --------        d-----w-        C:\Users\Keno\AppData\Local\{27D56FE2-9999-4500-8F2E-18D080FB51DE}
2012-03-19 22:15:59        --------        d-----w-        C:\Users\Keno\AppData\Local\{7A39FBE5-B9E4-4D04-90B8-BBE22C7BC0AE}
2012-03-19 22:15:25        --------        d-----w-        C:\Users\Keno\AppData\Local\{AB897304-887D-4F1A-9746-209ED6038DC1}
2012-03-19 22:14:06        --------        d-----w-        C:\Users\Keno\AppData\Local\{103ACF2C-0854-4734-A357-C0E3DD31838E}
2012-03-19 22:10:52        --------        d-----w-        C:\Users\Keno\AppData\Local\{27468F43-AB32-4C5A-A063-500111E1445C}
2012-03-19 21:21:24        --------        d-----w-        C:\Users\Keno\AppData\Local\{3010831A-496C-474F-ABD4-40847202EBCC}
2012-03-19 21:12:20        --------        d-----w-        C:\Users\Keno\AppData\Local\{258FCCBD-444C-42C6-863E-5947A9627833}
2012-03-19 20:57:31        --------        d-----w-        C:\Users\Keno\AppData\Local\{99E063F9-FD50-4C72-BAFD-19941DB05055}
2012-03-19 20:52:14        --------        d-----w-        C:\Users\Keno\AppData\Local\{6D25F825-5BDB-4947-9D30-5B924C2F3BA3}
2012-03-19 19:58:37        --------        d-----w-        C:\Users\Keno\AppData\Local\{35D0E6B7-C0AD-4233-B17C-E17645C1577D}
2012-03-19 19:42:18        --------        d-----w-        C:\Users\Keno\AppData\Local\{244ED422-47D8-4CCA-9143-0083923E808C}
2012-03-19 19:35:23        --------        d-----w-        C:\Users\Keno\AppData\Local\{010840A1-29F5-426F-8074-7BBF1810EE4A}
2012-03-19 18:42:51        --------        d-----w-        C:\Users\Keno\AppData\Local\{F9819BC5-3524-4B8E-A294-10A9FB6F282E}
2012-03-19 18:37:32        --------        d-----w-        C:\Users\Keno\AppData\Local\{B22FFEEF-A731-4F9D-B48C-111AA7C1C961}
2012-03-19 18:37:03        --------        d-----w-        C:\Users\Keno\AppData\Local\{46CDEB32-8BB7-4658-854F-23A0599F1BF6}
2012-03-18 11:48:12        592824        ----a-w-        C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
2012-03-18 11:48:12        44472        ----a-w-        C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
2012-03-16 20:51:15        --------        d-----w-        C:\Users\Keno\AppData\Local\Babylon
2012-03-16 20:51:14        --------        d-----w-        C:\Users\Keno\AppData\Roaming\Babylon
2012-03-16 20:51:14        --------        d-----w-        C:\ProgramData\Babylon
2012-03-14 08:31:41        5559152        ----a-w-        C:\Windows\System32\ntoskrnl.exe
2012-03-14 08:31:40        3968368        ----a-w-        C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-14 08:31:39        3913584        ----a-w-        C:\Windows\SysWow64\ntoskrnl.exe
2012-03-14 06:24:52        3145728        ----a-w-        C:\Windows\System32\win32k.sys
2012-03-14 06:24:50        1544192        ----a-w-        C:\Windows\System32\DWrite.dll
2012-03-14 06:24:50        1077248        ----a-w-        C:\Windows\SysWow64\DWrite.dll
2012-03-14 06:24:23        9216        ----a-w-        C:\Windows\System32\rdrmemptylst.exe
2012-03-14 06:24:23        77312        ----a-w-        C:\Windows\System32\rdpwsx.dll
2012-03-14 06:24:23        149504        ----a-w-        C:\Windows\System32\rdpcorekmts.dll
2012-03-14 06:24:22        826880        ----a-w-        C:\Windows\SysWow64\rdpcore.dll
2012-03-14 06:24:22        23552        ----a-w-        C:\Windows\System32\drivers\tdtcp.sys
2012-03-14 06:24:22        210944        ----a-w-        C:\Windows\System32\drivers\rdpwd.sys
2012-03-14 06:24:22        1031680        ----a-w-        C:\Windows\System32\rdpcore.dll
2012-03-05 19:34:36        --------        d-----w-        C:\Users\Keno\AppData\Local\Google
.
==================== Find3M  ====================
.
2012-03-24 16:55:58        414368        ----a-w-        C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-23 08:18:36        279656        ------w-        C:\Windows\System32\MpSigStub.exe
2012-02-16 09:32:16        472808        ----a-w-        C:\Windows\SysWow64\deployJava1.dll
2012-01-11 13:50:14        286720        ----a-w-        C:\Windows\SysWow64\d3dy569y8.dll
2012-01-11 13:50:14        1332736        ----a-w-        C:\Windows\System32\xpt8inke.tsp
2012-01-04 10:44:20        509952        ----a-w-        C:\Windows\System32\ntshrui.dll
2012-01-04 08:58:41        442880        ----a-w-        C:\Windows\SysWow64\ntshrui.dll
2012-01-04 00:48:42        354176        ----a-w-        C:\Windows\SysWow64\DivXControlPanelApplet.cpl
.
============= FINISH: 23:43:14,36 ===============

--- --- ---

Dies ist mein Malwarebericht:
Code:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Datenbank Version: v2012.04.02.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Keno :: KENOPAPE [Administrator]

02.04.2012 17:54:42
mbam-log-2012-04-02 (17-54-42).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 399772
Laufzeit: 1 Stunde(n), 46 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)




Dies mein Antivir Bericht:
PHP-Code:


Avira Free Antivirus
Erstellungsdatum der Reportdatei
Montag2. April 2012  15:00

Es wird nach 3572891 Virenstämmen gesucht
.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer   Avira AntiVir Personal Free Antivirus
Seriennummer   
0000149996-ADJIE-0000001
Plattform      
Windows 7 x64
Windowsversion 
: (Service Pack 1)  [6.1.7601]
Boot Modus     Normal gebootet
Benutzername   
SYSTEM
Computername   
KENOP***

Versionsinformationen:
BUILD.DAT      12.0.0.855     41827 Bytes  12.10.2011 16:36:00
AVSCAN
.EXE     12.1.0.17     490448 Bytes  11.10.2011 12:59:38
AVSCAN
.DLL     12.1.0.17      65744 Bytes  11.10.2011 12:59:58
LUKE
.DLL       12.1.0.17      68304 Bytes  11.10.2011 12:59:47
AVSCPLR
.DLL    12.1.0.22      99848 Bytes  01.04.2012 15:14:14
AVREG
.DLL      12.1.0.29     227848 Bytes  01.04.2012 15:14:13
VBASE000
.VDF   7.10.0.0    19875328 Bytes  06.11.2009 18:18:34
VBASE001
.VDF   7.11.0.0    13342208 Bytes  14.12.2010 09:07:39
VBASE002
.VDF   7.11.19.170 14374912 Bytes  20.12.2011 15:13:10
VBASE003
.VDF   7.11.21.238  4472832 Bytes  01.02.2012 15:13:33
VBASE004
.VDF   7.11.26.44   4329472 Bytes  28.03.2012 15:13:53
VBASE005
.VDF   7.11.26.45      2048 Bytes  28.03.2012 15:13:53
VBASE006
.VDF   7.11.26.46      2048 Bytes  28.03.2012 15:13:53
VBASE007
.VDF   7.11.26.47      2048 Bytes  28.03.2012 15:13:53
VBASE008
.VDF   7.11.26.48      2048 Bytes  28.03.2012 15:13:53
VBASE009
.VDF   7.11.26.49      2048 Bytes  28.03.2012 15:13:53
VBASE010
.VDF   7.11.26.50      2048 Bytes  28.03.2012 15:13:53
VBASE011
.VDF   7.11.26.51      2048 Bytes  28.03.2012 15:13:53
VBASE012
.VDF   7.11.26.52      2048 Bytes  28.03.2012 15:13:53
VBASE013
.VDF   7.11.26.53      2048 Bytes  28.03.2012 15:13:54
VBASE014
.VDF   7.11.26.107   221696 Bytes  30.03.2012 15:13:55
VBASE015
.VDF   7.11.26.108     2048 Bytes  30.03.2012 15:13:55
VBASE016
.VDF   7.11.26.109     2048 Bytes  30.03.2012 15:13:55
VBASE017
.VDF   7.11.26.110     2048 Bytes  30.03.2012 15:13:55
VBASE018
.VDF   7.11.26.111     2048 Bytes  30.03.2012 15:13:55
VBASE019
.VDF   7.11.26.112     2048 Bytes  30.03.2012 15:13:55
VBASE020
.VDF   7.11.26.113     2048 Bytes  30.03.2012 15:13:55
VBASE021
.VDF   7.11.26.114     2048 Bytes  30.03.2012 15:13:55
VBASE022
.VDF   7.11.26.115     2048 Bytes  30.03.2012 15:13:55
VBASE023
.VDF   7.11.26.116     2048 Bytes  30.03.2012 15:13:55
VBASE024
.VDF   7.11.26.117     2048 Bytes  30.03.2012 15:13:55
VBASE025
.VDF   7.11.26.118     2048 Bytes  30.03.2012 15:13:55
VBASE026
.VDF   7.11.26.119     2048 Bytes  30.03.2012 15:13:56
VBASE027
.VDF   7.11.26.120     2048 Bytes  30.03.2012 15:13:56
VBASE028
.VDF   7.11.26.121     2048 Bytes  30.03.2012 15:13:56
VBASE029
.VDF   7.11.26.122     2048 Bytes  30.03.2012 15:13:56
VBASE030
.VDF   7.11.26.123     2048 Bytes  30.03.2012 15:13:56
VBASE031
.VDF   7.11.26.144   203776 Bytes  01.04.2012 15:13:57
Engineversion  
8.2.10.34 
AEVDF
.DLL      8.1.2.2       106868 Bytes  01.04.2012 15:14:12
AESCRIPT
.DLL   8.1.4.15      442747 Bytes  01.04.2012 15:14:12
AESCN
.DLL      8.1.8.2       131444 Bytes  01.04.2012 15:14:11
AESBX
.DLL      8.2.5.5       606579 Bytes  01.04.2012 15:14:13
AERDL
.DLL      8.1.9.15      639348 Bytes  08.09.2011 21:16:06
AEPACK
.DLL     8.2.16.9      807287 Bytes  01.04.2012 15:14:11
AEOFFICE
.DLL   8.1.2.25      201084 Bytes  01.04.2012 15:14:09
AEHEUR
.DLL     8.1.4.10     4551031 Bytes  01.04.2012 15:14:08
AEHELP
.DLL     8.1.19.0      254327 Bytes  01.04.2012 15:14:00
AEGEN
.DLL      8.1.5.23      409973 Bytes  01.04.2012 15:14:00
AEEXP
.DLL      8.1.0.27       82293 Bytes  01.04.2012 15:14:13
AEEMU
.DLL      8.1.3.0       393589 Bytes  01.09.2011 21:46:01
AECORE
.DLL     8.1.25.6      201078 Bytes  01.04.2012 15:13:59
AEBB
.DLL       8.1.1.0        53618 Bytes  01.09.2011 21:46:01
AVWINLL
.DLL    12.1.0.17      27344 Bytes  11.10.2011 12:59:41
AVPREF
.DLL     12.1.0.17      51920 Bytes  11.10.2011 12:59:38
AVREP
.DLL      12.1.0.17     179408 Bytes  11.10.2011 12:59:38
AVARKT
.DLL     12.1.0.17     223184 Bytes  11.10.2011 12:59:36
AVEVTLOG
.DLL   12.1.0.17     169168 Bytes  11.10.2011 12:59:37
SQLITE3
.DLL    3.7.0.0       398288 Bytes  11.10.2011 12:59:51
AVSMTP
.DLL     12.1.0.17      62928 Bytes  11.10.2011 12:59:39
NETNT
.DLL      12.1.0.17      17104 Bytes  11.10.2011 12:59:47
RCIMAGE
.DLL    12.1.0.17    4447952 Bytes  11.10.2011 13:00:00
RCTEXT
.DLL     12.1.0.16      98512 Bytes  11.10.2011 13:00:00

Konfiguration für den aktuellen Suchlauf
:
Job Name..............................: AVGuardAsyncScan
Konfigurationsdatei
...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_4f798fd0\guard_slideup.avp
Protokollierung
.......................: standard
Primäre Aktion
........................: interaktiv
Sekundäre Aktion
......................: quarantäne
Durchsuche Masterbootsektoren
.........: ein
Durchsuche Bootsektoren
...............: aus
Durchsuche aktive Programme
...........: ein
Durchsuche Registrierung
..............: aus
Suche nach Rootkits
...................: aus
Integritätsprüfung von Systemdateien
..: aus
Datei Suchmodus
.......................: Alle Dateien
Durchsuche Archive
....................: ein
Rekursionstiefe einschränken
..........: 20
Archiv Smart Extensions
...............: ein
Makrovirenheuristik
...................: ein
Dateiheuristik
........................: vollständig

Beginn des Suchlaufs
Montag2. April 2012  15:00

Der Suchlauf über gestartete Prozesse wird begonnen
:
Durchsuche Prozess 'avscan.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'teeworlds.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'gmer.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'mbam.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'plugin-container.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'spotify.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'UNS.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'NASvc.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'CFSvcs.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'firefox.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'CFSwMgr.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'hpqgpc01.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'hpqbam08.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'NDSTray.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'hpqSTE08.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'avgnt.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'DivXUpdate.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'hpwuSchd2.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'jusched.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'iTunesHelper.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'NBAgent.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'soffice.bin' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'soffice.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'hpqtra08.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'CVHSVC.EXE' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'sftlist.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'svchost.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'sftvsa.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'SeaPort.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'LMS.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'svchost.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'AppleMobileDeviceService.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'avguard.exe' '1' Modul(ewurden durchsucht
Durchsuche Prozess 
'sched.exe' '1' Modul(ewurden durchsucht

Der Suchlauf über 
die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\Users\Keno\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\472dd92c-266876e2'
C:\Users\Keno\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\472dd92c-266876e2
  
[0ArchivtypZIP
  
--> a/Test.class
      [
FUND]      Enthält Erkennungsmuster des Exploits EXP/CVE-2012-0507
  
--> a/Help.class
      [
FUND]      Enthält Erkennungsmuster des Exploits EXP/JAVA.Loader.Gen

Beginne mit der Desinfektion
:
C:\Users\Keno\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\472dd92c-266876e2
  
[FUND]      Enthält Erkennungsmuster des Exploits EXP/2012-0507.D.1
  
[HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4aee07d4.qua' verschoben!


Ende des SuchlaufsMontag2. April 2012  15:08
Benötigte Zeit
00:04 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

      
0 Verzeichnisse wurden überprüft
     38 Dateien wurden geprüft
      3 Viren bzw
unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw
unerwünschte Programme wurden repariert
      1 Dateien wurden in 
die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
     35 Dateien ohne Befall
      1 Archive wurden durchsucht
      0 Warnungen
      1 Hinweise


Die Suchergebnisse werden an den Guard übermittelt

Alle anderen Funktionen meines Computers gehen noch.
Ich bedanke mich schonmal im vorraus und wünsche allen eine gute Nacht.
Gruß Keno :dankeschoen:



Hier ist nochmal der Link zu den beiden Bildern:
hxxp://www.sevenforums.com/system-security/200214-window-7-firewall-error-code-0x80070424.html

markusg 03.04.2012 08:24

hi
Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

KenoP 03.04.2012 11:54

Danke für die schnelle Antwort. Hier ist die Olt.txt:
Code:

OTL logfile created on: 03.04.2012 12:33:17 - Run 1
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Users\Keno\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,87 Gb Total Physical Memory | 2,34 Gb Available Physical Memory | 60,43% Memory free
7,73 Gb Paging File | 5,96 Gb Available in Paging File | 77,10% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,73 Gb Total Space | 125,97 Gb Free Space | 54,13% Space Free | Partition Type: NTFS
Drive D: | 232,64 Gb Total Space | 223,61 Gb Free Space | 96,12% Space Free | Partition Type: NTFS
Drive E: | 290,58 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: KENOPAPE | User Name: Keno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.04.03 12:30:39 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
PRC - [2011.10.11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 14:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.01.17 19:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 19:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.09.02 19:25:46 | 001,234,216 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
PRC - [2010.06.03 17:09:00 | 000,304,560 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010.05.04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) -- c:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010.03.03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.03.03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.07.28 21:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009.03.10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.12.04 13:36:13 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2011.07.29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.06.24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2012.03.23 16:41:04 | 000,305,664 | ---- | M] (Works Ltd.) [Auto | Running] -- C:\Windows\SysNative\aptwgv56x.dll -- (LanmanWorkstation)
SRV:64bit: - [2010.04.26 22:49:36 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.07.28 16:48:06 | 000,140,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV - [2012.04.03 01:40:27 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2011.12.07 00:45:17 | 000,114,000 | ---- | M] (Joosoft.com GmbH) [Auto | Running] -- C:\Windows\SysWOW64\UpdSvc.dll -- (Update-Service)
SRV - [2011.10.11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.09.28 13:30:28 | 000,489,384 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programme\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2010.09.22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.09.21 15:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.07.28 23:36:52 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010.05.11 10:40:52 | 000,124,368 | ---- | M] (Toshiba Europe GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO)
SRV - [2010.05.04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- c:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @c:\Program Files (x86)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.17 17:00:44 | 000,258,928 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programme\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV - [2010.03.03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.03.03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.02.23 18:57:42 | 000,835,952 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programme\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV - [2010.02.05 18:44:48 | 000,137,560 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2010.01.28 17:44:40 | 000,249,200 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe -- (cfWiMAXService)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.10.06 10:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.03.10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.04.02 17:12:53 | 000,132,320 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.03.25 21:27:23 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2012.03.25 21:27:23 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.10.11 15:00:01 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.10.11 15:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.05.10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.04.20 10:24:56 | 000,169,584 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.01.15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.04.27 04:56:34 | 006,659,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.04.27 02:23:08 | 001,103,904 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192se.sys -- (rtl8192se)
DRV:64bit: - [2010.04.26 22:17:26 | 000,195,584 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.03.31 15:50:16 | 000,724,536 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2010.03.10 19:51:32 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.03.05 12:11:30 | 000,720,952 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDMI64.sys -- (CnxtHdmiAudService)
DRV:64bit: - [2010.02.01 11:29:48 | 000,232,992 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010.01.15 13:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.09.17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.30 21:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009.07.14 16:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.07 09:51:42 | 000,009,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FwLnk.sys -- (FwLnk)
DRV:64bit: - [2009.06.22 18:06:38 | 000,035,008 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2009.06.20 04:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.06.19 20:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {47BA5EA9-629E-423A-B058-C422803BB4AD}
IE:64bit: - HKLM\..\SearchScopes\{47BA5EA9-629E-423A-B058-C422803BB4AD}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {2A05C438-AF1D-480A-8EFF-D61157D84FE7}
IE - HKLM\..\SearchScopes\{2A05C438-AF1D-480A-8EFF-D61157D84FE7}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&AF=109989&babsrc=SP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
IE - HKCU\..\SearchScopes\{5F60A953-D45D-4A67-8DD3-650D26CB7BB8}: "URL" = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{ECFA0E70-C7FF-443E-9D69-8CC3A9A840CD}: "URL" = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://ssnhdn.listen2myradio.com/"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_228.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Keno\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.29 23:54:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.03.27 00:42:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.18 13:48:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.27 00:42:22 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.29 23:54:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\files32\backup\thunderbirdbkplugin
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\files32\antispam\tbspamfilter
 
[2011.07.06 15:32:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Keno\AppData\Roaming\mozilla\Extensions
[2012.03.28 14:13:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Keno\AppData\Roaming\mozilla\Firefox\Profiles\7epc4x0r.default\extensions
[2012.03.28 14:13:46 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Keno\AppData\Roaming\mozilla\Firefox\Profiles\7epc4x0r.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.03.29 21:22:19 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-1.xml
[2011.08.19 22:11:11 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-2.xml
[2011.09.02 14:51:31 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-3.xml
[2011.09.07 16:24:01 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-4.xml
[2011.10.19 03:21:13 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-5.xml
[2011.11.11 16:19:47 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-6.xml
[2011.08.17 19:13:36 | 000,001,056 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin.xml
[2012.02.21 17:17:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.03.18 13:48:12 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.21 17:17:29 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.03.16 22:51:18 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012.02.21 17:17:29 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.21 17:17:29 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.21 17:17:29 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.21 17:17:29 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.21 17:17:29 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
Hosts file not found
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HSON] C:\Programme\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Programme\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Programme\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosNC] C:\Programme\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Programme\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Programme\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Programme\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NBAgent] c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe" File not found
O4 - HKCU..\Run: [Facebook Update] C:\Users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [IcqUpdater] "C:\Users\Keno\AppData\Local\Temp\IcqUpdater.exe" update 4132 Global\MMutexLib_Global_AppInstance_YzpccHJvZ3JhfjJcaWNxNy41XGljcS5leGU "C:\Program Files (x86)\ICQ7.5\updates\downloaded" "C:\PROGRA~2\ICQ7.5\ICQ.exe silent loginmode=4 noupdate=1" autorun File not found
O4 - Startup: C:\Users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Windows\SysWOW64\d3dy569y8.dll ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DA91AA9D-A387-41A9-AE6E-1C23B8285E9B}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.01.24 04:59:32 | 000,000,065 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{06fbf9cd-1166-11e0-8a16-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{06fbf9cd-1166-11e0-8a16-806e6f6e6963}\Shell\AutoRun\command - "" = E:\MSWorks\Autorun.exe -- [2007.06.27 13:57:51 | 000,107,848 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{45bd0f41-75b2-11e1-962c-00266c9eac55}\Shell - "" = AutoRun
O33 - MountPoints2\{45bd0f7b-75b2-11e1-962c-00266c9eac55}\Shell - "" = AutoRun
O33 - MountPoints2\{45bd0f7b-75b2-11e1-962c-00266c9eac55}\Shell\AutoRun\command - "" = F:\Launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.04.03 12:30:36 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
[2012.04.02 17:56:13 | 000,000,000 | ---D | C] -- C:\Users\Keno\Desktop\Pc diagnose
[2012.04.02 17:53:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERSetup
[2012.04.02 14:18:07 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Malwarebytes
[2012.04.02 14:18:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.04.02 14:18:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.04.02 14:18:01 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.04.02 14:18:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.04.01 17:11:47 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Avira
[2012.04.01 17:11:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.04.01 17:11:15 | 000,132,320 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.04.01 17:11:15 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012.04.01 17:11:15 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2012.04.01 17:11:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.04.01 17:11:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012.04.01 16:25:28 | 000,000,000 | ---D | C] -- C:\ProgramData\BullGuard
[2012.04.01 16:13:17 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Ahead
[2012.03.28 13:29:12 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Spotify
[2012.03.28 13:28:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Spotify
[2012.03.27 00:44:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\DDMSettings
[2012.03.27 00:42:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2012.03.27 00:42:07 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2012.03.27 00:41:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared
[2012.03.27 00:41:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2012.03.27 00:39:51 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2012.03.25 22:01:42 | 000,000,000 | ---D | C] -- C:\Users\Keno\Documents\My Games
[2012.03.25 21:59:24 | 000,000,000 | -HSD | C] -- C:\ProgramData\SecuROM
[2012.03.25 21:31:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Ubisoft
[2012.03.25 21:28:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Tages
[2012.03.24 19:07:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\HP
[2012.03.24 19:06:06 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\DAEMON Tools Lite
[2012.03.24 19:06:04 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012.03.24 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\res
[2012.03.24 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\Readme
[2012.03.24 15:40:40 | 000,000,000 | ---D | C] -- C:\Users\Keno\Prerequisites
[2012.03.24 15:40:40 | 000,000,000 | ---D | C] -- C:\Users\Keno\EULA
[2012.03.24 15:40:39 | 000,000,000 | ---D | C] -- C:\Users\Keno\0x0007
[2012.03.24 15:10:19 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{59CAAA9E-35F0-47AA-BBE6-67F29997E9B0}
[2012.03.23 16:41:04 | 000,305,664 | ---- | C] (Works Ltd.) -- C:\Windows\SysNative\aptwgv56x.dll
[2012.03.20 00:50:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{88062434-F90A-4E12-94DB-F4C651E9CBF6}
[2012.03.20 00:37:18 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{92F9B859-A904-4878-967D-582420951EB6}
[2012.03.20 00:33:34 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{C8E5DD37-666A-406F-BBD9-42EDE137943B}
[2012.03.20 00:31:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{73CE502F-B735-4396-A4A5-8E56BEEDB9FC}
[2012.03.20 00:30:13 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{40BD12F0-4DFF-4BF0-808D-A62EA4DA128B}
[2012.03.20 00:28:49 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{81C29D9D-E641-420D-B29F-EF5F7331DAE7}
[2012.03.20 00:26:22 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{4DF4D427-D0C2-4D45-B6AB-390E829139F5}
[2012.03.20 00:22:38 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{4D36FC9A-5630-4E2A-9142-812C34B703B4}
[2012.03.20 00:19:26 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{27D56FE2-9999-4500-8F2E-18D080FB51DE}
[2012.03.20 00:15:59 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{7A39FBE5-B9E4-4D04-90B8-BBE22C7BC0AE}
[2012.03.20 00:15:25 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{AB897304-887D-4F1A-9746-209ED6038DC1}
[2012.03.20 00:14:06 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{103ACF2C-0854-4734-A357-C0E3DD31838E}
[2012.03.20 00:10:52 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{27468F43-AB32-4C5A-A063-500111E1445C}
[2012.03.19 23:21:24 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{3010831A-496C-474F-ABD4-40847202EBCC}
[2012.03.19 23:12:20 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{258FCCBD-444C-42C6-863E-5947A9627833}
[2012.03.19 22:57:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{99E063F9-FD50-4C72-BAFD-19941DB05055}
[2012.03.19 22:52:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{6D25F825-5BDB-4947-9D30-5B924C2F3BA3}
[2012.03.19 21:58:37 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{35D0E6B7-C0AD-4233-B17C-E17645C1577D}
[2012.03.19 21:42:18 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{244ED422-47D8-4CCA-9143-0083923E808C}
[2012.03.19 21:35:23 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{010840A1-29F5-426F-8074-7BBF1810EE4A}
[2012.03.19 20:42:51 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{F9819BC5-3524-4B8E-A294-10A9FB6F282E}
[2012.03.19 20:37:32 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{B22FFEEF-A731-4F9D-B48C-111AA7C1C961}
[2012.03.19 20:37:03 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{46CDEB32-8BB7-4658-854F-23A0599F1BF6}
[2012.03.16 22:51:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Babylon
[2012.03.16 22:51:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Babylon
[2012.03.16 22:51:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012.03.15 22:41:05 | 000,000,000 | ---D | C] -- C:\Users\Keno\Documents\Azteken
[2012.03.05 21:35:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012.03.05 21:34:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2012.03.05 21:34:36 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Google
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Keno\Documents\*.tmp files -> C:\Users\Keno\Documents\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.04.03 12:34:12 | 000,016,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 12:34:12 | 000,016,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 12:32:46 | 001,614,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.04.03 12:32:46 | 000,697,534 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.04.03 12:32:46 | 000,652,812 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.04.03 12:32:46 | 000,148,540 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.04.03 12:32:46 | 000,121,486 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.04.03 12:30:39 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
[2012.04.03 12:27:04 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.04.03 12:26:48 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.03 12:26:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.04.03 12:26:37 | 3113,361,408 | -HS- | M] () -- C:\hiberfil.sys
[2012.04.03 00:44:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.04.03 00:20:01 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
[2012.04.02 21:20:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
[2012.04.02 17:57:08 | 000,000,000 | ---- | M] () -- C:\Users\Keno\defogger_reenable
[2012.04.02 17:12:53 | 000,132,320 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.04.02 14:09:23 | 000,899,676 | ---- | M] () -- C:\Users\Keno\AppData\Local\census.cache
[2012.04.02 14:08:37 | 000,117,389 | ---- | M] () -- C:\Users\Keno\AppData\Local\ars.cache
[2012.04.02 13:58:36 | 000,000,036 | ---- | M] () -- C:\Users\Keno\AppData\Local\housecall.guid.cache
[2012.04.01 17:11:33 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.04.01 16:12:50 | 000,000,026 | ---- | M] () -- C:\Windows\Irremote.ini
[2012.03.29 18:07:49 | 001,309,045 | ---- | M] () -- C:\Users\Keno\Desktop\DSCI0039.rar
[2012.03.29 13:07:31 | 000,088,170 | ---- | M] () -- C:\Users\Keno\Desktop\post.jpg
[2012.03.29 12:52:04 | 000,056,126 | ---- | M] () -- C:\Users\Keno\Desktop\564464_324022480984679_176951389025123_841124_1385893687_n.jpg
[2012.03.28 13:29:11 | 000,001,808 | ---- | M] () -- C:\Users\Keno\Desktop\Spotify.lnk
[2012.03.27 00:42:25 | 000,001,616 | ---- | M] () -- C:\Users\Keno\Desktop\DivX Movies.lnk
[2012.03.25 21:27:23 | 000,314,016 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012.03.25 21:27:23 | 000,043,680 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012.03.25 18:46:16 | 567,014,990 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.03.23 18:29:04 | 000,112,154 | ---- | M] () -- C:\Users\Keno\Desktop\watch.htm
[2012.03.23 16:41:04 | 000,305,664 | ---- | M] (Works Ltd.) -- C:\Windows\SysNative\aptwgv56x.dll
[2012.03.19 22:11:50 | 000,160,329 | ---- | M] () -- C:\Users\Keno\Desktop\DSCI0130.jpg
[2012.03.16 22:52:49 | 000,002,044 | ---- | M] () -- C:\Users\Keno\Desktop\JDownloader.lnk
[2012.03.16 22:51:25 | 000,000,237 | ---- | M] () -- C:\user.js
[2012.03.14 10:34:36 | 000,295,120 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.13 10:44:42 | 001,592,786 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Keno\Documents\*.tmp files -> C:\Users\Keno\Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.04.03 01:40:39 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.02 17:57:08 | 000,000,000 | ---- | C] () -- C:\Users\Keno\defogger_reenable
[2012.04.02 14:09:23 | 000,899,676 | ---- | C] () -- C:\Users\Keno\AppData\Local\census.cache
[2012.04.02 14:08:37 | 000,117,389 | ---- | C] () -- C:\Users\Keno\AppData\Local\ars.cache
[2012.04.02 13:58:36 | 000,000,036 | ---- | C] () -- C:\Users\Keno\AppData\Local\housecall.guid.cache
[2012.04.01 17:11:32 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.04.01 16:12:50 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
[2012.03.29 18:07:48 | 001,309,045 | ---- | C] () -- C:\Users\Keno\Desktop\DSCI0039.rar
[2012.03.29 13:07:31 | 000,088,170 | ---- | C] () -- C:\Users\Keno\Desktop\post.jpg
[2012.03.29 12:52:02 | 000,056,126 | ---- | C] () -- C:\Users\Keno\Desktop\564464_324022480984679_176951389025123_841124_1385893687_n.jpg
[2012.03.28 13:29:11 | 000,001,808 | ---- | C] () -- C:\Users\Keno\Desktop\Spotify.lnk
[2012.03.28 13:29:11 | 000,001,794 | ---- | C] () -- C:\Users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2012.03.27 00:42:25 | 000,001,616 | ---- | C] () -- C:\Users\Keno\Desktop\DivX Movies.lnk
[2012.03.25 21:27:23 | 000,314,016 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012.03.25 21:27:23 | 000,043,680 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012.03.23 18:29:03 | 000,112,154 | ---- | C] () -- C:\Users\Keno\Desktop\watch.htm
[2012.03.19 22:11:50 | 000,160,329 | ---- | C] () -- C:\Users\Keno\Desktop\DSCI0130.jpg
[2012.03.16 22:52:49 | 000,002,044 | ---- | C] () -- C:\Users\Keno\Desktop\JDownloader.lnk
[2012.03.16 22:52:37 | 000,002,008 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.03.16 22:52:37 | 000,001,952 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.03.16 22:52:37 | 000,001,931 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.03.16 22:51:24 | 000,000,237 | ---- | C] () -- C:\user.js
[2012.03.05 21:34:41 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.05 21:34:41 | 000,001,102 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.02.29 23:50:33 | 000,186,075 | ---- | C] () -- C:\Windows\hpoins14.dat
[2012.02.29 23:50:33 | 000,001,498 | ---- | C] () -- C:\Windows\hpomdl14.dat
[2012.01.11 15:50:14 | 000,286,720 | ---- | C] () -- C:\Windows\SysWow64\d3dy569y8.dll
[2011.12.07 00:52:31 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.09.11 15:48:58 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2011.08.04 17:01:51 | 001,592,786 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.12.27 05:16:38 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2010.12.27 05:08:17 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2010.11.17 10:00:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.11.16 18:01:20 | 000,002,012 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
 
========== LOP Check ==========
 
[2012.03.16 22:51:14 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Babylon
[2012.03.24 19:07:46 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DAEMON Tools Lite
[2011.08.24 16:58:50 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DVDVideoSoft
[2011.07.06 15:34:25 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.12.04 16:12:09 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\OpenOffice.org
[2012.02.02 19:09:05 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\redsn0w
[2012.04.03 01:28:13 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\SoftGrid Client
[2012.04.03 01:02:35 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Spotify
[2012.04.02 16:20:13 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Teeworlds
[2012.03.23 16:44:15 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Toshiba
[2011.08.11 21:49:45 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\TP
[2012.03.25 21:31:00 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Ubisoft
[2011.07.06 19:21:50 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\WildTangent
[2011.10.29 21:46:20 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\WindSolutions
[2012.04.02 21:20:00 | 000,000,902 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
[2012.04.03 00:20:01 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
[2012.04.01 15:55:13 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

Und meine Extras.txt
Code:

OTL Extras logfile created on: 03.04.2012 12:33:17 - Run 1
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Users\Keno\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,87 Gb Total Physical Memory | 2,34 Gb Available Physical Memory | 60,43% Memory free
7,73 Gb Paging File | 5,96 Gb Available in Paging File | 77,10% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,73 Gb Total Space | 125,97 Gb Free Space | 54,13% Space Free | Partition Type: NTFS
Drive D: | 232,64 Gb Total Space | 223,61 Gb Free Space | 96,12% Space Free | Partition Type: NTFS
Drive E: | 290,58 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: KENOPAPE | User Name: Keno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{24811C12-F4A9-4D0F-8494-A7B8FE46123C}" = TOSHIBA ReelTime
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{61D4B846-49F8-2639-A4EB-977875265F37}" = ATI Catalyst Install Manager
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89505FE0-A07E-928A-42F4-DA1B2788C01B}" = ccc-utility64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
"{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher
"{EB773820-0871-46A8-9B96-F2B04F8B34F0}" = HP Deskjet All-In-One Driver Software 13.0 Rel. 1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_AUDIO_HDA_HDMI" = Conexant Audio Driver For AMD HDMI Codec
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.01 (64-Bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{04B9F1A8-CC3B-CCF8-71B6-1ABFE4E00590}" = CCC Help Korean
"{04DE4606-6C76-A25C-BD13-646479CE1A5C}" = CCC Help Russian
"{058E65E2-AFC2-8974-43A2-1EA5A4A53471}" = ccc-core-static
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{06A81056-303F-A212-191D-35310DE5759F}" = CCC Help English
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{073B89C3-BA88-41B5-965F-B35A88EAE838}" = TOSHIBA Supervisor Password
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{0AA381AC-7BBB-5B29-836C-5E13BB91154A}" = CCC Help Hungarian
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DDCEDBA-8C17-CC50-7448-9131F3EF7517}" = Catalyst Control Center Localization All
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{0FF68F26-416C-4954-ACA5-6AD5F9DE99C1}" = Nero Multimedia Suite 10 Essentials
"{1023383E-D9F6-478C-A965-23A4657B3C9A}" = Sacred 2
"{162E46EB-F7C6-4B01-2384-349980B3F1BF}" = Catalyst Control Center Core Implementation
"{16622EEF-D159-3EB8-0EE3-F01B98317CED}" = CCC Help Swedish
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = Toshiba Assist
"{1C0526C4-478A-9066-F37A-E58F08A21FE9}" = Catalyst Control Center Graphics Full New
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F1E9571-0EA2-7AA3-647B-16698BED9CF4}" = CCC Help Danish
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}" = Nero MediaHub 10
"{1FDB8BA3-9E5F-369F-C2A2-AA4AD06F0640}" = CCC Help French
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2290A680-4083-410A-ADCC-7092C67FC052}" = TOSHIBA Online Product Information
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{24642C6B-1F1F-362F-6A7F-14C75C9EE603}" = CCC Help Turkish
"{2640314A-2D9A-4F58-B501-DB109CD9DBA2}" = DJ_AIO_ProductContext
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{313B4B6B-61B3-5F70-647B-E6285A9D81DF}" = CCC Help Spanish
"{3264BE02-6AC0-96B3-A212-392A850D58CA}" = CCC Help German
"{32DACAC3-6538-405D-915E-8F2D026F199C}" = DJ_AIO_Software_min
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3CB58AB7-6750-F510-F055-27FA68D77472}" = CCC Help Dutch
"{3D047C6C-19EE-46E3-C14B-9FA84260DF9B}" = Photo Service - powered by myphotobook
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{506DDFBE-983F-4BC3-84B8-65F423B2D798}" = NVIDIA PhysX
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{53007195-C491-23E9-D420-EDAB61E57609}" = CCC Help Polish
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5833EB1F-F1FD-DA8E-B2BA-C23E58BB0C65}" = Catalyst Control Center Graphics Full Existing
"{5C4D532E-4EC9-11E1-9544-B8AC6F97B88E}" = Google Earth Plug-in
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A8941B-6E97-B11C-1B10-C3370E4CC885}" = Catalyst Control Center Graphics Previews Common
"{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6B59A12B-D448-E129-28E9-57D1E2E5F7BB}" = CCC Help Chinese Traditional
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6CDB6681-B777-4DAD-412E-7933B9296850}" = CCC Help Greek
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"{787F0AC6-1C11-44AF-A07A-82C153D39FCA}_is1" = eMpTy-V-loader version 2.2
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7B81F6BB-7C9C-E66F-9989-42EEB1076F84}" = Catalyst Control Center InstallProxy
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{85010422-4932-6A9E-C222-A994DA299C81}" = CCC Help Portuguese
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BD785CF-30C7-4182-B250-0D5FCE78D4DD}" = Catalyst Control Center - Branding
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E9CEA3B-EBD1-439C-A01D-830CB39613C6}" = TOSHIBA Hardware Setup
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}" = Toshiba Manuals
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}" = TOSHIBA Media Controller
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A9BE8E5-2263-3EFA-FDD1-11F6E267EEF9}" = CCC Help Norwegian
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C6210BC-CF1C-E637-C74D-28612585CAD9}" = CCC Help Chinese Standard
"{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E48FF52-082C-4CC2-BB67-6E10D09C0431}" = Windows Live UX Platform Language Pack
"{A12EA295-32EA-42BB-8442-2C2BE852D4AA}" = inSSIDer 2.0
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6B90148-02C5-4fd3-8D7A-EF2386835CB9}" = F4100_Help
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A74F16FA-1D5B-405B-8D8D-1BC6F9DAED8B}" = Amazon.de
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1031-7B44-A95000000001}" = Adobe Reader 9.5.0 - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AD99B476-6FB7-4985-A3C3-E40595A7E6DE}" = DJ_AIO_Software
"{AFE6E077-E0A3-2993-0913-8DEEADF4E2DE}" = CCC Help Italian
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B95B1BA9-F887-4B3C-8D3A-CCD4C4675120}" = Microsoft Default Manager
"{BA28817B-738A-9284-D3D6-E973982AEF3B}" = Catalyst Control Center Graphics Previews Vista
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C58362EF-CABB-B475-065B-FD07C0D49770}" = CCC Help Czech
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{d05a1414-a955-4c5c-9716-b7777ef86e85}" = F4100
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D432AD16-2F8C-0022-E2F1-E27DCB5F6949}" = CCC Help Japanese
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}" = Black & White® 2
"{DBB7021A-3437-446F-ACE5-7261644A972C}" = Toshiba TEMPRO
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0FAA369-B0E3-48B8-9447-4873103B0012}" = TOSHIBA ConfigFree
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E616437B-CE55-B463-ED6B-408E29A073CB}" = CCC Help Finnish
"{E718AAF4-CB80-9649-347E-C9A9803BE6D0}" = CCC Help Thai
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}" = TOSHIBA Media Controller Plug-in
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F5EB2C27-3F16-01B6-BA56-316BC0F8CA87}" = Catalyst Control Center Graphics Light
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FDE58148-57E7-43BF-879A-29CCE818C078}" = eBay
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe AIR" = Adobe AIR
"Avira AntiVir Desktop" = Avira Free Antivirus
"DivX Setup" = DivX-Setup
"EAX Unified" = EAX Unified
"eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1" = Photo Service - powered by myphotobook
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}" = TOSHIBA ReelTime
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}" = TOSHIBA Bulletin Board
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.0.4 (Basic)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.60.1.1000
"Mozilla Firefox 11.0 (x86 de)" = Mozilla Firefox 11.0 (x86 de)
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"TOSHIBA Game Console" = WildTangent ORB Game Console
"WildTangent toshiba Master Uninstall" = WildTangent-Spiele
"WinLiveSuite" = Windows Live Essentials
"WT088682" = Bejeweled 2 Deluxe
"WT088696" = Chuzzle Deluxe
"WT088759" = Polar Bowler
"WT089367" = Farm Mania 2
"WT089378" = Jewel Quest II
"WT089380" = Penguins!
"WT089381" = Slingo Supreme
"WT089388" = Zuma Deluxe
"WT089395" = Plants vs. Zombies - Game of the Year
"WT089404" = Fishdom
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Midnight Racing" = Midnight Racing
"Spotify" = Spotify
 
========== Last 10 Event Log Errors ==========
 
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
 
< End of report >


markusg 03.04.2012 13:46

hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



[CODE]
:OTL
SRV:64bit: - [2012.03.23 16:41:04 | 000,305,664 | ---- | M] (Works Ltd.) [Auto | Running] -- C:\Windows\SysNative\aptwgv56x.dll -- (LanmanWorkstation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Windows\SysWOW64\d3dy569y8.dll ()
[2012.03.23 16:41:04 | 000,305,664 | ---- | M] (Works Ltd.) -- C:\Windows\SysNative\aptwgv56x.dll
:Files
C:\Windows\SysWOW64\d3dy569y8.dll
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang
in den Thread posten!




Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus :)

KenoP 03.04.2012 15:51

Erst ab 5 Fehlern pro Seite gibt es Punktabzug...:zunge:

Ich hab das angewendet was du mir gesagt hast und es hat auch geklappt-ich habe jetzt auch eine Textdatei, doch kann ich jetzt keine Internetseiten aufrufen. Das Wlan und Internet sind verbunden trotzdem funktionieren Firefox und Internet Explorer nicht mehr.
Jetzt bin ich mit dem Pc meiner Mutter online.
Meine _Olt Datei:
Code:

OTL logfile created on: 03.04.2012 12:33:17 - Run 1
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Users\Keno\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,87 Gb Total Physical Memory | 2,34 Gb Available Physical Memory | 60,43% Memory free
7,73 Gb Paging File | 5,96 Gb Available in Paging File | 77,10% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,73 Gb Total Space | 125,97 Gb Free Space | 54,13% Space Free | Partition Type: NTFS
Drive D: | 232,64 Gb Total Space | 223,61 Gb Free Space | 96,12% Space Free | Partition Type: NTFS
Drive E: | 290,58 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: KENOPAPE | User Name: Keno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.04.03 12:30:39 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
PRC - [2011.10.11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.10.11 14:59:37 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.10.11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.01.17 19:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 19:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.09.02 19:25:46 | 001,234,216 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
PRC - [2010.06.03 17:09:00 | 000,304,560 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010.05.04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) -- c:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010.03.03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.03.03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009.07.28 21:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009.03.10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.12.04 13:36:13 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2011.07.29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.06.24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2012.03.23 16:41:04 | 000,305,664 | ---- | M] (Works Ltd.) [Auto | Running] -- C:\Windows\SysNative\aptwgv56x.dll -- (LanmanWorkstation)
SRV:64bit: - [2010.04.26 22:49:36 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.07.28 16:48:06 | 000,140,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV - [2012.04.03 01:40:27 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2011.12.07 00:45:17 | 000,114,000 | ---- | M] (Joosoft.com GmbH) [Auto | Running] -- C:\Windows\SysWOW64\UpdSvc.dll -- (Update-Service)
SRV - [2011.10.11 14:59:49 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.10.11 14:59:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.09.28 13:30:28 | 000,489,384 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programme\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2010.09.22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.09.21 15:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.07.28 23:36:52 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010.05.11 10:40:52 | 000,124,368 | ---- | M] (Toshiba Europe GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO)
SRV - [2010.05.04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- c:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @c:\Program Files (x86)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.17 17:00:44 | 000,258,928 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programme\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV - [2010.03.03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.03.03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.02.23 18:57:42 | 000,835,952 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programme\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV - [2010.02.05 18:44:48 | 000,137,560 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2010.01.28 17:44:40 | 000,249,200 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe -- (cfWiMAXService)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.10.06 10:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.03.10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.04.02 17:12:53 | 000,132,320 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012.03.25 21:27:23 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2012.03.25 21:27:23 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.10.11 15:00:01 | 000,097,312 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.10.11 15:00:01 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.05.10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.04.20 10:24:56 | 000,169,584 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.01.15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.04.27 04:56:34 | 006,659,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.04.27 02:23:08 | 001,103,904 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192se.sys -- (rtl8192se)
DRV:64bit: - [2010.04.26 22:17:26 | 000,195,584 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.03.31 15:50:16 | 000,724,536 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2010.03.10 19:51:32 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.03.05 12:11:30 | 000,720,952 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDMI64.sys -- (CnxtHdmiAudService)
DRV:64bit: - [2010.02.01 11:29:48 | 000,232,992 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010.01.15 13:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.09.17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.30 21:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009.07.14 16:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.07 09:51:42 | 000,009,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FwLnk.sys -- (FwLnk)
DRV:64bit: - [2009.06.22 18:06:38 | 000,035,008 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2009.06.20 04:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.06.19 20:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {47BA5EA9-629E-423A-B058-C422803BB4AD}
IE:64bit: - HKLM\..\SearchScopes\{47BA5EA9-629E-423A-B058-C422803BB4AD}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {2A05C438-AF1D-480A-8EFF-D61157D84FE7}
IE - HKLM\..\SearchScopes\{2A05C438-AF1D-480A-8EFF-D61157D84FE7}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&AF=109989&babsrc=SP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
IE - HKCU\..\SearchScopes\{5F60A953-D45D-4A67-8DD3-650D26CB7BB8}: "URL" = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{ECFA0E70-C7FF-443E-9D69-8CC3A9A840CD}: "URL" = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://ssnhdn.listen2myradio.com/"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_228.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Keno\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.29 23:54:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.03.27 00:42:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.18 13:48:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.27 00:42:22 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.29 23:54:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\files32\backup\thunderbirdbkplugin
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\files32\antispam\tbspamfilter
 
[2011.07.06 15:32:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Keno\AppData\Roaming\mozilla\Extensions
[2012.03.28 14:13:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Keno\AppData\Roaming\mozilla\Firefox\Profiles\7epc4x0r.default\extensions
[2012.03.28 14:13:46 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Keno\AppData\Roaming\mozilla\Firefox\Profiles\7epc4x0r.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.03.29 21:22:19 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-1.xml
[2011.08.19 22:11:11 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-2.xml
[2011.09.02 14:51:31 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-3.xml
[2011.09.07 16:24:01 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-4.xml
[2011.10.19 03:21:13 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-5.xml
[2011.11.11 16:19:47 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-6.xml
[2011.08.17 19:13:36 | 000,001,056 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin.xml
[2012.02.21 17:17:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.03.18 13:48:12 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.21 17:17:29 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.03.16 22:51:18 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012.02.21 17:17:29 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.21 17:17:29 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.21 17:17:29 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.21 17:17:29 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.21 17:17:29 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
Hosts file not found
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HSON] C:\Programme\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Programme\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Programme\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosNC] C:\Programme\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Programme\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Programme\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Programme\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NBAgent] c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe" File not found
O4 - HKCU..\Run: [Facebook Update] C:\Users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [IcqUpdater] "C:\Users\Keno\AppData\Local\Temp\IcqUpdater.exe" update 4132 Global\MMutexLib_Global_AppInstance_YzpccHJvZ3JhfjJcaWNxNy41XGljcS5leGU "C:\Program Files (x86)\ICQ7.5\updates\downloaded" "C:\PROGRA~2\ICQ7.5\ICQ.exe silent loginmode=4 noupdate=1" autorun File not found
O4 - Startup: C:\Users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Windows\SysWOW64\d3dy569y8.dll ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DA91AA9D-A387-41A9-AE6E-1C23B8285E9B}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.01.24 04:59:32 | 000,000,065 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{06fbf9cd-1166-11e0-8a16-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{06fbf9cd-1166-11e0-8a16-806e6f6e6963}\Shell\AutoRun\command - "" = E:\MSWorks\Autorun.exe -- [2007.06.27 13:57:51 | 000,107,848 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{45bd0f41-75b2-11e1-962c-00266c9eac55}\Shell - "" = AutoRun
O33 - MountPoints2\{45bd0f7b-75b2-11e1-962c-00266c9eac55}\Shell - "" = AutoRun
O33 - MountPoints2\{45bd0f7b-75b2-11e1-962c-00266c9eac55}\Shell\AutoRun\command - "" = F:\Launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.04.03 12:30:36 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
[2012.04.02 17:56:13 | 000,000,000 | ---D | C] -- C:\Users\Keno\Desktop\Pc diagnose
[2012.04.02 17:53:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERSetup
[2012.04.02 14:18:07 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Malwarebytes
[2012.04.02 14:18:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.04.02 14:18:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.04.02 14:18:01 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.04.02 14:18:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.04.01 17:11:47 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Avira
[2012.04.01 17:11:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.04.01 17:11:15 | 000,132,320 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.04.01 17:11:15 | 000,097,312 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012.04.01 17:11:15 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2012.04.01 17:11:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.04.01 17:11:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012.04.01 16:25:28 | 000,000,000 | ---D | C] -- C:\ProgramData\BullGuard
[2012.04.01 16:13:17 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Ahead
[2012.03.28 13:29:12 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Spotify
[2012.03.28 13:28:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Spotify
[2012.03.27 00:44:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\DDMSettings
[2012.03.27 00:42:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2012.03.27 00:42:07 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2012.03.27 00:41:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared
[2012.03.27 00:41:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2012.03.27 00:39:51 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2012.03.25 22:01:42 | 000,000,000 | ---D | C] -- C:\Users\Keno\Documents\My Games
[2012.03.25 21:59:24 | 000,000,000 | -HSD | C] -- C:\ProgramData\SecuROM
[2012.03.25 21:31:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Ubisoft
[2012.03.25 21:28:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Tages
[2012.03.24 19:07:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\HP
[2012.03.24 19:06:06 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\DAEMON Tools Lite
[2012.03.24 19:06:04 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012.03.24 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\res
[2012.03.24 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\Readme
[2012.03.24 15:40:40 | 000,000,000 | ---D | C] -- C:\Users\Keno\Prerequisites
[2012.03.24 15:40:40 | 000,000,000 | ---D | C] -- C:\Users\Keno\EULA
[2012.03.24 15:40:39 | 000,000,000 | ---D | C] -- C:\Users\Keno\0x0007
[2012.03.24 15:10:19 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{59CAAA9E-35F0-47AA-BBE6-67F29997E9B0}
[2012.03.23 16:41:04 | 000,305,664 | ---- | C] (Works Ltd.) -- C:\Windows\SysNative\aptwgv56x.dll
[2012.03.20 00:50:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{88062434-F90A-4E12-94DB-F4C651E9CBF6}
[2012.03.20 00:37:18 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{92F9B859-A904-4878-967D-582420951EB6}
[2012.03.20 00:33:34 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{C8E5DD37-666A-406F-BBD9-42EDE137943B}
[2012.03.20 00:31:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{73CE502F-B735-4396-A4A5-8E56BEEDB9FC}
[2012.03.20 00:30:13 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{40BD12F0-4DFF-4BF0-808D-A62EA4DA128B}
[2012.03.20 00:28:49 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{81C29D9D-E641-420D-B29F-EF5F7331DAE7}
[2012.03.20 00:26:22 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{4DF4D427-D0C2-4D45-B6AB-390E829139F5}
[2012.03.20 00:22:38 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{4D36FC9A-5630-4E2A-9142-812C34B703B4}
[2012.03.20 00:19:26 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{27D56FE2-9999-4500-8F2E-18D080FB51DE}
[2012.03.20 00:15:59 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{7A39FBE5-B9E4-4D04-90B8-BBE22C7BC0AE}
[2012.03.20 00:15:25 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{AB897304-887D-4F1A-9746-209ED6038DC1}
[2012.03.20 00:14:06 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{103ACF2C-0854-4734-A357-C0E3DD31838E}
[2012.03.20 00:10:52 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{27468F43-AB32-4C5A-A063-500111E1445C}
[2012.03.19 23:21:24 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{3010831A-496C-474F-ABD4-40847202EBCC}
[2012.03.19 23:12:20 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{258FCCBD-444C-42C6-863E-5947A9627833}
[2012.03.19 22:57:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{99E063F9-FD50-4C72-BAFD-19941DB05055}
[2012.03.19 22:52:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{6D25F825-5BDB-4947-9D30-5B924C2F3BA3}
[2012.03.19 21:58:37 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{35D0E6B7-C0AD-4233-B17C-E17645C1577D}
[2012.03.19 21:42:18 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{244ED422-47D8-4CCA-9143-0083923E808C}
[2012.03.19 21:35:23 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{010840A1-29F5-426F-8074-7BBF1810EE4A}
[2012.03.19 20:42:51 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{F9819BC5-3524-4B8E-A294-10A9FB6F282E}
[2012.03.19 20:37:32 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{B22FFEEF-A731-4F9D-B48C-111AA7C1C961}
[2012.03.19 20:37:03 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{46CDEB32-8BB7-4658-854F-23A0599F1BF6}
[2012.03.16 22:51:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Babylon
[2012.03.16 22:51:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Babylon
[2012.03.16 22:51:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012.03.15 22:41:05 | 000,000,000 | ---D | C] -- C:\Users\Keno\Documents\Azteken
[2012.03.05 21:35:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012.03.05 21:34:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2012.03.05 21:34:36 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Google
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Keno\Documents\*.tmp files -> C:\Users\Keno\Documents\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.04.03 12:34:12 | 000,016,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 12:34:12 | 000,016,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 12:32:46 | 001,614,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.04.03 12:32:46 | 000,697,534 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.04.03 12:32:46 | 000,652,812 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.04.03 12:32:46 | 000,148,540 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.04.03 12:32:46 | 000,121,486 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.04.03 12:30:39 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
[2012.04.03 12:27:04 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.04.03 12:26:48 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.03 12:26:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.04.03 12:26:37 | 3113,361,408 | -HS- | M] () -- C:\hiberfil.sys
[2012.04.03 00:44:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.04.03 00:20:01 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
[2012.04.02 21:20:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
[2012.04.02 17:57:08 | 000,000,000 | ---- | M] () -- C:\Users\Keno\defogger_reenable
[2012.04.02 17:12:53 | 000,132,320 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.04.02 14:09:23 | 000,899,676 | ---- | M] () -- C:\Users\Keno\AppData\Local\census.cache
[2012.04.02 14:08:37 | 000,117,389 | ---- | M] () -- C:\Users\Keno\AppData\Local\ars.cache
[2012.04.02 13:58:36 | 000,000,036 | ---- | M] () -- C:\Users\Keno\AppData\Local\housecall.guid.cache
[2012.04.01 17:11:33 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.04.01 16:12:50 | 000,000,026 | ---- | M] () -- C:\Windows\Irremote.ini
[2012.03.29 18:07:49 | 001,309,045 | ---- | M] () -- C:\Users\Keno\Desktop\DSCI0039.rar
[2012.03.29 13:07:31 | 000,088,170 | ---- | M] () -- C:\Users\Keno\Desktop\post.jpg
[2012.03.29 12:52:04 | 000,056,126 | ---- | M] () -- C:\Users\Keno\Desktop\564464_324022480984679_176951389025123_841124_1385893687_n.jpg
[2012.03.28 13:29:11 | 000,001,808 | ---- | M] () -- C:\Users\Keno\Desktop\Spotify.lnk
[2012.03.27 00:42:25 | 000,001,616 | ---- | M] () -- C:\Users\Keno\Desktop\DivX Movies.lnk
[2012.03.25 21:27:23 | 000,314,016 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012.03.25 21:27:23 | 000,043,680 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012.03.25 18:46:16 | 567,014,990 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.03.23 18:29:04 | 000,112,154 | ---- | M] () -- C:\Users\Keno\Desktop\watch.htm
[2012.03.23 16:41:04 | 000,305,664 | ---- | M] (Works Ltd.) -- C:\Windows\SysNative\aptwgv56x.dll
[2012.03.19 22:11:50 | 000,160,329 | ---- | M] () -- C:\Users\Keno\Desktop\DSCI0130.jpg
[2012.03.16 22:52:49 | 000,002,044 | ---- | M] () -- C:\Users\Keno\Desktop\JDownloader.lnk
[2012.03.16 22:51:25 | 000,000,237 | ---- | M] () -- C:\user.js
[2012.03.14 10:34:36 | 000,295,120 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.13 10:44:42 | 001,592,786 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Keno\Documents\*.tmp files -> C:\Users\Keno\Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.04.03 01:40:39 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.02 17:57:08 | 000,000,000 | ---- | C] () -- C:\Users\Keno\defogger_reenable
[2012.04.02 14:09:23 | 000,899,676 | ---- | C] () -- C:\Users\Keno\AppData\Local\census.cache
[2012.04.02 14:08:37 | 000,117,389 | ---- | C] () -- C:\Users\Keno\AppData\Local\ars.cache
[2012.04.02 13:58:36 | 000,000,036 | ---- | C] () -- C:\Users\Keno\AppData\Local\housecall.guid.cache
[2012.04.01 17:11:32 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.04.01 16:12:50 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
[2012.03.29 18:07:48 | 001,309,045 | ---- | C] () -- C:\Users\Keno\Desktop\DSCI0039.rar
[2012.03.29 13:07:31 | 000,088,170 | ---- | C] () -- C:\Users\Keno\Desktop\post.jpg
[2012.03.29 12:52:02 | 000,056,126 | ---- | C] () -- C:\Users\Keno\Desktop\564464_324022480984679_176951389025123_841124_1385893687_n.jpg
[2012.03.28 13:29:11 | 000,001,808 | ---- | C] () -- C:\Users\Keno\Desktop\Spotify.lnk
[2012.03.28 13:29:11 | 000,001,794 | ---- | C] () -- C:\Users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2012.03.27 00:42:25 | 000,001,616 | ---- | C] () -- C:\Users\Keno\Desktop\DivX Movies.lnk
[2012.03.25 21:27:23 | 000,314,016 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012.03.25 21:27:23 | 000,043,680 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012.03.23 18:29:03 | 000,112,154 | ---- | C] () -- C:\Users\Keno\Desktop\watch.htm
[2012.03.19 22:11:50 | 000,160,329 | ---- | C] () -- C:\Users\Keno\Desktop\DSCI0130.jpg
[2012.03.16 22:52:49 | 000,002,044 | ---- | C] () -- C:\Users\Keno\Desktop\JDownloader.lnk
[2012.03.16 22:52:37 | 000,002,008 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.03.16 22:52:37 | 000,001,952 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.03.16 22:52:37 | 000,001,931 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.03.16 22:51:24 | 000,000,237 | ---- | C] () -- C:\user.js
[2012.03.05 21:34:41 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.05 21:34:41 | 000,001,102 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.02.29 23:50:33 | 000,186,075 | ---- | C] () -- C:\Windows\hpoins14.dat
[2012.02.29 23:50:33 | 000,001,498 | ---- | C] () -- C:\Windows\hpomdl14.dat
[2012.01.11 15:50:14 | 000,286,720 | ---- | C] () -- C:\Windows\SysWow64\d3dy569y8.dll
[2011.12.07 00:52:31 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.09.11 15:48:58 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2011.08.04 17:01:51 | 001,592,786 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.12.27 05:16:38 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2010.12.27 05:08:17 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2010.11.17 10:00:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.11.16 18:01:20 | 000,002,012 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
 
========== LOP Check ==========
 
[2012.03.16 22:51:14 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Babylon
[2012.03.24 19:07:46 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DAEMON Tools Lite
[2011.08.24 16:58:50 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DVDVideoSoft
[2011.07.06 15:34:25 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.12.04 16:12:09 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\OpenOffice.org
[2012.02.02 19:09:05 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\redsn0w
[2012.04.03 01:28:13 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\SoftGrid Client
[2012.04.03 01:02:35 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Spotify
[2012.04.02 16:20:13 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Teeworlds
[2012.03.23 16:44:15 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Toshiba
[2011.08.11 21:49:45 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\TP
[2012.03.25 21:31:00 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Ubisoft
[2011.07.06 19:21:50 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\WildTangent
[2011.10.29 21:46:20 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\WindSolutions
[2012.04.02 21:20:00 | 000,000,902 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
[2012.04.03 00:20:01 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
[2012.04.01 15:55:13 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

Ich weiß zwar nicht ob das Hochladen auch ein Test sein ich mache es jetzt auf den hier auf dem neuen Computer.
-edit-
Der Upload war erfolgreich.

markusg 03.04.2012 15:58

welchen "neuen" computer meinst du?
upload hat übrigens geklappt, danke
und woher soll ich das ohne logs wissen.
wenn du hier hilfe willst, musst du schon das machen da steht, ansonsten ist das schreiben von anleitungen für mich hier sinnlos...
und ich kann die zeit für nutzer nutzen, die hier auchtatsächlich mitarbeiten und hilfe wollen.
im betroffenen konto anmelden
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.
Downloade dir bitte Combofix von einem dieser Downloadspiegel

Link 1
Link 2


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

KenoP 03.04.2012 16:19

Es tut mir leid. Das sollte kein Vorwurf sein. Ich hab dein Script von [Code] bis[Reboot] kopiert und in das weiße Feld des Programm von Oldtimer eingefügt.War das richtig ?
Ich beginn gerade mit ComoboFix, doch irgendwie gelingt es mir nicht antivir zu deaktivieren.
Ich benutze einen nicht infizierten Pc um ins Internet zu gelangen.

markusg 03.04.2012 16:36

sorry, der "vorwurf" war nicht für dich gedacht, hatte da zu viel in der zwischenablage.
wenn du über den avira schirm, rechtsklick, guard deaktivieren gewählt hast, ignoriere die combofix meldung über das aktieve antimalware

KenoP 03.04.2012 17:44

Da bin ich ja beruhigt...:)
hier ist meine Logdatei:
Code:

ComboFix 12-04-03.02 - Keno 03.04.2012  17:40:15.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3959.2409 [GMT 2:00]
ausgeführt von:: c:\users\Keno\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Keno\Documents\~WRL1600.tmp
c:\windows\system32\drivers\etc\hosts.txt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-03-03 bis 2012-04-03  ))))))))))))))))))))))))))))))
.
.
2012-04-03 16:17 . 2012-04-03 16:17        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-04-03 15:34 . 2011-06-17 10:35        83120        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-04-03 15:34 . 2011-06-17 10:35        116568        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-04-03 15:34 . 2012-04-03 15:34        --------        d-----w-        c:\programdata\Avira
2012-04-03 15:34 . 2012-04-03 15:34        --------        d-----w-        c:\program files (x86)\Avira
2012-04-03 13:28 . 2012-04-03 14:47        --------        d-----w-        C:\_OTL
2012-04-02 23:40 . 2012-04-02 23:40        418464        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-04-02 15:53 . 2012-04-02 15:53        --------        d-----w-        c:\programdata\SUPERSetup
2012-04-02 12:18 . 2012-04-02 12:18        --------        d-----w-        c:\users\Keno\AppData\Roaming\Malwarebytes
2012-04-02 12:18 . 2012-04-02 12:18        --------        d-----w-        c:\programdata\Malwarebytes
2012-04-02 12:18 . 2012-04-02 14:20        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-02 12:18 . 2011-12-10 13:24        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-04-01 14:25 . 2012-04-01 14:34        --------        d-----w-        c:\programdata\BullGuard
2012-04-01 14:13 . 2012-04-01 14:13        --------        d-----w-        c:\users\Keno\AppData\Local\Ahead
2012-03-28 11:29 . 2012-04-03 11:55        --------        d-----w-        c:\users\Keno\AppData\Local\Spotify
2012-03-28 11:28 . 2012-04-03 11:15        --------        d-----w-        c:\users\Keno\AppData\Roaming\Spotify
2012-03-26 22:44 . 2012-03-26 22:44        --------        d-----w-        c:\users\Keno\AppData\Local\DDMSettings
2012-03-26 22:42 . 2012-03-26 22:42        --------        d-----w-        c:\program files\DivX
2012-03-26 22:41 . 2012-03-26 22:42        --------        d-----w-        c:\program files (x86)\Common Files\DivX Shared
2012-03-26 22:41 . 2012-03-26 22:42        --------        d-----w-        c:\program files (x86)\DivX
2012-03-26 22:39 . 2012-03-26 22:42        --------        d-----w-        c:\programdata\DivX
2012-03-25 19:59 . 2012-03-25 19:59        --------        d-sh--w-        c:\programdata\SecuROM
2012-03-25 19:31 . 2012-03-25 19:31        --------        d-----w-        c:\users\Keno\AppData\Roaming\Ubisoft
2012-03-25 19:28 . 2012-03-25 19:28        --------        d-----w-        c:\programdata\Tages
2012-03-25 19:27 . 2012-03-25 19:27        43680        ----a-w-        c:\windows\system32\drivers\lirsgt.sys
2012-03-25 19:27 . 2012-03-25 19:27        314016        ----a-w-        c:\windows\system32\drivers\atksgt.sys
2012-03-24 17:07 . 2012-03-24 17:07        --------        d-----w-        c:\users\Keno\AppData\Local\HP
2012-03-24 17:06 . 2012-03-24 17:07        --------        d-----w-        c:\users\Keno\AppData\Roaming\DAEMON Tools Lite
2012-03-24 17:06 . 2012-03-24 17:06        --------        d-----w-        c:\programdata\DAEMON Tools Lite
2012-03-24 14:53 . 2006-09-28 15:05        3977496        ----a-w-        c:\windows\system32\d3dx9_31.dll
2012-03-24 13:41 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\res
2012-03-24 13:41 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\Readme
2012-03-24 13:40 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\Prerequisites
2012-03-24 13:40 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\EULA
2012-03-24 13:40 . 2009-10-25 17:08        --------        d-----w-        c:\users\Keno\0x0007
2012-03-23 14:57 . 2012-03-14 03:27        8669240        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{94168AFD-FEBB-45E0-AC33-918B039A07D7}\mpengine.dll
2012-03-18 11:48 . 2012-03-18 11:48        592824        ----a-w-        c:\program files (x86)\Mozilla Firefox\gkmedias.dll
2012-03-18 11:48 . 2012-03-18 11:48        44472        ----a-w-        c:\program files (x86)\Mozilla Firefox\mozglue.dll
2012-03-16 20:51 . 2012-03-16 20:51        237        ----a-w-        C:\user.js
2012-03-16 20:51 . 2012-03-16 20:51        --------        d-----w-        c:\users\Keno\AppData\Local\Babylon
2012-03-16 20:51 . 2012-03-16 20:51        --------        d-----w-        c:\users\Keno\AppData\Roaming\Babylon
2012-03-16 20:51 . 2012-03-16 20:51        --------        d-----w-        c:\programdata\Babylon
2012-03-14 08:31 . 2011-11-19 15:20        5559152        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-03-14 08:31 . 2011-11-19 14:50        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 08:31 . 2011-11-19 14:50        3913584        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 06:24 . 2012-02-03 04:34        3145728        ----a-w-        c:\windows\system32\win32k.sys
2012-03-14 06:24 . 2012-02-10 06:36        1544192        ----a-w-        c:\windows\system32\DWrite.dll
2012-03-14 06:24 . 2012-02-10 05:38        1077248        ----a-w-        c:\windows\SysWow64\DWrite.dll
2012-03-14 06:24 . 2012-01-25 06:38        77312        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-03-14 06:24 . 2012-01-25 06:38        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-03-14 06:24 . 2012-01-25 06:33        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-03-14 06:24 . 2012-02-17 06:38        1031680        ----a-w-        c:\windows\system32\rdpcore.dll
2012-03-14 06:24 . 2012-02-17 05:34        826880        ----a-w-        c:\windows\SysWow64\rdpcore.dll
2012-03-14 06:24 . 2012-02-17 04:58        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-03-14 06:24 . 2012-02-17 04:57        23552        ----a-w-        c:\windows\system32\drivers\tdtcp.sys
2012-03-05 19:34 . 2012-03-05 19:35        --------        d-----w-        c:\program files (x86)\Google
2012-03-05 19:34 . 2012-03-05 19:34        --------        d-----w-        c:\users\Keno\AppData\Local\Google
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-02 23:40 . 2011-07-06 13:41        70304        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-23 08:18 . 2011-08-28 17:38        279656        ------w-        c:\windows\system32\MpSigStub.exe
2012-02-16 09:32 . 2011-12-04 11:34        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-01-27 11:19 . 2012-01-27 11:19        86528        ----a-w-        c:\windows\SysWow64\iesysprep.dll
2012-01-27 11:19 . 2012-01-27 11:19        76800        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe
2012-01-27 11:19 . 2012-01-27 11:19        74752        ----a-w-        c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-01-27 11:19 . 2012-01-27 11:19        74752        ----a-w-        c:\windows\SysWow64\iesetup.dll
2012-01-27 11:19 . 2012-01-27 11:19        63488        ----a-w-        c:\windows\SysWow64\tdc.ocx
2012-01-27 11:19 . 2012-01-27 11:19        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll
2012-01-27 11:19 . 2012-01-27 11:19        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-01-27 11:19 . 2012-01-27 11:19        367104        ----a-w-        c:\windows\SysWow64\html.iec
2012-01-27 11:19 . 2012-01-27 11:19        23552        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2012-01-27 11:19 . 2012-01-27 11:19        161792        ----a-w-        c:\windows\SysWow64\msls31.dll
2012-01-27 11:19 . 2012-01-27 11:19        152064        ----a-w-        c:\windows\SysWow64\wextract.exe
2012-01-27 11:19 . 2012-01-27 11:19        150528        ----a-w-        c:\windows\SysWow64\iexpress.exe
2012-01-27 11:19 . 2012-01-27 11:19        110592        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll
2012-01-27 11:19 . 2012-01-27 11:19        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-01-27 11:19 . 2012-01-27 11:19        35840        ----a-w-        c:\windows\SysWow64\imgutil.dll
2012-01-27 11:19 . 2012-01-27 11:19        11776        ----a-w-        c:\windows\SysWow64\mshta.exe
2012-01-27 11:19 . 2012-01-27 11:19        101888        ----a-w-        c:\windows\SysWow64\admparse.dll
2012-01-27 11:19 . 2012-01-27 11:19        91648        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe
2012-01-27 11:19 . 2012-01-27 11:19        89088        ----a-w-        c:\windows\system32\RegisterIEPKEYs.exe
2012-01-27 11:19 . 2012-01-27 11:19        85504        ----a-w-        c:\windows\system32\iesetup.dll
2012-01-27 11:19 . 2012-01-27 11:19        76800        ----a-w-        c:\windows\system32\tdc.ocx
2012-01-27 11:19 . 2012-01-27 11:19        603648        ----a-w-        c:\windows\system32\vbscript.dll
2012-01-27 11:19 . 2012-01-27 11:19        49664        ----a-w-        c:\windows\system32\imgutil.dll
2012-01-27 11:19 . 2012-01-27 11:19        48640        ----a-w-        c:\windows\system32\mshtmler.dll
2012-01-27 11:19 . 2012-01-27 11:19        448512        ----a-w-        c:\windows\system32\html.iec
2012-01-27 11:19 . 2012-01-27 11:19        30720        ----a-w-        c:\windows\system32\licmgr10.dll
2012-01-27 11:19 . 2012-01-27 11:19        222208        ----a-w-        c:\windows\system32\msls31.dll
2012-01-27 11:19 . 2012-01-27 11:19        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-01-27 11:19 . 2012-01-27 11:19        165888        ----a-w-        c:\windows\system32\iexpress.exe
2012-01-27 11:19 . 2012-01-27 11:19        160256        ----a-w-        c:\windows\system32\wextract.exe
2012-01-27 11:19 . 2012-01-27 11:19        135168        ----a-w-        c:\windows\system32\IEAdvpack.dll
2012-01-27 11:19 . 2012-01-27 11:19        12288        ----a-w-        c:\windows\system32\mshta.exe
2012-01-27 11:19 . 2012-01-27 11:19        114176        ----a-w-        c:\windows\system32\admparse.dll
2012-01-27 11:19 . 2012-01-27 11:19        111616        ----a-w-        c:\windows\system32\iesysprep.dll
2012-01-11 13:50 . 2012-01-11 13:50        1332736        ----a-w-        c:\windows\system32\xpt8inke.tsp
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-09-05 137536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-09-02 1234216]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-26 102400]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 136176]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
R2 Update-Service;Update-Service;c:\windows\System32\svchost.exe [2009-07-14 27136]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 253600]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 136176]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-05-11 124368]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-04-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 23:40]
.
2012-04-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
- c:\users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-05 19:15]
.
2012-04-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
- c:\users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-05 19:15]
.
2012-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 19:34]
.
2012-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 19:34]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-05-11 1050072]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://ssnhdn.listen2myradio.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109989
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 8ee9dc020000000000004ceddee5aca3
FF - user.js: extensions.BabylonToolbar_i.hardId - 8ee9dc020000000000004ceddee5aca3
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15415
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:51
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe
Wow6432Node-HKLM-Run-NBKeyScan - c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
Toolbar-Locked - (no file)
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
AddRemove-{43B74FAB-FB58-447D-8D3A-5F638AF36FD1} - c:\programdata\{D8116CA6-DBDF-4415-AB4A-BE0CEFB71935}\Netzmanager1.050.1606_101110a.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1620826539-68575984-2147015703-1001\Software\SecuROM\License information*]
"datasecu"=hex:eb,6c,eb,d6,57,cb,37,60,6e,b2,56,00,7a,c7,4e,79,17,66,b0,c8,50,
  91,b2,6c,fe,a8,33,24,e5,e2,80,e0,f6,0e,aa,5f,77,73,4b,a5,8d,0e,7f,0a,39,80,\
"rkeysecu"=hex:20,d3,04,85,f1,53,f0,bd,95,c0,da,ac,04,08,88,50
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-04-03  18:33:46 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-04-03 16:33
.
Vor Suchlauf: 10 Verzeichnis(se), 136.866.410.496 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 136.350.638.080 Bytes frei
.
- - End Of File - - D999336E7F1050CFE152A9F2323552C0

Ich hatte nicht gewusst das Deamontool illegal ist, das hab ich erst hier im Forum gelsen. Deshalb habe ich es schon vor paar Tagen gelöscht.

Firewall ist wieder AKTIV!!!!:taenzer: :applaus::applaus::applaus:
Ichw eiß jetzt nicht wieso aber die Firewall ist wieder an.
Jetzt gibts da nur noch das Problem mit der Hostdatei die anscheinend bei dem Durchführen des einen Programmes gelöscht wurde.(Ich hab das dor irgendwie gelesen).
DANKE für die HILFE :dankeschoen:
:party:

Ich werde jetzt mal gucken ob die Hostdatei noch vorhanden ist.

Zitat:

Zitat von
[CODE
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Keno\Documents\~WRL1600.tmp
c:\windows\system32\drivers\etc\hosts.txt
.[/CODE]
.

Hier hab ich das gelesen :)

markusg 03.04.2012 20:36

passt aber immernoch nicht.
kannst du noch mal n neues otl log posten?
Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

KenoP 03.04.2012 21:04

Das Programm hat mir nur die OLT.txt Datei ausgespuckt...
Code:

OTL logfile created on: 03.04.2012 22:01:22 - Run 4
OTL by OldTimer - Version 3.2.39.2    Folder = C:\Users\Keno\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,87 Gb Total Physical Memory | 2,33 Gb Available Physical Memory | 60,38% Memory free
7,73 Gb Paging File | 5,89 Gb Available in Paging File | 76,17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,73 Gb Total Space | 126,64 Gb Free Space | 54,42% Space Free | Partition Type: NTFS
Drive D: | 232,64 Gb Total Space | 223,61 Gb Free Space | 96,12% Space Free | Partition Type: NTFS
Drive F: | 952,19 Mb Total Space | 897,72 Mb Free Space | 94,28% Space Free | Partition Type: FAT
 
Computer Name: KENOPAPE | User Name: Keno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.04.03 12:30:39 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
PRC - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.09.05 21:15:43 | 000,137,536 | ---- | M] (Facebook Inc.) -- C:\Users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.21 07:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.04.21 07:52:36 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.01.17 19:50:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011.01.17 19:50:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010.09.02 19:25:46 | 001,234,216 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
PRC - [2010.06.03 17:09:00 | 000,304,560 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2010.05.04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) -- c:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2009.07.28 21:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009.03.10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.12.04 13:36:13 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2011.07.29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.06.24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2010.04.26 22:49:36 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.07.28 16:48:06 | 000,140,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV - [2012.04.03 01:40:27 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2011.12.07 00:45:17 | 000,114,000 | ---- | M] (Joosoft.com GmbH) [Auto | Stopped] -- C:\Windows\SysWOW64\UpdSvc.dll -- (Update-Service)
SRV - [2011.10.01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.04.21 07:52:36 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.09.28 13:30:28 | 000,489,384 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programme\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2010.09.22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010.09.21 15:49:00 | 002,286,976 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2010.07.28 23:36:52 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010.05.11 10:40:52 | 000,124,368 | ---- | M] (Toshiba Europe GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO)
SRV - [2010.05.04 13:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- c:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) @c:\Program Files (x86)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.17 17:00:44 | 000,258,928 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programme\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV - [2010.03.03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2010.03.03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2010.02.23 18:57:42 | 000,835,952 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programme\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV - [2010.02.05 18:44:48 | 000,137,560 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2010.01.28 17:44:40 | 000,249,200 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe -- (cfWiMAXService)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.10.06 10:21:50 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.03.10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.03.25 21:27:23 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2012.03.25 21:27:23 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011.10.01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.06.17 12:35:49 | 000,116,568 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011.06.17 12:35:49 | 000,083,120 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011.05.10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.04.20 10:24:56 | 000,169,584 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.01.15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.04.27 04:56:34 | 006,659,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.04.27 02:23:08 | 001,103,904 | ---- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192se.sys -- (rtl8192se)
DRV:64bit: - [2010.04.26 22:17:26 | 000,195,584 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.03.31 15:50:16 | 000,724,536 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2010.03.10 19:51:32 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010.03.05 12:11:30 | 000,720,952 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDMI64.sys -- (CnxtHdmiAudService)
DRV:64bit: - [2010.02.01 11:29:48 | 000,232,992 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010.01.15 13:22:08 | 000,538,136 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.09.17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:64bit: - [2009.07.30 21:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009.07.14 16:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.07 09:51:42 | 000,009,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FwLnk.sys -- (FwLnk)
DRV:64bit: - [2009.06.22 18:06:38 | 000,035,008 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2009.06.20 04:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.06.19 20:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {47BA5EA9-629E-423A-B058-C422803BB4AD}
IE:64bit: - HKLM\..\SearchScopes\{47BA5EA9-629E-423A-B058-C422803BB4AD}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {2A05C438-AF1D-480A-8EFF-D61157D84FE7}
IE - HKLM\..\SearchScopes\{2A05C438-AF1D-480A-8EFF-D61157D84FE7}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&AF=109989&babsrc=SP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
IE - HKCU\..\SearchScopes\{5F60A953-D45D-4A67-8DD3-650D26CB7BB8}: "URL" = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibade-win7-ie-search-21&index=blended&linkCode=ur2
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{ECFA0E70-C7FF-443E-9D69-8CC3A9A840CD}: "URL" = hxxp://rover.ebay.com/rover/1/707-44556-9400-9/4?satitle={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "hxxp://ssnhdn.listen2myradio.com/"
FF - prefs.js..keyword.URL: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_228.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Keno\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.29 23:54:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.03.27 00:42:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.18 13:48:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.27 00:42:22 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012.02.29 23:54:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\files32\backup\thunderbirdbkplugin
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\files32\antispam\tbspamfilter
 
[2011.07.06 15:32:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Keno\AppData\Roaming\mozilla\Extensions
[2012.03.28 14:13:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Keno\AppData\Roaming\mozilla\Firefox\Profiles\7epc4x0r.default\extensions
[2012.03.28 14:13:46 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Keno\AppData\Roaming\mozilla\Firefox\Profiles\7epc4x0r.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.03.29 21:22:19 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-1.xml
[2011.08.19 22:11:11 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-2.xml
[2011.09.02 14:51:31 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-3.xml
[2011.09.07 16:24:01 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-4.xml
[2011.10.19 03:21:13 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-5.xml
[2011.11.11 16:19:47 | 000,000,950 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin-6.xml
[2011.08.17 19:13:36 | 000,001,056 | ---- | M] () -- C:\Users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\searchplugins\icqplugin.xml
[2012.02.21 17:17:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.03.18 13:48:12 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.02.21 17:17:29 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.03.16 22:51:18 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012.02.21 17:17:29 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.02.21 17:17:29 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.02.21 17:17:29 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.02.21 17:17:29 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.02.21 17:17:29 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.04.03 18:21:02 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Programme\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Programme\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HSON] C:\Programme\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Programme\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Programme\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Programme\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosNC] C:\Programme\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Programme\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Programme\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Programme\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Programme\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Programme\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NBAgent] c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DA91AA9D-A387-41A9-AE6E-1C23B8285E9B}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.04.03 18:21:04 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012.04.03 18:17:40 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.04.03 17:38:32 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.04.03 17:38:32 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.04.03 17:38:32 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.04.03 17:34:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.04.03 17:34:45 | 000,116,568 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012.04.03 17:34:45 | 000,083,120 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012.04.03 17:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.04.03 17:34:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012.04.03 17:24:46 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012.04.03 17:23:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.04.03 17:12:39 | 004,455,431 | R--- | C] (Swearware) -- C:\Users\Keno\Desktop\ComboFix.exe
[2012.04.03 15:28:08 | 000,000,000 | ---D | C] -- C:\_OTL
[2012.04.03 12:30:36 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
[2012.04.02 17:56:13 | 000,000,000 | ---D | C] -- C:\Users\Keno\Desktop\Pc diagnose
[2012.04.02 17:53:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERSetup
[2012.04.02 14:18:07 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Malwarebytes
[2012.04.02 14:18:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.04.02 14:18:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.04.02 14:18:01 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.04.02 14:18:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.04.01 16:25:28 | 000,000,000 | ---D | C] -- C:\ProgramData\BullGuard
[2012.04.01 16:13:17 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Ahead
[2012.03.28 13:29:12 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Spotify
[2012.03.28 13:28:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Spotify
[2012.03.27 00:44:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\DDMSettings
[2012.03.27 00:42:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2012.03.27 00:42:07 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2012.03.27 00:41:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared
[2012.03.27 00:41:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2012.03.27 00:39:51 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2012.03.25 22:01:42 | 000,000,000 | ---D | C] -- C:\Users\Keno\Documents\My Games
[2012.03.25 21:59:24 | 000,000,000 | -HSD | C] -- C:\ProgramData\SecuROM
[2012.03.25 21:31:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Ubisoft
[2012.03.25 21:28:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Tages
[2012.03.24 19:07:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\HP
[2012.03.24 19:06:06 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\DAEMON Tools Lite
[2012.03.24 19:06:04 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012.03.24 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\res
[2012.03.24 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\Keno\Readme
[2012.03.24 15:40:40 | 000,000,000 | ---D | C] -- C:\Users\Keno\Prerequisites
[2012.03.24 15:40:40 | 000,000,000 | ---D | C] -- C:\Users\Keno\EULA
[2012.03.24 15:40:39 | 000,000,000 | ---D | C] -- C:\Users\Keno\0x0007
[2012.03.24 15:10:19 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{59CAAA9E-35F0-47AA-BBE6-67F29997E9B0}
[2012.03.20 00:50:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{88062434-F90A-4E12-94DB-F4C651E9CBF6}
[2012.03.20 00:37:18 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{92F9B859-A904-4878-967D-582420951EB6}
[2012.03.20 00:33:34 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{C8E5DD37-666A-406F-BBD9-42EDE137943B}
[2012.03.20 00:31:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{73CE502F-B735-4396-A4A5-8E56BEEDB9FC}
[2012.03.20 00:30:13 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{40BD12F0-4DFF-4BF0-808D-A62EA4DA128B}
[2012.03.20 00:28:49 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{81C29D9D-E641-420D-B29F-EF5F7331DAE7}
[2012.03.20 00:26:22 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{4DF4D427-D0C2-4D45-B6AB-390E829139F5}
[2012.03.20 00:22:38 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{4D36FC9A-5630-4E2A-9142-812C34B703B4}
[2012.03.20 00:19:26 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{27D56FE2-9999-4500-8F2E-18D080FB51DE}
[2012.03.20 00:15:59 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{7A39FBE5-B9E4-4D04-90B8-BBE22C7BC0AE}
[2012.03.20 00:15:25 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{AB897304-887D-4F1A-9746-209ED6038DC1}
[2012.03.20 00:14:06 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{103ACF2C-0854-4734-A357-C0E3DD31838E}
[2012.03.20 00:10:52 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{27468F43-AB32-4C5A-A063-500111E1445C}
[2012.03.19 23:21:24 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{3010831A-496C-474F-ABD4-40847202EBCC}
[2012.03.19 23:12:20 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{258FCCBD-444C-42C6-863E-5947A9627833}
[2012.03.19 22:57:31 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{99E063F9-FD50-4C72-BAFD-19941DB05055}
[2012.03.19 22:52:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{6D25F825-5BDB-4947-9D30-5B924C2F3BA3}
[2012.03.19 21:58:37 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{35D0E6B7-C0AD-4233-B17C-E17645C1577D}
[2012.03.19 21:42:18 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{244ED422-47D8-4CCA-9143-0083923E808C}
[2012.03.19 21:35:23 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{010840A1-29F5-426F-8074-7BBF1810EE4A}
[2012.03.19 20:42:51 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{F9819BC5-3524-4B8E-A294-10A9FB6F282E}
[2012.03.19 20:37:32 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{B22FFEEF-A731-4F9D-B48C-111AA7C1C961}
[2012.03.19 20:37:03 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\{46CDEB32-8BB7-4658-854F-23A0599F1BF6}
[2012.03.16 22:51:15 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Babylon
[2012.03.16 22:51:14 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Roaming\Babylon
[2012.03.16 22:51:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012.03.15 22:41:05 | 000,000,000 | ---D | C] -- C:\Users\Keno\Documents\Azteken
[2012.03.05 21:35:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012.03.05 21:34:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2012.03.05 21:34:36 | 000,000,000 | ---D | C] -- C:\Users\Keno\AppData\Local\Google
 
========== Files - Modified Within 30 Days ==========
 
[2012.04.03 22:01:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.03 21:55:19 | 000,697,534 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.04.03 21:55:19 | 000,652,812 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.04.03 21:55:19 | 000,148,540 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.04.03 21:55:19 | 000,121,486 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.04.03 21:55:18 | 001,614,892 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.04.03 21:52:14 | 000,016,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 21:52:14 | 000,016,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.04.03 21:45:12 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.04.03 21:44:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.04.03 21:44:34 | 3113,361,408 | -HS- | M] () -- C:\hiberfil.sys
[2012.04.03 20:44:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.04.03 18:21:02 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.04.03 18:20:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
[2012.04.03 17:34:51 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2012.04.03 17:07:32 | 004,455,431 | R--- | M] (Swearware) -- C:\Users\Keno\Desktop\ComboFix.exe
[2012.04.03 12:30:39 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Keno\Desktop\OTL.exe
[2012.04.02 21:20:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
[2012.04.02 17:57:08 | 000,000,000 | ---- | M] () -- C:\Users\Keno\defogger_reenable
[2012.04.02 14:09:23 | 000,899,676 | ---- | M] () -- C:\Users\Keno\AppData\Local\census.cache
[2012.04.02 14:08:37 | 000,117,389 | ---- | M] () -- C:\Users\Keno\AppData\Local\ars.cache
[2012.04.02 13:58:36 | 000,000,036 | ---- | M] () -- C:\Users\Keno\AppData\Local\housecall.guid.cache
[2012.04.01 16:12:50 | 000,000,026 | ---- | M] () -- C:\Windows\Irremote.ini
[2012.03.29 18:07:49 | 001,309,045 | ---- | M] () -- C:\Users\Keno\Desktop\DSCI0039.rar
[2012.03.29 13:07:31 | 000,088,170 | ---- | M] () -- C:\Users\Keno\Desktop\post.jpg
[2012.03.29 12:52:04 | 000,056,126 | ---- | M] () -- C:\Users\Keno\Desktop\564464_324022480984679_176951389025123_841124_1385893687_n.jpg
[2012.03.28 13:29:11 | 000,001,808 | ---- | M] () -- C:\Users\Keno\Desktop\Spotify.lnk
[2012.03.27 00:42:25 | 000,001,616 | ---- | M] () -- C:\Users\Keno\Desktop\DivX Movies.lnk
[2012.03.25 21:27:23 | 000,314,016 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012.03.25 21:27:23 | 000,043,680 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012.03.25 18:46:16 | 567,014,990 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.03.23 18:29:04 | 000,112,154 | ---- | M] () -- C:\Users\Keno\Desktop\watch.htm
[2012.03.19 22:11:50 | 000,160,329 | ---- | M] () -- C:\Users\Keno\Desktop\DSCI0130.jpg
[2012.03.16 22:52:49 | 000,002,044 | ---- | M] () -- C:\Users\Keno\Desktop\JDownloader.lnk
[2012.03.16 22:51:25 | 000,000,237 | ---- | M] () -- C:\user.js
[2012.03.14 10:34:36 | 000,295,120 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.13 10:44:42 | 001,592,786 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
 
========== Files Created - No Company Name ==========
 
[2012.04.03 17:38:32 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.04.03 17:38:32 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.04.03 17:38:32 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.04.03 17:38:32 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.04.03 17:38:32 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.04.03 17:34:51 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2012.04.03 01:40:39 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.02 17:57:08 | 000,000,000 | ---- | C] () -- C:\Users\Keno\defogger_reenable
[2012.04.02 14:09:23 | 000,899,676 | ---- | C] () -- C:\Users\Keno\AppData\Local\census.cache
[2012.04.02 14:08:37 | 000,117,389 | ---- | C] () -- C:\Users\Keno\AppData\Local\ars.cache
[2012.04.02 13:58:36 | 000,000,036 | ---- | C] () -- C:\Users\Keno\AppData\Local\housecall.guid.cache
[2012.04.01 16:12:50 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
[2012.03.29 18:07:48 | 001,309,045 | ---- | C] () -- C:\Users\Keno\Desktop\DSCI0039.rar
[2012.03.29 13:07:31 | 000,088,170 | ---- | C] () -- C:\Users\Keno\Desktop\post.jpg
[2012.03.29 12:52:02 | 000,056,126 | ---- | C] () -- C:\Users\Keno\Desktop\564464_324022480984679_176951389025123_841124_1385893687_n.jpg
[2012.03.28 13:29:11 | 000,001,808 | ---- | C] () -- C:\Users\Keno\Desktop\Spotify.lnk
[2012.03.28 13:29:11 | 000,001,794 | ---- | C] () -- C:\Users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2012.03.27 00:42:25 | 000,001,616 | ---- | C] () -- C:\Users\Keno\Desktop\DivX Movies.lnk
[2012.03.25 21:27:23 | 000,314,016 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012.03.25 21:27:23 | 000,043,680 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012.03.23 18:29:03 | 000,112,154 | ---- | C] () -- C:\Users\Keno\Desktop\watch.htm
[2012.03.19 22:11:50 | 000,160,329 | ---- | C] () -- C:\Users\Keno\Desktop\DSCI0130.jpg
[2012.03.16 22:52:49 | 000,002,044 | ---- | C] () -- C:\Users\Keno\Desktop\JDownloader.lnk
[2012.03.16 22:52:37 | 000,002,008 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.03.16 22:52:37 | 000,001,952 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.03.16 22:52:37 | 000,001,931 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.03.16 22:51:24 | 000,000,237 | ---- | C] () -- C:\user.js
[2012.03.05 21:34:41 | 000,001,106 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.03.05 21:34:41 | 000,001,102 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.02.29 23:50:33 | 000,186,075 | ---- | C] () -- C:\Windows\hpoins14.dat
[2012.02.29 23:50:33 | 000,001,498 | ---- | C] () -- C:\Windows\hpomdl14.dat
[2011.12.07 00:52:31 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.09.11 15:48:58 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2011.08.04 17:01:51 | 001,592,786 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.12.27 05:16:38 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2010.12.27 05:08:17 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2010.11.17 10:00:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.11.16 18:01:20 | 000,002,012 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
 
========== LOP Check ==========
 
[2012.03.16 22:51:14 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Babylon
[2012.03.24 19:07:46 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DAEMON Tools Lite
[2011.08.24 16:58:50 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DVDVideoSoft
[2011.07.06 15:34:25 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.12.04 16:12:09 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\OpenOffice.org
[2012.02.02 19:09:05 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\redsn0w
[2012.04.03 01:28:13 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\SoftGrid Client
[2012.04.03 13:15:00 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Spotify
[2012.04.02 16:20:13 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Teeworlds
[2012.03.23 16:44:15 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Toshiba
[2011.08.11 21:49:45 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\TP
[2012.03.25 21:31:00 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\Ubisoft
[2011.07.06 19:21:50 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\WildTangent
[2011.10.29 21:46:20 | 000,000,000 | ---D | M] -- C:\Users\Keno\AppData\Roaming\WindSolutions
[2012.04.02 21:20:00 | 000,000,902 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
[2012.04.03 18:20:00 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
[2012.04.01 15:55:13 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >


markusg 04.04.2012 09:28

hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



[CODE]
:OTL
SRV - [2011.12.07 00:45:17 | 000,114,000 | ---- | M] (Joosoft.com GmbH) [Auto | Stopped] -- C:\Windows\SysWOW64\UpdSvc.dll -- (Update-Service)
:Files
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang
in den Thread posten!




Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus :)

KenoP 04.04.2012 13:16

Hier ist meine _OTL DAtei

HTML-Code:

All processes killed7
Error: Unable to interpret <[CODE]> in the current context!
========== OTL ==========
Service Update-Service stopped successfully!
Service Update-Service deleted successfully!
C:\Windows\SysWOW64\UpdSvc.dll moved successfully.
========== FILES ==========
========== COMMANDS ==========
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Keno
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Keno
->Temp folder emptied: 78618 bytes
->Temporary Internet Files folder emptied: 188444 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 5877547 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 883269 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 7,00 mb
 
 
OTL by OldTimer - Version 3.2.39.2 log created on 04042012_140435

Files\Folders moved on Reboot...
C:\Users\Keno\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...


markusg 04.04.2012 14:42

kannst du jetzt noch mal combofix ausführen und das log posten?

KenoP 04.04.2012 15:12

Log-Daten
Combofix Logfile:
Code:

ComboFix 12-04-03.02 - Keno 04.04.2012  15:47:08.2.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3959.2661 [GMT 2:00]
ausgeführt von:: c:\users\Keno\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-03-04 bis 2012-04-04  ))))))))))))))))))))))))))))))
.
.
2012-04-04 13:54 . 2012-04-04 13:54        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-04-04 11:52 . 2012-03-14 03:27        8669240        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{592B52F1-BC57-4FDC-B5DD-841B85ACFF7B}\mpengine.dll
2012-04-03 20:25 . 2012-04-03 20:25        --------        d-----w-        c:\users\Keno\AppData\Roaming\Avira
2012-04-03 15:34 . 2011-06-17 10:35        83120        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-04-03 15:34 . 2011-06-17 10:35        116568        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-04-03 15:34 . 2012-04-03 15:34        --------        d-----w-        c:\programdata\Avira
2012-04-03 15:34 . 2012-04-03 15:34        --------        d-----w-        c:\program files (x86)\Avira
2012-04-03 13:28 . 2012-04-04 12:14        --------        d-----w-        C:\_OTL
2012-04-02 23:40 . 2012-04-02 23:40        418464        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-04-02 15:53 . 2012-04-02 15:53        --------        d-----w-        c:\programdata\SUPERSetup
2012-04-02 12:18 . 2012-04-02 12:18        --------        d-----w-        c:\users\Keno\AppData\Roaming\Malwarebytes
2012-04-02 12:18 . 2012-04-02 12:18        --------        d-----w-        c:\programdata\Malwarebytes
2012-04-02 12:18 . 2012-04-02 14:20        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-04-02 12:18 . 2011-12-10 13:24        23152        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-04-01 14:25 . 2012-04-01 14:34        --------        d-----w-        c:\programdata\BullGuard
2012-04-01 14:13 . 2012-04-01 14:13        --------        d-----w-        c:\users\Keno\AppData\Local\Ahead
2012-03-28 11:29 . 2012-04-03 11:55        --------        d-----w-        c:\users\Keno\AppData\Local\Spotify
2012-03-28 11:28 . 2012-04-03 11:15        --------        d-----w-        c:\users\Keno\AppData\Roaming\Spotify
2012-03-26 22:44 . 2012-03-26 22:44        --------        d-----w-        c:\users\Keno\AppData\Local\DDMSettings
2012-03-26 22:42 . 2012-03-26 22:42        --------        d-----w-        c:\program files\DivX
2012-03-26 22:41 . 2012-03-26 22:42        --------        d-----w-        c:\program files (x86)\Common Files\DivX Shared
2012-03-26 22:41 . 2012-03-26 22:42        --------        d-----w-        c:\program files (x86)\DivX
2012-03-26 22:39 . 2012-03-26 22:42        --------        d-----w-        c:\programdata\DivX
2012-03-25 19:59 . 2012-03-25 19:59        --------        d-sh--w-        c:\programdata\SecuROM
2012-03-25 19:31 . 2012-03-25 19:31        --------        d-----w-        c:\users\Keno\AppData\Roaming\Ubisoft
2012-03-25 19:28 . 2012-03-25 19:28        --------        d-----w-        c:\programdata\Tages
2012-03-25 19:27 . 2012-03-25 19:27        43680        ----a-w-        c:\windows\system32\drivers\lirsgt.sys
2012-03-25 19:27 . 2012-03-25 19:27        314016        ----a-w-        c:\windows\system32\drivers\atksgt.sys
2012-03-24 17:07 . 2012-03-24 17:07        --------        d-----w-        c:\users\Keno\AppData\Local\HP
2012-03-24 17:06 . 2012-03-24 17:07        --------        d-----w-        c:\users\Keno\AppData\Roaming\DAEMON Tools Lite
2012-03-24 17:06 . 2012-03-24 17:06        --------        d-----w-        c:\programdata\DAEMON Tools Lite
2012-03-24 14:53 . 2006-09-28 15:05        3977496        ----a-w-        c:\windows\system32\d3dx9_31.dll
2012-03-24 13:41 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\res
2012-03-24 13:41 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\Readme
2012-03-24 13:40 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\Prerequisites
2012-03-24 13:40 . 2009-09-22 15:47        --------        d-----w-        c:\users\Keno\EULA
2012-03-24 13:40 . 2009-10-25 17:08        --------        d-----w-        c:\users\Keno\0x0007
2012-03-18 11:48 . 2012-03-18 11:48        592824        ----a-w-        c:\program files (x86)\Mozilla Firefox\gkmedias.dll
2012-03-18 11:48 . 2012-03-18 11:48        44472        ----a-w-        c:\program files (x86)\Mozilla Firefox\mozglue.dll
2012-03-16 20:51 . 2012-03-16 20:51        237        ----a-w-        C:\user.js
2012-03-16 20:51 . 2012-03-16 20:51        --------        d-----w-        c:\users\Keno\AppData\Local\Babylon
2012-03-16 20:51 . 2012-03-16 20:51        --------        d-----w-        c:\users\Keno\AppData\Roaming\Babylon
2012-03-16 20:51 . 2012-03-16 20:51        --------        d-----w-        c:\programdata\Babylon
2012-03-14 08:31 . 2011-11-19 15:20        5559152        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-03-14 08:31 . 2011-11-19 14:50        3968368        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 08:31 . 2011-11-19 14:50        3913584        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 06:24 . 2012-02-03 04:34        3145728        ----a-w-        c:\windows\system32\win32k.sys
2012-03-14 06:24 . 2012-02-10 06:36        1544192        ----a-w-        c:\windows\system32\DWrite.dll
2012-03-14 06:24 . 2012-02-10 05:38        1077248        ----a-w-        c:\windows\SysWow64\DWrite.dll
2012-03-14 06:24 . 2012-01-25 06:38        77312        ----a-w-        c:\windows\system32\rdpwsx.dll
2012-03-14 06:24 . 2012-01-25 06:38        149504        ----a-w-        c:\windows\system32\rdpcorekmts.dll
2012-03-14 06:24 . 2012-01-25 06:33        9216        ----a-w-        c:\windows\system32\rdrmemptylst.exe
2012-03-14 06:24 . 2012-02-17 06:38        1031680        ----a-w-        c:\windows\system32\rdpcore.dll
2012-03-14 06:24 . 2012-02-17 05:34        826880        ----a-w-        c:\windows\SysWow64\rdpcore.dll
2012-03-14 06:24 . 2012-02-17 04:58        210944        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-03-14 06:24 . 2012-02-17 04:57        23552        ----a-w-        c:\windows\system32\drivers\tdtcp.sys
2012-03-05 19:34 . 2012-03-05 19:35        --------        d-----w-        c:\program files (x86)\Google
2012-03-05 19:34 . 2012-03-05 19:34        --------        d-----w-        c:\users\Keno\AppData\Local\Google
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-02 23:40 . 2011-07-06 13:41        70304        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-23 07:18 . 2011-08-28 17:38        279656        ------w-        c:\windows\system32\MpSigStub.exe
2012-02-16 09:32 . 2011-12-04 11:34        472808        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2012-01-27 11:19 . 2012-01-27 11:19        86528        ----a-w-        c:\windows\SysWow64\iesysprep.dll
2012-01-27 11:19 . 2012-01-27 11:19        76800        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe
2012-01-27 11:19 . 2012-01-27 11:19        74752        ----a-w-        c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-01-27 11:19 . 2012-01-27 11:19        74752        ----a-w-        c:\windows\SysWow64\iesetup.dll
2012-01-27 11:19 . 2012-01-27 11:19        63488        ----a-w-        c:\windows\SysWow64\tdc.ocx
2012-01-27 11:19 . 2012-01-27 11:19        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll
2012-01-27 11:19 . 2012-01-27 11:19        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-01-27 11:19 . 2012-01-27 11:19        367104        ----a-w-        c:\windows\SysWow64\html.iec
2012-01-27 11:19 . 2012-01-27 11:19        23552        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2012-01-27 11:19 . 2012-01-27 11:19        161792        ----a-w-        c:\windows\SysWow64\msls31.dll
2012-01-27 11:19 . 2012-01-27 11:19        152064        ----a-w-        c:\windows\SysWow64\wextract.exe
2012-01-27 11:19 . 2012-01-27 11:19        150528        ----a-w-        c:\windows\SysWow64\iexpress.exe
2012-01-27 11:19 . 2012-01-27 11:19        110592        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll
2012-01-27 11:19 . 2012-01-27 11:19        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-01-27 11:19 . 2012-01-27 11:19        35840        ----a-w-        c:\windows\SysWow64\imgutil.dll
2012-01-27 11:19 . 2012-01-27 11:19        11776        ----a-w-        c:\windows\SysWow64\mshta.exe
2012-01-27 11:19 . 2012-01-27 11:19        101888        ----a-w-        c:\windows\SysWow64\admparse.dll
2012-01-27 11:19 . 2012-01-27 11:19        91648        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe
2012-01-27 11:19 . 2012-01-27 11:19        89088        ----a-w-        c:\windows\system32\RegisterIEPKEYs.exe
2012-01-27 11:19 . 2012-01-27 11:19        85504        ----a-w-        c:\windows\system32\iesetup.dll
2012-01-27 11:19 . 2012-01-27 11:19        76800        ----a-w-        c:\windows\system32\tdc.ocx
2012-01-27 11:19 . 2012-01-27 11:19        603648        ----a-w-        c:\windows\system32\vbscript.dll
2012-01-27 11:19 . 2012-01-27 11:19        49664        ----a-w-        c:\windows\system32\imgutil.dll
2012-01-27 11:19 . 2012-01-27 11:19        48640        ----a-w-        c:\windows\system32\mshtmler.dll
2012-01-27 11:19 . 2012-01-27 11:19        448512        ----a-w-        c:\windows\system32\html.iec
2012-01-27 11:19 . 2012-01-27 11:19        30720        ----a-w-        c:\windows\system32\licmgr10.dll
2012-01-27 11:19 . 2012-01-27 11:19        222208        ----a-w-        c:\windows\system32\msls31.dll
2012-01-27 11:19 . 2012-01-27 11:19        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-01-27 11:19 . 2012-01-27 11:19        165888        ----a-w-        c:\windows\system32\iexpress.exe
2012-01-27 11:19 . 2012-01-27 11:19        160256        ----a-w-        c:\windows\system32\wextract.exe
2012-01-27 11:19 . 2012-01-27 11:19        135168        ----a-w-        c:\windows\system32\IEAdvpack.dll
2012-01-27 11:19 . 2012-01-27 11:19        12288        ----a-w-        c:\windows\system32\mshta.exe
2012-01-27 11:19 . 2012-01-27 11:19        114176        ----a-w-        c:\windows\system32\admparse.dll
2012-01-27 11:19 . 2012-01-27 11:19        111616        ----a-w-        c:\windows\system32\iesysprep.dll
2012-01-11 13:50 . 2012-01-11 13:50        1332736        ----a-w-        c:\windows\system32\xpt8inke.tsp
.
.
(((((((((((((((((((((((((((((  SnapShot@2012-04-03_16.21.17  )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-04 13:54 . 2012-04-04 13:54        13306              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2012-04-03 16:18 . 2012-04-03 16:18        13306              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2009-07-14 04:54 . 2012-04-03 16:19        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-04-04 13:55        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-04-04 13:55        81920              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-03 16:19        81920              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-03 16:19        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-04 13:55        32768              c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-16 15:48 . 2012-04-04 12:24        67852              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-04 12:24        34432              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-07-06 16:48 . 2012-04-04 12:24        15148              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1620826539-68575984-2147015703-1001_UserData.bin
- 2011-07-06 12:23 . 2012-04-01 15:38        49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-07-06 12:23 . 2012-04-03 17:20        49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-04-03 17:20        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-01 15:38        16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-07-08 09:44 . 2012-04-03 16:40        5656              c:\windows\system32\wdi\ERCQueuedResolutions.dat
- 2012-04-03 16:18 . 2012-04-03 16:18        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-04 13:54 . 2012-04-04 13:54        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-04 13:54 . 2012-04-04 13:54        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-04-03 16:18 . 2012-04-03 16:18        2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-11-17 07:31 . 2012-04-04 13:45        318394              c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
- 2009-07-14 02:36 . 2012-04-03 15:29        652812              c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-04-04 12:27        652812              c:\windows\system32\perfh009.dat
- 2009-07-14 17:58 . 2012-04-03 15:29        697534              c:\windows\system32\perfh007.dat
+ 2009-07-14 17:58 . 2012-04-04 12:27        697534              c:\windows\system32\perfh007.dat
- 2009-07-14 02:36 . 2012-04-03 15:29        121486              c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2012-04-04 12:27        121486              c:\windows\system32\perfc009.dat
+ 2009-07-14 17:58 . 2012-04-04 12:27        148540              c:\windows\system32\perfc007.dat
- 2009-07-14 17:58 . 2012-04-03 15:29        148540              c:\windows\system32\perfc007.dat
+ 2009-07-14 05:01 . 2012-04-04 13:54        279032              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-04-03 16:18        279032              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-07-06 16:41 . 2012-04-03 16:18        3220516              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1620826539-68575984-2147015703-1001-8192.dat
+ 2011-07-06 16:41 . 2012-04-04 13:54        3220516              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1620826539-68575984-2147015703-1001-8192.dat
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-09-05 137536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-09-02 1234216]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-26 102400]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
.
c:\users\Keno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 136176]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 253600]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 136176]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-05-11 124368]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Update-Service-Installer-Service        REG_MULTI_SZ          Update-Service-Installer-Service
Update-Service        REG_MULTI_SZ          Update-Service
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-04-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 23:40]
.
2012-04-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001Core.job
- c:\users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-05 19:15]
.
2012-04-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1620826539-68575984-2147015703-1001UA.job
- c:\users\Keno\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-09-05 19:15]
.
2012-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 19:34]
.
2012-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05 19:34]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
"TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-05-11 1050072]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
"SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU]
"00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272]
"SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NCInstallQueue"="netman.dll" [2009-07-14 360448]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.babylon.com/?AF=109989&babsrc=HP_ss&mntrId=8ee9dc020000000000004ceddee5aca3
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Keno\AppData\Roaming\Mozilla\Firefox\Profiles\7epc4x0r.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://ssnhdn.listen2myradio.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109989
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 8ee9dc020000000000004ceddee5aca3
FF - user.js: extensions.BabylonToolbar_i.hardId - 8ee9dc020000000000004ceddee5aca3
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15415
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:51
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1620826539-68575984-2147015703-1001\Software\SecuROM\License information*]
"datasecu"=hex:eb,6c,eb,d6,57,cb,37,60,6e,b2,56,00,7a,c7,4e,79,17,66,b0,c8,50,
  91,b2,6c,fe,a8,33,24,e5,e2,80,e0,f6,0e,aa,5f,77,73,4b,a5,8d,0e,7f,0a,39,80,\
"rkeysecu"=hex:20,d3,04,85,f1,53,f0,bd,95,c0,da,ac,04,08,88,50
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2012-04-04  16:04:30 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2012-04-04 14:04
ComboFix2.txt  2012-04-03 16:33
.
Vor Suchlauf: 13 Verzeichnis(se), 135.780.675.584 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 135.324.409.856 Bytes frei
.
- - End Of File - - C5EDA8267E85D7CABDFD30696FEF1400

--- --- ---

markusg 04.04.2012 15:45

bitte noch nicht weg laufen, ich brauch noch n bissel zeit und da stimmt immernoch was nicht

KenoP 04.04.2012 15:47

Internet geht immer nochn nicht =(
Da steht immer server nicht gefunden.

markusg 04.04.2012 16:02

dazu kommen wir noch.
gehe mal auf start, ausführen, tippe:
regedit.exe
navigiere zu:
HKEY_CURRENT_USER
klappe es auf, suche nach software, ebenfalls aufklappen
gucke ob dort
Joosoft.com einträge zu finden sind, auf der linken seite.

falls ja, rechtsklick, exportieren, speichere es irgendwo, wo du es leicht wieder findest.
das selbe unter
HKEY_local machine
gib mir bescheid ob was gefunden wurde.

KenoP 04.04.2012 16:52

Ich hab die Joobsoft.com Anwendung nun hochgeladen. Hat etwas gedauert, da eder Pc meiner Mutter etwas lahm ist =)

markusg 04.04.2012 16:57

hi, sorry das es bei dir etwas länger dauert. melde mich bald möglich.

markusg 04.04.2012 17:10

öffne noch mal
regedit.exe
klappe auf der linken seite alles zu
drücke dann f3
dann sollte ein suchen feld geöffnet werden.
dort dann einfügen:
Joosoft
ok klicken
und, wenn es funde gibt, die jeweiligen schlüssel auf der rechten seite exportieren und dann hochladen (außer es ist der selbe von vorhin)

KenoP 04.04.2012 17:11

kein Problem, ich hab nichts besonderes vor außer kranl zu sein und dabei im Bett zu liegen =) hab außerdem ne schönes neues Buch, fast 800 Seiten!!!, da wird einem nicht langweilig =)

-edit-
Hab die neue Datei jetzt hochgeladen.

markusg 04.04.2012 19:24

danke
führe mal lsp fix aus:
LSPfix - Freeware - DE - Download.CHIP.eu
und gucke ob dann das inet wieder funktioniert.

KenoP 04.04.2012 19:55

Ja es hat geklappt =) DANKE!!!
Ich werd mir wohl ein anderes Antivirusprogramm holen und auch besser darauf achten welche Seiten ich besuche!
Vielen vielen Dank!
Ich melde mich nochmal ob es morgen immer noch funktioniert :D

markusg 05.04.2012 10:37

hi,
aber wie gesagt, da ist noch etwas, dass mir nicht gefällt, da müssen wir jetzt noch mal rann:
  • Von hier den PPFScanner herunterladen und die ZIP auf einen USB-Stick entpacken.
  • Den befallenen Rechner über die F8 Taste (beim Booten drücken) in den abgesicherten Modus booten.
  • Stick in den Rechner einstecken.
  • Danach die PPFScan.exe vom Stick starten.
  • Klicke im PPFScanner oben links auf den Menüpunkt Programm, es öffnet sich dann ein Untermenü.
  • Wähle im Untermenü Script laden und ausführen.
  • Du hast dann im daraufhin erscheinenden Dialog die Möglichkeit, durch die Ordner zu browsen und eine Datei auszuwählen. Wähle hier die Datei Erweiterter Scan.scp aus, die sich im PPFScanner Ordner befindet, klicke dann auf Öffnen und bestätige die erscheinende Messagebox mit Ja.
  • Nach dem Scan beendet sich der Scanner. Es befinden sich dann im Ordner C:\PPF_Scan1 einige Text-Dateien. rechtsklick auf diesen ordner, und mit winrar zb packen.
    hänge das archiv an deine nächste antwort an.

KenoP 05.04.2012 11:57

Ich hab mir jetzt AVG als Virenschutzprogramm runtergeladen, kann ich das schon installieren oder soll ich damit bisanch der Diagnose/Reperatur warten?

Ich habe die Datei im Uploadchannel hochgeladen, hier konnte ich das nicht, da man nur zip-dateien hochladen kann.
Keno

markusg 05.04.2012 12:03

nein, bitte damit warten.

markusg 05.04.2012 13:26

kannst du den scan mal im normalen modus machen? logs wieder in den up-channel

KenoP 05.04.2012 14:58

Ich hab jetzt den Scan gemacht, dazu kommt dann noch der Bericht von Antivir, dass 3 Maleware gefunden hat.
Keno

Antivir Bericht:
Code:


Avira AntiVir Personal
Erstellungsdatum der Reportdatei: Donnerstag, 5. April 2012  15:06

Es wird nach 2789985 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen seit s nicht mehr zur Verfügung.

Lizenznehmer  : Avira AntiVir Personal - FREE Antivirus
Seriennummer  : 0000149996-ADJIE-0000001
Plattform      : Windows 7 x64
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus    : Normal gebootet
Benutzername  : Keno
Computername  : KENOPAPE

Versionsinformationen:
BUILD.DAT      : 10.0.0.650          Bytes  17.06.2011 15:21:00
AVSCAN.EXE    : 10.0.4.2      442024 Bytes  17.06.2011 10:34:55
AVSCAN.DLL    : 10.0.3.0      56168 Bytes  17.06.2011 10:35:46
LUKE.DLL      : 10.0.3.2      104296 Bytes  17.06.2011 10:35:33
LUKERES.DLL    : 10.0.0.0      13672 Bytes  14.01.2010 12:22:40
VBASE000.VDF  : 7.10.0.0    19875328 Bytes  06.11.2009 10:49:21
VBASE001.VDF  : 7.11.0.0    13342208 Bytes  14.12.2010 05:52:59
VBASE002.VDF  : 7.11.3.0    1950720 Bytes  09.02.2011 05:53:00
VBASE003.VDF  : 7.11.5.225  1980416 Bytes  07.04.2011 10:35:39
VBASE004.VDF  : 7.11.8.178  2354176 Bytes  31.05.2011 10:18:22
VBASE005.VDF  : 7.11.8.179      2048 Bytes  31.05.2011 10:18:22
VBASE006.VDF  : 7.11.8.180      2048 Bytes  31.05.2011 10:18:22
VBASE007.VDF  : 7.11.8.181      2048 Bytes  31.05.2011 10:18:23
VBASE008.VDF  : 7.11.8.182      2048 Bytes  31.05.2011 10:18:23
VBASE009.VDF  : 7.11.8.183      2048 Bytes  31.05.2011 10:18:23
VBASE010.VDF  : 7.11.8.184      2048 Bytes  31.05.2011 10:18:23
VBASE011.VDF  : 7.11.8.185      2048 Bytes  31.05.2011 10:18:23
VBASE012.VDF  : 7.11.8.186      2048 Bytes  31.05.2011 10:18:23
VBASE013.VDF  : 7.11.8.222    121856 Bytes  02.06.2011 23:49:15
VBASE014.VDF  : 7.11.9.7      134656 Bytes  04.06.2011 13:10:35
VBASE015.VDF  : 7.11.9.42    136192 Bytes  06.06.2011 13:39:56
VBASE016.VDF  : 7.11.9.72    117248 Bytes  07.06.2011 12:44:57
VBASE017.VDF  : 7.11.9.107    130560 Bytes  09.06.2011 05:03:40
VBASE018.VDF  : 7.11.9.143    132096 Bytes  10.06.2011 14:53:41
VBASE019.VDF  : 7.11.9.172    141824 Bytes  14.06.2011 04:29:55
VBASE020.VDF  : 7.11.9.214    144896 Bytes  15.06.2011 14:32:34
VBASE021.VDF  : 7.11.9.244    196608 Bytes  16.06.2011 15:51:31
VBASE022.VDF  : 7.11.9.245      2048 Bytes  16.06.2011 15:51:31
VBASE023.VDF  : 7.11.9.246      2048 Bytes  16.06.2011 15:51:31
VBASE024.VDF  : 7.11.9.247      2048 Bytes  16.06.2011 15:51:31
VBASE025.VDF  : 7.11.9.248      2048 Bytes  16.06.2011 15:51:31
VBASE026.VDF  : 7.11.9.249      2048 Bytes  16.06.2011 15:51:31
VBASE027.VDF  : 7.11.9.250      2048 Bytes  16.06.2011 15:51:31
VBASE028.VDF  : 7.11.9.251      2048 Bytes  16.06.2011 15:51:31
VBASE029.VDF  : 7.11.9.252      2048 Bytes  16.06.2011 15:51:31
VBASE030.VDF  : 7.11.9.253      2048 Bytes  16.06.2011 15:51:31
VBASE031.VDF  : 7.11.10.5      45056 Bytes  17.06.2011 10:49:39
Engineversion  : 8.2.5.20 
AEVDF.DLL      : 8.1.2.1      106868 Bytes  21.04.2011 05:52:30
AESCRIPT.DLL  : 8.1.3.65    1606010 Bytes  15.06.2011 22:54:00
AESCN.DLL      : 8.1.7.2      127349 Bytes  21.04.2011 05:52:28
AESBX.DLL      : 8.2.1.34      323957 Bytes  15.06.2011 22:54:00
AERDL.DLL      : 8.1.9.9      639347 Bytes  17.06.2011 10:34:32
AEPACK.DLL    : 8.2.6.9      557429 Bytes  15.06.2011 22:54:00
AEOFFICE.DLL  : 8.1.1.25      205178 Bytes  15.06.2011 22:54:00
AEHEUR.DLL    : 8.1.2.128    3547512 Bytes  15.06.2011 22:54:00
AEHELP.DLL    : 8.1.17.2      246135 Bytes  15.06.2011 22:54:00
AEGEN.DLL      : 8.1.5.6      401780 Bytes  15.06.2011 22:54:00
AEEMU.DLL      : 8.1.3.0      393589 Bytes  21.04.2011 05:52:17
AECORE.DLL    : 8.1.21.1      196983 Bytes  15.06.2011 22:54:00
AEBB.DLL      : 8.1.1.0        53618 Bytes  21.04.2011 05:52:16
AVWINLL.DLL    : 10.0.0.0      19304 Bytes  21.04.2011 05:52:39
AVPREF.DLL    : 10.0.0.0      44904 Bytes  17.06.2011 10:34:52
AVREP.DLL      : 10.0.0.8      62209 Bytes  17.06.2011 10:34:52
AVREG.DLL      : 10.0.3.2      53096 Bytes  17.06.2011 10:34:52
AVSCPLR.DLL    : 10.0.4.2      84840 Bytes  17.06.2011 10:34:56
AVARKT.DLL    : 10.0.22.6    231784 Bytes  17.06.2011 10:34:40
AVEVTLOG.DLL  : 10.0.0.8      203112 Bytes  17.06.2011 10:34:47
SQLITE3.DLL    : 3.6.19.0      355688 Bytes  28.01.2010 11:59:50
AVSMTP.DLL    : 10.0.0.17      63848 Bytes  21.04.2011 05:52:38
NETNT.DLL      : 10.0.0.0      11624 Bytes  21.04.2011 05:52:50
RCIMAGE.DLL    : 10.0.0.26    2550120 Bytes  17.06.2011 10:35:48
RCTEXT.DLL    : 10.0.58.0      98152 Bytes  17.06.2011 10:35:48

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: ShlExt
Konfigurationsdatei...................: C:\Users\Keno\AppData\Local\Temp\6489d049.avp
Protokollierung.......................: niedrig
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:,
Durchsuche aktive Programme...........: aus
Durchsuche Registrierung..............: aus
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Intelligente Dateiauswahl
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: mittel

Beginn des Suchlaufs: Donnerstag, 5. April 2012  15:06

Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\Program Files (x86)'
C:\Program Files (x86)\DivX\DivX Plus Web Player\StreamEngine\DivXAACDecode.dll
[FUND]      Enthält verdächtigen Code: HEUR/Crypted
--> Object
[FUND]      Enthält verdächtigen Code: HEUR/Crypted
C:\Program Files (x86)\DivX\DivX Plus Web Player\StreamEngine\DivXASPDecode.dll
[FUND]      Enthält verdächtigen Code: HEUR/Crypted
--> Object
[FUND]      Enthält verdächtigen Code: HEUR/Crypted
C:\Program Files (x86)\DivX\DivX Plus Web Player\StreamEngine\DivXAVCDecode.dll
[FUND]      Enthält verdächtigen Code: HEUR/Crypted
--> Object
[FUND]      Enthält verdächtigen Code: HEUR/Crypted

Beginne mit der Desinfektion:
C:\Program Files (x86)\DivX\DivX Plus Web Player\StreamEngine\DivXAVCDecode.dll
  [FUND]      Enthält verdächtigen Code: HEUR/Crypted
  [HINWEIS]  Die Datei konnte nicht ins Quarantäneverzeichnis verschoben werden!
  [HINWEIS]  Die Datei existiert nicht!
C:\Program Files (x86)\DivX\DivX Plus Web Player\StreamEngine\DivXASPDecode.dll
  [FUND]      Enthält verdächtigen Code: HEUR/Crypted
  [HINWEIS]  Die Datei konnte nicht ins Quarantäneverzeichnis verschoben werden!
  [HINWEIS]  Die Datei existiert nicht!
C:\Program Files (x86)\DivX\DivX Plus Web Player\StreamEngine\DivXAACDecode.dll
  [FUND]      Enthält verdächtigen Code: HEUR/Crypted
  [HINWEIS]  Die Datei konnte nicht ins Quarantäneverzeichnis verschoben werden!
  [HINWEIS]  Die Datei existiert nicht!


Ende des Suchlaufs: Donnerstag, 5. April 2012  15:39
Benötigte Zeit: 30:56 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

  5631 Verzeichnisse wurden überprüft
 375226 Dateien wurden geprüft
      0 Viren bzw. unerwünschte Programme wurden gefunden
      3 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 375223 Dateien ohne Befall
  1653 Archive wurden durchsucht
      0 Warnungen
      3 Hinweise


markusg 05.04.2012 15:00

deine avira version sieht veraltet aus, mach mal nen rechtsklick auf den schirm, update
dann noch mal scannen log posten bitte, und danke für den upload

KenoP 05.04.2012 20:48

Das hat etwas lange gedauert ....
Hier ist der Bericht:
Code:


Avira AntiVir Personal
Erstellungsdatum der Reportdatei: Donnerstag, 5. April 2012  20:19

Es wird nach 3588407 Virenstämmen gesucht.

Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  : Avira AntiVir Personal - Free Antivirus
Seriennummer  : 0000149996-ADJIE-0000001
Plattform      : Windows 7 x64
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus    : Normal gebootet
Benutzername  : Keno
Computername  : KENOPAPE

Versionsinformationen:
BUILD.DAT      : 10.2.0.707    36070 Bytes  25.01.2012 12:53:00
AVSCAN.EXE    : 10.3.0.7      484008 Bytes  05.04.2012 17:13:02
AVSCAN.DLL    : 10.0.5.0      57192 Bytes  05.04.2012 17:13:02
LUKE.DLL      : 10.3.0.5      45416 Bytes  05.04.2012 17:13:02
LUKERES.DLL    : 10.0.0.0      13672 Bytes  14.01.2010 12:22:40
AVSCPLR.DLL    : 10.3.0.7      119656 Bytes  05.04.2012 17:13:02
AVREG.DLL      : 10.3.0.9      88833 Bytes  05.04.2012 17:13:02
VBASE000.VDF  : 7.10.0.0    19875328 Bytes  06.11.2009 10:49:21
VBASE001.VDF  : 7.11.0.0    13342208 Bytes  14.12.2010 05:52:59
VBASE002.VDF  : 7.11.19.170 14374912 Bytes  20.12.2011 17:13:01
VBASE003.VDF  : 7.11.21.238  4472832 Bytes  01.02.2012 17:13:01
VBASE004.VDF  : 7.11.26.44  4329472 Bytes  28.03.2012 17:13:01
VBASE005.VDF  : 7.11.26.45      2048 Bytes  28.03.2012 17:13:01
VBASE006.VDF  : 7.11.26.46      2048 Bytes  28.03.2012 17:13:01
VBASE007.VDF  : 7.11.26.47      2048 Bytes  28.03.2012 17:13:01
VBASE008.VDF  : 7.11.26.48      2048 Bytes  28.03.2012 17:13:01
VBASE009.VDF  : 7.11.26.49      2048 Bytes  28.03.2012 17:13:01
VBASE010.VDF  : 7.11.26.50      2048 Bytes  28.03.2012 17:13:01
VBASE011.VDF  : 7.11.26.51      2048 Bytes  28.03.2012 17:13:01
VBASE012.VDF  : 7.11.26.52      2048 Bytes  28.03.2012 17:13:01
VBASE013.VDF  : 7.11.26.53      2048 Bytes  28.03.2012 17:13:01
VBASE014.VDF  : 7.11.26.107  221696 Bytes  30.03.2012 17:13:01
VBASE015.VDF  : 7.11.26.179  224768 Bytes  02.04.2012 17:13:01
VBASE016.VDF  : 7.11.26.241  142336 Bytes  04.04.2012 17:13:01
VBASE017.VDF  : 7.11.26.242    2048 Bytes  04.04.2012 17:13:01
VBASE018.VDF  : 7.11.26.243    2048 Bytes  04.04.2012 17:13:01
VBASE019.VDF  : 7.11.26.244    2048 Bytes  04.04.2012 17:13:01
VBASE020.VDF  : 7.11.26.245    2048 Bytes  04.04.2012 17:13:01
VBASE021.VDF  : 7.11.26.246    2048 Bytes  04.04.2012 17:13:01
VBASE022.VDF  : 7.11.26.247    2048 Bytes  04.04.2012 17:13:01
VBASE023.VDF  : 7.11.26.248    2048 Bytes  04.04.2012 17:13:01
VBASE024.VDF  : 7.11.26.249    2048 Bytes  04.04.2012 17:13:01
VBASE025.VDF  : 7.11.26.250    2048 Bytes  04.04.2012 17:13:01
VBASE026.VDF  : 7.11.26.251    2048 Bytes  04.04.2012 17:13:01
VBASE027.VDF  : 7.11.26.252    2048 Bytes  04.04.2012 17:13:01
VBASE028.VDF  : 7.11.26.253    2048 Bytes  04.04.2012 17:13:01
VBASE029.VDF  : 7.11.26.254    2048 Bytes  04.04.2012 17:13:01
VBASE030.VDF  : 7.11.26.255    2048 Bytes  04.04.2012 17:13:01
VBASE031.VDF  : 7.11.27.24    74240 Bytes  05.04.2012 17:13:01
Engineversion  : 8.2.10.38
AEVDF.DLL      : 8.1.2.2      106868 Bytes  05.04.2012 17:13:01
AESCRIPT.DLL  : 8.1.4.16      446842 Bytes  05.04.2012 17:13:01
AESCN.DLL      : 8.1.8.2      131444 Bytes  05.04.2012 17:13:01
AESBX.DLL      : 8.2.5.5      606579 Bytes  05.04.2012 17:13:01
AERDL.DLL      : 8.1.9.15      639348 Bytes  05.04.2012 17:13:01
AEPACK.DLL    : 8.2.16.9      807287 Bytes  05.04.2012 17:13:01
AEOFFICE.DLL  : 8.1.2.27      201082 Bytes  05.04.2012 17:13:01
AEHEUR.DLL    : 8.1.4.12    4604278 Bytes  05.04.2012 17:13:01
AEHELP.DLL    : 8.1.19.1      254327 Bytes  05.04.2012 17:13:01
AEGEN.DLL      : 8.1.5.23      409973 Bytes  05.04.2012 17:13:01
AEEXP.DLL      : 8.1.0.28      82292 Bytes  05.04.2012 17:13:01
AEEMU.DLL      : 8.1.3.0      393589 Bytes  21.04.2011 05:52:17
AECORE.DLL    : 8.1.25.6      201078 Bytes  05.04.2012 17:13:01
AEBB.DLL      : 8.1.1.0        53618 Bytes  21.04.2011 05:52:16
AVWINLL.DLL    : 10.0.0.0      19304 Bytes  21.04.2011 05:52:39
AVPREF.DLL    : 10.0.3.2      44904 Bytes  05.04.2012 17:13:02
AVREP.DLL      : 10.0.0.10    174120 Bytes  05.04.2012 17:13:02
AVARKT.DLL    : 10.0.26.1    255336 Bytes  05.04.2012 17:13:02
AVEVTLOG.DLL  : 10.0.0.9      203112 Bytes  05.04.2012 17:13:02
SQLITE3.DLL    : 3.6.19.0      355688 Bytes  28.01.2010 11:59:50
AVSMTP.DLL    : 10.0.0.17      63848 Bytes  21.04.2011 05:52:38
NETNT.DLL      : 10.0.0.0      11624 Bytes  21.04.2011 05:52:50
RCIMAGE.DLL    : 10.0.0.35    2589544 Bytes  05.04.2012 17:13:00
RCTEXT.DLL    : 10.0.64.0      98664 Bytes  05.04.2012 17:13:00

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Vollständige Systemprüfung
Konfigurationsdatei...................: C:\program files (x86)\avira\antivir desktop\sysscan.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, D:, Q:,
Durchsuche aktive Programme...........: ein
Laufende Programme erweitert..........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: ein
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert

Beginn des Suchlaufs: Donnerstag, 5. April 2012  20:19

Der Suchlauf nach versteckten Objekten wird begonnen.
HKEY_LOCAL_MACHINE\Software\McAfee\symboliclinkvalue
  [HINWEIS]  Der Registrierungseintrag ist nicht sichtbar.

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'avscan.exe' - '72' Modul(e) wurden durchsucht
Durchsuche Prozess 'avcenter.exe' - '112' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '50' Modul(e) wurden durchsucht
Durchsuche Prozess 'teeworlds.exe' - '59' Modul(e) wurden durchsucht
Durchsuche Prozess 'UNS.exe' - '56' Modul(e) wurden durchsucht
Durchsuche Prozess 'NASvc.exe' - '42' Modul(e) wurden durchsucht
Durchsuche Prozess 'CFSvcs.exe' - '48' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '76' Modul(e) wurden durchsucht
Durchsuche Prozess 'CFSwMgr.exe' - '56' Modul(e) wurden durchsucht
Durchsuche Prozess 'NDSTray.exe' - '78' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '101' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpqgpc01.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpqbam08.exe' - '30' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpqSTE08.exe' - '59' Modul(e) wurden durchsucht
Durchsuche Prozess 'DivXUpdate.exe' - '58' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpwuSchd2.exe' - '20' Modul(e) wurden durchsucht
Durchsuche Prozess 'jusched.exe' - '25' Modul(e) wurden durchsucht
Durchsuche Prozess 'iTunesHelper.exe' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'CVHSVC.EXE' - '81' Modul(e) wurden durchsucht
Durchsuche Prozess 'NBAgent.exe' - '72' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.bin' - '93' Modul(e) wurden durchsucht
Durchsuche Prozess 'soffice.exe' - '20' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpqtra08.exe' - '80' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftlist.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftvsa.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'SeaPort.exe' - '50' Modul(e) wurden durchsucht
Durchsuche Prozess 'LMS.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'AppleMobileDeviceService.exe' - '64' Modul(e) wurden durchsucht

Der Suchlauf über die Masterbootsektoren wird begonnen:
Masterbootsektor HD0
    [INFO]      Es wurde kein Virus gefunden!
Masterbootsektor HD1
    [INFO]      Es wurde kein Virus gefunden!

Der Suchlauf über die Bootsektoren wird begonnen:
Bootsektor 'C:\'
    [INFO]      Es wurde kein Virus gefunden!
Bootsektor 'D:\'
    [INFO]      Es wurde kein Virus gefunden!
Bootsektor 'Q:\'
    [INFO]      Es wurde kein Virus gefunden!
    [INFO]      Bitte starten Sie den Suchlauf erneut mit Administratorrechten

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '204' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\' <WINDOWS>
C:\Users\Keno\Desktop\Sd card\Neuer Ordner\MovedFiles.zip
  [0] Archivtyp: ZIP
  --> MovedFiles/04032012_152808/C_Windows/SysNative/aptwgv56x.dll
      [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
C:\Users\Keno\Desktop\Sd card\Pc diagnose\MovedFiles.zip
  [0] Archivtyp: ZIP
  --> MovedFiles/04032012_152808/C_Windows/SysNative/aptwgv56x.dll
      [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
C:\Windows\System32\consrv.dll
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen2
C:\_OTL\MovedFiles.zip
  [0] Archivtyp: ZIP
  --> MovedFiles/04032012_152808/C_Windows/SysNative/aptwgv56x.dll
      [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
C:\_OTL\MovedFiles\04032012_152808\C_Windows\SysNative\aptwgv56x.dll
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
Beginne mit der Suche in 'D:\' <Data>
Beginne mit der Suche in 'Q:\'
Der zu durchsuchende Pfad Q:\ konnte nicht geöffnet werden!
Systemfehler [5]: Zugriff verweigert

Beginne mit der Desinfektion:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
C:\_OTL\MovedFiles\04032012_152808\C_Windows\SysNative\aptwgv56x.dll
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4a6459cb.qua' verschoben!
C:\_OTL\MovedFiles.zip
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '52f17673.qua' verschoben!
C:\Windows\System32\consrv.dll
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen2
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '00b62c9b.qua' verschoben!
C:\Users\Keno\Desktop\Sd card\Pc diagnose\MovedFiles.zip
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '66996359.qua' verschoben!
C:\Users\Keno\Desktop\Sd card\Neuer Ordner\MovedFiles.zip
  [FUND]      Ist das Trojanische Pferd TR/ATRAPS.Gen
  [HINWEIS]  Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '231d4e67.qua' verschoben!


Ende des Suchlaufs: Donnerstag, 5. April 2012  21:46
Benötigte Zeit:  1:24:50 Stunde(n)

Der Suchlauf wurde vollständig durchgeführt.

  36014 Verzeichnisse wurden überprüft
 892658 Dateien wurden geprüft
      5 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      5 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 892653 Dateien ohne Befall
  5615 Archive wurden durchsucht
      0 Warnungen
      6 Hinweise
 502547 Objekte wurden beim Rootkitscan durchsucht
      1 Versteckte Objekte wurden gefunden


markusg 06.04.2012 14:46

sorry, das letzte ppf scan log hat noch was ergeben, was ner untersuchung bedarf
hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
C:\Program Files (x86)\InstallShield Installation Information\{9D3D8C60-A55F-4fed-B2B9-173001290E16}
 :Files
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang
in den Thread posten!




Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus :)

KenoP 06.04.2012 18:24

Hi

Code:

All processes killed
========== OTL ==========
========== COMMANDS ==========
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Keno
->Flash cache emptied: 1499 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Keno
->Temp folder emptied: 321467 bytes
->Temporary Internet Files folder emptied: 9314157 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 276544429 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1663809 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 2338 bytes
 
Total Files Cleaned = 275,00 mb
 
 
OTL by OldTimer - Version 3.2.39.2 log created on 04062012_162154

Files\Folders moved on Reboot...
C:\Users\Keno\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...


markusg 06.04.2012 18:29

hab nen fehler drinn, so ists richtig:
:OTL
:Files
C:\Program Files (x86)\InstallShield Installation Information\{9D3D8C60-A55F-4fed-B2B9-173001290E16}
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]

KenoP 06.04.2012 19:27

Hier das verbesserte, ich lads jetzt auch hoch


Code:

All processes killed
========== OTL ==========
========== FILES ==========
C:\Program Files (x86)\InstallShield Installation Information\{9D3D8C60-A55F-4fed-B2B9-173001290E16} folder moved successfully.
========== COMMANDS ==========
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Keno
->Flash cache emptied: 3220 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Keno
->Temp folder emptied: 9701301 bytes
->Temporary Internet Files folder emptied: 64613 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 84101201 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 546198 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 90,00 mb
 
 
OTL by OldTimer - Version 3.2.39.2 log created on 04062012_201820

Files\Folders moved on Reboot...
C:\Users\Keno\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Ich krieg das nicht hochgeladen, die Verbindung geht immer verloren.
Es kommt dann immer das Zeichen für eingeschränkte Konnektivität.
-edit-
hat doch funktioniert. musste nur die Leistung meines Routers wieder runter setzten..:D

KenoP 09.04.2012 18:08

Frohe Ostern =)

markusg 10.04.2012 17:32

download tdss killer:
http://www.trojaner-board.de/82358-t...entfernen.html
Klicke auf Change parameters
• Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system
• Klick auf OK und anschließend auf Start scan
- bei funden erst mal immer skip wählen, log posten

KenoP 12.04.2012 14:06

Entschuldige bitte, dass das so lange gedauert hat, ich war bei meinem Vater und hatte meinen Lapptop nicht dabei.
Ich hab den Scan mit TDSSKiller so ausgeführt wie es in der Anleitung stand, doch habe gab es dabei keinen Fund.

markusg 12.04.2012 14:24

wo ist das log?

KenoP 12.04.2012 18:50

Code:

19:48:25.0808 2404        TDSS rootkit removing tool 2.7.28.0 Apr 10 2012 16:54:05
19:48:26.0077 2404        ============================================================
19:48:26.0077 2404        Current date / time: 2012/04/12 19:48:26.0077
19:48:26.0077 2404        SystemInfo:
19:48:26.0077 2404       
19:48:26.0077 2404        OS Version: 6.1.7601 ServicePack: 1.0
19:48:26.0077 2404        Product type: Workstation
19:48:26.0078 2404        ComputerName: KENOPAPE
19:48:26.0078 2404        UserName: Keno
19:48:26.0078 2404        Windows directory: C:\Windows
19:48:26.0078 2404        System windows directory: C:\Windows
19:48:26.0078 2404        Running under WOW64
19:48:26.0078 2404        Processor architecture: Intel x64
19:48:26.0078 2404        Number of processors: 4
19:48:26.0078 2404        Page size: 0x1000
19:48:26.0078 2404        Boot type: Normal boot
19:48:26.0078 2404        ============================================================
19:48:26.0987 2404        Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:48:26.0995 2404        Drive \Device\Harddisk1\DR1 - Size: 0x3B880000 (0.93 Gb), SectorSize: 0x200, Cylinders: 0x79, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:48:27.0001 2404        \Device\Harddisk0\DR0:
19:48:27.0002 2404        MBR used
19:48:27.0002 2404        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xC8800, BlocksNum 0x1D173800
19:48:27.0002 2404        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D23C000, BlocksNum 0x1D149830
19:48:27.0002 2404        \Device\Harddisk1\DR1:
19:48:27.0003 2404        MBR used
19:48:27.0003 2404        \Device\Harddisk1\DR1\Partition0: MBR, Type 0x6, StartLBA 0x81, BlocksNum 0x1DC37F
19:48:27.0259 2404        Initialize success
19:48:27.0259 2404        ============================================================
19:48:28.0102 1364        ============================================================
19:48:28.0102 1364        Scan started
19:48:28.0102 1364        Mode: Manual;
19:48:28.0102 1364        ============================================================
19:48:30.0718 1364        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
19:48:30.0735 1364        1394ohci - ok
19:48:30.0978 1364        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
19:48:30.0988 1364        ACPI - ok
19:48:31.0122 1364        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
19:48:31.0128 1364        AcpiPmi - ok
19:48:31.0503 1364        AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:48:31.0505 1364        AdobeFlashPlayerUpdateSvc - ok
19:48:31.0708 1364        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
19:48:31.0739 1364        adp94xx - ok
19:48:31.0903 1364        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
19:48:31.0925 1364        adpahci - ok
19:48:32.0008 1364        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
19:48:32.0018 1364        adpu320 - ok
19:48:32.0057 1364        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
19:48:32.0058 1364        AeLookupSvc - ok
19:48:32.0188 1364        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
19:48:32.0255 1364        AFD - ok
19:48:32.0404 1364        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
19:48:32.0424 1364        agp440 - ok
19:48:32.0520 1364        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
19:48:32.0521 1364        ALG - ok
19:48:32.0644 1364        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
19:48:32.0650 1364        aliide - ok
19:48:33.0173 1364        AMD External Events Utility (61a18bcaf557cd6614309e4978b81056) C:\Windows\system32\atiesrxx.exe
19:48:33.0174 1364        AMD External Events Utility - ok
19:48:33.0555 1364        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
19:48:33.0567 1364        amdide - ok
19:48:33.0825 1364        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
19:48:33.0835 1364        AmdK8 - ok
19:48:34.0336 1364        amdkmdag        (f05b22ce901fc26ae55a1a27aa674d96) C:\Windows\system32\DRIVERS\atikmdag.sys
19:48:34.0460 1364        amdkmdag - ok
19:48:34.0577 1364        amdkmdap        (ed25d58581b5a28593c277f482fccd62) C:\Windows\system32\DRIVERS\atikmpag.sys
19:48:34.0583 1364        amdkmdap - ok
19:48:34.0879 1364        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
19:48:34.0896 1364        AmdPPM - ok
19:48:35.0082 1364        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
19:48:35.0099 1364        amdsata - ok
19:48:35.0241 1364        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
19:48:35.0286 1364        amdsbs - ok
19:48:35.0385 1364        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
19:48:35.0418 1364        amdxata - ok
19:48:35.0522 1364        AntiVirSchedulerService (c27d46b06d340293670450fce9dfb166) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
19:48:35.0523 1364        AntiVirSchedulerService - ok
19:48:35.0575 1364        AntiVirService  (72d90e56563165984224493069c69ed4) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
19:48:35.0577 1364        AntiVirService - ok
19:48:35.0974 1364        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
19:48:35.0981 1364        AppID - ok
19:48:36.0048 1364        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
19:48:36.0048 1364        AppIDSvc - ok
19:48:36.0384 1364        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
19:48:36.0385 1364        Appinfo - ok
19:48:36.0518 1364        Apple Mobile Device (d8e18021f91ad79ca8491cb5a5da22d4) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
19:48:36.0520 1364        Apple Mobile Device - ok
19:48:36.0730 1364        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
19:48:36.0745 1364        arc - ok
19:48:36.0880 1364        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
19:48:36.0891 1364        arcsas - ok
19:48:37.0060 1364        aspnet_state    (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
19:48:37.0117 1364        aspnet_state - ok
19:48:37.0276 1364        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
19:48:37.0282 1364        AsyncMac - ok
19:48:37.0342 1364        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
19:48:37.0347 1364        atapi - ok
19:48:37.0560 1364        athr            (e857eee6b92aaa473ebb3465add8f7e7) C:\Windows\system32\DRIVERS\athrx.sys
19:48:37.0625 1364        athr - ok
19:48:37.0904 1364        atksgt          (fc0e8778c000291caf60eb88c011e931) C:\Windows\system32\DRIVERS\atksgt.sys
19:48:37.0914 1364        atksgt - ok
19:48:38.0249 1364        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
19:48:38.0280 1364        AudioEndpointBuilder - ok
19:48:38.0358 1364        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
19:48:38.0362 1364        AudioSrv - ok
19:48:38.0596 1364        avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\Windows\system32\DRIVERS\avgntflt.sys
19:48:38.0607 1364        avgntflt - ok
19:48:38.0651 1364        avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\Windows\system32\DRIVERS\avipbb.sys
19:48:38.0657 1364        avipbb - ok
19:48:38.0807 1364        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
19:48:38.0807 1364        AxInstSV - ok
19:48:38.0963 1364        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
19:48:38.0994 1364        b06bdrv - ok
19:48:39.0104 1364        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
19:48:39.0119 1364        b57nd60a - ok
19:48:39.0213 1364        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
19:48:39.0213 1364        BDESVC - ok
19:48:39.0275 1364        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
19:48:39.0322 1364        Beep - ok
19:48:39.0384 1364        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
19:48:39.0400 1364        BFE - ok
19:48:39.0462 1364        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll
19:48:39.0494 1364        BITS - ok
19:48:39.0650 1364        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
19:48:39.0650 1364        blbdrive - ok
19:48:39.0774 1364        Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
19:48:39.0790 1364        Bonjour Service - ok
19:48:39.0899 1364        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
19:48:39.0930 1364        bowser - ok
19:48:40.0118 1364        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
19:48:40.0118 1364        BrFiltLo - ok
19:48:40.0196 1364        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
19:48:40.0211 1364        BrFiltUp - ok
19:48:40.0492 1364        BridgeMP        (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
19:48:40.0492 1364        BridgeMP - ok
19:48:40.0601 1364        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
19:48:40.0601 1364        Browser - ok
19:48:40.0648 1364        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
19:48:40.0679 1364        Brserid - ok
19:48:40.0710 1364        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
19:48:40.0726 1364        BrSerWdm - ok
19:48:40.0742 1364        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
19:48:40.0742 1364        BrUsbMdm - ok
19:48:40.0757 1364        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
19:48:40.0773 1364        BrUsbSer - ok
19:48:40.0804 1364        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
19:48:40.0804 1364        BTHMODEM - ok
19:48:40.0944 1364        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
19:48:40.0944 1364        bthserv - ok
19:48:40.0976 1364        catchme - ok
19:48:41.0163 1364        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
19:48:41.0178 1364        cdfs - ok
19:48:41.0381 1364        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
19:48:41.0459 1364        cdrom - ok
19:48:41.0522 1364        Scan interrupted by user!
19:48:41.0522 1364        Scan interrupted by user!
19:48:41.0522 1364        Scan interrupted by user!
19:48:41.0522 1364        ============================================================
19:48:41.0522 1364        Scan finished
19:48:41.0522 1364        ============================================================
19:48:41.0522 4216        Detected object count: 0
19:48:41.0522 4216        Actual detected object count: 0
19:48:42.0083 4452        ============================================================
19:48:42.0083 4452        Scan started
19:48:42.0083 4452        Mode: Manual;
19:48:42.0083 4452        ============================================================
19:48:43.0035 4452        1394ohci        (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
19:48:43.0035 4452        1394ohci - ok
19:48:43.0596 4452        ACPI            (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
19:48:43.0596 4452        ACPI - ok
19:48:44.0080 4452        AcpiPmi        (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
19:48:44.0080 4452        AcpiPmi - ok
19:48:44.0548 4452        AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:48:44.0548 4452        AdobeFlashPlayerUpdateSvc - ok
19:48:44.0954 4452        adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
19:48:44.0954 4452        adp94xx - ok
19:48:45.0266 4452        adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
19:48:45.0281 4452        adpahci - ok
19:48:45.0484 4452        adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
19:48:45.0484 4452        adpu320 - ok
19:48:45.0624 4452        AeLookupSvc    (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
19:48:45.0624 4452        AeLookupSvc - ok
19:48:45.0765 4452        AFD            (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
19:48:45.0780 4452        AFD - ok
19:48:46.0046 4452        agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
19:48:46.0046 4452        agp440 - ok
19:48:46.0155 4452        ALG            (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
19:48:46.0155 4452        ALG - ok
19:48:46.0264 4452        aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
19:48:46.0264 4452        aliide - ok
19:48:46.0358 4452        AMD External Events Utility (61a18bcaf557cd6614309e4978b81056) C:\Windows\system32\atiesrxx.exe
19:48:46.0358 4452        AMD External Events Utility - ok
19:48:46.0451 4452        amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
19:48:46.0451 4452        amdide - ok
19:48:46.0529 4452        AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
19:48:46.0529 4452        AmdK8 - ok
19:48:47.0372 4452        amdkmdag        (f05b22ce901fc26ae55a1a27aa674d96) C:\Windows\system32\DRIVERS\atikmdag.sys
19:48:47.0418 4452        amdkmdag - ok
19:48:47.0637 4452        amdkmdap        (ed25d58581b5a28593c277f482fccd62) C:\Windows\system32\DRIVERS\atikmpag.sys
19:48:47.0637 4452        amdkmdap - ok
19:48:47.0746 4452        AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
19:48:47.0746 4452        AmdPPM - ok
19:48:47.0933 4452        amdsata        (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
19:48:47.0933 4452        amdsata - ok
19:48:48.0105 4452        amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
19:48:48.0105 4452        amdsbs - ok
19:48:48.0183 4452        amdxata        (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
19:48:48.0183 4452        amdxata - ok
19:48:48.0339 4452        AntiVirSchedulerService (c27d46b06d340293670450fce9dfb166) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
19:48:48.0339 4452        AntiVirSchedulerService - ok
19:48:48.0573 4452        AntiVirService  (72d90e56563165984224493069c69ed4) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
19:48:48.0573 4452        AntiVirService - ok
19:48:48.0760 4452        AppID          (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
19:48:48.0760 4452        AppID - ok
19:48:48.0822 4452        AppIDSvc        (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
19:48:48.0822 4452        AppIDSvc - ok
19:48:48.0932 4452        Appinfo        (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
19:48:48.0932 4452        Appinfo - ok
19:48:49.0072 4452        Apple Mobile Device (d8e18021f91ad79ca8491cb5a5da22d4) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
19:48:49.0072 4452        Apple Mobile Device - ok
19:48:49.0197 4452        arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
19:48:49.0197 4452        arc - ok
19:48:49.0290 4452        arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
19:48:49.0290 4452        arcsas - ok
19:48:49.0462 4452        aspnet_state    (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
19:48:49.0462 4452        aspnet_state - ok
19:48:49.0665 4452        AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
19:48:49.0665 4452        AsyncMac - ok
19:48:49.0868 4452        atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
19:48:49.0868 4452        atapi - ok
19:48:50.0086 4452        athr            (e857eee6b92aaa473ebb3465add8f7e7) C:\Windows\system32\DRIVERS\athrx.sys
19:48:50.0102 4452        athr - ok
19:48:50.0258 4452        atksgt          (fc0e8778c000291caf60eb88c011e931) C:\Windows\system32\DRIVERS\atksgt.sys
19:48:50.0258 4452        atksgt - ok
19:48:50.0367 4452        AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
19:48:50.0367 4452        AudioEndpointBuilder - ok
19:48:50.0429 4452        AudioSrv        (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
19:48:50.0445 4452        AudioSrv - ok
19:48:50.0570 4452        avgntflt        (b1224e6b086cd6548315b04ab575a23e) C:\Windows\system32\DRIVERS\avgntflt.sys
19:48:50.0570 4452        avgntflt - ok
19:48:50.0585 4452        avipbb          (ed45f12cfa62b83765c9c1496758cc87) C:\Windows\system32\DRIVERS\avipbb.sys
19:48:50.0585 4452        avipbb - ok
19:48:50.0788 4452        AxInstSV        (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
19:48:50.0804 4452        AxInstSV - ok
19:48:51.0022 4452        b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
19:48:51.0038 4452        b06bdrv - ok
19:48:51.0194 4452        b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
19:48:51.0194 4452        b57nd60a - ok
19:48:51.0303 4452        BDESVC          (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
19:48:51.0303 4452        BDESVC - ok
19:48:51.0412 4452        Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
19:48:51.0412 4452        Beep - ok
19:48:51.0568 4452        BFE            (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
19:48:51.0568 4452        BFE - ok
19:48:51.0880 4452        BITS            (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll
19:48:51.0880 4452        BITS - ok
19:48:51.0958 4452        blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
19:48:51.0958 4452        blbdrive - ok
19:48:52.0083 4452        Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
19:48:52.0083 4452        Bonjour Service - ok
19:48:52.0223 4452        bowser          (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
19:48:52.0223 4452        bowser - ok
19:48:52.0286 4452        BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
19:48:52.0286 4452        BrFiltLo - ok
19:48:52.0379 4452        BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
19:48:52.0395 4452        BrFiltUp - ok
19:48:52.0629 4452        BridgeMP        (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
19:48:52.0629 4452        BridgeMP - ok
19:48:52.0816 4452        Browser        (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
19:48:52.0816 4452        Browser - ok
19:48:53.0112 4452        Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
19:48:53.0112 4452        Brserid - ok
19:48:53.0222 4452        BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
19:48:53.0222 4452        BrSerWdm - ok
19:48:53.0331 4452        BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
19:48:53.0346 4452        BrUsbMdm - ok
19:48:53.0393 4452        BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
19:48:53.0393 4452        BrUsbSer - ok
19:48:53.0471 4452        BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
19:48:53.0471 4452        BTHMODEM - ok
19:48:53.0705 4452        bthserv        (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
19:48:53.0705 4452        bthserv - ok
19:48:53.0705 4452        catchme - ok
19:48:53.0861 4452        cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
19:48:53.0861 4452        cdfs - ok
19:48:53.0986 4452        cdrom          (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
19:48:53.0986 4452        cdrom - ok
19:48:54.0064 4452        CertPropSvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
19:48:54.0064 4452        CertPropSvc - ok
19:48:54.0220 4452        cfWiMAXService  (41e7c4fa6491747402cfca77cc1c7aab) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
19:48:54.0220 4452        cfWiMAXService - ok
19:48:54.0485 4452        circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
19:48:54.0501 4452        circlass - ok
19:48:54.0704 4452        CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
19:48:54.0719 4452        CLFS - ok
19:48:54.0922 4452        clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:48:54.0953 4452        clr_optimization_v2.0.50727_32 - ok
19:48:55.0125 4452        clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:48:55.0125 4452        clr_optimization_v2.0.50727_64 - ok
19:48:55.0218 4452        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:48:55.0359 4452        clr_optimization_v4.0.30319_32 - ok
19:48:55.0530 4452        clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:48:55.0640 4452        clr_optimization_v4.0.30319_64 - ok
19:48:55.0983 4452        CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
19:48:55.0998 4452        CmBatt - ok
19:48:56.0186 4452        cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
19:48:56.0201 4452        cmdide - ok
19:48:56.0435 4452        CNG            (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
19:48:56.0498 4452        CNG - ok
19:48:56.0700 4452        CnxtHdAudService (25c58ee97be0416a373e3e4f855206b5) C:\Windows\system32\drivers\CHDRT64.sys
19:48:56.0700 4452        CnxtHdAudService - ok
19:48:57.0059 4452        CnxtHdmiAudService (89c99ab4ae9535f727791592d84d4821) C:\Windows\system32\drivers\CHDMI64.sys
19:48:57.0059 4452        CnxtHdmiAudService - ok
19:48:57.0200 4452        Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
19:48:57.0215 4452        Compbatt - ok
19:48:57.0293 4452        CompositeBus    (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
19:48:57.0293 4452        CompositeBus - ok
19:48:57.0324 4452        COMSysApp - ok
19:48:57.0418 4452        ConfigFree Service (cab0eeaf5295fc96ddd3e19dce27e131) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
19:48:57.0418 4452        ConfigFree Service - ok
19:48:57.0636 4452        crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
19:48:57.0652 4452        crcdisk - ok
19:48:57.0933 4452        CryptSvc        (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
19:48:57.0933 4452        CryptSvc - ok
19:48:58.0214 4452        cvhsvc          (72794d112cbaff3bc0c29bf7350d4741) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
19:48:58.0245 4452        cvhsvc - ok
19:48:58.0385 4452        DcomLaunch      (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
19:48:58.0385 4452        DcomLaunch - ok
19:48:58.0526 4452        defragsvc      (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
19:48:58.0541 4452        defragsvc - ok
19:48:58.0884 4452        DfsC            (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
19:48:58.0916 4452        DfsC - ok
19:48:59.0196 4452        Dhcp            (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
19:48:59.0196 4452        Dhcp - ok
19:48:59.0415 4452        discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
19:48:59.0477 4452        discache - ok
19:48:59.0867 4452        Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
19:48:59.0992 4452        Disk - ok
19:49:00.0242 4452        Dnscache        (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
19:49:00.0242 4452        Dnscache - ok
19:49:00.0444 4452        dot3svc        (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
19:49:00.0460 4452        dot3svc - ok
19:49:00.0741 4452        Dot4            (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
19:49:00.0741 4452        Dot4 - ok
19:49:00.0834 4452        Dot4Print      (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\DRIVERS\Dot4Prt.sys
19:49:00.0944 4452        Dot4Print - ok
19:49:01.0037 4452        dot4usb        (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
19:49:01.0037 4452        dot4usb - ok
19:49:01.0115 4452        DPS            (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
19:49:01.0115 4452        DPS - ok
19:49:01.0302 4452        drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
19:49:01.0302 4452        drmkaud - ok
19:49:01.0677 4452        DXGKrnl        (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
19:49:01.0692 4452        DXGKrnl - ok
19:49:01.0802 4452        EapHost        (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
19:49:01.0802 4452        EapHost - ok
19:49:02.0067 4452        ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
19:49:02.0176 4452        ebdrv - ok
19:49:02.0254 4452        EFS            (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
19:49:02.0254 4452        EFS - ok
19:49:02.0348 4452        ehRecvr        (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
19:49:02.0363 4452        ehRecvr - ok
19:49:02.0379 4452        ehSched        (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
19:49:02.0379 4452        ehSched - ok
19:49:02.0519 4452        elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
19:49:02.0550 4452        elxstor - ok
19:49:02.0644 4452        ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
19:49:02.0644 4452        ErrDev - ok
19:49:02.0722 4452        EventSystem    (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
19:49:02.0722 4452        EventSystem - ok
19:49:02.0800 4452        exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
19:49:02.0800 4452        exfat - ok
19:49:02.0831 4452        fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
19:49:02.0831 4452        fastfat - ok
19:49:03.0034 4452        Fax            (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
19:49:03.0050 4452        Fax - ok
19:49:03.0268 4452        fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
19:49:03.0268 4452        fdc - ok
19:49:03.0362 4452        fdPHost        (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
19:49:03.0362 4452        fdPHost - ok
19:49:03.0377 4452        FDResPub        (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
19:49:03.0377 4452        FDResPub - ok
19:49:03.0471 4452        FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
19:49:03.0486 4452        FileInfo - ok
19:49:03.0533 4452        Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
19:49:03.0549 4452        Filetrace - ok
19:49:03.0580 4452        flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
19:49:03.0596 4452        flpydisk - ok
19:49:03.0674 4452        FltMgr          (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
19:49:03.0689 4452        FltMgr - ok
19:49:03.0767 4452        FontCache      (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
19:49:03.0798 4452        FontCache - ok
19:49:03.0970 4452        FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:49:03.0986 4452        FontCache3.0.0.0 - ok
19:49:04.0157 4452        FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
19:49:04.0173 4452        FsDepends - ok
19:49:04.0298 4452        Fs_Rec          (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
19:49:04.0313 4452        Fs_Rec - ok
19:49:04.0391 4452        fvevol          (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
19:49:04.0422 4452        fvevol - ok
19:49:05.0046 4452        FwLnk          (60acb128e64c35c2b4e4aab1b0a5c293) C:\Windows\system32\DRIVERS\FwLnk.sys
19:49:05.0062 4452        FwLnk - ok
19:49:05.0234 4452        gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
19:49:05.0249 4452        gagp30kx - ok
19:49:05.0343 4452        GameConsoleService (1fda0df739234c4023851a282dd28704) C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
19:49:05.0374 4452        GameConsoleService - ok
19:49:05.0468 4452        GEARAspiWDM    (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
19:49:05.0468 4452        GEARAspiWDM - ok
19:49:05.0748 4452        gpsvc          (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
19:49:05.0780 4452        gpsvc - ok
19:49:05.0967 4452        gupdate        (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:49:05.0967 4452        gupdate - ok
19:49:05.0998 4452        gupdatem        (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:49:05.0998 4452        gupdatem - ok
19:49:06.0076 4452        hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
19:49:06.0092 4452        hcw85cir - ok
19:49:06.0170 4452        HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
19:49:06.0201 4452        HdAudAddService - ok
19:49:06.0310 4452        HDAudBus        (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
19:49:06.0310 4452        HDAudBus - ok
19:49:06.0357 4452        HECIx64        (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
19:49:06.0372 4452        HECIx64 - ok
19:49:06.0497 4452        HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
19:49:06.0513 4452        HidBatt - ok
19:49:06.0575 4452        HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
19:49:06.0591 4452        HidBth - ok
19:49:06.0622 4452        HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
19:49:06.0638 4452        HidIr - ok
19:49:06.0684 4452        hidserv        (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
19:49:06.0684 4452        hidserv - ok
19:49:06.0809 4452        HidUsb          (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
19:49:06.0809 4452        HidUsb - ok
19:49:06.0887 4452        hkmsvc          (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
19:49:06.0887 4452        hkmsvc - ok
19:49:07.0059 4452        HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
19:49:07.0074 4452        HomeGroupListener - ok
19:49:07.0168 4452        HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
19:49:07.0168 4452        HomeGroupProvider - ok
19:49:07.0527 4452        hpqcxs08        (1dae5c46d42b02a6d5862e1482efb390) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
19:49:07.0527 4452        hpqcxs08 - ok
19:49:07.0730 4452        hpqddsvc        (99e8eef42fe2f4af29b08c3355dd7685) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
19:49:07.0730 4452        hpqddsvc - ok
19:49:08.0088 4452        HpSAMD          (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
19:49:08.0104 4452        HpSAMD - ok
19:49:08.0494 4452        HTTP            (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
19:49:08.0650 4452        HTTP - ok
19:49:08.0900 4452        hwpolicy        (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
19:49:08.0915 4452        hwpolicy - ok
19:49:09.0102 4452        i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
19:49:09.0134 4452        i8042prt - ok
19:49:09.0212 4452        iaStor          (85977cd13fc16069ce0af7943a811775) C:\Windows\system32\DRIVERS\iaStor.sys
19:49:09.0212 4452        iaStor - ok
19:49:09.0336 4452        iaStorV        (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
19:49:09.0352 4452        iaStorV - ok
19:49:09.0430 4452        idsvc          (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:49:09.0492 4452        idsvc - ok
19:49:09.0773 4452        iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
19:49:09.0789 4452        iirsp - ok
19:49:10.0226 4452        IKEEXT          (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
19:49:10.0257 4452        IKEEXT - ok
19:49:10.0350 4452        intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
19:49:10.0350 4452        intelide - ok
19:49:10.0428 4452        intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
19:49:10.0428 4452        intelppm - ok
19:49:10.0522 4452        IPBusEnum      (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
19:49:10.0522 4452        IPBusEnum - ok
19:49:10.0740 4452        IpFilterDriver  (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:49:10.0756 4452        IpFilterDriver - ok
19:49:11.0115 4452        iphlpsvc        (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
19:49:11.0130 4452        iphlpsvc - ok
19:49:11.0224 4452        IPMIDRV        (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
19:49:11.0224 4452        IPMIDRV - ok
19:49:11.0271 4452        IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
19:49:11.0271 4452        IPNAT - ok
19:49:11.0552 4452        iPod Service    (3c0d4b3e80fc4854ca325dd123cc4ded) C:\Program Files\iPod\bin\iPodService.exe
19:49:11.0583 4452        iPod Service - ok
19:49:11.0801 4452        IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
19:49:11.0801 4452        IRENUM - ok
19:49:11.0926 4452        isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
19:49:11.0942 4452        isapnp - ok
19:49:12.0035 4452        iScsiPrt        (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
19:49:12.0066 4452        iScsiPrt - ok
19:49:12.0347 4452        kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
19:49:12.0347 4452        kbdclass - ok
19:49:12.0722 4452        kbdhid          (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
19:49:12.0722 4452        kbdhid - ok
19:49:12.0909 4452        KeyIso          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:49:12.0909 4452        KeyIso - ok
19:49:12.0971 4452        KSecDD          (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
19:49:12.0987 4452        KSecDD - ok
19:49:13.0018 4452        KSecPkg        (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
19:49:13.0034 4452        KSecPkg - ok
19:49:13.0174 4452        ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
19:49:13.0190 4452        ksthunk - ok
19:49:13.0283 4452        KtmRm          (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
19:49:13.0299 4452        KtmRm - ok
19:49:13.0548 4452        L1C            (655a5d8e80869781cce23760ada7e695) C:\Windows\system32\DRIVERS\L1C62x64.sys
19:49:13.0548 4452        L1C - ok
19:49:14.0110 4452        LanmanServer    (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll
19:49:14.0110 4452        LanmanServer - ok
19:49:14.0235 4452        lirsgt          (156ab2e56dc3ca0b582e3362e07cded7) C:\Windows\system32\DRIVERS\lirsgt.sys
19:49:14.0235 4452        lirsgt - ok
19:49:14.0297 4452        lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
19:49:14.0313 4452        lltdio - ok
19:49:14.0391 4452        lltdsvc        (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
19:49:14.0406 4452        lltdsvc - ok
19:49:14.0547 4452        lmhosts        (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
19:49:14.0547 4452        lmhosts - ok
19:49:14.0640 4452        LMS            (23de5b62b0445a6f874be633c95b483e) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
19:49:14.0640 4452        LMS - ok
19:49:14.0781 4452        LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
19:49:14.0781 4452        LSI_FC - ok
19:49:14.0828 4452        LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
19:49:14.0828 4452        LSI_SAS - ok
19:49:14.0890 4452        LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
19:49:14.0906 4452        LSI_SAS2 - ok
19:49:15.0015 4452        LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
19:49:15.0015 4452        LSI_SCSI - ok
19:49:15.0062 4452        luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
19:49:15.0077 4452        luafv - ok
19:49:15.0171 4452        Mcx2Svc        (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
19:49:15.0186 4452        Mcx2Svc - ok
19:49:15.0218 4452        megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
19:49:15.0233 4452        megasas - ok
19:49:15.0249 4452        MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
19:49:15.0264 4452        MegaSR - ok
19:49:15.0452 4452        MMCSS          (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
19:49:15.0452 4452        MMCSS - ok
19:49:15.0748 4452        Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
19:49:15.0748 4452        Modem - ok
19:49:15.0904 4452        monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
19:49:15.0920 4452        monitor - ok
19:49:16.0013 4452        mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
19:49:16.0013 4452        mouclass - ok
19:49:16.0122 4452        mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
19:49:16.0122 4452        mouhid - ok
19:49:16.0325 4452        mountmgr        (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
19:49:16.0341 4452        mountmgr - ok
19:49:16.0434 4452        mpio            (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
19:49:16.0450 4452        mpio - ok
19:49:16.0528 4452        mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
19:49:16.0528 4452        mpsdrv - ok
19:49:16.0856 4452        MpsSvc          (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
19:49:16.0934 4452        MpsSvc - ok
19:49:17.0105 4452        MRxDAV          (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
19:49:17.0121 4452        MRxDAV - ok
19:49:17.0370 4452        mrxsmb          (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:49:17.0386 4452        mrxsmb - ok
19:49:17.0464 4452        mrxsmb10        (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:49:17.0480 4452        mrxsmb10 - ok
19:49:17.0526 4452        mrxsmb20        (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:49:17.0526 4452        mrxsmb20 - ok
19:49:17.0573 4452        msahci          (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
19:49:17.0589 4452        msahci - ok
19:49:17.0823 4452        msdsm          (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
19:49:17.0838 4452        msdsm - ok
19:49:17.0885 4452        MSDTC          (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
19:49:17.0901 4452        MSDTC - ok
19:49:18.0088 4452        Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
19:49:18.0088 4452        Msfs - ok
19:49:18.0338 4452        mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
19:49:18.0353 4452        mshidkmdf - ok
19:49:18.0587 4452        msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
19:49:18.0587 4452        msisadrv - ok
19:49:18.0665 4452        MSiSCSI        (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
19:49:18.0665 4452        MSiSCSI - ok
19:49:18.0696 4452        msiserver - ok
19:49:18.0852 4452        MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
19:49:18.0852 4452        MSKSSRV - ok
19:49:19.0118 4452        MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
19:49:19.0133 4452        MSPCLOCK - ok
19:49:19.0305 4452        MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
19:49:19.0305 4452        MSPQM - ok
19:49:19.0398 4452        MsRPC          (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
19:49:19.0398 4452        MsRPC - ok
19:49:19.0632 4452        mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
19:49:19.0632 4452        mssmbios - ok
19:49:19.0851 4452        MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
19:49:19.0851 4452        MSTEE - ok
19:49:19.0929 4452        MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
19:49:19.0929 4452        MTConfig - ok
19:49:19.0976 4452        Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
19:49:19.0976 4452        Mup - ok
19:49:20.0054 4452        napagent        (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
19:49:20.0069 4452        napagent - ok
19:49:20.0210 4452        NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
19:49:20.0225 4452        NativeWifiP - ok
19:49:20.0319 4452        NAUpdate        (9d1cce440552500ded3a62f9d779cdb4) c:\Program Files (x86)\Nero\Update\NASvc.exe
19:49:20.0319 4452        NAUpdate - ok
19:49:20.0553 4452        NDIS            (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
19:49:20.0584 4452        NDIS - ok
19:49:20.0678 4452        NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
19:49:20.0678 4452        NdisCap - ok
19:49:20.0724 4452        NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
19:49:20.0724 4452        NdisTapi - ok
19:49:20.0818 4452        Ndisuio        (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
19:49:20.0834 4452        Ndisuio - ok
19:49:21.0005 4452        NdisWan        (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
19:49:21.0021 4452        NdisWan - ok
19:49:21.0114 4452        NDProxy        (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
19:49:21.0114 4452        NDProxy - ok
19:49:21.0208 4452        Net Driver HPZ12 (d5ac41ae382738483faffbd7e373d49a) C:\Windows\system32\HPZinw12.dll
19:49:21.0208 4452        Net Driver HPZ12 - ok
19:49:21.0317 4452        NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
19:49:21.0333 4452        NetBIOS - ok
19:49:21.0380 4452        NetBT          (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
19:49:21.0395 4452        NetBT - ok
19:49:21.0458 4452        Netlogon        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:49:21.0458 4452        Netlogon - ok
19:49:21.0567 4452        Netman          (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
19:49:21.0614 4452        Netman - ok
19:49:21.0832 4452        NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:49:21.0848 4452        NetMsmqActivator - ok
19:49:21.0863 4452        NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:49:21.0863 4452        NetPipeActivator - ok
19:49:22.0113 4452        netprofm        (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
19:49:22.0128 4452        netprofm - ok
19:49:22.0331 4452        NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:49:22.0331 4452        NetTcpActivator - ok
19:49:22.0347 4452        NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:49:22.0347 4452        NetTcpPortSharing - ok
19:49:22.0440 4452        nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
19:49:22.0456 4452        nfrd960 - ok
19:49:22.0518 4452        NlaSvc          (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
19:49:22.0534 4452        NlaSvc - ok
19:49:22.0565 4452        Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
19:49:22.0581 4452        Npfs - ok
19:49:22.0612 4452        nsi            (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
19:49:22.0612 4452        nsi - ok
19:49:22.0643 4452        nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
19:49:22.0643 4452        nsiproxy - ok
19:49:23.0002 4452        Ntfs            (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
19:49:23.0080 4452        Ntfs - ok
19:49:23.0189 4452        Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
19:49:23.0189 4452        Null - ok
19:49:23.0252 4452        nvraid          (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
19:49:23.0267 4452        nvraid - ok
19:49:23.0314 4452        nvstor          (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
19:49:23.0314 4452        nvstor - ok
19:49:23.0376 4452        nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
19:49:23.0392 4452        nv_agp - ok
19:49:23.0439 4452        ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
19:49:23.0439 4452        ohci1394 - ok
19:49:23.0501 4452        ose            (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:49:23.0517 4452        ose - ok
19:49:23.0720 4452        osppsvc        (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
19:49:23.0907 4452        osppsvc - ok
19:49:24.0078 4452        p2pimsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
19:49:24.0094 4452        p2pimsvc - ok
19:49:24.0156 4452        p2psvc          (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
19:49:24.0172 4452        p2psvc - ok
19:49:24.0234 4452        Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
19:49:24.0234 4452        Parport - ok
19:49:24.0281 4452        partmgr        (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
19:49:24.0281 4452        partmgr - ok
19:49:24.0328 4452        PcaSvc          (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
19:49:24.0328 4452        PcaSvc - ok
19:49:24.0437 4452        pci            (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
19:49:24.0437 4452        pci - ok
19:49:24.0546 4452        pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
19:49:24.0562 4452        pciide - ok
19:49:24.0936 4452        pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
19:49:24.0952 4452        pcmcia - ok
19:49:24.0999 4452        pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
19:49:24.0999 4452        pcw - ok
19:49:25.0280 4452        PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
19:49:25.0326 4452        PEAUTH - ok
19:49:25.0420 4452        PerfHost        (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
19:49:25.0420 4452        PerfHost - ok
19:49:25.0529 4452        PGEffect        (663962900e7fea522126ba287715bb4a) C:\Windows\system32\DRIVERS\pgeffect.sys
19:49:25.0529 4452        PGEffect - ok
19:49:25.0701 4452        pla            (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
19:49:25.0763 4452        pla - ok
19:49:26.0091 4452        PlugPlay        (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
19:49:26.0231 4452        PlugPlay - ok
19:49:26.0387 4452        Pml Driver HPZ12 (37f6046cdc630442d7dc087501ff6fc6) C:\Windows\system32\HPZipm12.dll
19:49:26.0387 4452        Pml Driver HPZ12 - ok
19:49:26.0465 4452        PNRPAutoReg    (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
19:49:26.0465 4452        PNRPAutoReg - ok
19:49:26.0699 4452        PNRPsvc        (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
19:49:26.0699 4452        PNRPsvc - ok
19:49:27.0074 4452        PolicyAgent    (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
19:49:27.0214 4452        PolicyAgent - ok
19:49:27.0339 4452        Power          (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
19:49:27.0339 4452        Power - ok
19:49:27.0526 4452        PptpMiniport    (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
19:49:27.0557 4452        PptpMiniport - ok
19:49:27.0635 4452        Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
19:49:27.0635 4452        Processor - ok
19:49:27.0713 4452        ProfSvc        (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
19:49:27.0713 4452        ProfSvc - ok
19:49:27.0744 4452        ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:49:27.0760 4452        ProtectedStorage - ok
19:49:27.0838 4452        Psched          (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
19:49:27.0838 4452        Psched - ok
19:49:28.0119 4452        ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
19:49:28.0166 4452        ql2300 - ok
19:49:28.0306 4452        ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
19:49:28.0306 4452        ql40xx - ok
19:49:28.0431 4452        QWAVE          (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
19:49:28.0431 4452        QWAVE - ok
19:49:28.0462 4452        QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
19:49:28.0478 4452        QWAVEdrv - ok
19:49:28.0493 4452        RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
19:49:28.0493 4452        RasAcd - ok
19:49:28.0540 4452        RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
19:49:28.0556 4452        RasAgileVpn - ok
19:49:28.0680 4452        RasAuto        (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
19:49:28.0680 4452        RasAuto - ok
19:49:28.0790 4452        Rasl2tp        (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:49:28.0805 4452        Rasl2tp - ok
19:49:28.0899 4452        RasMan          (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
19:49:28.0899 4452        RasMan - ok
19:49:29.0024 4452        RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
19:49:29.0039 4452        RasPppoe - ok
19:49:29.0086 4452        RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
19:49:29.0102 4452        RasSstp - ok
19:49:29.0180 4452        rdbss          (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
19:49:29.0180 4452        rdbss - ok
19:49:29.0273 4452        rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
19:49:29.0289 4452        rdpbus - ok
19:49:29.0523 4452        RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:49:29.0632 4452        RDPCDD - ok
19:49:29.0944 4452        RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
19:49:29.0960 4452        RDPENCDD - ok
19:49:30.0147 4452        RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
19:49:30.0162 4452        RDPREFMP - ok
19:49:30.0459 4452        RDPWD          (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
19:49:30.0506 4452        RDPWD - ok
19:49:30.0646 4452        rdyboost        (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
19:49:30.0662 4452        rdyboost - ok
19:49:30.0755 4452        RemoteAccess    (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
19:49:30.0755 4452        RemoteAccess - ok
19:49:30.0911 4452        RemoteRegistry  (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
19:49:30.0911 4452        RemoteRegistry - ok
19:49:30.0958 4452        RpcEptMapper    (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
19:49:30.0974 4452        RpcEptMapper - ok
19:49:31.0052 4452        RpcLocator      (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
19:49:31.0052 4452        RpcLocator - ok
19:49:31.0176 4452        RpcSs          (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
19:49:31.0176 4452        RpcSs - ok
19:49:31.0239 4452        rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
19:49:31.0239 4452        rspndr - ok
19:49:31.0364 4452        RSUSBSTOR      (907c4464381b5ebdfdc60f6c7d0dedfc) C:\Windows\system32\Drivers\RtsUStor.sys
19:49:31.0364 4452        RSUSBSTOR - ok
19:49:31.0551 4452        rtl8192se      (7475548b0ba58eba4d12414fc9e9dfe6) C:\Windows\system32\DRIVERS\rtl8192se.sys
19:49:31.0566 4452        rtl8192se - ok
19:49:31.0816 4452        SamSs          (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:49:31.0832 4452        SamSs - ok
19:49:32.0159 4452        sbp2port        (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
19:49:32.0175 4452        sbp2port - ok
19:49:32.0284 4452        SCardSvr        (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
19:49:32.0284 4452        SCardSvr - ok
19:49:32.0409 4452        scfilter        (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
19:49:32.0409 4452        scfilter - ok
19:49:32.0596 4452        Schedule        (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
19:49:32.0612 4452        Schedule - ok
19:49:32.0705 4452        SCPolicySvc    (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
19:49:32.0705 4452        SCPolicySvc - ok
19:49:32.0799 4452        SDRSVC          (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
19:49:32.0799 4452        SDRSVC - ok
19:49:32.0877 4452        SeaPort        (4a5809a1d796e2675ac0332bf7b0cb11) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
19:49:32.0877 4452        SeaPort - ok
19:49:32.0955 4452        secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
19:49:32.0970 4452        secdrv - ok
19:49:33.0064 4452        seclogon        (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
19:49:33.0064 4452        seclogon - ok
19:49:33.0126 4452        SENS            (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll
19:49:33.0126 4452        SENS - ok
19:49:33.0158 4452        SensrSvc        (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
19:49:33.0158 4452        SensrSvc - ok
19:49:33.0251 4452        Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
19:49:33.0282 4452        Serenum - ok
19:49:33.0392 4452        Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
19:49:33.0392 4452        Serial - ok
19:49:33.0454 4452        sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
19:49:33.0454 4452        sermouse - ok
19:49:33.0626 4452        SessionEnv      (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
19:49:33.0626 4452        SessionEnv - ok
19:49:33.0719 4452        sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
19:49:33.0719 4452        sffdisk - ok
19:49:33.0766 4452        sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
19:49:33.0766 4452        sffp_mmc - ok
19:49:33.0813 4452        sffp_sd        (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
19:49:33.0813 4452        sffp_sd - ok
19:49:33.0860 4452        sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
19:49:33.0875 4452        sfloppy - ok
19:49:34.0031 4452        Sftfs          (c6cc9297bd53e5229653303e556aa539) C:\Windows\system32\DRIVERS\Sftfslh.sys
19:49:34.0047 4452        Sftfs - ok
19:49:34.0452 4452        sftlist        (13693b6354dd6e72dc5131da7d764b90) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
19:49:34.0468 4452        sftlist - ok
19:49:34.0702 4452        Sftplay        (390aa7bc52cee43f6790cdea1e776703) C:\Windows\system32\DRIVERS\Sftplaylh.sys
19:49:34.0702 4452        Sftplay - ok
19:49:34.0764 4452        Sftredir        (617e29a0b0a2807466560d4c4e338d3e) C:\Windows\system32\DRIVERS\Sftredirlh.sys
19:49:34.0780 4452        Sftredir - ok
19:49:34.0920 4452        Sftvol          (8f571f016fa1976f445147e9e6c8ae9b) C:\Windows\system32\DRIVERS\Sftvollh.sys
19:49:34.0920 4452        Sftvol - ok
19:49:35.0045 4452        sftvsa          (c3cddd18f43d44ab713cf8c4916f7696) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
19:49:35.0045 4452        sftvsa - ok
19:49:35.0310 4452        SharedAccess    (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
19:49:35.0310 4452        SharedAccess - ok
19:49:35.0451 4452        ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
19:49:35.0466 4452        ShellHWDetection - ok
19:49:35.0622 4452        SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
19:49:35.0622 4452        SiSRaid2 - ok
19:49:35.0669 4452        SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
19:49:35.0669 4452        SiSRaid4 - ok
19:49:35.0763 4452        Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
19:49:35.0778 4452        Smb - ok
19:49:35.0981 4452        SNMPTRAP        (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
19:49:35.0981 4452        SNMPTRAP - ok
19:49:36.0059 4452        spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
19:49:36.0075 4452        spldr - ok
19:49:36.0184 4452        Spooler        (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
19:49:36.0184 4452        Spooler - ok
19:49:36.0434 4452        sppsvc          (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
19:49:36.0480 4452        sppsvc - ok
19:49:36.0590 4452        sppuinotify    (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
19:49:36.0605 4452        sppuinotify - ok
19:49:36.0714 4452        srv            (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
19:49:36.0777 4452        srv - ok
19:49:36.0995 4452        srv2            (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
19:49:37.0042 4452        srv2 - ok
19:49:37.0151 4452        srvnet          (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
19:49:37.0167 4452        srvnet - ok
19:49:37.0229 4452        SSDPSRV        (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
19:49:37.0229 4452        SSDPSRV - ok
19:49:37.0276 4452        SstpSvc        (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
19:49:37.0276 4452        SstpSvc - ok
19:49:37.0354 4452        stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
19:49:37.0401 4452        stexstor - ok
19:49:37.0650 4452        stisvc          (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
19:49:37.0666 4452        stisvc - ok
19:49:37.0900 4452        swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
19:49:37.0916 4452        swenum - ok
19:49:38.0025 4452        swprv          (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
19:49:38.0040 4452        swprv - ok
19:49:38.0290 4452        SynTP          (470c47daba9ca3966f0ab3f835d7d135) C:\Windows\system32\DRIVERS\SynTP.sys
19:49:38.0290 4452        SynTP - ok
19:49:38.0508 4452        SysMain        (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
19:49:38.0571 4452        SysMain - ok
19:49:38.0820 4452        TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
19:49:38.0836 4452        TabletInputService - ok
19:49:38.0898 4452        TapiSrv        (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
19:49:38.0914 4452        TapiSrv - ok
19:49:39.0008 4452        TBS            (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
19:49:39.0023 4452        TBS - ok
19:49:39.0382 4452        Tcpip          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
19:49:39.0491 4452        Tcpip - ok
19:49:39.0772 4452        TCPIP6          (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
19:49:39.0788 4452        TCPIP6 - ok
19:49:39.0944 4452        tcpipreg        (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
19:49:39.0959 4452        tcpipreg - ok
19:49:40.0100 4452        tdcmdpst        (fd542b661bd22fa69ca789ad0ac58c29) C:\Windows\system32\DRIVERS\tdcmdpst.sys
19:49:40.0115 4452        tdcmdpst - ok
19:49:40.0178 4452        TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
19:49:40.0193 4452        TDPIPE - ok
19:49:40.0349 4452        TDTCP          (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
19:49:40.0349 4452        TDTCP - ok
19:49:40.0568 4452        tdx            (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
19:49:40.0568 4452        tdx - ok
19:49:40.0677 4452        TemproMonitoringService (40e154b3125e17ce6f2afad57afcfeb2) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
19:49:40.0724 4452        TemproMonitoringService - ok
19:49:40.0817 4452        TermDD          (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
19:49:40.0817 4452        TermDD - ok
19:49:40.0989 4452        TermService    (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
19:49:41.0004 4452        TermService - ok
19:49:41.0145 4452        Themes          (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
19:49:41.0145 4452        Themes - ok
19:49:41.0176 4452        THREADORDER    (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
19:49:41.0192 4452        THREADORDER - ok
19:49:41.0332 4452        TMachInfo      (28644b0523d64eff2fc7312a2ee74b0a) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
19:49:41.0348 4452        TMachInfo - ok
19:49:41.0535 4452        TODDSrv        (ed32035bdfeced1ad66d459fd9cc1140) C:\Windows\system32\TODDSrv.exe
19:49:41.0535 4452        TODDSrv - ok
19:49:41.0660 4452        TosCoSrv        (db9719688c08f42705feb3f6a0c98b91) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
19:49:41.0660 4452        TosCoSrv - ok
19:49:41.0706 4452        TOSHIBA eco Utility Service (3e6756677e16532d235c6cb20614f369) C:\Program Files\TOSHIBA\TECO\TecoService.exe
19:49:41.0706 4452        TOSHIBA eco Utility Service - ok
19:49:41.0784 4452        TOSHIBA HDD SSD Alert Service (74c2fa8c3765ee71a9c22182ec108457) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
19:49:41.0784 4452        TOSHIBA HDD SSD Alert Service - ok
19:49:41.0894 4452        TPCHSrv        (97687d094aa597da366e1194b218cc6c) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
19:49:41.0925 4452        TPCHSrv - ok
19:49:42.0018 4452        TrkWks          (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
19:49:42.0018 4452        TrkWks - ok
19:49:42.0096 4452        TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
19:49:42.0096 4452        TrustedInstaller - ok
19:49:42.0174 4452        tssecsrv        (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:49:42.0174 4452        tssecsrv - ok
19:49:42.0284 4452        TsUsbFlt        (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
19:49:42.0284 4452        TsUsbFlt - ok
19:49:42.0471 4452        tunnel          (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
19:49:42.0471 4452        tunnel - ok
19:49:42.0564 4452        TVALZ          (550b567f9364d8f7684c3fb3ea665a72) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
19:49:42.0580 4452        TVALZ - ok
19:49:42.0736 4452        TVALZFL        (9c7191f4b2e49bff47a6c1144b5923fa) C:\Windows\system32\DRIVERS\TVALZFL.sys
19:49:42.0736 4452        TVALZFL - ok
19:49:42.0876 4452        uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
19:49:42.0892 4452        uagp35 - ok
19:49:43.0001 4452        udfs            (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
19:49:43.0032 4452        udfs - ok
19:49:43.0313 4452        UI0Detect      (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
19:49:43.0313 4452        UI0Detect - ok
19:49:43.0360 4452        uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
19:49:43.0360 4452        uliagpkx - ok
19:49:43.0422 4452        umbus          (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
19:49:43.0438 4452        umbus - ok
19:49:43.0734 4452        UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
19:49:43.0750 4452        UmPass - ok
19:49:44.0031 4452        UNS            (cc3775100aba633984f73dfae1f55cae) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
19:49:44.0078 4452        UNS - ok
19:49:44.0218 4452        upnphost        (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
19:49:44.0218 4452        upnphost - ok
19:49:44.0405 4452        USBAAPL64      (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
19:49:44.0405 4452        USBAAPL64 - ok
19:49:44.0499 4452        usbccgp        (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
19:49:44.0514 4452        usbccgp - ok
19:49:44.0577 4452        usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
19:49:44.0592 4452        usbcir - ok
19:49:44.0670 4452        usbehci        (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
19:49:44.0670 4452        usbehci - ok
19:49:44.0795 4452        usbhub          (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
19:49:44.0826 4452        usbhub - ok
19:49:44.0951 4452        usbohci        (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
19:49:44.0967 4452        usbohci - ok
19:49:45.0138 4452        usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
19:49:45.0154 4452        usbprint - ok
19:49:45.0279 4452        usbscan        (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
19:49:45.0279 4452        usbscan - ok
19:49:45.0404 4452        USBSTOR        (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:49:45.0404 4452        USBSTOR - ok
19:49:45.0513 4452        usbuhci        (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
19:49:45.0513 4452        usbuhci - ok
19:49:45.0716 4452        usbvideo        (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
19:49:45.0731 4452        usbvideo - ok
19:49:45.0950 4452        UxSms          (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
19:49:45.0965 4452        UxSms - ok
19:49:46.0028 4452        VaultSvc        (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:49:46.0028 4452        VaultSvc - ok
19:49:46.0121 4452        VClone          (fd911873c0bb6945fa38c16e9a2b58f9) C:\Windows\system32\DRIVERS\VClone.sys
19:49:46.0168 4452        VClone - ok
19:49:46.0340 4452        vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
19:49:46.0355 4452        vdrvroot - ok
19:49:46.0574 4452        vds            (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
19:49:46.0589 4452        vds - ok
19:49:47.0010 4452        vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
19:49:47.0010 4452        vga - ok
19:49:47.0073 4452        VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
19:49:47.0073 4452        VgaSave - ok
19:49:47.0151 4452        vhdmp          (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
19:49:47.0166 4452        vhdmp - ok
19:49:47.0322 4452        viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
19:49:47.0322 4452        viaide - ok
19:49:47.0354 4452        volmgr          (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
19:49:47.0354 4452        volmgr - ok
19:49:47.0447 4452        volmgrx        (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
19:49:47.0463 4452        volmgrx - ok
19:49:47.0525 4452        volsnap        (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
19:49:47.0556 4452        volsnap - ok
19:49:47.0697 4452        vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
19:49:47.0712 4452        vsmraid - ok
19:49:47.0790 4452        VSS            (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
19:49:47.0822 4452        VSS - ok
19:49:47.0900 4452        vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
19:49:47.0915 4452        vwifibus - ok
19:49:47.0962 4452        vwififlt        (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
19:49:47.0962 4452        vwififlt - ok
19:49:48.0071 4452        vwifimp        (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
19:49:48.0071 4452        vwifimp - ok
19:49:48.0274 4452        W32Time        (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
19:49:48.0274 4452        W32Time - ok
19:49:48.0399 4452        WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
19:49:48.0414 4452        WacomPen - ok
19:49:48.0711 4452        WANARP          (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
19:49:48.0726 4452        WANARP - ok
19:49:48.0742 4452        Wanarpv6        (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
19:49:48.0742 4452        Wanarpv6 - ok
19:49:49.0475 4452        wbengine        (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
19:49:49.0506 4452        wbengine - ok
19:49:49.0584 4452        WbioSrvc        (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
19:49:49.0584 4452        WbioSrvc - ok
19:49:49.0678 4452        wcncsvc        (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
19:49:49.0678 4452        wcncsvc - ok
19:49:49.0725 4452        WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
19:49:49.0725 4452        WcsPlugInService - ok
19:49:49.0787 4452        Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
19:49:49.0787 4452        Wd - ok
19:49:49.0850 4452        Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
19:49:49.0912 4452        Wdf01000 - ok
19:49:50.0052 4452        WdiServiceHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
19:49:50.0052 4452        WdiServiceHost - ok
19:49:50.0068 4452        WdiSystemHost  (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
19:49:50.0068 4452        WdiSystemHost - ok
19:49:50.0208 4452        WebClient      (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
19:49:50.0208 4452        WebClient - ok
19:49:50.0318 4452        Wecsvc          (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
19:49:50.0318 4452        Wecsvc - ok
19:49:50.0349 4452        wercplsupport  (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
19:49:50.0349 4452        wercplsupport - ok
19:49:50.0380 4452        WerSvc          (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
19:49:50.0380 4452        WerSvc - ok
19:49:50.0598 4452        WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
19:49:50.0614 4452        WfpLwf - ok
19:49:50.0676 4452        WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
19:49:50.0692 4452        WIMMount - ok
19:49:50.0895 4452        WinDefend - ok
19:49:50.0926 4452        WinHttpAutoProxySvc - ok
19:49:51.0051 4452        Winmgmt        (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
19:49:51.0051 4452        Winmgmt - ok
19:49:51.0207 4452        WinRM          (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
19:49:51.0254 4452        WinRM - ok
19:49:51.0566 4452        WinUsb          (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
19:49:51.0566 4452        WinUsb - ok
19:49:51.0987 4452        Wlansvc        (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
19:49:52.0049 4452        Wlansvc - ok
19:49:52.0205 4452        wlcrasvc        (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
19:49:52.0268 4452        wlcrasvc - ok
19:49:52.0346 4452        wlidsvc        (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:49:52.0377 4452        wlidsvc - ok
19:49:52.0470 4452        WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
19:49:52.0470 4452        WmiAcpi - ok
19:49:52.0626 4452        wmiApSrv        (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
19:49:52.0626 4452        wmiApSrv - ok
19:49:52.0736 4452        WMPNetworkSvc - ok
19:49:52.0938 4452        WPCSvc          (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
19:49:52.0938 4452        WPCSvc - ok
19:49:53.0079 4452        WPDBusEnum      (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
19:49:53.0079 4452        WPDBusEnum - ok
19:49:53.0250 4452        ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
19:49:53.0250 4452        ws2ifsl - ok
19:49:53.0422 4452        wscsvc          (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll
19:49:53.0422 4452        wscsvc - ok
19:49:53.0500 4452        WSearch - ok
19:49:54.0124 4452        wuauserv        (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
19:49:54.0202 4452        wuauserv - ok
19:49:54.0623 4452        WudfPf          (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
19:49:54.0639 4452        WudfPf - ok
19:49:54.0748 4452        WUDFRd          (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:49:54.0764 4452        WUDFRd - ok
19:49:54.0873 4452        wudfsvc        (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
19:49:54.0873 4452        wudfsvc - ok
19:49:55.0044 4452        WwanSvc        (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
19:49:55.0060 4452        WwanSvc - ok
19:49:55.0185 4452        MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
19:49:55.0247 4452        \Device\Harddisk0\DR0 - ok
19:49:55.0263 4452        MBR (0x1B8)    (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR1
19:49:55.0263 4452        \Device\Harddisk1\DR1 - ok
19:49:55.0294 4452        Boot (0x1200)  (40a5a910bc56917a255e7a1cfa5f32f3) \Device\Harddisk0\DR0\Partition0
19:49:55.0294 4452        \Device\Harddisk0\DR0\Partition0 - ok
19:49:55.0559 4452        Boot (0x1200)  (83e5e0e9a43c1de4ee77bed41a405271) \Device\Harddisk0\DR0\Partition1
19:49:55.0559 4452        \Device\Harddisk0\DR0\Partition1 - ok
19:49:55.0575 4452        Boot (0x1200)  (0ee0cefe49d48e22e0f39493bc5186eb) \Device\Harddisk1\DR1\Partition0
19:49:55.0575 4452        \Device\Harddisk1\DR1\Partition0 - ok
19:49:55.0575 4452        ============================================================
19:49:55.0575 4452        Scan finished
19:49:55.0575 4452        ============================================================
19:49:55.0590 4140        Detected object count: 0
19:49:55.0590 4140        Actual detected object count: 0


markusg 13.04.2012 15:29

besteht das problem mit der firewall noch?

KenoP 13.04.2012 16:40

Nein, sie funltioniert wieder =)

markusg 13.04.2012 19:36

das ist doch schon mal was.
lade den CCleaner standard:
CCleaner Download - CCleaner 3.17.1689
falls der CCleaner
bereits instaliert, überspringen.
instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

KenoP 13.04.2012 21:13

Ich wusste nicht so genau ob die Zusaztausstattung von Toshiba, auch der Hersteller meines Lapptops, wirklich notwendig für meinen Pc ist, da ich sie eigentlich noch nie richtig genutzt habe .
Ebens weiß ich nicht wozu die ganzen Microsoftprogramme zuständig sind, ich habe sie erstmal als notwendig gekennzeichnet.


Code:

Adobe AIR        Adobe Systems Inc.        15.11.2010                2.0.3.13070        -notwendig-
Adobe Flash Player 11 ActiveX 64-bit        Adobe Systems Incorporated        23.03.2012        6,00MB        11.1.102.63        -notwendig-       
Adobe Flash Player 11 Plugin 64-bit        Adobe Systems Incorporated        02.04.2012        6,00MB        11.2.202.228        -notwendig-
Adobe Reader 9.5.1 - Deutsch        Adobe Systems Incorporated        11.04.2012        118,6MB        9.5.1        -notwendig-
Amazon.de        Amazon EU S.a.r.L.        26.12.2010        -unnötig-               
Apple Application Support        Apple Inc.        30.10.2011        61,1MB        2.1.5        -notwendig-
Apple Mobile Device Support        Apple Inc.        30.10.2011        24,4MB        4.0.0.96        -notwendig-
Apple Software Update        Apple Inc.        05.07.2011        2,25MB        2.1.3.127        -notwendig-
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver        Atheros Communications Inc.        26.12.2010        -unbekannt-                1.0.0.26
ATI Catalyst Install Manager        ATI Technologies, Inc.        26.12.2010        22,3MB        3.0.769.0        -notwendig-
Avira AntiVir Personal - Free Antivirus        Avira GmbH        04.04.2012        74,3MB        10.2.0.707        -notwendig-
Bing Bar        Microsoft Corporation        26.12.2010                5.0.1401.0        -unnötig-
Black & White® 2        Lionhead Studios        08.10.2011                1.00.0000        -unnötig-
Bonjour        Apple Inc.        30.10.2011        2,00MB        3.0.0.10 -ubekannt-
CCleaner        Piriform        12.04.2012                3.17 -notwendig-
Conexant Audio Driver For AMD HDMI Codec        Conexant        26.12.2010                4.98.26.0        -notwendig-
Conexant HD Audio        Conexant        26.12.2010                4.119.0.61        -notwendig-
DivX-Setup        DivX, LLC        26.03.2012                2.6.1.8 -unnötig-
EAX Unified                10.09.2011                -unbekannt-
eBay        eBay Inc.        15.11.2010        0,16MB        1.1.9        unnötig-
eMpTy-V-loader version 2.2        Daniel Schmidt        23.08.2011        1,27MB        2.2 -unbeannt-
Facebook Video Calling 1.2.0.159        Skype Limited        22.03.2012        4,76MB        1.2.159 -notwendig-
Google Earth Plug-in        Google        04.03.2012        48,7MB        6.2.1.6014        -notwendig-
HP Customer Participation Program 13.0        HP        28.02.2012                13.0 -notwendig-
HP Deskjet All-In-One Driver Software 13.0 Rel. 1        HP        28.02.2012                13.0        -notwendig-
HP Imaging Device Functions 13.0        HP        28.02.2012                13.0        -notwendig-
HP Photosmart Essential 3.5        HP        28.02.2012                3.5        -notwendig-
HP Smart Web Printing 4.51        HP        28.02.2012                4.51        -notwendig-
HP Solution Center 13.0        HP        28.02.2012                13.0        -notwendig-
HP Update        Hewlett-Packard        28.02.2012        3,73MB        4.000.011.006        -notwendig-
inSSIDer 2.0        MetaGeek        02.02.2012        4,31MB        2.0.7        -unbekannt-
Intel(R) Management Engine Components        Intel Corporation        27.12.2010                6.0.0.1179        -notwendig-
Intel(R) Rapid Storage Technology        Intel Corporation        13.04.2012                9.5.7.1002        -notwendig-
iTunes        Apple Inc.        30.10.2011        169,5MB        10.5.0.142        -notwendig-
Java(TM) 6 Update 31        Oracle        15.02.2012        95,1MB        6.0.310        -notwendig-
JDownloader 0.9        AppWork GmbH        15.03.2012                0.9        -unnötig-
K-Lite Codec Pack 6.0.4 (Basic)                03.08.2011        14,2MB        6.0.4        -unbeannt-
Malwarebytes Anti-Malware Version 1.60.1.1000        Malwarebytes Corporation        01.04.2012        17,4MB        1.60.1.1000        -notwendig-
Microsoft .NET Framework 4 Client Profile        Microsoft Corporation        07.07.2011        38,8MB        4.0.30319        -notwendig-
Microsoft .NET Framework 4 Client Profile DEU Language Pack        Microsoft Corporation        07.07.2011        2,94MB        4.0.30319        -notwendig-
Microsoft .NET Framework 4 Extended        Microsoft Corporation        03.08.2011        52,0MB        4.0.30319        -notwendig-
Microsoft .NET Framework 4 Extended DEU Language Pack        Microsoft Corporation        03.08.2011        10,7MB        4.0.30319        -notwendig-
Microsoft Office 2010        Microsoft Corporation        26.12.2010        6,31MB        14.0.4763.1000        -notwendig-
Microsoft Office Klick-und-Los 2010        Microsoft Corporation        10.08.2011                14.0.4763.1000        -notwendig-
Microsoft Office Starter 2010 - Deutsch        Microsoft Corporation        10.08.2011                14.0.4763.1000        -notwendig-
Microsoft Silverlight        Microsoft Corporation        17.02.2012        94,5MB        4.1.10111.0        -notwendig-
Microsoft SQL Server 2005 Compact Edition [ENU]        Microsoft Corporation        15.11.2010        1,70MB        3.1.0000        -notwendig-
Microsoft Visual C++ 2005 Redistributable        Microsoft Corporation        31.03.2012        2,38MB        8.0.61001        -notwendig-
Microsoft Visual C++ 2005 Redistributable (x64)        Microsoft Corporation        31.03.2012        0,82MB        8.0.61000        -notwendig-
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17        Microsoft Corporation        15.11.2010        0,77MB        9.0.30729        -notwendig-
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148        Microsoft Corporation        26.12.2010        0,77MB        9.0.30729.4148        -notwendig-
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161        Microsoft Corporation        23.08.2011        0,77MB        9.0.30729.6161        -notwendig-
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17        Microsoft Corporation        15.11.2010        0,58MB        9.0.30729        -notwendig-
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148        Microsoft Corporation        15.11.2010        0,58MB        9.0.30729.4148        -notwendig-
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161        Microsoft Corporation        27.08.2011        0,59MB        9.0.30729.6161        -notwendig-
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219        Microsoft Corporation        16.10.2011        12,3MB        10.0.40219        -notwendig-
Microsoft WSE 3.0 Runtime        Microsoft Corp.        18.08.2011        0,92MB        3.0.5305.0
Midnight Racing                17.02.2012                1.0        -notwendig-
Mozilla Firefox 11.0 (x86 de)        Mozilla        17.03.2012        35,9MB        11.0        -notwendig-
MSXML 4.0 SP2 (KB954430)        Microsoft Corporation        06.07.2011        1,28MB        4.20.9870.0        -notwendig-
MSXML 4.0 SP2 (KB973688)        Microsoft Corporation        06.07.2011        1,33MB        4.20.9876.0        -notwendig-
Nero BackItUp 10        Nero AG        15.11.2010        107,5MB        5.4.24700.31.100        -notwendig-
Nero BurnRights 10        Nero AG        15.11.2010        6,42MB        4.0.11300.14.100        -notwendig-
Nero Express 10        Nero AG        15.11.2010        159,5MB        10.0.12100.22.100        -notwendig-
Nero InfoTool 10        Nero AG        15.11.2010        8,35MB        7.0.11400.15.100        -notwendig-
Nero MediaHub 10        Nero AG        15.11.2010        159,0MB        1.0.14800.28.100        -notwendig-
Nero Multimedia Suite 10 Essentials        Nero AG        15.11.2010        704MB        10.0.15000        -notwendig-
Nero RescueAgent 10        Nero AG        15.11.2010        6,83MB        3.0.11800.26.100        -notwendig-
Nero StartSmart 10        Nero AG        15.11.2010        137,1MB        10.0.12300.27.100        -notwendig-
Nero Update        Nero AG        15.11.2010        1,44MB        1.0.0018        -notwendig-
NVIDIA PhysX        NVIDIA Corporation        14.09.2011        119,9MB        9.09.0209        -notwendig-
OpenOffice.org 3.3        OpenOffice.org        03.12.2011        415MB        3.3.9567        -notwendig-
Photo Service - powered by myphotobook        myphotobook GmbH        15.11.2010                1.2.0-545        -notwendig-
PlayReady PC Runtime amd64        Microsoft Corporation        15.11.2010        2,06MB        1.3.0        -notwendig-
QuickTime        Apple Inc.        30.10.2011        73,3MB        7.71.80.42        -notwendig-
Realtek USB 2.0 Card Reader        Realtek Semiconductor Corp.        15.11.2010                6.1.7600.30111        -notwendig-
Realtek WLAN Driver        REALTEK Semiconductor Corp.        26.12.2010                2.00.0013        -notwendig-
Sacred 2        Ascaron Entertainment        17.09.2011        12.321MB        2.0.2.0        -unnötig-
Shop for HP Supplies        HP        28.02.2012                13.0        -notwendig-
Skype Toolbars        Skype Technologies S.A.        15.11.2010        5,36MB        1.0.4051 -notwendig-
Skype™ 5.5        Skype Technologies S.A.        31.12.2011        17,0MB        5.5.124        -notwendig-
Spotify        Spotify AB        27.03.2012                0.8.2.610.g090a06f8        -unnötig-
Synaptics Pointing Device Driver        Synaptics Incorporated        15.11.2010                15.0.8.1        -unbekannt-
Toshiba Assist        TOSHIBA        15.11.2010                3.00.10                -unbekannt-
TOSHIBA Bulletin Board        TOSHIBA Corporation        26.12.2010                1.6.08.64        -unbekannt-
TOSHIBA ConfigFree        TOSHIBA CORPORATION        26.12.2010        91,5MB        8.0.34        -unbekannt-
TOSHIBA Disc Creator        TOSHIBA Corporation        15.11.2010        10,3MB        2.1.0.2 for x64        -unbekannt-
TOSHIBA eco Utility        TOSHIBA Corporation        26.12.2010        6,99MB        1.2.10.64        -unbekannt-
TOSHIBA Face Recognition        TOSHIBA Corporation        26.12.2010                3.1.3.64        -unbekannt-
TOSHIBA Hardware Setup        TOSHIBA Corporation        26.12.2010                2.00.06        -unbekannt-
TOSHIBA HDD/SSD Alert        TOSHIBA Corporation        15.11.2010        39,4MB        3.1.64.6        -unbekannt-
Toshiba Manuals        TOSHIBA        15.11.2010                10.02        -unbekannt-
TOSHIBA Media Controller        TOSHIBA CORPORATION        26.12.2010                        -unbekannt-
TOSHIBA Media Controller Plug-in        TOSHIBA CORPORATION        26.12.2010        4,89MB        1.0.5.12        -unbekannt-
TOSHIBA Online Product Information        TOSHIBA        15.11.2010                2.09.0001        -unbekannt-
TOSHIBA PC Health Monitor        TOSHIBA Corporation        26.12.2010        28,0MB        1.6.0.64        -unbekannt-
TOSHIBA Recovery Media Creator        TOSHIBA Corporation        15.11.2010        3,11MB        2.1.0.5 x64        -unbekannt-
TOSHIBA Recovery Media Creator Reminder        TOSHIBA        15.11.2010        0,45MB        1.00.0019        -unbekannt-
TOSHIBA ReelTime        TOSHIBA Corporation        26.12.2010                1.7.16.64        -unbekannt-
TOSHIBA Service Station        TOSHIBA        26.12.2010                2.1.40        -unbekannt-
TOSHIBA Supervisor Password        TOSHIBA Corporation        26.12.2010                2.00.03        -unbekannt-
Toshiba TEMPRO        Toshiba Europe GmbH        15.11.2010        10,9MB        3.33        -unbekannt-
TOSHIBA Value Added Package        TOSHIBA Corporation        26.12.2010        86,4MB        1.3.19.64        -unbekannt-
TOSHIBA Web Camera Application        TOSHIBA Corporation        26.12.2010                1.1.1.15        -unbekannt-
TRORMCLauncher                26.12.2010        -unbekannt-               
WildTangent-Spiele        WildTangent        26.12.2010                1.0.1.5        -unnötig-
Windows Live Essentials        Microsoft Corporation        16.11.2010                15.4.3502.0922        -unbekannt-
Windows Live Mesh ActiveX control for remote connections        Microsoft Corporation        15.11.2010        5,58MB        15.4.5722.2        -unbekannt-
WinRAR 4.01 (64-Bit)        win.rar GmbH        05.07.2011                4.01.0        -notwendig-


markusg 14.04.2012 20:04

deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden
adobe reader:
Adobe - Adobe Reader herunterladen - Alle Versionen
haken bei mcafee security scan raus nehmen

bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok



deinstaliere:
Amazon
Bing
Black &
DivX
eBay
JDownloader
K-Lite
Sacred
Skype Toolbars
Spotify
WildTangent
Windows Live : alle die du nicht nutzt

öffne otl, bereinigen, pc startetneu
öffne ccleaner analysieren, ccleaner starten, pc neustarten, testen wie das system läuft

KenoP 15.04.2012 17:50

Also hab jetzt alle Programme gelöscht, jezt wird aber immer mal zwischendurch der Ton so komische verzerrt und die die Wiedergabe der Medien wird verlangsamt, z.B. bei Videos oder Musik.
Ansonsten ist das eingentliche Problem gelöst, die Firewall ist wieder eingeschaltet.

KenoP 16.04.2012 20:51

Hey, die Störgeräusche sind jetzt weg und System läuft einwandfrei :)
Vielen vielen Dank, dass du mir so schnell und ausführlich geholfen hast. Ich hoffe dieses Forum gibt es auch weiterhin, da es einfach einzigartig ist mit seiner Professionalität und den super Helfern ;) vor allem den einen den ich abbekommen habe =) :daumenhoc
Danke !!!
Ich hab nur noch eine Frage: Kann ich jetzt AVG installieren ?


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:23 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20