Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   neuen GVU-trojaner mit web-cam eingefangen (bin laie) (https://www.trojaner-board.de/118589-neuen-gvu-trojaner-web-cam-eingefangen-laie.html)

Schmelzkas 04.07.2012 20:09

OTL logfile created on: 04.07.2012 19:55:32 - Run 1
 
OTL logfile created on: 04.07.2012 19:55:32 - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Manu&Micha\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

5,90 Gb Total Physical Memory | 4,92 Gb Available Physical Memory | 83,36% Memory free
11,79 Gb Paging File | 10,89 Gb Available in Paging File | 92,34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 446,13 Gb Total Space | 362,59 Gb Free Space | 81,28% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 171,79 Gb Free Space | 36,88% Space Free | Partition Type: NTFS

Computer Name: PC-FAMILIE-KIS | User Name: Familie *** | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\**********\Downloads\OTL.exe (OldTimer Tools)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV:64bit: - (EvtEng) Intel(R) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) Intel(R) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV:64bit: - (BTHSSecurityMgr) Intel(R) Centrino(R) Wireless Bluetooth(R) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel(R) Corporation)
SRV:64bit: - (AMPPALR3) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (TurboBoost) Intel(R) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NAUpdate) @C:\Program Files (x86) -- C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (FSORSPClient) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (Bluetooth OBEX Service) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation)
SRV - (Bluetooth Media Service) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation)
SRV - (Bluetooth Device Monitor) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (SftService) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (RoxWatch12) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FSMA) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSDFWD) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\FWES\Program\fsdfwd.exe (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (fsbts) -- C:\WINDOWS\SysNative\drivers\fsbts.sys ()
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\WINDOWS\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (iBtFltCoex) -- C:\WINDOWS\SysNative\drivers\iBtFltCoex.sys (Intel Corporation)
DRV:64bit: - (btmhsf) -- C:\WINDOWS\SysNative\drivers\btmhsf.sys (Intel Corporation)
DRV:64bit: - (FSES) -- C:\WINDOWS\SysNative\drivers\fses.sys (F-Secure Corporation)
DRV:64bit: - (NETwNs64) ___ Intel(R) -- C:\WINDOWS\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (AMPPALP) -- C:\WINDOWS\SysNative\drivers\AmpPal.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (AMPPAL) -- C:\WINDOWS\SysNative\drivers\AmpPal.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (nvpciflt) -- C:\WINDOWS\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (Sftvol) -- C:\WINDOWS\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\WINDOWS\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\WINDOWS\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\WINDOWS\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\WINDOWS\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\WINDOWS\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (btmaux) -- C:\WINDOWS\SysNative\drivers\btmaux.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\WINDOWS\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (Netaapl) -- C:\WINDOWS\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (igfx) -- C:\WINDOWS\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) -- C:\WINDOWS\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (iwdbus) -- C:\WINDOWS\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (intaud_WaveExtensible) -- C:\WINDOWS\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) -- C:\WINDOWS\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\WINDOWS\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (NvStUSB) -- C:\WINDOWS\SysNative\drivers\nvstusb.sys ()
DRV:64bit: - (CtClsFlt) -- C:\WINDOWS\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (iaStor) -- C:\WINDOWS\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (Acceler) -- C:\WINDOWS\SysNative\drivers\Accelern.sys (ST Microelectronics)
DRV:64bit: - (TurboB) -- C:\WINDOWS\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\WINDOWS\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\WINDOWS\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\WINDOWS\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel(R) -- C:\WINDOWS\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel(R) -- C:\WINDOWS\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (SynTP) -- C:\WINDOWS\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (stdcfltn) -- C:\WINDOWS\SysNative\drivers\stdcfltn.sys (ST Microelectronics)
DRV:64bit: - (qicflt) -- C:\WINDOWS\SysNative\drivers\qicflt.sys (Quanta Computer)
DRV:64bit: - (PxHlpa64) -- C:\WINDOWS\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Impcd) -- C:\WINDOWS\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (FSFW) -- C:\WINDOWS\SysNative\drivers\fsdfw.sys (F-Secure Corporation)
DRV:64bit: - (amdsbs) -- C:\WINDOWS\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\WINDOWS\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\WINDOWS\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\WINDOWS\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:\WINDOWS\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\WINDOWS\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\WINDOWS\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\WINDOWS\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\WINDOWS\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\WINDOWS\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WimFltr) -- C:\WINDOWS\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (F-Secure Gatekeeper) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsgk.sys ()
DRV - (fsbts) -- C:\WINDOWS\SysWOW64\drivers\fsbts.sys ()
DRV - (F-Secure HIPS) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (fsvista) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsvista.sys ()
DRV - (WIMMount) -- C:\WINDOWS\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE:64bit: - HKLM\..\SearchScopes\{8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE - HKLM\..\SearchScopes\{8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKCU\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: C:\Program Files (x86)\VR-Web Sicherheitspaket\NRS\litmus-ff@f-secure.com [2012.06.05 05:42:50 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files (x86)\VR-Web Sicherheitspaket\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files (x86)\VR-Web Sicherheitspaket\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Stage Remote] C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKLM..\RunOnce: [ICDRegOCX0] C:\Windows\SysWow64\IEAdvpack.dll (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000023 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} https://www.icloud.com/system/iCloud.cab (iCloud Web App Plugin)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0B79CA25-257B-4436-9C60-6B7D0E3BA12F}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E21BF8B8-85B1-44CF-A7C8-4B8D5CDD54E7}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\WINDOWS\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\WINDOWS\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012.06.21 14:13:27 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012.06.21 14:13:27 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012.06.21 14:13:26 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012.06.21 14:13:06 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012.06.21 14:13:06 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012.06.21 14:13:06 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012.06.21 14:12:57 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012.06.21 14:12:57 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012.06.20 14:23:52 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012.06.20 14:23:52 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012.06.14 11:41:58 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012.06.14 11:41:58 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012.06.14 11:41:58 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012.06.14 11:41:58 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012.06.14 11:41:57 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012.06.14 11:41:57 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012.06.14 11:41:57 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012.06.14 11:41:57 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012.06.14 11:41:56 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012.06.14 11:41:56 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012.06.14 11:41:56 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012.06.14 11:41:55 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012.06.14 11:41:55 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012.06.14 09:55:17 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012.06.14 09:55:17 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012.06.14 09:55:17 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012.06.14 09:54:50 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012.06.14 09:54:45 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012.06.14 09:54:43 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012.06.14 09:54:30 | 003,216,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2012.06.14 09:54:12 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012.06.14 09:54:11 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012.06.12 11:45:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.12 11:44:58 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.12 11:44:57 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.12 11:44:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes

========== Files - Modified Within 30 Days ==========

[2012.07.04 19:41:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.04 19:40:56 | 453,640,191 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.04 18:44:28 | 004,503,728 | ---- | M] () -- C:\ProgramData\l_u0_0.pad
[2012.07.04 18:01:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.04 17:00:00 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012.07.04 14:40:54 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.04 14:40:54 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.04 14:34:30 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.04 13:55:56 | 001,636,224 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.07.04 13:55:56 | 000,704,554 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.07.04 13:55:56 | 000,659,832 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.04 13:55:56 | 000,151,676 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.07.04 13:55:56 | 000,124,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.07.01 17:50:12 | 000,002,046 | ---- | M] () -- C:\Windows\tasks\hpwebreg_CN17F232ZR05JW.job
[2012.06.18 13:54:53 | 000,319,144 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.13 14:48:49 | 000,002,767 | ---- | M] () -- C:\Users\Public\Desktop\SyncUP.lnk
[2012.06.11 10:40:14 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012.06.11 10:40:14 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.06.08 19:34:37 | 000,000,592 | ---- | M] () -- C:\Windows\wiso.ini

========== Files Created - No Company Name ==========

[2012.07.04 13:55:07 | 004,503,728 | ---- | C] () -- C:\ProgramData\l_u0_0.pad
[2012.06.13 14:48:49 | 000,002,767 | ---- | C] () -- C:\Users\Public\Desktop\SyncUP.lnk
[2012.02.13 18:48:28 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012.02.13 18:48:27 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.02.13 18:48:25 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2012.01.26 09:15:18 | 000,000,592 | ---- | C] () -- C:\Windows\wiso.ini
[2011.11.10 15:02:07 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.11.09 21:40:56 | 000,042,672 | ---- | C] () -- C:\Windows\SysWow64\drivers\fsbts.sys
[2011.09.04 18:14:20 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.09.04 18:14:15 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.02.11 12:22:50 | 001,614,118 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

< End of report >

OTL Extras logfile created on: 04.07.2012 19:52:21 - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Manu&Micha\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

5,90 Gb Total Physical Memory | 5,04 Gb Available Physical Memory | 85,44% Memory free
11,79 Gb Paging File | 10,95 Gb Available in Paging File | 92,89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 446,13 Gb Total Space | 362,60 Gb Free Space | 81,28% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 171,79 Gb Free Space | 36,88% Space Free | Partition Type: NTFS

Computer Name: PC-FAMILIE-KIS | User Name: Familie Kis | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0CE47953-3018-496B-ADCB-01DA519C5C52}" = rport=137 | protocol=17 | dir=out | app=system |
"{15AEA468-3658-4791-A4FB-D6B7C0634BF7}" = lport=445 | protocol=6 | dir=in | app=system |
"{3E5ADC2C-9AA4-4B49-8D06-4F42897495B6}" = lport=137 | protocol=17 | dir=in | app=system |
"{427ABD68-AAAA-4E33-8398-36D1778CD7CB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{49C01C75-B8FC-49B3-A5B6-F2798C752E3D}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4F4C29A1-76F4-48AB-9C12-745D084E2365}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{521D1A7A-6EF2-416E-88A6-64862B1AFBCE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{52455552-7CA8-4C9A-9202-02C1F8B5C71F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{544799DA-3FFE-4AF5-A81B-0CF1F4E5D194}" = lport=138 | protocol=17 | dir=in | app=system |
"{663CBDFE-F086-477D-B03C-556D376E64C9}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{6A80C42B-2DAA-4564-9A3F-FAD2F96ADB95}" = rport=138 | protocol=17 | dir=out | app=system |
"{6BD7A234-E09F-41FB-B402-F4FD63EAA0AA}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{7AF17284-921D-4EF1-B8B3-4F2DD094F57B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{85815A28-D0B0-4615-A8E2-7E4DDE578B93}" = lport=9700 | protocol=17 | dir=in | name=syncup_udp_9700 |
"{877B8FB6-0831-48E5-9B66-2B1A4FA37D65}" = rport=139 | protocol=6 | dir=out | app=system |
"{89183243-A91D-4AAF-859F-5EF4067DC303}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8EC55C8F-836A-4275-8505-BD29780F5D1D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{96CBC303-787A-47D6-BFB7-1BA72881EB79}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{98FA4FEF-37F7-4621-BF0C-9711980A7AA6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9A76F116-B0C9-4B56-99DD-E9542F1E17E5}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{9DEE76FE-F348-446C-816D-B2314BD47897}" = lport=139 | protocol=6 | dir=in | app=system |
"{AB128467-6896-42BF-A633-C4DBF8D61723}" = rport=445 | protocol=6 | dir=out | app=system |
"{B6169184-6095-45CC-86DF-180E89EE3F22}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C6F00A0A-8C36-4C5F-82A8-6437188ED440}" = lport=9701 | protocol=6 | dir=in | name=syncup_tcp_9701 |
"{E7DCB591-318E-4230-BF01-499F130D0110}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EA3867E6-FCCA-4074-8967-53AB45427264}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EF0A97F7-8452-413C-8451-446E84038F8C}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F89D3CEB-720B-4358-BA0B-56583A6E0718}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FBB41206-F948-4167-A4D3-A88B1E855E16}" = lport=9702 | protocol=6 | dir=in | name=syncup_tcp_9702 |
"{FE4B3B3B-F9CF-4B43-9664-368804981316}" = lport=9700 | protocol=6 | dir=in | name=syncup_tcp_9700 |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01EDD04C-41B3-4D0D-B9BE-42F9910FA072}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe |
"{0F693BAE-F559-40AB-BFB5-11AA3A5D922B}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremote.exe |
"{1566765A-75F3-4C45-9E26-0B910192B0E6}" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet 6500 e710n-z\bin\hpnetworkcommunicator.exe |
"{173D12C2-D521-404E-8C7A-D5E55BF375B1}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\controller.exe |
"{199F38BB-F3CE-4843-83A7-DD171401038A}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremote.exe |
"{1D702905-8587-4CCF-A3EC-EB57FADC89AD}" = dir=in | app=c:\program files (x86)\dell\videostage\videostage.exe |
"{206725CB-FF36-4201-8818-A030A44029FB}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{329D6840-959E-4AEA-858D-B46F71D56434}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{339EBCC8-0A9A-4D0B-9735-E4F8CFE5B0EA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{39DB9F25-5E2D-4407-91BE-6CAA7505A1D5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3C790775-5167-4C01-902A-CE7C3A8C3941}" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet 6500 e710n-z\bin\devicesetup.exe |
"{3E79D69A-EC7E-4B41-A2B6-18E9D30CCABE}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\installerhelp.exe |
"{40324FC4-3190-44EA-8EA0-14DA01B7EA2B}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{408F603B-E30B-4D78-8E92-A5101C85FF24}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{44163625-11D3-42D7-B71B-8427E6A75BD2}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\dmr.exe |
"{46C0A58D-1893-4073-95A3-A58870A3843A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{49B52138-8014-4E0D-A75E-C8E8200CD0ED}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{50AFA3BA-2655-4892-B748-3CBC1D9E836C}" = dir=in | app=c:\program files\dell stage\dell stage\stage_primary.exe |
"{58C4A6E0-FC2E-42C8-9AAA-ED233657D3D0}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{5A82CDB8-3796-41E5-9879-C95683072C1B}" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet 6500 e710n-z\bin\devicesetup.exe |
"{63BF8D0C-6460-489A-9495-9832B3BC5C88}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{640982C9-35A8-419E-A52D-991CEE49E8F1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{691CA600-FEA1-4E1B-A85C-362A0714262D}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{6FB16CCE-074F-463E-8A4F-0D60A3AE3A19}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{7A5C977A-8909-474D-87A0-8D46166165F3}" = protocol=17 | dir=in | app=c:\program files (x86)\dell\stage remote\stageremoteservice.exe |
"{8326D8AE-2E40-4B39-A1C8-1521BC510C30}" = dir=in | app=c:\program files\dell stage\dell stage\accuweather\accuweather.exe |
"{834A43FC-FEBE-4B37-990B-8C45661A963B}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{8A37E44D-385E-489D-BB81-55835482B699}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\dmr.exe |
"{8BAADCDF-1B72-430F-B8E2-162A06AE1790}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8C77CDEA-C62E-4370-8BA0-40A238211888}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{8E9FA262-6C13-421D-86BB-FBF333E9C630}" = dir=in | app=c:\program files (x86)\intel corporation\intel widi\widiapp.exe |
"{91AC097D-DC86-4918-81EF-52577D67EF37}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\installerhelp.exe |
"{92FDEBBE-0DF1-41D3-8047-188D806246CA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A80416CC-786D-41DB-89A2-EFD2E7E89CA8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AD4DC30A-8AE1-43AA-803B-05F815C20C50}" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet 6500 e710n-z\bin\hpnetworkcommunicator.exe |
"{B1C4A220-1818-40A1-9CCD-CDC2EDB28742}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C7C42589-43B3-491B-8DB2-F440ECDCE71A}" = dir=in | app=c:\program files\dell stage\musicstage\musicstageengine.exe |
"{CA790AA6-F2BC-4A91-9F9A-F1FBC6193144}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{CD116302-767C-4678-9C2D-F3649D85F6E2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D04AD301-C0AA-4988-A561-9B0F24D8C549}" = protocol=6 | dir=out | app=system |
"{D2EDB294-E68C-4EA4-90C1-7A4858D94257}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D47C9E5E-8398-4273-9EF8-C99F0363CF0D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D57B707A-CF28-4B80-A6E9-62F040AEE03D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E7EB0351-5764-44F0-8108-A914359B1903}" = protocol=6 | dir=in | app=c:\program files (x86)\dell\stage remote\controller.exe |
"{F24D4C1A-A338-4858-AF87-1DABAAFF1184}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{F3CFA907-B13B-4B60-8EB0-A5EE675B89DB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F62D5324-1A6A-43FA-8D96-BBD5339367A5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F6B155DF-00C7-4F0C-B2FF-900A47E51BC0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FECAC864-D0AF-4B2B-9B17-D04754835E88}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416024FF}" = Java(TM) 6 Update 24 (64-bit)
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display
"{2ABA2E8D-23CF-418F-BC8F-2EC99FA51A3F}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{AF43C18E-693D-4126-B190-8F55E3623D5D}" = HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 269.59
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 269.59
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 269.59
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.23
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.2.24.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Überwachungstool für die Intel® Turbo-Boost-Technik 2.0
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D61E4101-9E15-4D0E-ABD1-1ABD36B43330}" = Intel(R) PROSet/Wireless WiFi-Software
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Dell Support Center" = Dell Support Center
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CC1DAFB-40C8-4903-953D-471E541477C7}" = WISO Steuer-Sparbuch 2012
"{0DD706AF-B542-438C-999E-B30C7F625C8D}" = Intel(R) WiDi
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{130E5108-547F-4482-91EE-F45C784E08C7}" = HP Officejet 6500 E710n-z Hilfe
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2299EEBD-0A83-4B26-AA4A-057AE9E5BAE8}" = Dell Stage Remote
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 29
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3E90B7F4-1817-4405-B4A5-E4EA5EC0E2B3}" = Dell MusicStage
"{40F06490-8C14-43AA-99D3-EEEFDBAC3CFC}" = SyncUP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{554A4E80-0002-2006-0407-11FF59A27A18}" = 3D-Garten 8.0
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7FB00B6B-6843-97EC-EED6-78BD6D35370A}" = Zinio Reader 4
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{87434D51-51DB-4109-B68F-A829ECDCF380}" = AccelerometerP11
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{9193490D-5229-4FC4-9BB9-A6D63C09574A}" = High-Definition Video Playback
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8B88634-7F90-402F-B66A-86429755F6A5}" = eBay
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.3) MUI
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{AF4D3C63-009B-4A17-B02E-D395065DD3F0}" = Dell Stage Remote
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92C9CCE-E5F0-4125-977A-0590F3225B74}" = SyncUP
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2F57269-065E-4B19-8CDA-AB6C401FAF1A}" = Dell Stage
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Dell Webcam Central" = Dell Webcam Central
"F-Secure Product 444" = VR-Web Sicherheitspaket 4.0
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"ProInst" = Intel PROSet Wireless
"WinLiveSuite" = Windows Live Essentials
"ZinioReader4" = Zinio Reader 4

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 09.06.2012 04:50:33 | Computer Name = PC-Familie-Kis | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10.06.2012 06:41:24 | Computer Name = PC-Familie-Kis | Source = WinMgmt | ID = 10
Description =

Error - 10.06.2012 07:05:20 | Computer Name = PC-Familie-Kis | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10.06.2012 12:45:32 | Computer Name = PC-Familie-Kis | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10.06.2012 13:41:33 | Computer Name = PC-Familie-Kis | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 11.06.2012 03:25:00 | Computer Name = PC-Familie-Kis | Source = WinMgmt | ID = 10
Description =

Error - 12.06.2012 04:30:15 | Computer Name = PC-Familie-Kis | Source = WinMgmt | ID = 10
Description =

Error - 12.06.2012 04:53:42 | Computer Name = PC-Familie-Kis | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 12.06.2012 05:47:02 | Computer Name = PC-Familie-Kis | Source = WinMgmt | ID = 10
Description =

Error - 12.06.2012 14:31:41 | Computer Name = PC-Familie-Kis | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 14.04.2012 04:18:52 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
FSES

Error - 14.04.2012 04:19:20 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
von Dienst SftService erreicht.

Error - 14.04.2012 04:19:50 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
von Dienst SftService erreicht.

Error - 15.04.2012 09:14:24 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
FSES

Error - 15.04.2012 09:15:10 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
von Dienst SftService erreicht.

Error - 15.04.2012 16:51:27 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
FSES

Error - 15.04.2012 16:51:55 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
von Dienst SftService erreicht.

Error - 15.04.2012 16:52:25 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
von Dienst SftService erreicht.

Error - 16.04.2012 02:16:36 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7026
Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
FSES

Error - 16.04.2012 02:17:54 | Computer Name = PC-Familie-Kis | Source = Service Control Manager | ID = 7011
Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung
von Dienst SftService erreicht.


< End of report >

Schmelzkas 05.07.2012 05:07

neuen GVU-trojaner mit web-cam eingefangen (bin laie)
 
habe mir den gvu-trojaner eingefangen.
den otl hab ich schon gemacht. soweit so gut.

jetzt wirds für mich kompliziert, da ich nur am pc bin um max fotos abzuspeichern usw.

bitte um hilfe, dass ich dieses ding wieder los werde.#
die otl-texte hab ich beigefügt

Danke

cosinus 05.07.2012 15:27

Zitat:

Boot Mode: SafeMode with Networking |
Wenn dieser Modus funktioniert, kannst du erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Schmelzkas 05.07.2012 19:15

Hallo, habe Malware und ESET ausgeführt und ereldigt. Jetzt hab ich auch den Text in das feld eingetragen. Was dann? Problem auch, ich weiss nicht welche BIt-Variante wir haben. Und ich weiss dann auch nicht weiter. Wo soll ich wie was posten?? LOG.txt???

Hilfe, wie gesagt ich bin Laie. ich kann gut nach Anleitung arbeiten, aber das wars

OK, hab die version gefunden und uach den Log.txt ist jetzt da.

Aber wie mach ich das mit den code Tags??

Es lässt sich nur der erste Teil kopieren und "Enter" kann ich in der Ausführen-datei nicht machen, sonst klicke ich ok.

cosinus 05.07.2012 20:27

Also was du wie posten musst wurde echt alles bis ins kleinste Detail beschrieben!

Schmelzkas 05.07.2012 20:42

muss ich in die ausführen-datei rein oder hier im forum posten?

Tut mir ja echt leid, meine Kentnisse sind die eines Laien.:wtf::killpc:

cosinus 05.07.2012 21:03

Tur mir ja echt Leid für dich, aber wenn dich diese bis ins kleinste Detail ausgearbeiteten Anleitungen überfordern, wirst du hier nicht vernünftig dein Problem gelöst bekommen - ich denke ein Vor-Ort-Service wäre besser für dich

Schmelzkas 05.07.2012 21:12

ok dann hier:

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK


cosinus 05.07.2012 21:19

ESET hast du wahrscheinlich falsch gemacht, da gab es extra einen dicken Hinweis zu

Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen

Schmelzkas 05.07.2012 21:26

Unser Pc meldet sich von allein wenn es um Admin..rechte geht. Ich schalte ihn dann frei.

cosinus 05.07.2012 21:40

Und wieder hast du mal nicht richtig gelesen was in meiner Antwort steht! :stirn:

Schmelzkas 05.07.2012 22:22

Das hab ich schon. Ich habe auf den ESET-Button geklickt. Mit der rechten Maustaste. Es öffnet sich dann das Fenster Öffnen, in neuer Registerkarte öffnen usw.. Kein Fenster als "Admisnistrator anmelden".

Ich mach für heut schluss. melde mich morgen direkt als Administrator an.
Das geht ja.

Oder hab ich da auch schon wieder einen Denkfehler mit der rechten Maustaste auf dem ESET-Button?

Sollte das der Fall, bitte melden, dann geh ich zu nem Profi.

Aber so blöd kann ich gar nicht sein, wenn ich otl usw hinkriege.

Ich bin nur manchmal etwas kompliziert vom denken her, halt ne Frau. Es hat ja schliesslich geklappt mit dem posten. Ich mag doof:rolleyes: klingen, aber mir selber helfen mit ein wenig Hilfe von anderen geht bei mir.

Ich bitte um Antwort wg. dem ESET.

Danke

cosinus 06.07.2012 09:40

Zitat:

Bitte den Browser unbedingt so öffnen: per Rechtsklick => als Administrator ausführen
Was ist hier dran nicht zu verstehen?!
Browser komplett beenden, dann per Rechtsklick auf Firefox => als Administrator ausführen!
Bei einigen Anleitungen musst du noch mehr genau beachten also lies und arbeite sorgfältiger! Wenn du das nicht kannst oder willst musst du halt jmd für Geld kommen lassen

Schmelzkas 06.07.2012 10:19

Danke. Ich hab mir es schon gedacht das ich ganz zu Anfang den
Denkfehler hatte. Ich probiere es heut Nachmittag. Und wir werden
sehen. Ich brauch langer als andere aber ich Kriegs hin. Jetzt hat mich der
Ehrgeiz gepackt.

Schmelzkas 07.07.2012 17:33

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=da7ff7af0d166246a10290f25d65ee20
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-07 04:22:37
# local_time=2012-07-07 06:22:37 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=2304 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776573 100 94 348388 93302142 0 0
# compatibility_mode=8192 67108863 100 0 167988 167988 0 0
# scanned=159975
# found=3
# cleaned=0
# scan_time=5865
C:\Users\Manu&Micha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2NWLCZHI\main[1].htm        JS/Kryptik.QT trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\5f5b18de-2c08252d        probably a variant of Java/Exploit.CVE-2012-0507.CP trojan (unable to clean)        00000000000000000000000000000000        I
D:\PC-FAMILIE-KIS\Backup Set 2011-11-09 201640\Backup Files 2012-03-25 190001\Backup files 1.zip        a variant of Java/Exploit.CVE-2012-0507.B trojan (unable to clean)        00000000000000000000000000000000        I


cosinus 09.07.2012 11:10

Hätte da mal zwei Fragen bevor es weiter geht

1.) Geht der normale Modus von Windows (wieder) uneingeschränkt?
2.) Vermisst du irgendwas im Startmenü? Sind da leere Ordner unter alle Programme oder ist alles vorhanden?

Schmelzkas 09.07.2012 16:43

war bis jetzt nur im abgesicherten modus. ich probier´s. meld mich dann

sieht soweit so gut aus. Nur AppData ist nicht richtig da. F-secure hat sich grad aktualisiert.
Bin im normalen Modus jetzt.
Wie schauts aus? muss ich noch was machen?
Was kann ich vorbeugend tun?

cosinus 09.07.2012 19:05

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

Schmelzkas 09.07.2012 20:01

Anhang anbei:abklatsch:

cosinus 10.07.2012 11:04

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Schmelzkas 10.07.2012 17:57

OTL Logfile:
Code:

OTL logfile created on: 10.07.2012 18:35:59 - Run 2
OTL by OldTimer - Version 3.2.53.1    Folder = C:\
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,90 Gb Total Physical Memory | 4,08 Gb Available Physical Memory | 69,18% Memory free
11,79 Gb Paging File | 9,67 Gb Available in Paging File | 81,97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 446,13 Gb Total Space | 362,51 Gb Free Space | 81,26% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 171,87 Gb Free Space | 36,90% Space Free | Partition Type: NTFS
 
Computer Name: PC-FAMILIE-KIS | User Name: Familie Kis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\OTL3.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\fssm32.exe (F-Secure Corporation)
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\FSGK32.EXE (F-Secure Corporation)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Intel Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
PRC - C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe ()
PRC - C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe ()
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
PRC - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSHDLL32.EXE (F-Secure Corporation)
PRC - C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\de-DE\UI\ManagerUI.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\DataService.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\sqlite3.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll ()
MOD - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
MOD - c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll ()
MOD - C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\QtGui4.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\QtXml4.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\QtCore4.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qmng4.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Dell\Stage Remote\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPC\fspcfsm.eng ()
MOD - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\strres.eng ()
MOD - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\gres.dll ()
MOD - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\fsavures.eng ()
MOD - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\flyerres.eng ()
MOD - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\aboutres.dll ()
MOD - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\about.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (EvtEng) Intel(R) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) Intel(R) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation)
SRV:64bit: - (BTHSSecurityMgr) Intel(R) Centrino(R) Wireless Bluetooth(R) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel(R) Corporation)
SRV:64bit: - (AMPPALR3) -- C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (TurboBoost) Intel(R) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NAUpdate) @C:\Program Files (x86) -- C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (FSORSPClient) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (Bluetooth OBEX Service) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation)
SRV - (Bluetooth Media Service) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation)
SRV - (Bluetooth Device Monitor) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (SftService) -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (RoxWatch12) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (clr_optimization_v4.0.30319_32) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FSMA) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSDFWD) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\FWES\Program\fsdfwd.exe (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (fsbts) -- C:\WINDOWS\SysNative\drivers\fsbts.sys ()
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\WINDOWS\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (iBtFltCoex) -- C:\WINDOWS\SysNative\drivers\iBtFltCoex.sys (Intel Corporation)
DRV:64bit: - (btmhsf) -- C:\WINDOWS\SysNative\drivers\btmhsf.sys (Intel Corporation)
DRV:64bit: - (FSES) -- C:\WINDOWS\SysNative\drivers\fses.sys (F-Secure Corporation)
DRV:64bit: - (NETwNs64) ___ Intel(R) -- C:\WINDOWS\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (AMPPALP) -- C:\WINDOWS\SysNative\drivers\AmpPal.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (AMPPAL) -- C:\WINDOWS\SysNative\drivers\AmpPal.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (nvpciflt) -- C:\WINDOWS\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (Sftvol) -- C:\WINDOWS\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\WINDOWS\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\WINDOWS\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\WINDOWS\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\WINDOWS\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\WINDOWS\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (btmaux) -- C:\WINDOWS\SysNative\drivers\btmaux.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\WINDOWS\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (Netaapl) -- C:\WINDOWS\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (igfx) -- C:\WINDOWS\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) -- C:\WINDOWS\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (iwdbus) -- C:\WINDOWS\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (intaud_WaveExtensible) -- C:\WINDOWS\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) -- C:\WINDOWS\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\WINDOWS\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (NvStUSB) -- C:\WINDOWS\SysNative\drivers\nvstusb.sys ()
DRV:64bit: - (CtClsFlt) -- C:\WINDOWS\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (iaStor) -- C:\WINDOWS\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (Acceler) -- C:\WINDOWS\SysNative\drivers\Accelern.sys (ST Microelectronics)
DRV:64bit: - (TurboB) -- C:\WINDOWS\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\WINDOWS\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\WINDOWS\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\WINDOWS\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel(R) -- C:\WINDOWS\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel(R) -- C:\WINDOWS\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (SynTP) -- C:\WINDOWS\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (stdcfltn) -- C:\WINDOWS\SysNative\drivers\stdcfltn.sys (ST Microelectronics)
DRV:64bit: - (qicflt) -- C:\WINDOWS\SysNative\drivers\qicflt.sys (Quanta Computer)
DRV:64bit: - (PxHlpa64) -- C:\WINDOWS\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Impcd) -- C:\WINDOWS\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (FSFW) -- C:\WINDOWS\SysNative\drivers\fsdfw.sys (F-Secure Corporation)
DRV:64bit: - (amdsbs) -- C:\WINDOWS\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\WINDOWS\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\WINDOWS\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\WINDOWS\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:\WINDOWS\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\WINDOWS\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\WINDOWS\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\WINDOWS\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\WINDOWS\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\WINDOWS\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WimFltr) -- C:\WINDOWS\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (F-Secure Gatekeeper) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsgk.sys ()
DRV - (fsbts) -- C:\WINDOWS\SysWOW64\drivers\fsbts.sys ()
DRV - (F-Secure HIPS) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (fsvista) -- C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsvista.sys ()
DRV - (WIMMount) -- C:\WINDOWS\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE:64bit: - HKLM\..\SearchScopes\{8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE - HKLM\..\SearchScopes\{8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1000\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1001\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USCON/8
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1004\..\SearchScopes,DefaultScope = {8DC416EF-BEC2-4506-A1FB-852D2B6F6D64}
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1867405292-980960165-4268742590-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: C:\Program Files (x86)\VR-Web Sicherheitspaket\NRS\litmus-ff@f-secure.com [2012.06.05 05:42:50 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files (x86)\VR-Web Sicherheitspaket\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files (x86)\VR-Web Sicherheitspaket\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll (Intel Corporation)
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [NVHotkey] C:\Windows\SysNative\nvHotkey.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\WINDOWS\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Stage Remote] C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe ()
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files (x86)\VR-Web Sicherheitspaket\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1001..\Run: [BrowserChoice] "C:\WINDOWS\System32\browserchoice.exe" /run File not found
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1004..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1004..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1004..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000023 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\fslsp_x64.dll (F-Secure Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} https://www.icloud.com/system/iCloud.cab (iCloud Web App Plugin)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0B79CA25-257B-4436-9C60-6B7D0E3BA12F}: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E21BF8B8-85B1-44CF-A7C8-4B8D5CDD54E7}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\WINDOWS\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\WINDOWS\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
 
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: MCODS - Reg Error: Value error.
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: MCODS - Reg Error: Value error.
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: MCODS - Reg Error: Value error.
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.10 18:31:24 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\OTL3.exe
[2012.07.05 18:05:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.07.05 17:17:06 | 000,000,000 | ---D | C] -- C:\Users\Familie Kis\AppData\Roaming\Malwarebytes
[2012.07.05 17:17:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.05 17:17:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.05 17:17:02 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.07.05 17:17:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.06.12 11:45:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.12 11:44:58 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.12 11:44:57 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.12 11:44:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.10 18:31:24 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\OTL3.exe
[2012.07.10 18:22:03 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.07.10 18:04:44 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.10 18:04:44 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.10 18:01:01 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.07.10 17:57:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.10 17:57:14 | 000,000,530 | ---- | M] () -- C:\Windows\tasks\Scheduled scanning task.job
[2012.07.10 17:57:09 | 453,640,191 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.09 20:57:54 | 000,618,655 | ---- | M] () -- C:\adwcleaner.exe
[2012.07.09 20:35:39 | 000,001,752 | ---- | M] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2012.07.05 17:17:03 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.04 18:44:28 | 004,503,728 | ---- | M] () -- C:\ProgramData\l_u0_0.pad
[2012.07.04 17:00:00 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012.07.04 13:55:56 | 001,636,224 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.07.04 13:55:56 | 000,704,554 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.07.04 13:55:56 | 000,659,832 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.07.04 13:55:56 | 000,151,676 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.07.04 13:55:56 | 000,124,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.07.01 17:50:12 | 000,002,046 | ---- | M] () -- C:\Windows\tasks\hpwebreg_CN17F232ZR05JW.job
[2012.06.18 13:54:53 | 000,319,144 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.06.13 14:48:49 | 000,002,767 | ---- | M] () -- C:\Users\Public\Desktop\SyncUP.lnk
 
========== Files Created - No Company Name ==========
 
[2012.07.10 10:13:15 | 000,000,530 | ---- | C] () -- C:\Windows\tasks\Scheduled scanning task.job
[2012.07.09 20:57:54 | 000,618,655 | ---- | C] () -- C:\adwcleaner.exe
[2012.07.09 20:35:39 | 000,001,752 | ---- | C] () -- C:\Users\Public\Desktop\Browserwahl.lnk
[2012.07.05 17:17:03 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.04 13:55:07 | 004,503,728 | ---- | C] () -- C:\ProgramData\l_u0_0.pad
[2012.06.13 14:48:49 | 000,002,767 | ---- | C] () -- C:\Users\Public\Desktop\SyncUP.lnk
[2012.02.13 18:48:28 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012.02.13 18:48:27 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012.02.13 18:48:25 | 013,903,872 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2012.01.26 09:15:18 | 000,000,592 | ---- | C] () -- C:\Windows\wiso.ini
[2011.11.10 15:02:07 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.11.09 21:40:56 | 000,042,672 | ---- | C] () -- C:\Windows\SysWow64\drivers\fsbts.sys
[2011.09.04 18:14:20 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011.09.04 18:14:15 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011.02.11 12:22:50 | 001,614,118 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
 
========== LOP Check ==========
 
[2012.01.26 09:16:13 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Buhl Data Service
[2012.07.09 20:36:14 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Fingertapps
[2011.11.07 22:33:32 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Leadertech
[2011.11.10 21:47:31 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\TP
[2011.11.11 23:11:02 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Windows Live Writer
[2012.01.11 14:05:52 | 000,000,000 | ---D | M] -- C:\Users\Manu&Micha\AppData\Roaming\Fingertapps
[2011.11.09 22:22:49 | 000,000,000 | ---D | M] -- C:\Users\Manu&Micha\AppData\Roaming\Leadertech
[2012.07.01 21:32:29 | 000,000,000 | ---D | M] -- C:\Users\Manu&Micha\AppData\Roaming\SoftGrid Client
[2012.06.08 19:43:35 | 000,000,000 | ---D | M] -- C:\Users\Manu&Micha\AppData\Roaming\TeamViewer
[2012.01.19 18:21:33 | 000,000,000 | ---D | M] -- C:\Users\Manu&Micha\AppData\Roaming\Windows Live Writer
[2011.11.07 23:14:38 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012.05.13 15:44:53 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.07.10 17:57:14 | 000,000,530 | ---- | M] () -- C:\Windows\Tasks\Scheduled scanning task.job
[2012.07.04 17:00:00 | 000,000,422 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2011.11.07 23:29:04 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Adobe
[2012.07.09 20:36:16 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Apple Computer
[2012.01.26 09:16:13 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Buhl Data Service
[2011.11.07 22:33:33 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Creative
[2011.11.07 22:33:30 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Dell
[2011.11.07 22:33:39 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Dell Touch Zone
[2012.07.09 20:36:14 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Fingertapps
[2012.01.24 18:25:00 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\HpUpdate
[2011.11.07 22:33:06 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Identities
[2011.11.07 22:25:51 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Intel
[2011.11.07 22:33:32 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Leadertech
[2011.09.04 17:20:31 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Macromedia
[2012.07.05 17:17:06 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Malwarebytes
[2010.11.21 09:00:23 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Media Center Programs
[2011.11.20 11:14:48 | 000,000,000 | --SD | M] -- C:\Users\Familie Kis\AppData\Roaming\Microsoft
[2011.11.08 21:19:57 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Nero
[2011.11.07 22:33:36 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Roxio
[2011.11.10 21:47:31 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\TP
[2011.11.11 23:11:02 | 000,000,000 | ---D | M] -- C:\Users\Familie Kis\AppData\Roaming\Windows Live Writer
 
< %APPDATA%\*.exe /s >
[2011.09.04 17:19:10 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Familie Kis\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
 
< %SYSTEMDRIVE%\*.exe >
[2012.07.09 20:57:54 | 000,618,655 | ---- | M] () -- C:\adwcleaner.exe
[2012.07.10 18:31:24 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\OTL3.exe
 
< MD5 for: AGP440.SYS  >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\WINDOWS\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\WINDOWS\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\WINDOWS\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\WINDOWS\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: IASTOR.SYS  >
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Drivers\Chipset_IRST\f6flpy-x64\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\drivers\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_a36325196df56f7d\iaStor.sys
[2011.01.13 03:51:44 | 000,439,320 | ---- | M] (Intel Corporation) MD5=D469B77687E12FE43E344806740B624D -- C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_e3082ac13af8d3bf\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\WINDOWS\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.09.04 18:31:56 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\WINDOWS\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.09.04 18:31:56 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.09.04 18:31:56 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.09.04 18:31:56 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\WINDOWS\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\WINDOWS\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\WINDOWS\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\WINDOWS\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011.09.04 18:31:56 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\WINDOWS\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.09.04 18:31:56 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.09.04 18:31:56 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.09.04 18:31:56 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\WINDOWS\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\WINDOWS\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\WINDOWS\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\WINDOWS\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\WINDOWS\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\WINDOWS\SysWOW64\user32.dll
[2010.11.21 05:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\WINDOWS\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.21 05:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\WINDOWS\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\WINDOWS\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\WINDOWS\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\Windows\SysNative\wininit.exe
[2009.07.14 03:39:52 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=94355C28C1970635A31B3FE52EB7CEBA -- C:\WINDOWS\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\WINDOWS\SysWOW64\wininit.exe
[2009.07.14 03:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\WINDOWS\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 02:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\WINDOWS\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >

< End of report >

--- --- ---

cosinus 10.07.2012 22:01

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1867405292-980960165-4268742590-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
:Files
C:\ProgramData\l_u0_0.pad
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Schmelzkas 12.07.2012 16:25

ok. Komme erst Samstag dazu. Sobald ich es hab, meld ich mich.
Andere Frage: Kannst du mir sagen ob das F-secure als Anti-Virenprogramm ok ist.? Was kann ich vorbeugend sonst noch tun?
sollte man den Pc alle paar Wochen durch ein Malware-Programm laufen lassen?
:glaskugel:

cosinus 12.07.2012 18:54

Also ich weiß nicht wie oft ich das schon gepostet hab, das steht hier auch schon zuhauf in vielen Diskussionen - es ist eigentlich immer wieder das gleiche Fazit => Es gibt nicht den besten Virenscanner!

Die Frage - welcher Virenscanner oder ob der installierte reicht - taucht ständig auf.
Der Virenscanner - egal welcher - kann und wird niemals 100% Schutz bieten können. Neue/unbekannte Schädlinge können immer durch die Lappen gehen. Geld ausgeben muss man nicht für einen Scanner, sowas wie Avast oder Microsoft Security Essentials sind für die privaten Gebrauch völlig ausreichend.
Abgesehen davon nutzen verschiedene Virenscanner unterschiedliche Signaturen und Techniken, das führt dazu, dass zB Scanner1 Schädling X entdeckt, aber Schädling Y übersieht. Scanner2 erkennt Schädling Y, dafür aber Schädling X nicht...
Wichtiger ist, dass du dich an Regeln hälst. Der beste Virenscanner bringt nichts, wenn du dich falsch verhälst und fahrlässig/unvorsichtig bist. Airbag und Sicherheitsgurt im Auto sind ja auch keine Gründe dafür auf die Verkehrsregeln zu pfeifen.

Halte Dich am besten grob an diese Regeln:
  1. Sei misstrauisch im Internet und v.a. bei unbekannten E-Mails, sei vorsichtig bei der Herausgabe persönlicher Daten!!
  2. Halte Windows und alle verwendeten Programme immer aktuell - unterstützen kann dich dabei Secunia PSI
  3. Führe regelmäßig Backups auf externe Medien durch
  4. Arbeite mit eingeschränkten Rechten
  5. Nutze sicherere Programme wie zB Opera oder Firefox zum Surfen statt den IE, zum Mailen Thunderbird statt Outlook Express - E-Mails nur als reinen text anzeigen lassen
  6. automatische Wiedergabe von allen Laufwerken komplett deaktivieren, denn das ist ein unnötiges Sicherheitsrisiko
  7. Bei der Installation von Software möglichst darauf achten, dass die Setups aus offiziellen Quellen stammen und du bei der Installation nach Möglichkeit die benutzerdefinierte Methode wählst - dann hast du die Möglichkeit etwaigen Schrott (wie Toolbars oder sowas wie RegistryBooster) abzuwählen, welcher sonst einfach mitinstalliert wird.
  8. Bösartige bzw. ungewollte Sites von vornherein blockieren lassen mit Hilfe der MVPS Hosts File => Blocking Unwanted Parasites with a Hosts File
  9. Finger weg von: TuneUp, Registry-Cleanern aller Art, Softonic sowie illegalen Cracks/Keygens oder anderen "Tools" um ein kommerzielles Programm ohne Lizenz nutzen zu können
  10. dubiose Seiten bzw. Kinofilm-Streaming-Portale ebenfalls sein lassen, erstens handelt man sich dort schnell Malware ein oder kann in Abofallen geraten und zweitens bewegen sich diese Seiten in einer rechtlichen Grauzone.


Alles noch genauer erklärt steht hier => Kompromittierung unvermeidbar?

Schmelzkas 12.07.2012 19:11

Dank dir. Ich merke, man kann alt werden wie ne Kuh, na du kennst das ja.
Ich sende ein :dankeschoen: vorab. es tut gut, was geschafft zu haben. zumindestens vorerst :Boogie:

Ich meld mich dann samstag.

cosinus 12.07.2012 19:45

Ok, bis Samstag oder so :D

Schmelzkas 17.07.2012 18:34

Ich hoff es passt. wenn nicht, sags.
Wenn ja, was jetzt.


All processes killed
========== OTL ==========
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1867405292-980960165-4268742590-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
========== FILES ==========
C:\ProgramData\l_u0_0.pad moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Manu&Micha\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully.
C:\Users\Familie Kis\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Familie Kis
->Temp folder emptied: 166513500 bytes
->Temporary Internet Files folder emptied: 256861325 bytes
->Flash cache emptied: 56958 bytes

User: Manu&Micha
->Temp folder emptied: 1060818826 bytes
->Temporary Internet Files folder emptied: 121061416 bytes
->Apple Safari cache emptied: 55182336 bytes
->Flash cache emptied: 57164 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 527908739 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 41384 bytes

Total Files Cleaned = 2.087,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Familie Kis
->Flash cache emptied: 0 bytes

User: Manu&Micha
->Flash cache emptied: 0 bytes

User: Public

User: UpdatusUser

Total Flash Files Cleaned = 0,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.53.1 log created on 07172012_192347

cosinus 18.07.2012 15:42

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

Schmelzkas 31.07.2012 18:09

Hallo.Hab wie beschrieben den Virenscanner runtergefahren, hab den TDSS mit den geänderten Parameter ausgeführt und .... nichts gefunden.

TDSS=0

Was jetzt?

cosinus 01.08.2012 16:24

Was verstehst du du an Log posten nicht?
Du solltes es posten egal ob Fund oder kein Fund!

Schmelzkas 14.08.2012 13:26

Ja lesen ist nicht meine Stärke anscheinend. Report hab ich glatt überlesen. Sorry. Aber jetzt ist das Log anbei.

cosinus 14.08.2012 16:32

Bitte NICHT in den Anhang!
Grundsätzlich alle Logs direkt posten in CODE-Tags. Danke

Schmelzkas 14.08.2012 18:11

Code:

14:18:24.0194 10964  TDSS rootkit removing tool 2.8.6.0 Aug 13 2012 17:24:05
14:18:25.0083 10964  ============================================================
14:18:25.0083 10964  Current date / time: 2012/08/14 14:18:25.0083
14:18:25.0083 10964  SystemInfo:
14:18:25.0083 10964 
14:18:25.0083 10964  OS Version: 6.1.7601 ServicePack: 1.0
14:18:25.0083 10964  Product type: Workstation
14:18:25.0083 10964  ComputerName: PC-FAMILIE-KIS
14:18:25.0083 10964  UserName: Familie Kis
14:18:25.0083 10964  Windows directory: C:\Windows
14:18:25.0083 10964  System windows directory: C:\Windows
14:18:25.0083 10964  Running under WOW64
14:18:25.0083 10964  Processor architecture: Intel x64
14:18:25.0083 10964  Number of processors: 8
14:18:25.0083 10964  Page size: 0x1000
14:18:25.0083 10964  Boot type: Normal boot
14:18:25.0083 10964  ============================================================
14:18:26.0050 10964  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
14:18:26.0362 10964  Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
14:18:26.0425 10964  ============================================================
14:18:26.0425 10964  \Device\Harddisk0\DR0:
14:18:26.0440 10964  MBR partitions:
14:18:26.0440 10964  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x34000, BlocksNum 0x2710000
14:18:26.0440 10964  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2744000, BlocksNum 0x37C41830
14:18:26.0440 10964  \Device\Harddisk1\DR1:
14:18:26.0440 10964  MBR partitions:
14:18:26.0440 10964  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A385000
14:18:26.0440 10964  ============================================================
14:18:26.0472 10964  C: <-> \Device\Harddisk0\DR0\Partition2
14:18:26.0487 10964  D: <-> \Device\Harddisk1\DR1\Partition1
14:18:26.0487 10964  ============================================================
14:18:26.0487 10964  Initialize success
14:18:26.0487 10964  ============================================================
14:18:58.0701 6648  ============================================================
14:18:58.0701 6648  Scan started
14:18:58.0701 6648  Mode: Manual; SigCheck; TDLFS;
14:18:58.0701 6648  ============================================================
14:19:01.0806 6648  ================ Scan services =============================
14:19:01.0930 6648  [ a87d604aea360176311474c87a63bb88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
14:19:01.0993 6648  1394ohci - ok
14:19:02.0024 6648  [ e0065cbf1a25c015c218457d2cd522b9 ] Acceler        C:\Windows\system32\DRIVERS\Accelern.sys
14:19:17.0094 6648  Acceler - ok
14:19:17.0889 6648  [ d81d9e70b8a6dd14d42d7b4efa65d5f2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
14:19:18.0342 6648  ACPI - ok
14:19:18.0716 6648  [ 99f8e788246d495ce3794d7e7821d2ca ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
14:19:19.0434 6648  AcpiPmi - ok
14:19:21.0228 6648  [ 62b7936f9036dd6ed36e6a7efa805dc0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
14:19:21.0540 6648  AdobeARMservice - ok
14:19:21.0555 6648  [ 2f6b34b83843f0c5118b63ac634f5bf4 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
14:19:21.0618 6648  adp94xx - ok
14:19:21.0649 6648  [ 597f78224ee9224ea1a13d6350ced962 ] adpahci        C:\Windows\system32\drivers\adpahci.sys
14:19:21.0665 6648  adpahci - ok
14:19:21.0680 6648  [ e109549c90f62fb570b9540c4b148e54 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
14:19:21.0696 6648  adpu320 - ok
14:19:21.0727 6648  [ 4b78b431f225fd8624c5655cb1de7b61 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
14:19:21.0774 6648  AeLookupSvc - ok
14:19:21.0836 6648  [ d1e343bc00136ce03c4d403194d06a80 ] AERTFilters    C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
14:19:21.0852 6648  AERTFilters - ok
14:19:21.0899 6648  [ 1c7857b62de5994a75b054a9fd4c3825 ] AFD            C:\Windows\system32\drivers\afd.sys
14:19:21.0992 6648  AFD - ok
14:19:22.0023 6648  [ 608c14dba7299d8cb6ed035a68a15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
14:19:22.0039 6648  agp440 - ok
14:19:22.0070 6648  [ 3290d6946b5e30e70414990574883ddb ] ALG            C:\Windows\System32\alg.exe
14:19:22.0101 6648  ALG - ok
14:19:22.0117 6648  [ 5812713a477a3ad7363c7438ca2ee038 ] aliide          C:\Windows\system32\drivers\aliide.sys
14:19:22.0133 6648  aliide - ok
14:19:22.0148 6648  [ 1ff8b4431c353ce385c875f194924c0c ] amdide          C:\Windows\system32\drivers\amdide.sys
14:19:22.0164 6648  amdide - ok
14:19:22.0195 6648  [ 7024f087cff1833a806193ef9d22cda9 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
14:19:22.0226 6648  AmdK8 - ok
14:19:22.0242 6648  [ 1e56388b3fe0d031c44144eb8c4d6217 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
14:19:22.0289 6648  AmdPPM - ok
14:19:22.0289 6648  [ d4121ae6d0c0e7e13aa221aa57ef2d49 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
14:19:22.0335 6648  amdsata - ok
14:19:22.0351 6648  [ f67f933e79241ed32ff46a4f29b5120b ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
14:19:22.0367 6648  amdsbs - ok
14:19:22.0382 6648  [ 540daf1cea6094886d72126fd7c33048 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
14:19:22.0398 6648  amdxata - ok
14:19:22.0445 6648  [ 12e7a43a3c6840a063a82b04f7ef47c0 ] AMPPAL          C:\Windows\system32\DRIVERS\AMPPAL.sys
14:19:22.0507 6648  AMPPAL - ok
14:19:22.0523 6648  [ 12e7a43a3c6840a063a82b04f7ef47c0 ] AMPPALP        C:\Windows\system32\DRIVERS\amppal.sys
14:19:22.0538 6648  AMPPALP - ok
14:19:22.0601 6648  [ 2cc0cbf2707be4d5b6ce6b87d9da2f97 ] AMPPALR3        C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
14:19:30.0369 6648  AMPPALR3 - ok
14:19:30.0510 6648  [ 89a69c3f2f319b43379399547526d952 ] AppID          C:\Windows\system32\drivers\appid.sys
14:19:30.0728 6648  AppID - ok
14:19:30.0837 6648  [ 0bc381a15355a3982216f7172f545de1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
14:19:30.0947 6648  AppIDSvc - ok
14:19:31.0040 6648  [ 3977d4a871ca0d4f2ed1e7db46829731 ] Appinfo        C:\Windows\System32\appinfo.dll
14:19:31.0134 6648  Appinfo - ok
14:19:31.0259 6648  [ f401929ee0cc92bfe7f15161ca535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
14:19:31.0305 6648  Apple Mobile Device - ok
14:19:31.0337 6648  [ c484f8ceb1717c540242531db7845c4e ] arc            C:\Windows\system32\drivers\arc.sys
14:19:31.0493 6648  arc - ok
14:19:31.0524 6648  [ 019af6924aefe7839f61c830227fe79c ] arcsas          C:\Windows\system32\drivers\arcsas.sys
14:19:31.0555 6648  arcsas - ok
14:19:31.0836 6648  [ 9217d874131ae6ff8f642f124f00a555 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
14:19:31.0851 6648  aspnet_state - ok
14:19:31.0992 6648  [ 769765ce2cc62867468cea93969b2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
14:19:32.0070 6648  AsyncMac - ok
14:19:32.0241 6648  [ 02062c0b390b7729edc9e69c680a6f3c ] atapi          C:\Windows\system32\drivers\atapi.sys
14:19:32.0257 6648  atapi - ok
14:19:32.0663 6648  [ f23fef6d569fce88671949894a8becf1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:19:32.0959 6648  AudioEndpointBuilder - ok
14:19:33.0037 6648  [ f23fef6d569fce88671949894a8becf1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
14:19:33.0162 6648  AudioSrv - ok
14:19:33.0240 6648  [ a6bf31a71b409dfa8cac83159e1e2aff ] AxInstSV        C:\Windows\System32\AxInstSV.dll
14:19:33.0302 6648  AxInstSV - ok
14:19:33.0536 6648  [ 3e5b191307609f7514148c6832bb0842 ] b06bdrv        C:\Windows\system32\drivers\bxvbda.sys
14:19:33.0708 6648  b06bdrv - ok
14:19:33.0770 6648  [ b5ace6968304a3900eeb1ebfd9622df2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
14:19:33.0833 6648  b57nd60a - ok
14:19:33.0879 6648  [ fde360167101b4e45a96f939f388aeb0 ] BDESVC          C:\Windows\System32\bdesvc.dll
14:19:33.0942 6648  BDESVC - ok
14:19:33.0989 6648  [ 16a47ce2decc9b099349a5f840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
14:19:34.0051 6648  Beep - ok
14:19:34.0191 6648  [ 82974d6a2fd19445cc5171fc378668a4 ] BFE            C:\Windows\System32\bfe.dll
14:19:34.0457 6648  BFE - ok
14:19:34.0722 6648  [ 1ea7969e3271cbc59e1730697dc74682 ] BITS            C:\Windows\System32\qmgr.dll
14:19:34.0878 6648  BITS - ok
14:19:34.0956 6648  [ 61583ee3c3a17003c4acd0475646b4d3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
14:19:34.0987 6648  blbdrive - ok
14:19:35.0237 6648  [ 0f46d2845bd7ddaca52340ecc2b65da3 ] Bluetooth Device Monitor C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
14:19:35.0673 6648  Bluetooth Device Monitor - ok
14:19:35.0907 6648  [ 3341de556ec28252d603277609eef8bf ] Bluetooth Media Service C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
14:19:36.0251 6648  Bluetooth Media Service - ok
14:19:36.0375 6648  [ 5d5c3ec9be1107dedf0feb55b7f3bd77 ] Bluetooth OBEX Service C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
14:19:36.0937 6648  Bluetooth OBEX Service - ok
14:19:37.0202 6648  [ ebbcd5dfbb1de70e8f4af8fa59e401fd ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
14:19:37.0296 6648  Bonjour Service - ok
14:19:37.0311 6648  [ 6c02a83164f5cc0a262f4199f0871cf5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
14:19:37.0358 6648  bowser - ok
14:19:37.0374 6648  [ f09eee9edc320b5e1501f749fde686c8 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
14:19:37.0421 6648  BrFiltLo - ok
14:19:37.0436 6648  [ b114d3098e9bdb8bea8b053685831be6 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
14:19:37.0467 6648  BrFiltUp - ok
14:19:37.0499 6648  [ 8ef0d5c41ec907751b8429162b1239ed ] Browser        C:\Windows\System32\browser.dll
14:19:37.0561 6648  Browser - ok
14:19:37.0592 6648  [ 43bea8d483bf1870f018e2d02e06a5bd ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
14:19:37.0639 6648  Brserid - ok
14:19:37.0639 6648  [ a6eca2151b08a09caceca35c07f05b42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
14:19:37.0701 6648  BrSerWdm - ok
14:19:37.0795 6648  [ b79968002c277e869cf38bd22cd61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
14:19:37.0826 6648  BrUsbMdm - ok
14:19:37.0857 6648  [ a87528880231c54e75ea7a44943b38bf ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
14:19:37.0904 6648  BrUsbSer - ok
14:19:37.0967 6648  [ cf98190a94f62e405c8cb255018b2315 ] BthEnum        C:\Windows\system32\drivers\BthEnum.sys
14:19:38.0013 6648  BthEnum - ok
14:19:38.0029 6648  [ 9da669f11d1f894ab4eb69bf546a42e8 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
14:19:38.0060 6648  BTHMODEM - ok
14:19:38.0076 6648  [ 02dd601b708dd0667e1331fa8518e9ff ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
14:19:38.0123 6648  BthPan - ok
14:19:38.0169 6648  [ 64c198198501f7560ee41d8d1efa7952 ] BTHPORT        C:\Windows\system32\Drivers\BTHport.sys
14:19:38.0216 6648  BTHPORT - ok
14:19:38.0247 6648  [ 95f9c2976059462cbbf227f7aab10de9 ] bthserv        C:\Windows\system32\bthserv.dll
14:19:38.0310 6648  bthserv - ok
14:19:38.0372 6648  [ d6ceec2f878149e4db9fe93fa5d8fe60 ] BTHSSecurityMgr C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
14:19:39.0371 6648  BTHSSecurityMgr - ok
14:19:39.0402 6648  [ f188b7394d81010767b6df3178519a37 ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
14:19:39.0449 6648  BTHUSB - ok
14:19:39.0495 6648  [ ab0a33001fe7ebb209d9d52ced11be1a ] btmaux          C:\Windows\system32\DRIVERS\btmaux.sys
14:19:39.0511 6648  btmaux - ok
14:19:39.0558 6648  [ 40c6fec49d1cc4d112368a2bcd2bcbb7 ] btmhsf          C:\Windows\system32\DRIVERS\btmhsf.sys
14:19:39.0620 6648  btmhsf - ok
14:19:39.0651 6648  [ b8bd2bb284668c84865658c77574381a ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
14:19:39.0729 6648  cdfs - ok
14:19:39.0807 6648  [ f036ce71586e93d94dab220d7bdf4416 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
14:19:39.0823 6648  cdrom - ok
14:19:39.0948 6648  [ f17d1d393bbc69c5322fbfafaca28c7f ] CertPropSvc    C:\Windows\System32\certprop.dll
14:19:39.0995 6648  CertPropSvc - ok
14:19:40.0010 6648  [ d7cd5c4e1b71fa62050515314cfb52cf ] circlass        C:\Windows\system32\drivers\circlass.sys
14:19:40.0057 6648  circlass - ok
14:19:40.0088 6648  [ fe1ec06f2253f691fe36217c592a0206 ] CLFS            C:\Windows\system32\CLFS.sys
14:19:40.0151 6648  CLFS - ok
14:19:40.0213 6648  [ d88040f816fda31c3b466f0fa0918f29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:19:40.0385 6648  clr_optimization_v2.0.50727_32 - ok
14:19:40.0478 6648  [ d1ceea2b47cb998321c579651ce3e4f8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
14:19:40.0494 6648  clr_optimization_v2.0.50727_64 - ok
14:19:40.0697 6648  [ c5a75eb48e2344abdc162bda79e16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:19:40.0790 6648  clr_optimization_v4.0.30319_32 - ok
14:19:40.0821 6648  [ c6f9af94dcd58122a4d7e89db6bed29d ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
14:19:40.0868 6648  clr_optimization_v4.0.30319_64 - ok
14:19:41.0009 6648  [ 0840155d0bddf1190f84a663c284bd33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
14:19:41.0071 6648  CmBatt - ok
14:19:41.0087 6648  [ e19d3f095812725d88f9001985b94edd ] cmdide          C:\Windows\system32\drivers\cmdide.sys
14:19:41.0118 6648  cmdide - ok
14:19:41.0336 6648  [ 9ac4f97c2d3e93367e2148ea940cd2cd ] CNG            C:\Windows\system32\Drivers\cng.sys
14:19:41.0414 6648  CNG - ok
14:19:41.0601 6648  [ 102de219c3f61415f964c88e9085ad14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
14:19:41.0664 6648  Compbatt - ok
14:19:41.0679 6648  [ 03edb043586cceba243d689bdda370a8 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
14:19:41.0742 6648  CompositeBus - ok
14:19:41.0789 6648  COMSysApp - ok
14:19:41.0804 6648  [ 1c827878a998c18847245fe1f34ee597 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
14:19:41.0835 6648  crcdisk - ok
14:19:41.0913 6648  [ 4f5414602e2544a4554d95517948b705 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
14:19:41.0991 6648  CryptSvc - ok
14:19:42.0054 6648  [ bc3d4f90978cd7c8eabd1baf3bf7873a ] CtClsFlt        C:\Windows\system32\DRIVERS\CtClsFlt.sys
14:19:42.0881 6648  CtClsFlt - ok
14:19:43.0130 6648  [ 72794d112cbaff3bc0c29bf7350d4741 ] cvhsvc          C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
14:19:43.0427 6648  cvhsvc - ok
14:19:43.0536 6648  [ 5c627d1b1138676c0a7ab2c2c190d123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
14:19:43.0707 6648  DcomLaunch - ok
14:19:43.0754 6648  [ 3cec7631a84943677aa8fa8ee5b6b43d ] defragsvc      C:\Windows\System32\defragsvc.dll
14:19:43.0895 6648  defragsvc - ok
14:19:43.0910 6648  [ 9bb2ef44eaa163b29c4a4587887a0fe4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
14:19:43.0957 6648  DfsC - ok
14:19:44.0051 6648  [ 43d808f5d9e1a18e5eeb5ebc83969e4e ] Dhcp            C:\Windows\system32\dhcpcore.dll
14:19:44.0144 6648  Dhcp - ok
14:19:44.0191 6648  [ 13096b05847ec78f0977f2c0f79e9ab3 ] discache        C:\Windows\system32\drivers\discache.sys
14:19:44.0269 6648  discache - ok
14:19:44.0331 6648  [ 9819eee8b5ea3784ec4af3b137a5244c ] Disk            C:\Windows\system32\drivers\disk.sys
14:19:44.0378 6648  Disk - ok
14:19:44.0425 6648  [ 16835866aaa693c7d7fceba8fff706e4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
14:19:44.0519 6648  Dnscache - ok
14:19:44.0550 6648  [ b1fb3ddca0fdf408750d5843591afbc6 ] dot3svc        C:\Windows\System32\dot3svc.dll
14:19:44.0643 6648  dot3svc - ok
14:19:44.0690 6648  [ b26f4f737e8f9df4f31af6cf31d05820 ] DPS            C:\Windows\system32\dps.dll
14:19:44.0831 6648  DPS - ok
14:19:44.0893 6648  [ 9b19f34400d24df84c858a421c205754 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
14:19:44.0924 6648  drmkaud - ok
14:19:45.0221 6648  [ f5bee30450e18e6b83a5012c100616fd ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
14:19:46.0359 6648  DXGKrnl - ok
14:19:46.0437 6648  [ e2dda8726da9cb5b2c4000c9018a9633 ] EapHost        C:\Windows\System32\eapsvc.dll
14:19:46.0500 6648  EapHost - ok
14:19:47.0030 6648  [ dc5d737f51be844d8c82c695eb17372f ] ebdrv          C:\Windows\system32\drivers\evbda.sys
14:19:47.0498 6648  ebdrv - ok
14:19:47.0607 6648  [ c118a82cd78818c29ab228366ebf81c3 ] EFS            C:\Windows\System32\lsass.exe
14:19:47.0685 6648  EFS - ok
14:19:47.0779 6648  [ c4002b6b41975f057d98c439030cea07 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
14:19:48.0887 6648  ehRecvr - ok
14:19:48.0902 6648  [ 4705e8ef9934482c5bb488ce28afc681 ] ehSched        C:\Windows\ehome\ehsched.exe
14:19:48.0949 6648  ehSched - ok
14:19:49.0043 6648  [ 0e5da5369a0fcaea12456dd852545184 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
14:19:49.0121 6648  elxstor - ok
14:19:49.0136 6648  [ 34a3c54752046e79a126e15c51db409b ] ErrDev          C:\Windows\system32\drivers\errdev.sys
14:19:49.0167 6648  ErrDev - ok
14:19:49.0261 6648  [ 4166f82be4d24938977dd1746be9b8a0 ] EventSystem    C:\Windows\system32\es.dll
14:19:49.0417 6648  EventSystem - ok
14:19:49.0667 6648  [ 532b8ff8e07f3772b086620377654f95 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
14:19:49.0838 6648  EvtEng - ok
14:19:49.0916 6648  [ a510c654ec00c1e9bdd91eeb3a59823b ] exfat          C:\Windows\system32\drivers\exfat.sys
14:19:49.0963 6648  exfat - ok
14:19:50.0150 6648  [ 169897de484a79120af8c201883efdc4 ] F-Secure Gatekeeper C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsgk.sys
14:19:50.0181 6648  F-Secure Gatekeeper - ok
14:19:50.0228 6648  [ 2346842f07e2ab64d1dc83a67fccdfa1 ] F-Secure Gatekeeper Handler Starter C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\fsgk32st.exe
14:19:50.0259 6648  F-Secure Gatekeeper Handler Starter - ok
14:19:50.0337 6648  [ 0923c7370d08aa0e167f24fdee24a333 ] F-Secure HIPS  C:\Program Files (x86)\VR-Web Sicherheitspaket\HIPS\drivers\fshs.sys
14:19:50.0353 6648  F-Secure HIPS - ok
14:19:50.0400 6648  [ 0adc83218b66a6db380c330836f3e36d ] fastfat        C:\Windows\system32\drivers\fastfat.sys
14:19:50.0462 6648  fastfat - ok
14:19:50.0556 6648  [ dbefd454f8318a0ef691fdd2eaab44eb ] Fax            C:\Windows\system32\fxssvc.exe
14:19:50.0603 6648  Fax - ok
14:19:50.0649 6648  [ d765d19cd8ef61f650c384f62fac00ab ] fdc            C:\Windows\system32\drivers\fdc.sys
14:19:50.0712 6648  fdc - ok
14:19:50.0743 6648  [ 0438cab2e03f4fb61455a7956026fe86 ] fdPHost        C:\Windows\system32\fdPHost.dll
14:19:50.0790 6648  fdPHost - ok
14:19:50.0821 6648  [ 802496cb59a30349f9a6dd22d6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
14:19:50.0883 6648  FDResPub - ok
14:19:50.0930 6648  [ 655661be46b5f5f3fd454e2c3095b930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
14:19:50.0946 6648  FileInfo - ok
14:19:50.0961 6648  [ 5f671ab5bc87eea04ec38a6cd5962a47 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
14:19:51.0024 6648  Filetrace - ok
14:19:51.0071 6648  [ c172a0f53008eaeb8ea33fe10e177af5 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
14:19:51.0102 6648  flpydisk - ok
14:19:51.0133 6648  [ da6b67270fd9db3697b20fce94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
14:19:51.0164 6648  FltMgr - ok
14:19:51.0258 6648  [ 5c4cb4086fb83115b153e47add961a0c ] FontCache      C:\Windows\system32\FntCache.dll
14:19:51.0320 6648  FontCache - ok
14:19:51.0383 6648  [ a8b7f3818ab65695e3a0bb3279f6dce6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
14:19:51.0398 6648  FontCache3.0.0.0 - ok
14:19:51.0476 6648  [ d5c492752fccb61bffae361c82f914ac ] fsbts          C:\Windows\system32\Drivers\fsbts.sys
14:19:51.0507 6648  fsbts - ok
14:19:51.0507 6648  [ d43703496149971890703b4b1b723eac ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
14:19:51.0523 6648  FsDepends - ok
14:19:51.0757 6648  [ d40a0ee11b934e0472ab8a4bbf46d6d8 ] FSDFWD          C:\Program Files (x86)\VR-Web Sicherheitspaket\FWES\Program\fsdfwd.exe
14:19:51.0851 6648  FSDFWD - ok
14:19:51.0929 6648  [ 06c487127857ca7dd0bb6051d454dd90 ] FSES            C:\Windows\system32\drivers\fses.sys
14:19:51.0960 6648  FSES - ok
14:19:52.0022 6648  [ f68d7041a3a6f4707237891d476dd412 ] FSFW            C:\Windows\system32\drivers\fsdfw.sys
14:19:52.0038 6648  FSFW - ok
14:19:52.0163 6648  [ 8a556a81e9ff95bd9eb7207783e8fcf4 ] FSMA            C:\Program Files (x86)\VR-Web Sicherheitspaket\Common\FSMA32.EXE
14:19:52.0194 6648  FSMA - ok
14:19:52.0287 6648  [ 42aef6a385354aca65fc210ce7ce4d7c ] FSORSPClient    C:\Program Files (x86)\VR-Web Sicherheitspaket\ORSP Client\fsorsp.exe
14:19:52.0319 6648  FSORSPClient - ok
14:19:52.0350 6648  [ ca7903a77fe92a11045dab462574009f ] fsvista        C:\Program Files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsvista.sys
14:19:52.0365 6648  fsvista - ok
14:19:52.0506 6648  [ 6bd9295cc032dd3077c671fccf579a7b ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
14:19:52.0537 6648  Fs_Rec - ok
14:19:52.0662 6648  [ 1f7b25b858fa27015169fe95e54108ed ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
14:19:52.0693 6648  fvevol - ok
14:19:52.0724 6648  [ 8c778d335c9d272cfd3298ab02abe3b6 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
14:19:52.0740 6648  gagp30kx - ok
14:19:52.0818 6648  [ e403aacf8c7bb11375122d2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
14:19:52.0833 6648  GEARAspiWDM - ok
14:19:52.0943 6648  [ 277bbc7e1aa1ee957f573a10eca7ef3a ] gpsvc          C:\Windows\System32\gpsvc.dll
14:19:53.0099 6648  gpsvc - ok
14:19:53.0301 6648  [ f02a533f517eb38333cb12a9e8963773 ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
14:19:53.0333 6648  gupdate - ok
14:19:53.0442 6648  [ f02a533f517eb38333cb12a9e8963773 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
14:19:53.0457 6648  gupdatem - ok
14:19:53.0582 6648  [ cc839e8d766cc31a7710c9f38cf3e375 ] gusvc          C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
14:19:54.0393 6648  gusvc - ok
14:19:54.0471 6648  [ f2523ef6460fc42405b12248338ab2f0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
14:19:54.0503 6648  hcw85cir - ok
14:19:54.0565 6648  [ 975761c778e33cd22498059b91e7373a ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:19:54.0659 6648  HdAudAddService - ok
14:19:54.0737 6648  [ 97bfed39b6b79eb12cddbfeed51f56bb ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
14:19:54.0768 6648  HDAudBus - ok
14:19:54.0783 6648  [ 78e86380454a7b10a5eb255dc44a355f ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
14:19:54.0815 6648  HidBatt - ok
14:19:54.0815 6648  [ 7fd2a313f7afe5c4dab14798c48dd104 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
14:19:54.0846 6648  HidBth - ok
14:19:54.0893 6648  [ 0a77d29f311b88cfae3b13f9c1a73825 ] HidIr          C:\Windows\system32\drivers\hidir.sys
14:19:54.0924 6648  HidIr - ok
14:19:54.0955 6648  [ bd9eb3958f213f96b97b1d897dee006d ] hidserv        C:\Windows\system32\hidserv.dll
14:19:54.0986 6648  hidserv - ok
14:19:55.0033 6648  [ 9592090a7e2b61cd582b612b6df70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
14:19:55.0049 6648  HidUsb - ok
14:19:55.0095 6648  [ 387e72e739e15e3d37907a86d9ff98e2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
14:19:55.0142 6648  hkmsvc - ok
14:19:55.0173 6648  [ efdfb3dd38a4376f93e7985173813abd ] HomeGroupListener C:\Windows\system32\ListSvc.dll
14:19:55.0220 6648  HomeGroupListener - ok
14:19:55.0283 6648  [ 908acb1f594274965a53926b10c81e89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
14:19:55.0329 6648  HomeGroupProvider - ok
14:19:55.0345 6648  [ 39d2abcd392f3d8a6dce7b60ae7b8efc ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
14:19:55.0361 6648  HpSAMD - ok
14:19:55.0485 6648  [ 0ea7de1acb728dd5a369fd742d6eee28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
14:19:55.0548 6648  HTTP - ok
14:19:55.0563 6648  [ a5462bd6884960c9dc85ed49d34ff392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
14:19:55.0579 6648  hwpolicy - ok
14:19:55.0641 6648  [ fa55c73d4affa7ee23ac4be53b4592d3 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
14:19:55.0657 6648  i8042prt - ok
14:19:55.0735 6648  [ d469b77687e12fe43e344806740b624d ] iaStor          C:\Windows\system32\drivers\iaStor.sys
14:19:55.0766 6648  iaStor - ok
14:19:55.0875 6648  [ aaaf44db3bd0b9d1fb6969b23ecc8366 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
14:19:55.0985 6648  iaStorV - ok
14:19:56.0047 6648  [ fc47f5cf561bf0fd897efd1a9604dccf ] iBtFltCoex      C:\Windows\system32\DRIVERS\iBtFltCoex.sys
14:19:56.0078 6648  iBtFltCoex - ok
14:19:56.0187 6648  [ 5988fc40f8db5b0739cd1e3a5d0d78bd ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
14:19:56.0250 6648  idsvc - ok
14:19:56.0796 6648  [ 0bd58366c86ef9ddc4f61afed0cada99 ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
14:19:57.0077 6648  igfx - ok
14:19:57.0139 6648  [ 5c18831c61933628f5bb0ea2675b9d21 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
14:19:57.0170 6648  iirsp - ok
14:19:57.0389 6648  [ fcd84c381e0140af901e58d48882d26b ] IKEEXT          C:\Windows\System32\ikeext.dll
14:19:57.0529 6648  IKEEXT - ok
14:19:57.0591 6648  [ dd587a55390ed2295bce6d36ad567da9 ] Impcd          C:\Windows\system32\drivers\Impcd.sys
14:19:57.0638 6648  Impcd - ok
14:19:57.0685 6648  [ caddf0927dac63edae48f5c35a61d87d ] intaud_WaveExtensible C:\Windows\system32\drivers\intelaud.sys
14:19:57.0857 6648  intaud_WaveExtensible - ok
14:19:58.0059 6648  [ a5f7cef8a939ebe270462edefd629f20 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
14:19:58.0278 6648  IntcAzAudAddService - ok
14:19:58.0340 6648  [ fc727061c0f47c8059e88e05d5c8e381 ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
14:19:58.0371 6648  IntcDAud - ok
14:19:58.0403 6648  [ f00f20e70c6ec3aa366910083a0518aa ] intelide        C:\Windows\system32\drivers\intelide.sys
14:19:58.0434 6648  intelide - ok
14:19:58.0465 6648  [ ada036632c664caa754079041cf1f8c1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
14:19:58.0527 6648  intelppm - ok
14:19:58.0574 6648  [ 098a91c54546a3b878dad6a7e90a455b ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
14:19:58.0637 6648  IPBusEnum - ok
14:19:58.0668 6648  [ c9f0e1bd74365a8771590e9008d22ab6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:19:58.0699 6648  IpFilterDriver - ok
14:19:58.0824 6648  [ a34a587fffd45fa649fba6d03784d257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
14:19:58.0902 6648  iphlpsvc - ok
14:19:58.0917 6648  [ 0fc1aea580957aa8817b8f305d18ca3a ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
14:19:58.0949 6648  IPMIDRV - ok
14:19:58.0964 6648  [ af9b39a7e7b6caa203b3862582e9f2d0 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
14:19:59.0027 6648  IPNAT - ok
14:19:59.0245 6648  [ a9ab99ee7d39725eafec82732d2b3271 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
14:19:59.0370 6648  iPod Service - ok
14:19:59.0417 6648  [ 3abf5e7213eb28966d55d58b515d5ce9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
14:19:59.0448 6648  IRENUM - ok
14:19:59.0479 6648  [ 2f7b28dc3e1183e5eb418df55c204f38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
14:19:59.0510 6648  isapnp - ok
14:19:59.0557 6648  [ d931d7309deb2317035b07c9f9e6b0bd ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
14:19:59.0573 6648  iScsiPrt - ok
14:19:59.0635 6648  [ 716f66336f10885d935b08174dc54242 ] iwdbus          C:\Windows\system32\DRIVERS\iwdbus.sys
14:19:59.0744 6648  iwdbus - ok
14:19:59.0760 6648  [ bc02336f1cba7dcc7d1213bb588a68a5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
14:19:59.0791 6648  kbdclass - ok
14:19:59.0807 6648  [ 0705eff5b42a9db58548eec3b26bb484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
14:19:59.0838 6648  kbdhid - ok
14:19:59.0853 6648  [ c118a82cd78818c29ab228366ebf81c3 ] KeyIso          C:\Windows\system32\lsass.exe
14:19:59.0869 6648  KeyIso - ok
14:19:59.0916 6648  [ 97a7070aea4c058b6418519e869a63b4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
14:19:59.0963 6648  KSecDD - ok
14:19:59.0994 6648  [ 26c43a7c2862447ec59deda188d1da07 ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
14:20:00.0041 6648  KSecPkg - ok
14:20:00.0087 6648  [ 6869281e78cb31a43e969f06b57347c4 ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
14:20:00.0134 6648  ksthunk - ok
14:20:00.0197 6648  [ 6ab66e16aa859232f64deb66887a8c9c ] KtmRm          C:\Windows\system32\msdtckrm.dll
14:20:00.0290 6648  KtmRm - ok
14:20:00.0353 6648  [ d9f42719019740baa6d1c6d536cbdaa6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
14:20:00.0399 6648  LanmanServer - ok
14:20:00.0462 6648  [ 851a1382eed3e3a7476db004f4ee3e1a ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:20:00.0509 6648  LanmanWorkstation - ok
14:20:00.0571 6648  [ 1538831cf8ad2979a04c423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
14:20:00.0618 6648  lltdio - ok
14:20:00.0696 6648  [ c1185803384ab3feed115f79f109427f ] lltdsvc        C:\Windows\System32\lltdsvc.dll
14:20:00.0789 6648  lltdsvc - ok
14:20:00.0805 6648  [ f993a32249b66c9d622ea5592a8b76b8 ] lmhosts        C:\Windows\System32\lmhsvc.dll
14:20:00.0852 6648  lmhosts - ok
14:20:00.0899 6648  [ 7f32d4c47a50e7223491e8fb9359907d ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
14:20:00.0977 6648  LMS - ok
14:20:01.0039 6648  [ 1a93e54eb0ece102495a51266dcdb6a6 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
14:20:01.0055 6648  LSI_FC - ok
14:20:01.0070 6648  [ 1047184a9fdc8bdbff857175875ee810 ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
14:20:01.0086 6648  LSI_SAS - ok
14:20:01.0101 6648  [ 30f5c0de1ee8b5bc9306c1f0e4a75f93 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
14:20:01.0133 6648  LSI_SAS2 - ok
14:20:01.0164 6648  [ 0504eacaff0d3c8aed161c4b0d369d4a ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
14:20:01.0195 6648  LSI_SCSI - ok
14:20:01.0257 6648  [ 43d0f98e1d56ccddb0d5254cff7b356e ] luafv          C:\Windows\system32\drivers\luafv.sys
14:20:01.0304 6648  luafv - ok
14:20:01.0351 6648  [ 0be09cd858abf9df6ed259d57a1a1663 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
14:20:01.0398 6648  Mcx2Svc - ok
14:20:01.0413 6648  [ a55805f747c6edb6a9080d7c633bd0f4 ] megasas        C:\Windows\system32\drivers\megasas.sys
14:20:01.0429 6648  megasas - ok
14:20:01.0491 6648  [ baf74ce0072480c3b6b7c13b2a94d6b3 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
14:20:01.0523 6648  MegaSR - ok
14:20:01.0601 6648  [ a6518dcc42f7a6e999bb3bea8fd87567 ] MEIx64          C:\Windows\system32\DRIVERS\HECIx64.sys
14:20:01.0616 6648  MEIx64 - ok
14:20:01.0647 6648  [ e40e80d0304a73e8d269f7141d77250b ] MMCSS          C:\Windows\system32\mmcss.dll
14:20:01.0694 6648  MMCSS - ok
14:20:01.0710 6648  [ 800ba92f7010378b09f9ed9270f07137 ] Modem          C:\Windows\system32\drivers\modem.sys
14:20:01.0757 6648  Modem - ok
14:20:01.0819 6648  [ b03d591dc7da45ece20b3b467e6aadaa ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
14:20:01.0850 6648  monitor - ok
14:20:01.0881 6648  [ 7d27ea49f3c1f687d357e77a470aea99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
14:20:01.0897 6648  mouclass - ok
14:20:01.0913 6648  [ d3bf052c40b0c4166d9fd86a4288c1e6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
14:20:01.0944 6648  mouhid - ok
14:20:01.0959 6648  [ 32e7a3d591d671a6df2db515a5cbe0fa ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
14:20:01.0975 6648  mountmgr - ok
14:20:02.0006 6648  [ a44b420d30bd56e145d6a2bc8768ec58 ] mpio            C:\Windows\system32\drivers\mpio.sys
14:20:02.0037 6648  mpio - ok
14:20:02.0053 6648  [ 6c38c9e45ae0ea2fa5e551f2ed5e978f ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
14:20:02.0084 6648  mpsdrv - ok
14:20:02.0162 6648  [ 54ffc9c8898113ace189d4aa7199d2c1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
14:20:02.0318 6648  MpsSvc - ok
14:20:02.0349 6648  [ dc722758b8261e1abafd31a3c0a66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
14:20:02.0396 6648  MRxDAV - ok
14:20:02.0412 6648  [ a5d9106a73dc88564c825d317cac68ac ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
14:20:02.0443 6648  mrxsmb - ok
14:20:02.0552 6648  [ d711b3c1d5f42c0c2415687be09fc163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:20:02.0630 6648  mrxsmb10 - ok
14:20:02.0646 6648  [ 9423e9d355c8d303e76b8cfbd8a5c30c ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:20:02.0677 6648  mrxsmb20 - ok
14:20:02.0693 6648  [ c25f0bafa182cbca2dd3c851c2e75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
14:20:02.0708 6648  msahci - ok
14:20:02.0724 6648  [ db801a638d011b9633829eb6f663c900 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
14:20:02.0755 6648  msdsm - ok
14:20:02.0786 6648  [ de0ece52236cfa3ed2dbfc03f28253a8 ] MSDTC          C:\Windows\System32\msdtc.exe
14:20:02.0817 6648  MSDTC - ok
14:20:02.0849 6648  [ aa3fb40e17ce1388fa1bedab50ea8f96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
14:20:02.0895 6648  Msfs - ok
14:20:02.0927 6648  [ f9d215a46a8b9753f61767fa72a20326 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
14:20:02.0973 6648  mshidkmdf - ok
14:20:02.0973 6648  [ d916874bbd4f8b07bfb7fa9b3ccae29d ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
14:20:03.0129 6648  msisadrv - ok
14:20:03.0176 6648  [ 808e98ff49b155c522e6400953177b08 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
14:20:03.0239 6648  MSiSCSI - ok
14:20:03.0254 6648  msiserver - ok
14:20:03.0270 6648  [ 49ccf2c4fea34ffad8b1b59d49439366 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
14:20:03.0317 6648  MSKSSRV - ok
14:20:03.0332 6648  [ bdd71ace35a232104ddd349ee70e1ab3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
14:20:03.0379 6648  MSPCLOCK - ok
14:20:03.0395 6648  [ 4ed981241db27c3383d72092b618a1d0 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
14:20:03.0457 6648  MSPQM - ok
14:20:03.0551 6648  [ 759a9eeb0fa9ed79da1fb7d4ef78866d ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
14:20:03.0629 6648  MsRPC - ok
14:20:03.0644 6648  [ 0eed230e37515a0eaee3c2e1bc97b288 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
14:20:03.0660 6648  mssmbios - ok
14:20:03.0738 6648  [ 2e66f9ecb30b4221a318c92ac2250779 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
14:20:03.0800 6648  MSTEE - ok
14:20:03.0816 6648  [ 7ea404308934e675bffde8edf0757bcd ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
14:20:03.0847 6648  MTConfig - ok
14:20:03.0863 6648  [ f9a18612fd3526fe473c1bda678d61c8 ] Mup            C:\Windows\system32\Drivers\mup.sys
14:20:03.0878 6648  Mup - ok
14:20:03.0941 6648  [ 265937bc59819df1dab65e27c60f94c0 ] MyWiFiDHCPDNS  C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
14:20:04.0019 6648  MyWiFiDHCPDNS - ok
14:20:04.0081 6648  [ 582ac6d9873e31dfa28a4547270862dd ] napagent        C:\Windows\system32\qagentRT.dll
14:20:04.0206 6648  napagent - ok
14:20:04.0253 6648  [ 1ea3749c4114db3e3161156ffffa6b33 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
14:20:04.0299 6648  NativeWifiP - ok
14:20:04.0440 6648  [ 934bb0d23a25c8c136570800a5a149b6 ] NAUpdate        C:\Program Files (x86)\Nero\Update\NASvc.exe
14:20:04.0518 6648  NAUpdate - ok
14:20:04.0596 6648  [ c38b8ae57f78915905064a9a24dc1586 ] NDIS            C:\Windows\system32\drivers\ndis.sys
14:20:04.0736 6648  NDIS - ok
14:20:04.0752 6648  [ 9f9a1f53aad7da4d6fef5bb73ab811ac ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
14:20:04.0814 6648  NdisCap - ok
14:20:04.0845 6648  [ 30639c932d9fef22b31268fe25a1b6e5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
14:20:04.0877 6648  NdisTapi - ok
14:20:04.0908 6648  [ 136185f9fb2cc61e573e676aa5402356 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
14:20:04.0955 6648  Ndisuio - ok
14:20:04.0970 6648  [ 53f7305169863f0a2bddc49e116c2e11 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
14:20:05.0017 6648  NdisWan - ok
14:20:05.0033 6648  [ 015c0d8e0e0421b4cfd48cffe2825879 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
14:20:05.0095 6648  NDProxy - ok
14:20:05.0142 6648  [ 6f4607e2333fe21e9e3ff8133a88b35b ] Netaapl        C:\Windows\system32\DRIVERS\netaapl64.sys
14:20:05.0173 6648  Netaapl - ok
14:20:05.0220 6648  [ 86743d9f5d2b1048062b14b1d84501c4 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
14:20:05.0267 6648  NetBIOS - ok
14:20:05.0298 6648  [ 09594d1089c523423b32a4229263f068 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
14:20:05.0329 6648  NetBT - ok
14:20:05.0345 6648  [ c118a82cd78818c29ab228366ebf81c3 ] Netlogon        C:\Windows\system32\lsass.exe
14:20:05.0360 6648  Netlogon - ok
14:20:05.0516 6648  [ 847d3ae376c0817161a14a82c8922a9e ] Netman          C:\Windows\System32\netman.dll
14:20:05.0610 6648  Netman - ok
14:20:05.0657 6648  [ d22cd77d4f0d63d1169bb35911bff12d ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:20:05.0672 6648  NetMsmqActivator - ok
14:20:05.0672 6648  [ d22cd77d4f0d63d1169bb35911bff12d ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:20:05.0688 6648  NetPipeActivator - ok
14:20:05.0735 6648  [ 5f28111c648f1e24f7dbc87cdeb091b8 ] netprofm        C:\Windows\System32\netprofm.dll
14:20:05.0813 6648  netprofm - ok
14:20:05.0828 6648  [ d22cd77d4f0d63d1169bb35911bff12d ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:20:05.0859 6648  NetTcpActivator - ok
14:20:05.0859 6648  [ d22cd77d4f0d63d1169bb35911bff12d ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:20:05.0875 6648  NetTcpPortSharing - ok
14:20:06.0390 6648  [ 774c9eccef83ab8a3d1466f19809c95f ] NETwNs64        C:\Windows\system32\DRIVERS\NETwNs64.sys
14:20:07.0092 6648  NETwNs64 - ok
14:20:07.0123 6648  [ 77889813be4d166cdab78ddba990da92 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
14:20:07.0139 6648  nfrd960 - ok
14:20:07.0185 6648  [ 1ee99a89cc788ada662441d1e9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
14:20:07.0263 6648  NlaSvc - ok
14:20:07.0279 6648  [ 1e4c4ab5c9b8dd13179bbdc75a2a01f7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
14:20:07.0326 6648  Npfs - ok
14:20:07.0341 6648  [ d54bfdf3e0c953f823b3d0bfe4732528 ] nsi            C:\Windows\system32\nsisvc.dll
14:20:07.0388 6648  nsi - ok
14:20:07.0388 6648  [ e7f5ae18af4168178a642a9247c63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
14:20:07.0435 6648  nsiproxy - ok
14:20:07.0591 6648  [ a2f74975097f52a00745f9637451fdd8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
14:20:07.0653 6648  Ntfs - ok
14:20:07.0669 6648  [ 9899284589f75fa8724ff3d16aed75c1 ] Null            C:\Windows\system32\drivers\Null.sys
14:20:07.0716 6648  Null - ok
14:20:07.0747 6648  [ 0ebc9d13cd96c15b1b18d8678a609e4b ] nusb3hub        C:\Windows\system32\DRIVERS\nusb3hub.sys
14:20:07.0778 6648  nusb3hub - ok
14:20:07.0809 6648  [ 7bdec000d56d485021d9c1e63c2f81ca ] nusb3xhc        C:\Windows\system32\DRIVERS\nusb3xhc.sys
14:20:07.0825 6648  nusb3xhc - ok
14:20:08.0246 6648  [ 133abf21013397141ab991d14a415598 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
14:20:08.0574 6648  nvlddmkm - ok
14:20:08.0605 6648  [ 1c4ba91e68852ec526429c4892e8e79f ] nvpciflt        C:\Windows\system32\DRIVERS\nvpciflt.sys
14:20:08.0621 6648  nvpciflt - ok
14:20:08.0652 6648  [ 0a92cb65770442ed0dc44834632f66ad ] nvraid          C:\Windows\system32\drivers\nvraid.sys
14:20:08.0667 6648  nvraid - ok
14:20:08.0714 6648  [ dab0e87525c10052bf65f06152f37e4a ] nvstor          C:\Windows\system32\drivers\nvstor.sys
14:20:08.0745 6648  nvstor - ok
14:20:08.0792 6648  [ 92d06926c5da2a2e62e8fb5104f44d92 ] NvStUSB        C:\Windows\system32\drivers\nvstusb.sys
14:20:08.0823 6648  NvStUSB - ok
14:20:08.0917 6648  [ 8b130eff4fffb3f996c95f154ac82308 ] NVSvc          C:\Windows\system32\nvvsvc.exe
14:20:09.0104 6648  NVSvc - ok
14:20:09.0323 6648  [ 0c310811bb620161b79c2fec2fa97fba ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
14:20:09.0525 6648  nvUpdatusService - ok
14:20:09.0557 6648  [ 270d7cd42d6e3979f6dd0146650f0e05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
14:20:09.0588 6648  nv_agp - ok
14:20:09.0619 6648  [ 3589478e4b22ce21b41fa1bfc0b8b8a0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
14:20:09.0713 6648  ohci1394 - ok
14:20:09.0900 6648  [ 9d10f99a6712e28f8acd5641e3a7ea6b ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:20:09.0947 6648  ose - ok
14:20:10.0321 6648  [ 61bffb5f57ad12f83ab64b7181829b34 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
14:20:10.0617 6648  osppsvc - ok
14:20:10.0649 6648  [ 3eac4455472cc2c97107b5291e0dcafe ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
14:20:10.0758 6648  p2pimsvc - ok
14:20:10.0789 6648  [ 927463ecb02179f88e4b9a17568c63c3 ] p2psvc          C:\Windows\system32\p2psvc.dll
14:20:10.0836 6648  p2psvc - ok
14:20:10.0867 6648  [ 0086431c29c35be1dbc43f52cc273887 ] Parport        C:\Windows\system32\drivers\parport.sys
14:20:10.0914 6648  Parport - ok
14:20:10.0945 6648  [ e9766131eeade40a27dc27d2d68fba9c ] partmgr        C:\Windows\system32\drivers\partmgr.sys
14:20:10.0961 6648  partmgr - ok
14:20:10.0992 6648  [ 3aeaa8b561e63452c655dc0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
14:20:11.0039 6648  PcaSvc - ok
14:20:11.0070 6648  [ 94575c0571d1462a0f70bde6bd6ee6b3 ] pci            C:\Windows\system32\drivers\pci.sys
14:20:11.0085 6648  pci - ok
14:20:11.0117 6648  [ b5b8b5ef2e5cb34df8dcf8831e3534fa ] pciide          C:\Windows\system32\drivers\pciide.sys
14:20:11.0148 6648  pciide - ok
14:20:11.0179 6648  [ b2e81d4e87ce48589f98cb8c05b01f2f ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
14:20:11.0210 6648  pcmcia - ok
14:20:11.0226 6648  [ d6b9c2e1a11a3a4b26a182ffef18f603 ] pcw            C:\Windows\system32\drivers\pcw.sys
14:20:11.0257 6648  pcw - ok
14:20:11.0273 6648  [ 68769c3356b3be5d1c732c97b9a80d6e ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
14:20:11.0413 6648  PEAUTH - ok
14:20:11.0538 6648  [ e495e408c93141e8fc72dc0c6046ddfa ] PerfHost        C:\Windows\SysWow64\perfhost.exe
14:20:11.0569 6648  PerfHost - ok
14:20:11.0678 6648  [ c7cf6a6e137463219e1259e3f0f0dd6c ] pla            C:\Windows\system32\pla.dll
14:20:11.0787 6648  pla - ok
14:20:11.0897 6648  [ 25fbdef06c4d92815b353f6e792c8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
14:20:11.0959 6648  PlugPlay - ok
14:20:11.0990 6648  [ 7195581cec9bb7d12abe54036acc2e38 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
14:20:12.0021 6648  PNRPAutoReg - ok
14:20:12.0068 6648  [ 3eac4455472cc2c97107b5291e0dcafe ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
14:20:12.0146 6648  PNRPsvc - ok
14:20:12.0177 6648  [ 4f15d75adf6156bf56eced6d4a55c389 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
14:20:12.0271 6648  PolicyAgent - ok
14:20:12.0318 6648  [ 6ba9d927dded70bd1a9caded45f8b184 ] Power          C:\Windows\system32\umpo.dll
14:20:12.0365 6648  Power - ok
14:20:12.0396 6648  [ f92a2c41117a11a00be01ca01a7fcde9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
14:20:12.0458 6648  PptpMiniport - ok
14:20:12.0474 6648  [ 0d922e23c041efb1c3fac2a6f943c9bf ] Processor      C:\Windows\system32\drivers\processr.sys
14:20:12.0505 6648  Processor - ok
14:20:12.0552 6648  [ 53e83f1f6cf9d62f32801cf66d8352a8 ] ProfSvc        C:\Windows\system32\profsvc.dll
14:20:12.0599 6648  ProfSvc - ok
14:20:12.0599 6648  [ c118a82cd78818c29ab228366ebf81c3 ] ProtectedStorage C:\Windows\system32\lsass.exe
14:20:12.0614 6648  ProtectedStorage - ok
14:20:12.0661 6648  [ 0557cf5a2556bd58e26384169d72438d ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
14:20:12.0723 6648  Psched - ok
14:20:12.0755 6648  [ 87b04878a6d59d6c79251dc960c674c1 ] PxHlpa64        C:\Windows\system32\Drivers\PxHlpa64.sys
14:20:12.0770 6648  PxHlpa64 - ok
14:20:12.0801 6648  [ 0928bd20273625622722fe1de5bbde57 ] qicflt          C:\Windows\system32\DRIVERS\qicflt.sys
14:20:12.0833 6648  qicflt - ok
14:20:12.0942 6648  [ a53a15a11ebfd21077463ee2c7afeef0 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
14:20:13.0129 6648  ql2300 - ok
14:20:13.0160 6648  [ 4f6d12b51de1aaeff7dc58c4d75423c8 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
14:20:13.0191 6648  ql40xx - ok
14:20:13.0223 6648  [ 906191634e99aea92c4816150bda3732 ] QWAVE          C:\Windows\system32\qwave.dll
14:20:13.0254 6648  QWAVE - ok
14:20:13.0269 6648  [ 76707bb36430888d9ce9d705398adb6c ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
14:20:13.0316 6648  QWAVEdrv - ok
14:20:13.0347 6648  [ 5a0da8ad5762fa2d91678a8a01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
14:20:13.0394 6648  RasAcd - ok
14:20:13.0441 6648  [ 7ecff9b22276b73f43a99a15a6094e90 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
14:20:13.0472 6648  RasAgileVpn - ok
14:20:13.0503 6648  [ 8f26510c5383b8dbe976de1cd00fc8c7 ] RasAuto        C:\Windows\System32\rasauto.dll
14:20:13.0550 6648  RasAuto - ok
14:20:13.0581 6648  [ 471815800ae33e6f1c32fb1b97c490ca ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
14:20:13.0644 6648  Rasl2tp - ok
14:20:13.0691 6648  [ ee867a0870fc9e4972ba9eaad35651e2 ] RasMan          C:\Windows\System32\rasmans.dll
14:20:13.0784 6648  RasMan - ok
14:20:13.0815 6648  [ 855c9b1cd4756c5e9a2aa58a15f58c25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
14:20:13.0862 6648  RasPppoe - ok
14:20:13.0878 6648  [ e8b1e447b008d07ff47d016c2b0eeecb ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
14:20:13.0925 6648  RasSstp - ok
14:20:13.0956 6648  [ 77f665941019a1594d887a74f301fa2f ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
14:20:13.0987 6648  rdbss - ok
14:20:14.0034 6648  [ 302da2a0539f2cf54d7c6cc30c1f2d8d ] rdpbus          C:\Windows\system32\drivers\rdpbus.sys
14:20:14.0065 6648  rdpbus - ok
14:20:14.0096 6648  [ cea6cc257fc9b7715f1c2b4849286d24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
14:20:14.0127 6648  RDPCDD - ok
14:20:14.0127 6648  [ bb5971a4f00659529a5c44831af22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
14:20:14.0205 6648  RDPENCDD - ok
14:20:14.0205 6648  [ 216f3fa57533d98e1f74ded70113177a ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
14:20:14.0237 6648  RDPREFMP - ok
14:20:14.0268 6648  [ e61608aa35e98999af9aaeeea6114b0a ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
14:20:14.0315 6648  RDPWD - ok
14:20:14.0361 6648  [ 34ed295fa0121c241bfef24764fc4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
14:20:14.0393 6648  rdyboost - ok
14:20:14.0455 6648  [ 7196be857e29007470ff9b689c7f29a7 ] RegSrvc        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
14:20:14.0580 6648  RegSrvc - ok
14:20:14.0595 6648  [ 254fb7a22d74e5511c73a3f6d802f192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
14:20:14.0642 6648  RemoteAccess - ok
14:20:14.0673 6648  [ e4d94f24081440b5fc5aa556c7c62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
14:20:14.0720 6648  RemoteRegistry - ok
14:20:14.0783 6648  [ 3dd798846e2c28102b922c56e71b7932 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
14:20:14.0814 6648  RFCOMM - ok
14:20:14.0954 6648  [ 3c957189b31c34d3ad21967b12b6aed7 ] RoxMediaDB12OEM C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
14:20:15.0095 6648  RoxMediaDB12OEM - ok
14:20:15.0141 6648  [ 2b73088cc2ca757a172b425c9398e5bc ] RoxWatch12      C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
14:20:15.0173 6648  RoxWatch12 - ok
14:20:15.0188 6648  [ e4dc58cf7b3ea515ae917ff0d402a7bb ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
14:20:15.0235 6648  RpcEptMapper - ok
14:20:15.0266 6648  [ d5ba242d4cf8e384db90e6a8ed850b8c ] RpcLocator      C:\Windows\system32\locator.exe
14:20:15.0297 6648  RpcLocator - ok
14:20:15.0344 6648  [ 5c627d1b1138676c0a7ab2c2c190d123 ] RpcSs          C:\Windows\system32\rpcss.dll
14:20:15.0407 6648  RpcSs - ok
14:20:15.0453 6648  [ ddc86e4f8e7456261e637e3552e804ff ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
14:20:15.0485 6648  rspndr - ok
14:20:15.0547 6648  [ 9140db0911de035fed0a9a77a2d156ea ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
14:20:15.0609 6648  RTL8167 - ok
14:20:15.0641 6648  [ c118a82cd78818c29ab228366ebf81c3 ] SamSs          C:\Windows\system32\lsass.exe
14:20:15.0656 6648  SamSs - ok
14:20:15.0672 6648  [ ac03af3329579fffb455aa2daabbe22b ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
14:20:15.0703 6648  sbp2port - ok
14:20:15.0734 6648  [ 9b7395789e3791a3b6d000fe6f8b131e ] SCardSvr        C:\Windows\System32\SCardSvr.dll
14:20:15.0812 6648  SCardSvr - ok
14:20:15.0828 6648  [ 253f38d0d7074c02ff8deb9836c97d2b ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
14:20:15.0875 6648  scfilter - ok
14:20:15.0921 6648  [ 262f6592c3299c005fd6bec90fc4463a ] Schedule        C:\Windows\system32\schedsvc.dll
14:20:16.0062 6648  Schedule - ok
14:20:16.0077 6648  [ f17d1d393bbc69c5322fbfafaca28c7f ] SCPolicySvc    C:\Windows\System32\certprop.dll
14:20:16.0109 6648  SCPolicySvc - ok
14:20:16.0124 6648  [ 6ea4234dc55346e0709560fe7c2c1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
14:20:16.0155 6648  SDRSVC - ok
14:20:16.0187 6648  [ 3ea8a16169c26afbeb544e0e48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
14:20:16.0233 6648  secdrv - ok
14:20:16.0249 6648  [ bc617a4e1b4fa8df523a061739a0bd87 ] seclogon        C:\Windows\system32\seclogon.dll
14:20:16.0280 6648  seclogon - ok
14:20:16.0296 6648  [ c32ab8fa018ef34c0f113bd501436d21 ] SENS            C:\Windows\System32\sens.dll
14:20:16.0358 6648  SENS - ok
14:20:16.0374 6648  [ 0336cffafaab87a11541f1cf1594b2b2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
14:20:16.0389 6648  SensrSvc - ok
14:20:16.0436 6648  [ cb624c0035412af0debec78c41f5ca1b ] Serenum        C:\Windows\system32\drivers\serenum.sys
14:20:16.0467 6648  Serenum - ok
14:20:16.0483 6648  [ c1d8e28b2c2adfaec4ba89e9fda69bd6 ] Serial          C:\Windows\system32\drivers\serial.sys
14:20:16.0514 6648  Serial - ok
14:20:16.0545 6648  [ 1c545a7d0691cc4a027396535691c3e3 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
14:20:16.0577 6648  sermouse - ok
14:20:16.0592 6648  [ 0b6231bf38174a1628c4ac812cc75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
14:20:16.0639 6648  SessionEnv - ok
14:20:16.0655 6648  [ a554811bcd09279536440c964ae35bbf ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
14:20:16.0686 6648  sffdisk - ok
14:20:16.0717 6648  [ ff414f0baefeba59bc6c04b3db0b87bf ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
14:20:16.0733 6648  sffp_mmc - ok
14:20:16.0748 6648  [ dd85b78243a19b59f0637dcf284da63c ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
14:20:16.0779 6648  sffp_sd - ok
14:20:16.0795 6648  [ a9d601643a1647211a1ee2ec4e433ff4 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
14:20:16.0826 6648  sfloppy - ok
14:20:16.0873 6648  [ c6cc9297bd53e5229653303e556aa539 ] Sftfs          C:\Windows\system32\DRIVERS\Sftfslh.sys
14:20:16.0935 6648  Sftfs - ok
14:20:17.0045 6648  [ 13693b6354dd6e72dc5131da7d764b90 ] sftlist        C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
14:20:17.0138 6648  sftlist - ok
14:20:17.0169 6648  [ 390aa7bc52cee43f6790cdea1e776703 ] Sftplay        C:\Windows\system32\DRIVERS\Sftplaylh.sys
14:20:17.0185 6648  Sftplay - ok
14:20:17.0201 6648  [ 617e29a0b0a2807466560d4c4e338d3e ] Sftredir        C:\Windows\system32\DRIVERS\Sftredirlh.sys
14:20:17.0216 6648  Sftredir - ok
14:20:17.0575 6648  [ 74ec60e20516aaa573be74f31175270f ] SftService      C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
14:20:17.0778 6648  SftService - ok
14:20:17.0809 6648  [ 8f571f016fa1976f445147e9e6c8ae9b ] Sftvol          C:\Windows\system32\DRIVERS\Sftvollh.sys
14:20:17.0825 6648  Sftvol - ok
14:20:17.0856 6648  [ c3cddd18f43d44ab713cf8c4916f7696 ] sftvsa          C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
14:20:17.0887 6648  sftvsa - ok
14:20:17.0918 6648  [ b95f6501a2f8b2e78c697fec401970ce ] SharedAccess    C:\Windows\System32\ipnathlp.dll
14:20:18.0027 6648  SharedAccess - ok
14:20:18.0059 6648  [ aaf932b4011d14052955d4b212a4da8d ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:20:18.0137 6648  ShellHWDetection - ok
14:20:18.0152 6648  [ 843caf1e5fde1ffd5ff768f23a51e2e1 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
14:20:18.0183 6648  SiSRaid2 - ok
14:20:18.0199 6648  [ 6a6c106d42e9ffff8b9fcb4f754f6da4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
14:20:18.0215 6648  SiSRaid4 - ok
14:20:18.0230 6648  [ 548260a7b8654e024dc30bf8a7c5baa4 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
14:20:18.0277 6648  Smb - ok
14:20:18.0308 6648  [ 6313f223e817cc09aa41811daa7f541d ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
14:20:18.0324 6648  SNMPTRAP - ok
14:20:18.0371 6648  [ b9e31e5cacdfe584f34f730a677803f9 ] spldr          C:\Windows\system32\drivers\spldr.sys
14:20:18.0386 6648  spldr - ok
14:20:18.0402 6648  [ b96c17b5dc1424d56eea3a99e97428cd ] Spooler        C:\Windows\System32\spoolsv.exe
14:20:18.0480 6648  Spooler - ok
14:20:18.0667 6648  [ e17e0188bb90fae42d83e98707efa59c ] sppsvc          C:\Windows\system32\sppsvc.exe
14:20:18.0839 6648  sppsvc - ok
14:20:18.0870 6648  [ 93d7d61317f3d4bc4f4e9f8a96a7de45 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
14:20:18.0901 6648  sppuinotify - ok
14:20:18.0948 6648  [ 441fba48bff01fdb9d5969ebc1838f0b ] srv            C:\Windows\system32\DRIVERS\srv.sys
14:20:19.0057 6648  srv - ok
14:20:19.0088 6648  [ b4adebbf5e3677cce9651e0f01f7cc28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
14:20:19.0166 6648  srv2 - ok
14:20:19.0182 6648  [ 27e461f0be5bff5fc737328f749538c3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
14:20:19.0213 6648  srvnet - ok
14:20:19.0260 6648  [ 51b52fbd583cde8aa9ba62b8b4298f33 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
14:20:19.0291 6648  SSDPSRV - ok
14:20:19.0322 6648  [ ab7aebf58dad8daab7a6c45e6a8885cb ] SstpSvc        C:\Windows\system32\sstpsvc.dll
14:20:19.0353 6648  SstpSvc - ok
14:20:19.0385 6648  [ 92e7f6666633d2dd91d527503daa7be0 ] stdcfltn        C:\Windows\system32\DRIVERS\stdcfltn.sys
14:20:19.0400 6648  stdcfltn - ok
14:20:19.0463 6648  [ a4418ba8fa670d1e48d57632d50d552d ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
14:20:19.0541 6648  Stereo Service - ok
14:20:19.0572 6648  [ f3817967ed533d08327dc73bc4d5542a ] stexstor        C:\Windows\system32\drivers\stexstor.sys
14:20:19.0587 6648  stexstor - ok
14:20:19.0619 6648  [ decacb6921ded1a38642642685d77dac ] StillCam        C:\Windows\system32\DRIVERS\serscan.sys
14:20:19.0665 6648  StillCam - ok
14:20:19.0697 6648  [ 8dd52e8e6128f4b2da92ce27402871c1 ] stisvc          C:\Windows\System32\wiaservc.dll
14:20:19.0775 6648  stisvc - ok
14:20:19.0821 6648  [ 7731f46ec0d687a931cba063e8f90ef0 ] stllssvr        C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
14:20:19.0837 6648  stllssvr - ok
14:20:19.0853 6648  [ d01ec09b6711a5f8e7e6564a4d0fbc90 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
14:20:19.0868 6648  swenum - ok
14:20:19.0899 6648  [ e08e46fdd841b7184194011ca1955a0b ] swprv          C:\Windows\System32\swprv.dll
14:20:19.0977 6648  swprv - ok
14:20:20.0055 6648  [ 5e3b232a614339399acc71fa3aaaaa6b ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
14:20:20.0102 6648  SynTP - ok
14:20:20.0445 6648  [ bf9ccc0bf39b418c8d0ae8b05cf95b7d ] SysMain        C:\Windows\system32\sysmain.dll
14:20:20.0617 6648  SysMain - ok
14:20:20.0648 6648  [ e3c61fd7b7c2557e1f1b0b4cec713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:20:20.0679 6648  TabletInputService - ok
14:20:20.0695 6648  [ 40f0849f65d13ee87b9a9ae3c1dd6823 ] TapiSrv        C:\Windows\System32\tapisrv.dll
14:20:20.0757 6648  TapiSrv - ok
14:20:20.0757 6648  [ 1be03ac720f4d302ea01d40f588162f6 ] TBS            C:\Windows\System32\tbssvc.dll
14:20:20.0789 6648  TBS - ok
14:20:20.0851 6648  [ acb82bda8f46c84f465c1afa517dc4b9 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
14:20:20.0929 6648  Tcpip - ok
14:20:20.0976 6648  [ acb82bda8f46c84f465c1afa517dc4b9 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
14:20:21.0069 6648  TCPIP6 - ok
14:20:21.0085 6648  [ df687e3d8836bfb04fcc0615bf15a519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
14:20:21.0132 6648  tcpipreg - ok
14:20:21.0147 6648  [ 3371d21011695b16333a3934340c4e7c ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
14:20:21.0179 6648  TDPIPE - ok
14:20:21.0194 6648  [ 51c5eceb1cdee2468a1748be550cfbc8 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
14:20:21.0225 6648  TDTCP - ok
14:20:21.0241 6648  [ ddad5a7ab24d8b65f8d724f5c20fd806 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
14:20:21.0272 6648  tdx - ok
14:20:21.0288 6648  [ 561e7e1f06895d78de991e01dd0fb6e5 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
14:20:21.0319 6648  TermDD - ok
14:20:21.0366 6648  [ 2e648163254233755035b46dd7b89123 ] TermService    C:\Windows\System32\termsrv.dll
14:20:21.0475 6648  TermService - ok
14:20:21.0506 6648  [ f0344071948d1a1fa732231785a0664c ] Themes          C:\Windows\system32\themeservice.dll
14:20:21.0522 6648  Themes - ok
14:20:21.0537 6648  [ e40e80d0304a73e8d269f7141d77250b ] THREADORDER    C:\Windows\system32\mmcss.dll
14:20:21.0584 6648  THREADORDER - ok
14:20:21.0584 6648  [ 7e7afd841694f6ac397e99d75cead49d ] TrkWks          C:\Windows\System32\trkwks.dll
14:20:21.0631 6648  TrkWks - ok
14:20:21.0678 6648  [ 773212b2aaa24c1e31f10246b15b276c ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:20:21.0725 6648  TrustedInstaller - ok
14:20:21.0740 6648  [ ce18b2cdfc837c99e5fae9ca6cba5d30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
14:20:21.0771 6648  tssecsrv - ok
14:20:21.0787 6648  [ d11c783e3ef9a3c52c0ebe83cc5000e9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
14:20:21.0818 6648  TsUsbFlt - ok
14:20:21.0849 6648  [ 9cc2ccae8a84820eaecb886d477cbcb8 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
14:20:21.0881 6648  TsUsbGD - ok
14:20:21.0912 6648  [ 3566a8daafa27af944f5d705eaa64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
14:20:21.0959 6648  tunnel - ok
14:20:21.0990 6648  [ fd24f98d2898be093fe926604be7db99 ] TurboB          C:\Windows\system32\DRIVERS\TurboB.sys
14:20:22.0005 6648  TurboB - ok
14:20:22.0037 6648  [ 600b406a04d90f577fea8a88d7379f08 ] TurboBoost      C:\Program Files\Intel\TurboBoost\TurboBoost.exe
14:20:22.0068 6648  TurboBoost - ok
14:20:22.0083 6648  [ b4dd609bd7e282bfc683cec7eaaaad67 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
14:20:22.0099 6648  uagp35 - ok
14:20:22.0130 6648  [ ff4232a1a64012baa1fd97c7b67df593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
14:20:22.0208 6648  udfs - ok
14:20:22.0239 6648  [ 3cbdec8d06b9968aba702eba076364a1 ] UI0Detect      C:\Windows\system32\UI0Detect.exe
14:20:22.0271 6648  UI0Detect - ok
14:20:22.0317 6648  [ 4bfe1bc28391222894cbf1e7d0e42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
14:20:22.0333 6648  uliagpkx - ok
14:20:22.0333 6648  [ dc54a574663a895c8763af0fa1ff7561 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
14:20:22.0364 6648  umbus - ok
14:20:22.0411 6648  [ b2e8e8cb557b156da5493bbddcc1474d ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
14:20:22.0442 6648  UmPass - ok
14:20:22.0583 6648  [ 2c16648a12999ae69a9ebf41974b0ba2 ] UNS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
14:20:22.0832 6648  UNS - ok
14:20:22.0879 6648  [ d47ec6a8e81633dd18d2436b19baf6de ] upnphost        C:\Windows\System32\upnphost.dll
14:20:22.0957 6648  upnphost - ok
14:20:22.0988 6648  [ fb251567f41bc61988b26731dec19e4b ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
14:20:23.0035 6648  USBAAPL64 - ok
14:20:23.0051 6648  [ 19ad7990c0b67e48dac5b26f99628223 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
14:20:23.0082 6648  usbccgp - ok
14:20:23.0129 6648  [ af0892a803fdda7492f595368e3b68e7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
14:20:23.0144 6648  usbcir - ok
14:20:23.0160 6648  [ c025055fe7b87701eb042095df1a2d7b ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
14:20:23.0175 6648  usbehci - ok
14:20:23.0222 6648  [ 287c6c9410b111b68b52ca298f7b8c24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
14:20:23.0269 6648  usbhub - ok
14:20:23.0300 6648  [ 9840fc418b4cbd632d3d0a667a725c31 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
14:20:23.0316 6648  usbohci - ok
14:20:23.0347 6648  [ 73188f58fb384e75c4063d29413cee3d ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
14:20:23.0378 6648  usbprint - ok
14:20:23.0425 6648  [ aaa2513c8aed8b54b189fd0c6b1634c0 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
14:20:23.0441 6648  usbscan - ok
14:20:23.0472 6648  [ fed648b01349a3c8395a5169db5fb7d6 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:20:23.0503 6648  USBSTOR - ok
14:20:23.0534 6648  [ 62069a34518bcf9c1fd9e74b3f6db7cd ] usbuhci        C:\Windows\system32\drivers\usbuhci.sys
14:20:23.0581 6648  usbuhci - ok
14:20:23.0581 6648  [ 454800c2bc7f3927ce030141ee4f4c50 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
14:20:23.0628 6648  usbvideo - ok
14:20:23.0659 6648  [ edbb23cbcf2cdf727d64ff9b51a6070e ] UxSms          C:\Windows\System32\uxsms.dll
14:20:23.0706 6648  UxSms - ok
14:20:23.0706 6648  [ c118a82cd78818c29ab228366ebf81c3 ] VaultSvc        C:\Windows\system32\lsass.exe
14:20:23.0737 6648  VaultSvc - ok
14:20:23.0799 6648  [ c5c876ccfc083ff3b128f933823e87bd ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
14:20:23.0815 6648  vdrvroot - ok
14:20:23.0862 6648  [ 8d6b481601d01a456e75c3210f1830be ] vds            C:\Windows\System32\vds.exe
14:20:24.0002 6648  vds - ok
14:20:24.0033 6648  [ da4da3f5e02943c2dc8c6ed875de68dd ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
14:20:24.0049 6648  vga - ok
14:20:24.0065 6648  [ 53e92a310193cb3c03bea963de7d9cfc ] VgaSave        C:\Windows\System32\drivers\vga.sys
14:20:24.0111 6648  VgaSave - ok
14:20:24.0127 6648  [ 2ce2df28c83aeaf30084e1b1eb253cbb ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
14:20:24.0143 6648  vhdmp - ok
14:20:24.0158 6648  [ e5689d93ffe4e5d66c0178761240dd54 ] viaide          C:\Windows\system32\drivers\viaide.sys
14:20:24.0189 6648  viaide - ok
14:20:24.0205 6648  [ d2aafd421940f640b407aefaaebd91b0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
14:20:24.0221 6648  volmgr - ok
14:20:24.0267 6648  [ a255814907c89be58b79ef2f189b843b ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
14:20:24.0330 6648  volmgrx - ok
14:20:24.0330 6648  [ 0d08d2f3b3ff84e433346669b5e0f639 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
14:20:24.0361 6648  volsnap - ok
14:20:24.0408 6648  [ 5e2016ea6ebaca03c04feac5f330d997 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
14:20:24.0439 6648  vsmraid - ok
14:20:24.0548 6648  [ b60ba0bc31b0cb414593e169f6f21cc2 ] VSS            C:\Windows\system32\vssvc.exe
14:20:24.0673 6648  VSS - ok
14:20:24.0689 6648  [ 36d4720b72b5c5d9cb2b9c29e9df67a1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
14:20:24.0720 6648  vwifibus - ok
14:20:24.0751 6648  [ 6a3d66263414ff0d6fa754c646612f3f ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
14:20:24.0782 6648  vwififlt - ok
14:20:24.0798 6648  [ 6a638fc4bfddc4d9b186c28c91bd1a01 ] vwifimp        C:\Windows\system32\DRIVERS\vwifimp.sys
14:20:24.0829 6648  vwifimp - ok
14:20:24.0860 6648  [ 1c9d80cc3849b3788048078c26486e1a ] W32Time        C:\Windows\system32\w32time.dll
14:20:24.0938 6648  W32Time - ok
14:20:24.0969 6648  [ 4e9440f4f152a7b944cb1663d3935a3e ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
14:20:24.0985 6648  WacomPen - ok
14:20:25.0032 6648  [ 356afd78a6ed4457169241ac3965230c ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
14:20:25.0079 6648  WANARP - ok
14:20:25.0079 6648  [ 356afd78a6ed4457169241ac3965230c ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
14:20:25.0110 6648  Wanarpv6 - ok
14:20:25.0188 6648  [ 3cec96de223e49eaae3651fcf8faea6c ] WatAdminSvc    C:\Windows\system32\Wat\WatAdminSvc.exe
14:20:25.0328 6648  WatAdminSvc - ok
14:20:25.0375 6648  [ 78f4e7f5c56cb9716238eb57da4b6a75 ] wbengine        C:\Windows\system32\wbengine.exe
14:20:25.0453 6648  wbengine - ok
14:20:25.0484 6648  [ 3aa101e8edab2db4131333f4325c76a3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
14:20:25.0515 6648  WbioSrvc - ok
14:20:25.0578 6648  [ 7368a2afd46e5a4481d1de9d14848edd ] wcncsvc        C:\Windows\System32\wcncsvc.dll
14:20:25.0781 6648  wcncsvc - ok
14:20:25.0796 6648  [ 20f7441334b18cee52027661df4a6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:20:25.0827 6648  WcsPlugInService - ok
14:20:25.0874 6648  [ 72889e16ff12ba0f235467d6091b17dc ] Wd              C:\Windows\system32\drivers\wd.sys
14:20:25.0905 6648  Wd - ok
14:20:25.0921 6648  [ 441bd2d7b4f98134c3a4f9fa570fd250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
14:20:25.0983 6648  Wdf01000 - ok
14:20:25.0999 6648  [ bf1fc3f79b863c914687a737c2f3d681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
14:20:26.0077 6648  WdiServiceHost - ok
14:20:26.0077 6648  [ bf1fc3f79b863c914687a737c2f3d681 ] WdiSystemHost  C:\Windows\system32\wdi.dll
14:20:26.0093 6648  WdiSystemHost - ok
14:20:26.0139 6648  [ 63ce387483e74a0bd79ee4e5eba1fd2e ] wdkmd          C:\Windows\system32\DRIVERS\WDKMD.sys
14:20:26.0264 6648  wdkmd - ok
14:20:26.0311 6648  [ 3db6d04e1c64272f8b14eb8bc4616280 ] WebClient      C:\Windows\System32\webclnt.dll
14:20:26.0342 6648  WebClient - ok
14:20:26.0373 6648  [ c749025a679c5103e575e3b48e092c43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
14:20:26.0436 6648  Wecsvc - ok
14:20:26.0467 6648  [ 7e591867422dc788b9e5bd337a669a08 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
14:20:26.0514 6648  wercplsupport - ok
14:20:26.0529 6648  [ 6d137963730144698cbd10f202e9f251 ] WerSvc          C:\Windows\System32\WerSvc.dll
14:20:26.0576 6648  WerSvc - ok
14:20:26.0592 6648  [ 611b23304bf067451a9fdee01fbdd725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
14:20:26.0639 6648  WfpLwf - ok
14:20:26.0670 6648  [ b14ef15bd757fa488f9c970eee9c0d35 ] WimFltr        C:\Windows\system32\DRIVERS\wimfltr.sys
14:20:26.0685 6648  WimFltr - ok
14:20:26.0717 6648  [ 05ecaec3e4529a7153b3136ceb49f0ec ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
14:20:26.0732 6648  WIMMount - ok
14:20:26.0748 6648  WinDefend - ok
14:20:26.0748 6648  WinHttpAutoProxySvc - ok
14:20:26.0919 6648  [ 19b07e7e8915d701225da41cb3877306 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
14:20:26.0951 6648  Winmgmt - ok
14:20:27.0060 6648  [ bcb1310604aa415c4508708975b3931e ] WinRM          C:\Windows\system32\WsmSvc.dll
14:20:27.0278 6648  WinRM - ok
14:20:27.0387 6648  [ fe88b288356e7b47b74b13372add906d ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
14:20:27.0434 6648  WinUsb - ok
14:20:27.0621 6648  [ 4fada86e62f18a1b2f42ba18ae24e6aa ] Wlansvc        C:\Windows\System32\wlansvc.dll
14:20:27.0699 6648  Wlansvc - ok
14:20:27.0762 6648  [ 06c8fa1cf39de6a735b54d906ba791c6 ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
14:20:27.0777 6648  wlcrasvc - ok
14:20:28.0152 6648  [ 2bacd71123f42cea603f4e205e1ae337 ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
14:20:28.0214 6648  wlidsvc - ok
14:20:28.0245 6648  [ f6ff8944478594d0e414d3f048f0d778 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
14:20:31.0256 6648  WmiAcpi - ok
14:20:31.0319 6648  [ 38b84c94c5a8af291adfea478ae54f93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
14:20:31.0365 6648  wmiApSrv - ok
14:20:31.0412 6648  WMPNetworkSvc - ok
14:20:31.0475 6648  [ 96c6e7100d724c69fcf9e7bf590d1dca ] WPCSvc          C:\Windows\System32\wpcsvc.dll
14:20:31.0490 6648  WPCSvc - ok
14:20:31.0537 6648  [ 93221146d4ebbf314c29b23cd6cc391d ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
14:20:31.0553 6648  WPDBusEnum - ok
14:20:31.0631 6648  [ 6bcc1d7d2fd2453957c5479a32364e52 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
14:20:31.0662 6648  ws2ifsl - ok
14:20:31.0709 6648  [ e8b1fe6669397d1772d8196df0e57a9e ] wscsvc          C:\Windows\System32\wscsvc.dll
14:20:31.0755 6648  wscsvc - ok
14:20:31.0818 6648  [ 8d918b1db190a4d9b1753a66fa8c96e8 ] WSDPrintDevice  C:\Windows\system32\DRIVERS\WSDPrint.sys
14:20:31.0880 6648  WSDPrintDevice - ok
14:20:31.0880 6648  WSearch - ok
14:20:32.0270 6648  [ d9ef901dca379cfe914e9fa13b73b4c4 ] wuauserv        C:\Windows\system32\wuaueng.dll
14:20:32.0333 6648  wuauserv - ok
14:20:32.0364 6648  [ d3381dc54c34d79b22cee0d65ba91b7c ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
14:20:32.0426 6648  WudfPf - ok
14:20:32.0504 6648  [ cf8d590be3373029d57af80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
14:20:32.0567 6648  WUDFRd - ok
14:20:32.0582 6648  [ 7a95c95b6c4cf292d689106bcae49543 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
14:20:32.0613 6648  wudfsvc - ok
14:20:32.0676 6648  [ 9a3452b3c2a46c073166c5cf49fad1ae ] WwanSvc        C:\Windows\System32\wwansvc.dll
14:20:32.0723 6648  WwanSvc - ok
14:20:32.0754 6648  ================ Scan global ===============================
14:20:32.0785 6648  (ba0cd8c393e8c9f83354106093832c7b) C:\Windows\system32\basesrv.dll
14:20:32.0832 6648  (eb6a48cc998e1090e44e8e7f1009a640) C:\Windows\system32\winsrv.dll
14:20:32.0832 6648  (eb6a48cc998e1090e44e8e7f1009a640) C:\Windows\system32\winsrv.dll
14:20:32.0863 6648  (d6160f9d869ba3af0b787f971db56368) C:\Windows\system32\sxssrv.dll
14:20:32.0925 6648  (24acb7e5be595468e3b9aa488b9b4fcb) C:\Windows\system32\services.exe
14:20:32.0925 6648  [Global] - ok
14:20:32.0925 6648  ================ Scan MBR ==================================
14:20:32.0941 6648  MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
14:20:37.0871 6648  \Device\Harddisk0\DR0 - ok
14:20:38.0167 6648  MBR (0x1B8)    (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
14:20:38.0385 6648  \Device\Harddisk1\DR1 - ok
14:20:38.0385 6648  ================ Scan VBR ==================================
14:20:38.0401 6648  Boot (0x1200)  (dbde1d5aa3f68bc56fa95e6be3fdaf7e) \Device\Harddisk0\DR0\Partition1
14:20:38.0401 6648  \Device\Harddisk0\DR0\Partition1 - ok
14:20:38.0401 6648  Boot (0x1200)  (9490f5bf572552322077e7127a41a617) \Device\Harddisk0\DR0\Partition2
14:20:38.0401 6648  \Device\Harddisk0\DR0\Partition2 - ok
14:20:38.0401 6648  Boot (0x1200)  (e7208b097ac2cad3cc8a7b6f934d1600) \Device\Harddisk1\DR1\Partition1
14:20:38.0417 6648  \Device\Harddisk1\DR1\Partition1 - ok
14:20:38.0417 6648  ============================================================
14:20:38.0417 6648  Scan finished
14:20:38.0417 6648  ============================================================
14:20:38.0417 10100  Detected object count: 0
14:20:38.0417 10100  Actual detected object count: 0
15:20:22.0519 4448  Deinitialize success


cosinus 15.08.2012 17:44

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Schmelzkas 01.09.2012 20:03

Combofix Logfile:
Code:

ComboFix 12-08-25.04 - Familie Kis 25.08.2012  19:58:55.1.8 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.6038.3834 [GMT 2:00]
ausgeführt von:: c:\users\Manu&Micha\Downloads\ComboFix.exe
AV: VR-Web Sicherheitspaket 4.0 9.12 *Disabled/Updated* {15414183-282E-D62C-CA37-EF24860A2F17}
FW: VR-Web Sicherheitspaket 4.0 9.12 *Disabled* {2D7AC0A6-6241-D774-E168-461178D9686C}
SP: VR-Web Sicherheitspaket 4.0 9.12 *Disabled/Updated* {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\windows\RPSETUP.EXE.LOG
c:\windows\SysWow64\FlashPlayerInstaller.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-07-25 bis 2012-08-25  ))))))))))))))))))))))))))))))
.
.
2012-08-25 18:03 . 2012-08-25 18:03        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2012-08-25 18:03 . 2012-08-25 18:03        --------        d-----w-        c:\users\Familie Kis\AppData\Local\temp
2012-08-25 18:03 . 2012-08-25 18:03        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-08-25 17:53 . 2012-08-25 17:53        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{41B7EDA6-84BD-43DB-9F2A-5DC76C5FE2BF}\offreg.dll
2012-08-24 10:59 . 2012-08-01 22:58        9309624        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{41B7EDA6-84BD-43DB-9F2A-5DC76C5FE2BF}\mpengine.dll
2012-08-17 18:06 . 2012-07-06 20:07        552960        ----a-w-        c:\windows\system32\drivers\bthport.sys
2012-08-17 13:16 . 2012-05-05 08:36        503808        ----a-w-        c:\windows\system32\srcore.dll
2012-08-17 13:16 . 2012-05-05 07:46        43008        ----a-w-        c:\windows\SysWow64\srclient.dll
2012-08-17 13:15 . 2012-02-11 06:43        751104        ----a-w-        c:\windows\system32\win32spl.dll
2012-08-17 13:15 . 2012-02-11 06:36        559104        ----a-w-        c:\windows\system32\spoolsv.exe
2012-08-17 13:15 . 2012-02-11 06:36        67072        ----a-w-        c:\windows\splwow64.exe
2012-08-17 13:15 . 2012-02-11 05:43        492032        ----a-w-        c:\windows\SysWow64\win32spl.dll
2012-08-17 13:15 . 2012-07-04 22:16        73216        ----a-w-        c:\windows\system32\netapi32.dll
2012-08-17 13:15 . 2012-07-04 22:13        59392        ----a-w-        c:\windows\system32\browcli.dll
2012-08-17 13:15 . 2012-07-04 22:13        136704        ----a-w-        c:\windows\system32\browser.dll
2012-08-17 13:15 . 2012-07-04 21:14        41984        ----a-w-        c:\windows\SysWow64\browcli.dll
2012-08-17 13:15 . 2012-07-18 18:15        3148800        ----a-w-        c:\windows\system32\win32k.sys
2012-08-17 13:15 . 2012-05-14 05:26        956928        ----a-w-        c:\windows\system32\localspl.dll
2012-07-27 20:51 . 2012-07-27 20:51        184248        ----a-w-        c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-17 18:04 . 2011-11-07 21:10        62134624        ----a-w-        c:\windows\system32\MRT.exe
2012-08-17 13:14 . 2012-05-09 18:18        56016        ----a-w-        c:\windows\system32\drivers\fsbts.sys
2012-08-14 18:05 . 2012-04-02 06:40        426184        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-14 18:05 . 2011-09-04 14:49        70344        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-10 16:31 . 2012-07-10 16:31        595968        ----a-w-        C:\OTL3.exe
2012-07-09 18:57 . 2012-07-09 18:57        618655        ----a-w-        C:\adwcleaner.exe
2012-06-09 05:43 . 2012-07-11 09:56        14172672        ----a-w-        c:\windows\system32\shell32.dll
2012-06-06 06:06 . 2012-07-11 09:56        2004480        ----a-w-        c:\windows\system32\msxml6.dll
2012-06-06 06:06 . 2012-07-11 09:56        1881600        ----a-w-        c:\windows\system32\msxml3.dll
2012-06-06 06:02 . 2012-07-11 09:55        1133568        ----a-w-        c:\windows\system32\cdosys.dll
2012-06-06 05:05 . 2012-07-11 09:56        1390080        ----a-w-        c:\windows\SysWow64\msxml6.dll
2012-06-06 05:05 . 2012-07-11 09:56        1236992        ----a-w-        c:\windows\SysWow64\msxml3.dll
2012-06-06 05:03 . 2012-07-11 09:55        805376        ----a-w-        c:\windows\SysWow64\cdosys.dll
2012-06-02 22:19 . 2012-06-21 12:13        38424        ----a-w-        c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 12:13        2428952        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-21 12:13        57880        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 12:13        44056        ----a-w-        c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 12:13        701976        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-21 12:13        2622464        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-21 12:13        99840        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-21 12:12        186752        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-21 12:12        36864        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-02 05:50 . 2012-07-11 09:56        458704        ----a-w-        c:\windows\system32\drivers\cng.sys
2012-06-02 05:48 . 2012-07-11 09:56        95600        ----a-w-        c:\windows\system32\drivers\ksecdd.sys
2012-06-02 05:48 . 2012-07-11 09:56        151920        ----a-w-        c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 05:45 . 2012-07-11 09:56        340992        ----a-w-        c:\windows\system32\schannel.dll
2012-06-02 05:44 . 2012-07-11 09:56        307200        ----a-w-        c:\windows\system32\ncrypt.dll
2012-06-02 04:40 . 2012-07-11 09:56        22016        ----a-w-        c:\windows\SysWow64\secur32.dll
2012-06-02 04:40 . 2012-07-11 09:56        225280        ----a-w-        c:\windows\SysWow64\schannel.dll
2012-06-02 04:39 . 2012-07-11 09:56        219136        ----a-w-        c:\windows\SysWow64\ncrypt.dll
2012-06-02 04:34 . 2012-07-11 09:56        96768        ----a-w-        c:\windows\SysWow64\sspicli.dll
2012-05-31 10:25 . 2010-11-21 03:27        279656        ------w-        c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-07-27 35768]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2012-02-06 66872]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"F-Secure Manager"="c:\program files (x86)\VR-Web Sicherheitspaket\Common\FSM32.EXE" [2009-11-18 201128]
"F-Secure TNB"="c:\program files (x86)\VR-Web Sicherheitspaket\FSGUI\TNBUtil.exe" [2011-11-09 1655464]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2012-02-01 968048]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"OTL"="C:\OTL3.exe" [2012-07-10 595968]
.
c:\users\Manu&Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ctfmon.lnk - c:\windows\System32\rundll32.exe [2009-7-14 45568]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WISO Mein Steuer-Sparbuch heute.lnk - c:\program files (x86)\WISO\Steuersoftware 2012\mshaktuell.exe [2012-1-26 1380504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages        REG_MULTI_SZ          kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys [2011-11-09 50384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-22 136176]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 250056]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys [2011-10-19 195072]
R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-22 136176]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-01 340240]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-08-02 22528]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [2011-01-31 121960]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-09 1255736]
R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 fsbts;fsbts;c:\windows\system32\Drivers\fsbts.sys [2012-08-17 56016]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2011-10-17 27712]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616]
S1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files (x86)\VR-Web Sicherheitspaket\HIPS\drivers\fshs.sys [2009-11-18 59784]
S1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2009-11-18 94024]
S1 fsvista;F-Secure Vista Support Driver;c:\program files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsvista.sys [2009-11-18 16768]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-10-19 661504]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-10-20 135440]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-17 1999168]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-08-18 1692480]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-16 380224]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-10-19 195072]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-08-29 53760]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-15 327168]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files (x86)\VR-Web Sicherheitspaket\Anti-Virus\minifilter\fsgk.sys [2012-05-29 199848]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files (x86)\VR-Web Sicherheitspaket\ORSP Client\fsorsp.exe [2011-11-09 61088]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-09 60416]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-16 317440]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link der Serie 5000 Adaptertreiber für Windows 7 64-Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-10-31 8615936]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-02-10 82432]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-02-10 181760]
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-13 29288]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2011-05-17 42392]
.
.
Inhalt des "geplante Tasks" Ordners
.
2012-08-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 18:05]
.
2012-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-22 09:44]
.
2012-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-22 09:44]
.
2011-11-07 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2011-03-22 17:20]
.
2012-08-24 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2011-03-22 17:20]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2011-08-29 4146848]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"Stage Remote"="c:\program files (x86)\Dell\Stage Remote\StageRemote.exe" [2011-08-08 2034752]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-03 1580368]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-10-18 10357008]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-08-30 7284328]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-11-01 1935120]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-10-17 317248]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2012-02-01 2195824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files (x86)\VR-Web Sicherheitspaket\FSPS\program\FSLSP.DLL
TCP: DhcpNameServer = 192.168.178.1
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-BrowserChoice - c:\windows\System32\browserchoice.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-08-25  20:05:30
ComboFix-quarantined-files.txt  2012-08-25 18:05
.
Vor Suchlauf: 13 Verzeichnis(se), 391.247.515.648 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 391.103.934.464 Bytes frei
.
- - End Of File - - 8E29512A1E6880A174F420FAAAFD8AE8

--- --- ---

cosinus 03.09.2012 15:44

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:20 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131