Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Bundestrojaner? UKash Aufforderung mit Systemstillegung (https://www.trojaner-board.de/125113-bundestrojaner-ukash-aufforderung-systemstillegung.html)

Heistmer 03.10.2012 18:36

Bundestrojaner? UKash Aufforderung mit Systemstillegung
 
Guten Abend,

ich habe mir gestern morgen einen Trojaner / Virus eingefangen.

So sah es dann auf meinem Monitor aus.

hxxp://www.bilder-hochladen.net/files/big/3tqg-2c-9778.jpg

In erster Selbsthilfe habe ich mein System mit einer Boot CD neu gestartet, und mit einigen Scanner das System untersuchen lassen.
(Avira, Anti Maleware, Kaspary, Search & Destroy, Trojan Remover)

Grundsätzlich läuft das system nach einigen funden nun wieder. Jetzt hab ich ein wenig Gegoogelt und bin auf euer Board gestossen, und würde meinen Log gerne einmal begutachten lassen. Gefühlt ist die Reaktionsgeschwindigkeit des IE allerdings beeinträchtigt. Wenn ich eine Seite aufrufe benötigt er meinst eine kurze Gedenkminute. Allerdings halte ich es auch für möglich das ich duch die ganzen durchgeführten Scans der letzten Stunden einfach nicht mehr so geduldig bin :)

Den Defogger hab ich nach Anleitung gestartet
hier jetzt

die OTL.txt

Code:

OTL logfile created on: 03.10.2012 18:52:32 - Run 2
OTL by OldTimer - Version 3.2.70.1    Folder = C:\Users\Heistmer\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,40 Gb Available Physical Memory | 43,22% Memory free
6,71 Gb Paging File | 4,28 Gb Available in Paging File | 63,82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,11 Gb Total Space | 20,53 Gb Free Space | 4,55% Space Free | Partition Type: NTFS
Drive D: | 14,63 Gb Total Space | 10,08 Gb Free Space | 68,92% Space Free | Partition Type: FAT32
Drive J: | 931,50 Gb Total Space | 819,11 Gb Free Space | 87,93% Space Free | Partition Type: NTFS
 
Computer Name: Heistmer-ONE | User Name: Heistmer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
 
========== Processes (SafeList) ==========
 
PRC -  File not found
PRC - C:\Users\Heistmer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
PRC - C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Trillian\libspeex.dll ()
MOD - C:\Program Files (x86)\Trillian\libungif.dll ()
MOD - C:\Program Files (x86)\Trillian\zlib1.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\talk.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\events.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\toolkit.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\buddy.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\trillian.dll ()
MOD - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
MOD - C:\PROGRA~2\MICROS~1\Office12\ADDINS\UMOUTL~1.DLL ()
MOD - C:\PROGRA~2\MICROS~1\Office12\OUTLCTL.DLL ()
MOD - C:\PROGRA~2\MICROS~1\Office12\ADDINS\COLLEA~1.DLL ()
MOD - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (StkSSrv) -- C:\Windows\SysNative\StkCSrv.exe (Syntek America Inc.)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (DeviceMonitorService) -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (MotoHelper) -- C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (mysql) -- C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
SRV - (Apache2.2) -- C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (FileZilla Server) -- C:\Users\Heistmer\Eigene Webs\xampp\FileZillaFTP\FileZillaServer.exe (FileZilla Project)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (FlipShare Service) -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (getPlusHelper) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (cjpcsc) -- C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (IGDCTRL) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (MagicTuneEngine) -- C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (Capture Device Service) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (x10nets) -- C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (motusbdevice) -- C:\Windows\SysNative\DRIVERS\motusbdevice.sys (Motorola Inc)
DRV:64bit: - (motccgp) -- C:\Windows\SysNative\DRIVERS\motccgp.sys (Motorola)
DRV:64bit: - (motmodem) -- C:\Windows\SysNative\DRIVERS\motmodem.sys (Motorola)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Motousbnet) -- C:\Windows\SysNative\DRIVERS\Motousbnet.sys (Motorola)
DRV:64bit: - (cmnsusbser) -- C:\Windows\SysNative\DRIVERS\cmnsusbser.sys (Mobile Connector)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (acedrv10) -- C:\Windows\SysNative\drivers\acedrv10.sys (Protect Software GmbH)
DRV:64bit: - (acehlp10) -- C:\Windows\SysNative\drivers\acehlp10.sys (Protect Software GmbH)
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (motccgpfl) -- C:\Windows\SysNative\DRIVERS\motccgpfl.sys (Motorola)
DRV:64bit: - (BTCFilterService) -- C:\Windows\SysNative\DRIVERS\motfilt.sys (Motorola Inc)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (IntelDH64) -- C:\Windows\SysNative\Drivers\IntelDH64.sys (Intel Corporation)
DRV:64bit: - (3xHybr64) -- C:\Windows\SysNative\DRIVERS\3xHybr64.sys (NXP Semiconductors Germany GmbH)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (L8042Kbd) -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV:64bit: - (MotoSwitchService) -- C:\Windows\SysNative\DRIVERS\motswch.sys (Motorola)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (sxuptp) -- C:\Windows\SysNative\DRIVERS\sxuptp.sys (silex technology, Inc.)
DRV:64bit: - (StkCMini) -- C:\Windows\SysNative\Drivers\StkCMini.sys (Syntek)
DRV:64bit: - (cjusb) -- C:\Windows\SysNative\DRIVERS\cjusb.sys (REINER SCT)
DRV:64bit: - (e1express) -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (XUIF) -- C:\Windows\SysNative\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV:64bit: - (X10Hid) -- C:\Windows\SysNative\Drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (TVICHW64) -- C:\Windows\SysWOW64\drivers\TVICHW64.SYS (EnTech Taiwan)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = hxxp://www.Google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}: "URL" = hxxp://www2.iesearch.com/s/?&q={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "FireSearch"
FF - prefs.js..browser.startup.homepage: "hxxp://www2.firesearch.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.0
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@innoplus.de/inoPanoViewer: C:\Program Files (x86)\innoPlus\Rundum-Betrachter-innoPlus\npirsviewer.dll (INNOVA-engineering GmbH)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010.07.19 18:54:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.05 19:33:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.01.15 22:15:34 | 000,000,000 | ---D | M]
 
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Extensions
[2012.09.04 19:34:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions
[2010.05.19 23:02:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.08.26 21:16:36 | 000,000,000 | ---D | M] ("FireFTP") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2011.03.11 22:28:11 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.12.04 10:46:25 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.12.04 10:46:38 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\firebug@software.joehewitt.com
[2012.09.04 19:34:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.07.19 18:54:34 | 000,000,000 | ---D | M] (Adobe Contribute Toolbar) -- C:\PROGRAM FILES (X86)\ADOBE\ADOBE CONTRIBUTE CS5\PLUGINS\FIREFOXPLUGIN\{01A8CA0A-4C96-465B-A49B-65C46FAD54F9}
[2010.03.27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2008.06.18 09:47:34 | 000,397,312 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npdlplug.dll
[2011.10.26 20:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010.07.18 17:32:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.07.18 17:32:18 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.07.18 17:32:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.07.18 17:32:19 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.07.18 17:32:19 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.03.03 21:42:44 | 000,302,531 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.123topsearch.com
O1 - Hosts: 127.0.0.1        123topsearch.com
O1 - Hosts: 127.0.0.1        www.132.com
O1 - Hosts: 127.0.0.1        132.com
O1 - Hosts: 127.0.0.1        136136.net
O1 - Hosts: 127.0.0.1        www.136136.net
O1 - Hosts: 127.0.0.1        www.163ns.com
O1 - Hosts: 10430 more lines...
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [AVMFBoxMonitor] C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk = C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIC273~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([global.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([www.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} hxxp://quickscan.bitdefender.com/qsax/qsax64.cab (Bitdefender QuickScan Control)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} Reg Error: Value error. (Reg Error: Unable to open value key)
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab (WebSDev Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Unable to open value key)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B63BB61-2F55-48CA-BA01-587CE776F4AC}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GR99D3~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O27:64bit: - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\itunes.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell\AutoRun\command - "" = J:\setup.exe -a
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell - "" = AutoRun
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell\AutoRun\command - "" = G:\pushinst.exe
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\AutoRun\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\configure\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\install\command - "" = F:\SETUP.EXE
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 7 Days ==========
 
[2012.10.02 23:00:30 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.02 20:51:43 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2012.10.02 20:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.02 20:51:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.02 20:51:26 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.02 20:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 7 Days ==========
 
[2012.10.03 18:12:10 | 000,002,305 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
[2012.10.03 18:11:58 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.03 18:11:58 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.03 18:11:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.03 18:10:48 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.10.03 18:10:26 | 000,000,020 | ---- | M] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:36 | 000,050,477 | ---- | M] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | M] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.03 17:26:15 | 000,245,248 | ---- | M] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.10.02 23:07:26 | 000,513,501 | ---- | M] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.02 23:00:30 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.02 20:51:28 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 08:03:15 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.03 18:10:26 | 000,000,020 | ---- | C] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:35 | 000,050,477 | ---- | C] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | C] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 23:07:26 | 000,513,501 | ---- | C] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.02 20:51:28 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 07:54:28 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.06.07 21:24:07 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2011.10.16 11:51:19 | 000,000,430 | ---- | C] () -- C:\Windows\scummvm.ini
[2011.10.15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.26 07:31:00 | 000,169,757 | ---- | C] () -- C:\Users\Heistmer\fm_0911_34-35 (1).pdf
[2011.02.15 21:49:33 | 000,004,418 | ---- | C] () -- C:\Users\Heistmer\ESt2009_Heitmann_Rolf.elfo
[2011.02.15 21:16:26 | 000,000,071 | ---- | C] () -- C:\Windows\wiso.ini
[2011.02.06 11:39:21 | 000,000,482 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\RAExpertHistory.xml
[2010.11.25 21:38:09 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2010.03.02 20:56:15 | 000,260,318 | ---- | C] () -- C:\Users\Heistmer\verzeichniss.jpg
[2010.03.02 20:54:29 | 000,276,485 | ---- | C] () -- C:\Users\Heistmer\filme.jpg
[2010.02.25 08:59:03 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2008.11.30 01:05:35 | 000,000,029 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\default.rss
[2008.11.30 01:05:35 | 000,000,000 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\downloads.m3u
[2008.10.23 20:15:43 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.twlsj
[2008.10.23 19:53:53 | 000,258,064 | ---- | C] () -- C:\ProgramData\bold flag flag.m89kbj
[2008.10.23 19:32:02 | 000,319,504 | ---- | C] () -- C:\ProgramData\bold flag flag.fddwg
[2008.10.23 19:10:12 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.zj2d1
[2008.10.23 18:48:21 | 000,348,176 | ---- | C] () -- C:\ProgramData\bold flag flag.0f3nl
[2008.10.23 18:26:31 | 000,311,312 | ---- | C] () -- C:\ProgramData\bold flag flag.6lzxdq1
[2008.10.23 18:04:41 | 000,122,896 | ---- | C] () -- C:\ProgramData\bold flag flag.tczrs2
[2008.10.23 17:42:50 | 000,036,880 | ---- | C] () -- C:\ProgramData\bold flag flag.a19t49
[2008.10.23 17:21:00 | 000,196,624 | ---- | C] () -- C:\ProgramData\bold flag flag.0ehold
[2008.10.23 16:59:09 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.qr8rj
[2008.10.23 16:37:19 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.b8af8
[2008.10.23 16:15:29 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.h3kwaw
[2008.10.23 15:53:38 | 000,090,128 | ---- | C] () -- C:\ProgramData\bold flag flag.6ze1fa
[2008.10.23 15:31:48 | 000,339,984 | ---- | C] () -- C:\ProgramData\bold flag flag.h5gwda
[2008.10.23 15:09:57 | 000,147,472 | ---- | C] () -- C:\ProgramData\bold flag flag.l5j7y
[2008.10.23 14:48:07 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.ps2k65
[2008.10.23 14:26:22 | 000,385,040 | ---- | C] () -- C:\ProgramData\loud flag cdrom.qxp4q
[2008.10.23 14:25:46 | 000,200,720 | ---- | C] () -- C:\ProgramData\bold flag flag.g7hex
[2008.10.23 14:25:46 | 000,159,760 | ---- | C] () -- C:\ProgramData\bold flag flag.zdmqfk
[2008.10.23 14:20:50 | 000,012,304 | ---- | C] () -- C:\ProgramData\bold flag flag.7376dv
[2008.08.27 19:54:45 | 000,024,226 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\UserTile.png
[2008.05.26 21:20:45 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.03.25 12:15:10 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.19 22:03:44 | 000,005,070 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2008.03.19 22:03:44 | 000,000,168 | RHS- | C] () -- C:\ProgramData\568DE542ED.sys
[2008.03.13 21:09:22 | 000,245,248 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.13 20:45:55 | 000,000,732 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\d3d9caps64.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 17:29:43 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 01:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.19 01:04:28 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2012.08.19 15:18:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2012.08.19 15:17:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.03 18:10:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 6281 bytes -> C:\Windows\pOOrGUI:Source Setup Log.txt
@Alternate Data Stream - 24 bytes -> C:\Windows:7E92895CF0C0E947
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 1192 bytes -> C:\ProgramData\Microsoft:GU20qEzkcvUPQnca2EoO96egmYBo7
@Alternate Data Stream - 1188 bytes -> C:\ProgramData\Microsoft:6UbkivR8LfAWeH3hD48xECCj6
@Alternate Data Stream - 1124 bytes -> C:\ProgramData\Microsoft:0gtbGQ5UBdBtGnl3ms7gN6CAa

< End of report >

die Extras.txt

Code:

OTL Extras logfile created on: 03.10.2012 18:52:32 - Run 2
OTL by OldTimer - Version 3.2.70.1    Folder = C:\Users\Heistmer\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,40 Gb Available Physical Memory | 43,22% Memory free
6,71 Gb Paging File | 4,28 Gb Available in Paging File | 63,82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,11 Gb Total Space | 20,53 Gb Free Space | 4,55% Space Free | Partition Type: NTFS
Drive D: | 14,63 Gb Total Space | 10,08 Gb Free Space | 68,92% Space Free | Partition Type: FAT32
Drive J: | 931,50 Gb Total Space | 819,11 Gb Free Space | 87,93% Space Free | Partition Type: NTFS
 
Computer Name: Heistmer-ONE | User Name: Heistmer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Unable to open value key
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Unable to open value key
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Unable to open value key
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Mit Corel PaintShop Pro X4 durchsuchen] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L"
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Unable to open value key
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Unable to open value key
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Unable to open value key
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Mit Corel PaintShop Pro X4 durchsuchen] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L"
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 4D 3A 85 F0 D3 A5 CA 01  [binary data]
"VistaSp2" = C0 19 73 E5 3C BD CA 01  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3066119559-789599144-109096739-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 6
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
 
========== System Restore Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0252D094-9B67-4FAE-8D8D-52F9D173AF94}" = lport=22297 | protocol=6 | dir=in | name=tcp 22297 |
"{03F2D3D4-A268-451B-8C43-8E74FFD0B043}" = lport=20448 | protocol=6 | dir=in | name=tcp 20448 |
"{047E485A-D9CB-4944-AF87-D2A8FDEE4277}" = lport=20448 | protocol=6 | dir=in | name=tcp 20448 |
"{04A49102-545F-448D-8E40-24F3A383A5C4}" = lport=5031 | protocol=17 | dir=in | name=avm tapi services for fritz!box - udp 5031 |
"{17B323FB-34BB-4FE2-8D0D-8D39B2182EAD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1F470920-AEC8-4D09-8AF3-040942F3C9A8}" = lport=22297 | protocol=6 | dir=in | name=tcp 22297 |
"{29940FF4-2D13-412E-8DD2-187A316EE4DB}" = lport=19540 | protocol=17 | dir=in | name=sxuptp |
"{44FF179A-2AF7-41C8-BDD8-7D964D31CB71}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{51797DDB-817A-4CB7-BD3C-9A22C4B3E5AC}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5D418364-F3A4-4630-856C-7C961051FEF4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5FD2E84E-88B2-4A0D-8E23-D2E04DF6A019}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{77719058-0B4C-4533-9C0D-F2D767B8A3B5}" = lport=15307 | protocol=17 | dir=in | name=udp 15307 |
"{8A2694ED-E0AE-45E2-89E4-89B4F9D62A52}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{923958BE-80E9-4316-8376-EBA2521775EF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9F3E751F-1B37-42B9-A42B-D163B2EF55CD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B49D8F00-514D-4774-BF4F-04B5ABFDF8DB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DA4372E4-F5FD-4B21-92B4-09BAD512DD42}" = lport=28914 | protocol=17 | dir=in | name=udp 28914 |
"{EA21E8E8-918A-4B61-8A83-14FED1427F7B}" = lport=10243 | protocol=6 | dir=in | app=system |
"{EFA26135-9D51-4410-9F66-51FCE098FAB9}" = lport=15307 | protocol=17 | dir=in | name=udp 15307 |
"{FD3277D9-79AB-42BB-889A-D55940AF5856}" = lport=28914 | protocol=17 | dir=in | name=udp 28914 |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{026D12CE-6AE3-4BEC-AD1F-588AA41EB9C9}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0560C669-BB06-428D-BA47-C16552CF0322}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{084E0221-887D-4C51-B6B6-0A41D3FD4576}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\bin\sdklauncher.exe |
"{08A45051-543D-484F-B686-33F758A5FBB4}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\launcher.exe |
"{0A3E127D-C6FB-4B3F-B685-90C572FBC401}" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!dsl\igdctrl.exe |
"{0B90B642-1EF0-4CF0-BA64-0466B6C56EC0}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0BA74C84-D909-449D-BC7F-8A9FEFF94334}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{138957B5-C312-436E-8F69-26E0E95B31EB}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{13ABFFB1-FA2F-49E4-A33E-6DFAABDAFFC2}" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!dsl\webwaigd.exe |
"{147CE19C-7930-472D-9F35-E3F8561E64FC}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{157ED6C2-3603-4263-9929-195916D16EA3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{19B151EE-480A-4EDC-A587-B7FAACE029AC}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\need for speed(tm) hot pursuit\launcher.exe |
"{1C0A6D80-DE28-4117-8F7E-FC2A6457D5E0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{21C19F6A-13BF-4A93-A2EC-F0C383B7078D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2B5F656E-1325-4FBF-B267-6960B086C846}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{2C7C5C06-EF28-452E-A155-83EA8E2122A2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{33C6F804-674B-4E38-A7C7-9CC4785F12C2}" = protocol=17 | dir=in | app=c:\program files (x86)\tapi services for fritz!box\igd_finder.exe |
"{3416B360-69B1-4A92-9F28-6A907D76C69C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{3FC7BF23-9ECF-437F-8EBE-569068266AA0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5160D1EF-82EA-4D9C-BFA6-B28512E24C6B}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{581B64A4-F9DD-48AB-A5B3-4634806F6312}" = protocol=6 | dir=in | app=c:\program files (x86)\tapi services for fritz!box\fboxset.exe |
"{5CF3AA75-7CF4-4E8F-AAE9-4B899231A77D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5D8ADF8E-B552-46CC-BD62-FBCB307519E2}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{71924374-6F68-4E93-8279-52F4479C0504}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\die siedler - aufstieg eines königreichs\extra1\bin\settlers6.exe |
"{77B1C67E-6CEB-41CE-97DC-293F8391B439}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{78BF543E-1D04-490F-9AD4-199572835813}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7AA617D5-F1D0-453B-862B-BD7A83EE0D60}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\die siedler - aufstieg eines königreichs\base\bin\settlers6.exe |
"{7D117F23-7F2F-4423-BCBE-E418FA9D6915}" = protocol=6 | dir=out | app=system |
"{7D8A5535-73DD-4502-8662-D657D720E87F}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_launcher.exe |
"{86070009-DBEF-4878-8BA4-6E378E8F8693}" = protocol=6 | dir=in | app=c:\program files (x86)\tapi services for fritz!box\igd_finder.exe |
"{896EC062-E803-46C6-A5B4-6FAF84AB4C04}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{898DECB2-4CB5-4466-83D9-A606AF6C8B44}" = protocol=17 | dir=in | app=c:\program files (x86)\tapi services for fritz!box\fboxset.exe |
"{8CDE182E-8737-4E53-B6F7-EE52A92AF2CA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{92302374-FB6C-40E0-8B47-4FAA32E7A153}" = protocol=6 | dir=in | app=c:\program files\belkin\network usb hub control center\connect.exe |
"{99D1541A-14D8-4A01-8917-735E7871DC1C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A679CFF1-8DA7-4028-A271-9B4A55FE394F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\csHeistmer\counter-strike source\hl2.exe |
"{A7D1D623-FFCB-433F-815E-46860017AC77}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\die siedler - aufstieg eines königreichs\base\bin\settlers6.exe |
"{A8339C2B-836C-4260-B7AE-C1AD0A4DB181}" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!dsl\fboxupd.exe |
"{A8F452EC-1BF4-40B6-9AC3-8BAA3FEF6EBB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AB982F05-3699-4744-9C51-A66EE4C0386B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{B9470824-83F7-492F-967D-F316AF8F114B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{B9D362C2-BBBF-4FD2-A5B9-444E2B73E6EA}" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!dsl\igdctrl.exe |
"{BC8646F2-D527-418A-9244-99DB7BFE2D0C}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{C9EBEDF7-1E82-4249-AD1B-10A0C66E7930}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_launcher.exe |
"{CA6FDAEB-5A48-4C1F-93B0-CA84E76148B1}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{CCA952CE-BB14-4A88-8467-AD0EE0D0D7A5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\bin\sdklauncher.exe |
"{CDF68B6D-F7D4-45B4-9681-28DEA4C566EC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CF219D91-64BE-47FE-B4C5-1807669FBA73}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\csHeistmer\counter-strike source\hl2.exe |
"{D66B0BA8-2D6B-4922-AC10-E139EB15E103}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{D749AD2E-7BC0-461E-8DF7-AD6D5332378E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{DF820B05-FDD6-4DE0-804F-7250DEF3EC39}" = protocol=17 | dir=in | app=c:\program files\belkin\network usb hub control center\connect.exe |
"{E389D5EE-9DB8-43EC-BC78-BDADAFF1E474}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E562C3D6-2E92-4981-9F18-0299F7280A36}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{E594CEEE-B31A-4B9B-9BCE-DB6E793769E4}" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!dsl\webwaigd.exe |
"{E5C707DA-B993-4051-AD82-47D18E0F2F3C}" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!dsl\fboxupd.exe |
"{E5CEEC05-8BFA-4968-97C9-B7B7E656A532}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{E9E1693C-ECE1-474D-A29E-5AB37FA7AA37}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{ED1ED4D0-087E-4D32-A44B-167AB7181CA0}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F0D36C02-50EE-441D-81F0-38D9106DD386}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F7843AEA-3931-4F37-9C8A-EC35D8632D75}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\die siedler - aufstieg eines königreichs\extra1\bin\settlers6.exe |
"{F7D3A261-099C-43BA-8912-181EECA80571}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{FE69F843-44D9-4DF9-90E5-5309A11CD6E0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"TCP Query User{01F2850E-FD7F-4E97-95D5-FE25E77C0638}C:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe |
"TCP Query User{03689DF9-5F2C-439E-B43A-13357E5F5860}C:\program files (x86)\motorola media link\lite\mml.exe" = protocol=6 | dir=in | app=c:\program files (x86)\motorola media link\lite\mml.exe |
"TCP Query User{31B387F3-CD0C-405B-BA76-37E3EDD75E1B}C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe |
"TCP Query User{4318BDC8-FCE0-469F-8262-0830338E18A5}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe" = protocol=6 | dir=in | app=c:\program files (x86)\myphoneexplorer\myphoneexplorer.exe |
"TCP Query User{436F4A0A-6F41-4E1A-B7CE-80F4D47CBDC0}C:\program files (x86)\trillian\trillian.exe" = protocol=6 | dir=in | app=c:\program files (x86)\trillian\trillian.exe |
"TCP Query User{4AD3C76E-5B0E-4A52-B138-FADCC54BD340}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{5C0224B8-868A-4BE9-B39D-E8C859913FAB}C:\program files\belkin\network usb hub control center\connect.exe" = protocol=6 | dir=in | app=c:\program files\belkin\network usb hub control center\connect.exe |
"TCP Query User{656C527B-1FE0-4777-9647-6929DDEC8D68}C:\program files (x86)\steam\steamapps\csHeistmer\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\csHeistmer\counter-strike source\hl2.exe |
"TCP Query User{6CF25007-7321-458F-B2C7-C63D0DCB19AF}C:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe |
"TCP Query User{73850CE1-A65E-4D17-9F64-94AA9A7E4D1B}C:\downloads\software\fritz.box_fon_wlan_7270.04.80.recover-image.exe" = protocol=6 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7270.04.80.recover-image.exe |
"TCP Query User{80CC2666-1780-469D-8C9C-1D947D571C22}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{84AD2B4A-61D6-453B-BF6B-B962061F6396}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{AFB524B8-18F7-41F8-9086-581A1ACF70EC}C:\program files (x86)\trillian\trillian.exe" = protocol=6 | dir=in | app=c:\program files (x86)\trillian\trillian.exe |
"TCP Query User{E4A16374-9DAC-48E3-9985-D0AE46697D80}C:\program files (x86)\woopra\woopra.exe" = protocol=6 | dir=in | app=c:\program files (x86)\woopra\woopra.exe |
"UDP Query User{0519A1A5-1877-48B7-8C70-F4890B5ECF55}C:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe |
"UDP Query User{1175DE13-393B-4ADF-B20C-0B7B7FBA008E}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{128FEEDD-5355-40AF-8C7C-2CDF8D5D9F89}C:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre1.6.0_07\bin\javaw.exe |
"UDP Query User{13D2C4E9-ED03-472D-B50E-E5CAE9382EE7}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{2507AD2D-986B-4A4A-9C4F-64E9491A9A2D}C:\program files (x86)\trillian\trillian.exe" = protocol=17 | dir=in | app=c:\program files (x86)\trillian\trillian.exe |
"UDP Query User{2E69A4F9-B478-4F26-ACD4-084C818025A4}C:\program files (x86)\trillian\trillian.exe" = protocol=17 | dir=in | app=c:\program files (x86)\trillian\trillian.exe |
"UDP Query User{2FEC6C17-03EB-4592-89C9-2F099ED033F3}C:\program files\belkin\network usb hub control center\connect.exe" = protocol=17 | dir=in | app=c:\program files\belkin\network usb hub control center\connect.exe |
"UDP Query User{312259C7-8B5D-4F8B-A92D-670B6F680060}C:\program files (x86)\steam\steamapps\csHeistmer\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\csHeistmer\counter-strike source\hl2.exe |
"UDP Query User{45B06A2A-6367-4E56-9736-990B824F0BDE}C:\program files (x86)\motorola media link\lite\mml.exe" = protocol=17 | dir=in | app=c:\program files (x86)\motorola media link\lite\mml.exe |
"UDP Query User{5ACD836F-0955-4AD8-9E5B-5B18A662E55F}C:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!box monitor\fritzboxmonitor.exe |
"UDP Query User{5E111F05-C934-4993-96E3-B2A96939D7F4}C:\downloads\software\fritz.box_fon_wlan_7270.04.80.recover-image.exe" = protocol=17 | dir=in | app=c:\downloads\software\fritz.box_fon_wlan_7270.04.80.recover-image.exe |
"UDP Query User{79BF270D-9817-493C-90BC-26995BC1FE80}C:\program files (x86)\woopra\woopra.exe" = protocol=17 | dir=in | app=c:\program files (x86)\woopra\woopra.exe |
"UDP Query User{9EF15D5D-9F34-4DBA-88A3-8F6A495170CB}C:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files (x86)\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{B3D470C2-D595-457F-A3C0-8DF4F74A6DF4}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe" = protocol=17 | dir=in | app=c:\program files (x86)\myphoneexplorer\myphoneexplorer.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0015DE8E-8D9F-403E-8E5A-4098410E6125}" = PSPPro64
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1CCF1727-A817-4FEE-A028-5466FB542934}" = Motorola Mobile Drivers Installation 5.2.0
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java(TM) 7 Update 5 (64-bit)
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{64A3A4F4-B792-11D6-A78A-00B0D0160050}" = Java(TM) SE Development Kit 6 Update 5
"{68660049-8D48-427C-9FF7-139D8340CDC0}" = MSVC80_x64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel(R) PRO Network Connections 12.1.12.0
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{A301082B-5FDF-44B6-9757-983F62CDBD44}" = Pflege GoPal Favoriten
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}" = iTunes
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Belkin Network USB Hub Control Center" = Belkin Netzwerk USB-Hub Kontrollzentrum
"CANONIJINBOXADDON100" = Canon Inkjet Printer Driver Add-On Module
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"PROSetDX" = Intel(R) PRO Network Connections 12.1.12.0
"UltSounds" = Windows-Soundschemas
"UltSounds2" = Ultimate Extras sounds from Microsoft® Tinker™
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{00580795-581C-4587-B9F2-37320D7AB37F}" = Corel PaintShop Pro X4
"{00580795-581C-4587-B9F2-37320D7AB37F}" = ICA
"{006CAAEF-CA96-4181-AC22-FE56D61432E4}" = PSPPContent
"{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}" = Corel PaintShop Pro X4
"{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}" = IPM_PSP_COM
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{00D13418-7DDF-4D3D-A237-E297B103BB6B}" = Setup
"{00D74A7A-F7AD-4D00-ABD2-0973836292C7}" = PSPPHelp
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam(TM)
"{0711500B-9912-4D60-9A49-C577B4503D42}" = Nero Recode Help
"{07FF7593-9DEA-40B5-9F87-F557E65BBF60}" = Nero Recode
"{089DD780-DB3F-4CDB-A0C2-111360247298}" = PC Connectivity Solution
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F022A2E-7022-497D-90A5-0F46746D8275}" = Macromedia Extension Manager
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1122AAC4-AAAA-43BF-B2D4-3C8C12378952}" = Nero InfoTool
"{11A84FCA-C3C7-4AFD-A797-111DB8569DBC}" = Nero BurningROM
"{12345674-DE9A-677A-CCEE-666356D89777}" = Nero BurnRights
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1B040683-C390-4711-ABC7-DA8D85E470E7}" = NeroBurningROM
"{1BBD8D70-721A-41AD-AC8F-7308A0C8FA92}" = Adobe Creative Suite 5 Master Collection
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}" = Nero MediaHub 10
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{2457326B-C110-40C3-89B0-889CC913871A}" = AVM FRITZ!DSL
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{2D3455A8-3B15-41A8-99F8-0D4215746463}" = Nero StartSmart
"{3097B151-1F61-4211-A4CC-D70127B226AE}" = SoundTrax
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{378397D6-FD32-4092-A854-6A75CB7EDA46}" = MOTOROLA MEDIA LINK
"{3EE51BAD-9916-49C7-90BA-3D500B031E0C}_is1" = VSO Image Resizer 2.0.1.9
"{3F30CC51-0788-487B-AA83-7214A239C0C0}" = Nero Disc Copy Gadget Help
"{3F6D3D01-AAD3-482A-BFB7-81E0D3D09BC8}" = Steuer Update 14.01
"{42C8B7DF-FEB0-4D51-B169-506B6BEC5797}" = Nero 10 Menu TemplatePack 1
"{43FBAB46-5969-4200-9958-1FF81FEE506F}" = Nero 10 Movie ThemePack 1
"{44025BD7-AD10-4769-99AE-6378FD0303D6}" = Macromedia Dreamweaver 8
"{4769E972-2E92-49C5-B6F9-465EFD0C4D94}" = VirtualDJ PRO Full
"{47879FA7-BC8F-4D7F-8057-86D0416579FA}" = StarMoney
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4D42353B-533F-4306-AD0B-7FEF292ADE04}" = Nero CoverDesigner Help
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{4F91BB7B-34E9-4B52-B997-DD79C18EBB9C}" = Steuer Update 14.01
"{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService
"{5454083B-1308-4485-BF17-111000028701}" = Grand Theft Auto: Episodes from Liberty City
"{548F99E0-14CC-4D53-A7D6-4A62A5F2C748}" = Nero PhotoSnap
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{56BE5CC9-95E6-4128-ABEA-968414CA9C80}" = DolbyFiles
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A62A775-A29A-4CE1-BBC2-4A9CD0B211EF}" = Nero Live Help
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5C2E8A0F-80E2-4C68-8CC0-D8D16E7196BF}" = Nero RescueAgent Help
"{5C42EAB8-54F9-423A-948C-1CBEF25F8DB4}" = Nero PhotoSnap Help
"{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}" = CrissCross 8.40
"{5C9BB0B3-E830-4814-BBA4-D93535E1C7B9}" = Nero Live
"{62B002C5-1AB3-11D8-8092-00E018B21FC0}" = USB Mass Storage Toolbox
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{70F19404-B96C-4EBB-AD2B-3574F8736197}" = Nero 10 Movie ThemePack 2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75321954-2589-11DC-DDCC-E98356D81493}" = Nero DriveSpeed
"{753973C4-B961-43BF-B2D4-3C8C92F7216E}" = Nero DriveSpeed
"{7655E113-C306-11D9-A373-0050BAE317E1}" = MCE Software Encoder 1.1
"{78523651-D8B1-11DC-CCEE-741589645873}" = Nero DiscSpeed
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7EE873AF-46BB-4B5D-BA6F-CFE4B0566E22}" = TuneUp Utilities Language Pack (de-DE)
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{83A606F5-BF6F-42ED-9F33-B9F74297CDED}" = Need for Speed(TM) Hot Pursuit
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{8C654BD0-1949-43DE-84F2-EC2A1ABB0CB4}" = Nero ShowTime
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8EA79DBF-D637-448A-89D6-410A087A4493}" = Samsung_MonSetup
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{8F182094-4AF1-4961-896F-E497CDFF2370}" = MAGIX 3D Maker 7 Download-Version
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-0026-0000-0000-0000000FF1CE}" = Microsoft Expression Web
"{90120000-0026-0407-0000-0000000FF1CE}" = Microsoft Expression Web MUI (German)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0407-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00BA-0407-0000-0000000FF1CE}" = Microsoft Office Groove MUI (German) 2007
"{92146419-AE44-4C8B-A48B-0ABB1B5EC026}" = Nero 10 Menu TemplatePack 3
"{92A10E9D-EA00-4A46-8F22-EEA660992D61}" = Nero 10 Sample Videos
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{943CC0C0-2253-4FE0-9493-DD386F7857FD}" = Nero Express
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{948FFAAE-C57F-447B-9B07-3721E950BFDC}" = Nero ShowTime
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{96ED4B78-300E-4033-AE6C-C115CEB4DF07}" = Nero 10 ClipartPack
"{97F81AF1-0E47-DC99-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 ATL (x86) WinSXS MSM
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{A2433A63-5F5D-40E5-B529-9123C2B3E734}" = Anno 1701
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2C60BF1-82E3-493C-911D-14AD50471F2F}" = Rundum-Betrachter-innoPlus
"{A73BEC3C-40A0-480E-87EF-EFCD33629088}" = NeroExpress
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8399F58-234A-48C6-BA55-30C15738BF3C}" = Nero CoverDesigner
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AAA12554-2589-11DC-92EF-E98356D81493}" = Nero InfoTool
"{AABBCC54-D8B1-11DC-92EF-E98356D81493}" = Nero DiscSpeed
"{AC76BA86-7AD7-1031-7B44-A90000000001}" = Adobe Reader 9 - Deutsch
"{ACD15FDF-FC42-4175-B477-576F92FF2256}" = Nero 10 Sample ImagePack
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B1C0D829-FE30-059E-E93F-CDC7A48235C0}" = FlipShare
"{B2C12C8D-65DC-40BD-B309-5ADB0C6C8D8F}" = Nero WaveEditor
"{B2C85224-88C1-4ED2-8ECC-EF7362D9F63B}" = Movie Templates - Pack 1
"{B388231D-672A-4169-A3DF-BD80266252AB}" = StarMoney
"{B96C2601-52F5-4D5D-816A-63469EA311EF}" = "Nero SoundTrax Help
"{BAEBE7F0-BB3E-4228-BFE0-8FF70BB9B837}" = Menu Templates - Pack 1
"{BCD82AB5-670D-4242-90FA-1F97103C16CD}" = Movie Templates - Starter Kit
"{BD9F2135-1451-476E-A842-5133ED249C84}" = StarMoney 6.0 S-Edition
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}" = Menu Templates - Starter Kit
"{CD1826A5-CFCC-4C6E-9F9D-E181876162EA}" = Nero Rescue Agent
"{CDD0BC3E-4992-4962-8372-2D700425F42D}" = Menu Templates - Pack 2
"{CE026CFE-73FE-4FED-9D5F-2C8D4DB512B0}" = TuneUp Utilities Language Pack (de-DE)
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus(R) for Adobe
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D3F80A98-05AB-4D8C-9272-766CCFA6A48D}" = DIE SIEDLER - Aufstieg eines Königreichs (Alle Produkte)
"{D6044256-A309-43B5-9833-D3FAFE2AD24D}" = MagicTune Premium
"{D7C206B6-1A63-4389-A8B1-8F607D0BFF1F}" = Nero StartSmart Help
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DF94566F-BDEC-4529-9532-7FBBEDA38045}" = Menu Templates - Pack 3
"{E07B7A31-E160-466D-A003-3BB7B8989D52}" = Full Tilt Poker.Net
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E337B156-DF81-48D8-8977-B1574EE87BCF}" = USB2.0 Capture Device
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E4A8DD87-A746-4443-BF25-CAF99CED6767}" = Nero Disc Copy Gadget
"{E6D22FE1-AB5F-42CA-9480-6F70B96DDD88}" = Need for Speed™ Undercover
"{E712C273-7564-4C8E-AA59-0FA19BC35117}" = Nero 10 Menu TemplatePack 2
"{E86156E5-9859-440D-8876-26CED1349802}" = Nero WaveEditor Help
"{EA9FFE54-D8B1-11DC-92EF-E98356D81493}" = Nero BurnRights
"{EC1F15E1-F3CC-46EE-B7A5-849A08ED60DC}}_is1" = PantsOff 2.0
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = VideoStudio
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F53F6769-AC46-49E3-ABE3-2C8AFD39D0DD}" = Nero Vision
"{F55CA27A-8C3C-4E7D-891B-D29FD3259A94}" = TAXMAN 2008
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = VideoStudio
"{FC338210-F594-11D3-BA24-00001C3AB4DF}" = cyberJack Base Components
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Any Video Converter_is1" = Any Video Converter 2.7.5
"Artisteer 3" = Artisteer 3
"Avira AntiVir Desktop" = Avira Free Antivirus
"AVMFBox" = AVM FRITZ!Box Dokumentation
"AVMFBoxMonitor" = AVM FRITZ!Box Monitor
"AVMFBoxPrinter" = AVM FRITZ!Box Druckeranschluss
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"CoffeeCup Flash FireStarter" = CoffeeCup Flash FireStarter
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DeepScript_is1" = DeepScript 1.1
"Duke Nukem Forever German Text-Patch 1.00" = Duke Nukem Forever German Text-Patch 1.00
"ElsterFormular für Privatanwender 12.0.0.5880p" = ElsterFormular für Privatanwender
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FileZilla Client" = FileZilla Client 3.5.3
"Free YouTube Download_is1" = Free YouTube Download version 3.1.31.706
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.34.305
"GENEUIDE" = USB Storage Driver
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = Corel VideoStudio 12
"InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = Ulead VideoStudio 11
"Jack The MP3 Ripper_is1" = Jack The MP3 Ripper v1.1
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.15
"MAGIX_MSI_3D7" = MAGIX 3D Maker 7 Download-Version
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.65.0.1400
"MotoHelper" = MotoHelper 2.0.51 Driver 5.2.0
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"MPE" = MyPhoneExplorer
"PartyPoker" = PartyPoker
"PokerStars.net" = PokerStars.net
"ProtectDisc Driver 10" = ProtectDisc Helper Driver 10
"PunkBusterSvc" = PunkBuster Services
"ScummVM_is1" = ScummVM 0.9.1
"Steam App 730" = Counter-Strike: Global Offensive
"Steam App 745" = Counter-Strike: Global Offensive - SDK
"SystemRequirementsLab" = System Requirements Lab
"TAPI" = AVM TAPI Services for FRITZ!Box
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Trillian" = Trillian
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"Uninstall_is1" = Uninstall 1.0.0.1
"USB2.0 ATV" = USB2.0 ATV
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WebDesigner" = Microsoft Expression Web
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinRAR archiver" = WinRAR
"X10Hardware" = X10 Hardware(TM)
"xampp" = XAMPP 1.7.4
"xp-AntiSpy" = xp-AntiSpy 3.96-8
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"bleh eggs link" = CiD Help
"f6791b188d8f3ff8" = AVM FRITZ!Box USB-Fernanschluss
"Winamp Detect" = Winamp Anwendungserkennung
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 05.09.2012 14:31:49 | Computer Name = Heistmer-One | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung Adobe_Updater.exe, Version 6.0.2.1471, Zeitstempel
 0x49243d5d, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x000046af,  Prozess-ID 0xe10, Anwendungsstartzeit
 01cd8b94b471482e.
 
Error - 12.09.2012 14:48:12 | Computer Name = Heistmer-One | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung Adobe_Updater.exe, Version 6.0.2.1471, Zeitstempel
 0x49243d5d, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x0000577f,  Prozess-ID 0x15ac, Anwendungsstartzeit
 01cd9117268b1a70.
 
Error - 15.09.2012 04:40:41 | Computer Name = Heistmer-One | Source = Microsoft Office 12 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Outlook.
 
Error - 15.09.2012 05:24:53 | Computer Name = Heistmer-One | Source = Microsoft Office 12 | ID = 2000
Description = Accepted Safe Mode action : Microsoft Office Outlook.
 
Error - 15.09.2012 05:34:13 | Computer Name = Heistmer-One | Source = Microsoft Office 12 | ID = 2000
Description = Accepted Safe Mode action : Microsoft Office Outlook.
 
Error - 19.09.2012 17:00:54 | Computer Name = Heistmer-One | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung iexplore.exe, Version 9.0.8112.16448, Zeitstempel
 0x4feba22b, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x0000340c,  Prozess-ID 0x12a0, Anwendungsstartzeit
 01cd96a629f5216c.
 
Error - 22.09.2012 02:48:06 | Computer Name = Heistmer-One | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung OUTLOOK.EXE, Version 12.0.4518.1014, Zeitstempel
 0x4542840f, fehlerhaftes Modul OGL.DLL_unloaded, Version 0.0.0.0, Zeitstempel 0x454285ac,
 Ausnahmecode 0xc0000005, Fehleroffset 0x68813850,  Prozess-ID 0xc8c, Anwendungsstartzeit
 01cd988d02285a15.
 
Error - 22.09.2012 18:24:43 | Computer Name = Heistmer-One | Source = EventSystem | ID = 4609
Description =
 
Error - 02.10.2012 14:45:27 | Computer Name = Heistmer-One | Source = EventSystem | ID = 4609
Description =
 
Error - 03.10.2012 04:03:24 | Computer Name = Heistmer-One | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung firefox.exe, Version 1.9.2.3828, Zeitstempel
 0x4c25a4a3, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000,
 Ausnahmecode 0xc0000005, Fehleroffset 0x0000defd,  Prozess-ID 0x10b0, Anwendungsstartzeit
 01cda13c4b8e211b.
 
Error - 03.10.2012 04:33:39 | Computer Name = Heistmer-One | Source = Application Error | ID = 1000
Description = Fehlerhafte Anwendung rundll32.exe, Version 6.0.6000.16386, Zeitstempel
 0x4549b0e1, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.18508, Zeitstempel
 0x4e5674e4, Ausnahmecode 0xc0000005, Fehleroffset 0x000046b0,  Prozess-ID 0x1180,
 Anwendungsstartzeit 01cda141c9322f3b.
 
[ Media Center Events ]
Error - 02.12.2008 17:59:44 | Computer Name = Heistmer-One | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerAccumulate failed;
 Win32 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center
 Guide
 
Error - 20.02.2009 14:38:16 | Computer Name = Heistmer-One | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 10.03.2009 14:12:38 | Computer Name = Heistmer-One | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerAccumulate failed;
 Win32 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center
 Guide
 
Error - 10.03.2009 18:25:55 | Computer Name = Heistmer-One | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerAccumulate failed;
 Win32 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center
 Guide
 
Error - 13.04.2009 13:50:45 | Computer Name = Heistmer-One | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerAccumulate failed;
 Win32 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center
 Guide
 
Error - 27.12.2009 05:39:16 | Computer Name = Heistmer-One | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80004005
 
Error - 11.01.2010 15:21:42 | Computer Name = Heistmer-One | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80004005
 
Error - 09.06.2010 13:30:46 | Computer Name = Heistmer-One | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerRecord failed; Win32
 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center Guide

 
Error - 15.06.2010 14:01:35 | Computer Name = Heistmer-One | Source = ehRecvr | ID = 4
Description =
 
Error - 15.06.2010 14:11:39 | Computer Name = Heistmer-One | Source = Media Center Guide | ID = 0
Description = Ereignisinformationen: ERROR: SqmApiWrapper.TimerAccumulate failed;
 Win32 GetLastError returned 10000105  Prozess: DefaultDomain Objektname: Media Center
 Guide
 
[ OSession Events ]
Error - 12.06.2010 17:31:32 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 69
 seconds with 60 seconds of active time.  This session ended with a crash.
 
Error - 11.09.2010 04:56:30 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 293
 seconds with 180 seconds of active time.  This session ended with a crash.
 
Error - 05.10.2010 01:22:41 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 100
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 20.11.2010 05:05:10 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 96948
 seconds with 600 seconds of active time.  This session ended with a crash.
 
Error - 25.01.2011 14:27:30 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 825
 seconds with 60 seconds of active time.  This session ended with a crash.
 
Error - 29.01.2011 11:25:03 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 513
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 14.02.2011 02:23:36 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 51
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 23.08.2011 15:11:30 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 151
 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error - 11.06.2012 01:24:03 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 103
 seconds with 60 seconds of active time.  This session ended with a crash.
 
Error - 22.09.2012 02:48:05 | Computer Name = Heistmer-One | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 520
 seconds with 0 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 03.10.2012 10:03:08 | Computer Name = Heistmer-One | Source = DCOM | ID = 10005
Description =
 
Error - 03.10.2012 10:03:08 | Computer Name = Heistmer-One | Source = Service Control Manager | ID = 7009
Description =
 
Error - 03.10.2012 10:06:04 | Computer Name = Heistmer-One | Source = Service Control Manager | ID = 7022
Description =
 
Error - 03.10.2012 11:51:54 | Computer Name = Heistmer-One | Source = Service Control Manager | ID = 7024
Description =
 
Error - 03.10.2012 11:53:41 | Computer Name = Heistmer-One | Source = Dhcp | ID = 1001
Description = Diesem Computer konnte keine Netzwerkadresse durch den DHCP-Server
 für die Netzwerkkarte mit der Netzwerkadresse 001D9204693F zugeteilt werden. Der
 folgende Fehler ist aufgetreten:  %%258. Es wird weiterhin im Hintergrund versucht,
 eine Adresse vom Netzwerkadressserver (DHCP) zugeteilt zu bekommen.
 
Error - 03.10.2012 11:53:44 | Computer Name = Heistmer-One | Source = Microsoft-Windows-ResourcePublication | ID = 1002
Description =
 
Error - 03.10.2012 11:55:07 | Computer Name = Heistmer-One | Source = Service Control Manager | ID = 7000
Description =
 
Error - 03.10.2012 12:10:46 | Computer Name = Heistmer-One | Source = Service Control Manager | ID = 7024
Description =
 
Error - 03.10.2012 12:12:00 | Computer Name = Heistmer-One | Source = Print | ID = 19
Description = Der Druckspooler konnte den Drucker Canon Inkjet PIXMA iP3000 nicht
 unter dem Namen Canon Inkjet PIXMA iP3000 freigeben. Fehler: 2114. Der Drucker
kann nicht von anderen Benutzern im Netzwerk verwendet werden.
 
Error - 03.10.2012 12:13:32 | Computer Name = Heistmer-One | Source = Service Control Manager | ID = 7000
Description =
 
[ TuneUp Events ]
Error - 31.07.2012 16:57:28 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 01.08.2012 01:07:17 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 01.08.2012 12:42:40 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 02.08.2012 01:05:46 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 02.08.2012 12:37:12 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 03.08.2012 01:03:39 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 03.08.2012 13:12:12 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 04.08.2012 04:37:49 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 05.08.2012 05:21:43 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
Error - 05.08.2012 05:38:53 | Computer Name = Heistmer-One | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
 
 
< End of report >

Ich hoffe mal ich hab das nun nach den Regeln erstellt, und freu mich auf feedback.

cosinus 04.10.2012 11:26

Bitte keine Riesenbilder, die das Layout hier sprengen, in den Beitrag direkt setzen!
Entweder Bild verkleinern oder nur den Link posten - hab es schon für dich editiert

Zitat:

In erster Selbsthilfe habe ich mein System mit einer Boot CD neu gestartet, und mit einigen Scanner das System untersuchen lassen.
(Avira, Anti Maleware, Kaspary, Search & Destroy, Trojan Remover)
Schön und wo sind die Logs dazu? :glaskugel:

Solche Angaben reichen nicht, bitte poste die vollständigen Angaben/Logs der Virenscanner.

Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Heistmer 04.10.2012 12:45

Tut mir leid mit dem Bild, das war natürlich nicht meine Absicht.

Leider hab ich das Board erst gefunden, nachdem ich so wie ich es nun nach einigen Stunden Lesen in eurem Bord einschätze versucht habe es selber wieder in den grünen Bereich zu biegen.

Somit habe ich auch nicht die nötige Sorgfalt walten lassen und die Pogramme auch wieder deinstaliert. Somit hab ich wohl auch Log's gelöscht.

Natürlich erwarte ich nicht das mir dann aus einer Kristallkugel vorgelesen wird :)

Gefunden weil noch nicht deinstaliert, habe ich
den Log von Malwarebytes
Code:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.02.07

Windows Vista Service Pack 2 x64 NTFS (Abgesichertenmodus/Netzwerkfähig)
Internet Explorer 9.0.8112.16421
Heistmer :: Heistmer-ONE [Administrator]

02.10.2012 15:53:31
mbam-log-2012-10-02 (15-53-31).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|J:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 855611
Laufzeit: 2 Stunde(n), 27 Minute(n), 31 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\itunes.exe (Security.Hijack) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{C19E20BE-A447-AD7C-ACEA-BB05BF779818} (Backdoor.Bot.citdl) -> Daten: C:\Users\Heistmer\AppData\Roaming\Nayfo\coimek.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 1
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search|Local Page (Hijack.SearchPage) -> Bösartig: (hxxp://www2.iesearch.com/) Gut: (hxxp://www.Google.com/) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 2
C:\Windows\System32\drivers\downld (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\SysWOW64\drivers\downld (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 6

C:\Users\Heistmer\AppData\Roaming\Nayfo\coimek.exe (Backdoor.Bot.citdl) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Heistmer\AppData\Local\Temp\wgsdgsdgdsgsd.exe (Exploit.Drop.GS) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\lsass.exe (Trojan.Delf) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\System32\explorer.exe.vir (Heuristics.Reserved.Word.Exploit) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Windows\SysWOW64\explorer.exe.vir (Heuristics.Reserved.Word.Exploit) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

und den vom AdwCleaner

Code:

# AdwCleaner v2.003 - Datei am 10/02/2012 um 19:25:13 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows (TM) Vista Ultimate Service Pack 2 (64 bits)
# Benutzer : Heistmer - Heistmer-ONE
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Heistmer\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\.autoreg
Gelöscht mit Neustart : C:\ProgramData\boost_interprocess

***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v3.6.6 (de)

Profilname : default
Datei : C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\prefs.js

C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\user.js ... Gelöscht !

Gelöscht : user_pref("extensions.facemoods.DNSErrUrl", "hxxp://start.facemoods.com/?a=ddrnw&f=5");
Gelöscht : user_pref("extensions.facemoods.aflt", "ddrnw");
Gelöscht : user_pref("extensions.facemoods.dfltSrch", false);
Gelöscht : user_pref("extensions.facemoods.dnsErr", false);
Gelöscht : user_pref("extensions.facemoods.firstRun", true);
Gelöscht : user_pref("extensions.facemoods.hmpg", false);
Gelöscht : user_pref("extensions.facemoods.hmpgUrl", "hxxp://start.facemoods.com/?a=ddrnw");
Gelöscht : user_pref("extensions.facemoods.id", "82b97cd5000000000000001d9204693f");
Gelöscht : user_pref("extensions.facemoods.instlDay", "15264");
Gelöscht : user_pref("extensions.facemoods.mntz", "");
Gelöscht : user_pref("extensions.facemoods.newTab", false);
Gelöscht : user_pref("extensions.facemoods.prtnrId", "facemoods.com");
Gelöscht : user_pref("extensions.facemoods.searchProviderAdded", false);
Gelöscht : user_pref("extensions.facemoods.sid", "7ca4b45d87aa4c3799d6c3d6f61d1658");
Gelöscht : user_pref("extensions.facemoods.tlbrSrchUrl", "hxxp://start.facemoods.com/?a=ddrnw&f=3");
Gelöscht : user_pref("extensions.facemoods.vrsn", "1.4.17.11");

*************************

AdwCleaner[S1].txt - [2784 octets] - [02/10/2012 23:25:13]

########## EOF - C:\AdwCleaner[S1].txt - [2844 octets] ##########

Vielleicht noch einen Tip wo ich Log's von Pogrammen die von einer Boot CD gestartet wurden und aus einem erstelltem RamDrive gestartet wurden finden könnte?


Wobei das, so wie ich es im Kopf habe auch die Pogramme waren die dann auch wirklich was gefunden haben.

cosinus 04.10.2012 13:15

Malwarebytes erstellt bei jedem Scanvorgang genau ein Log. Hast du in der Vergangenheit schonmal mit Malwarebytes gescannt?
Wenn ja dann stehen auch alle Logs zu jedem Scanvorgang im Reiter Logdateien. Bitte alle posten, die dort sichtbar sind.

Heistmer 04.10.2012 13:45

Nein, Malwarebytes hab ich erst zu dem vorfall instaliert. Vorher kannte ich es gar nicht. Was mich auf ein jetzt auftauchendes Problem treffen lässt. Sonnst hatte ich Avira Laufen. Avira wird nicht mehr mitgestartet, und bei dem Versuch Avira manuell zu starten (Ich wollte grade sehen ob es dort noch logs gibt) bekahm ich die Meldung

"Dieses Pogramm wurde durch eine Gruppenrichtlinie geblockt. Weitere Informationen erhalten Sie vom Systemadministrator. "

Ich gehe mal davon aus das sind nachwirkungen von meinem Infekt?

cosinus 04.10.2012 13:49

Code:

# Betriebssystem : Windows (TM) Vista Ultimate Service Pack 2 (64 bits)
Wieso eigentlich ein Ultimate von Windows?
Ist das das rein zufällig ein Firmen-Rechner im Büro?

Heistmer 04.10.2012 14:11

Nein das ist kein Firmenrechner. Ich glaub in dem Fall hätte ich mich gar nicht erst damit auseinandergestetz. Sondern gleich jemanden drann gesetzt der sich damit auskennt :) Da währ ich gestern wohl auch nicht anwesend.

Das Vista war drauf als ich den Recher vor zwei Jahren übernemmen habe. Gibt es ein Problem mit der Version?

cosinus 04.10.2012 14:32

Problem nicht, aber ich frag mich warum im Privatumfeld eine Ultimateversion genutzt werden muss

Heistmer 04.10.2012 14:50

Kann ich nix zu sagen, da hab ich mich bisher auch noch nicht mit auseinandergesetzt.
Bisher hab ich meinen Rechner eingeschaltet, gesurft, Bilder gespeichert, Mails geschrieben, sich mit anderen über Hobbys in Foren ausgetauscht, und was man sonnst noch so macht, und wieder abgestellt. Hat also meistens Funktioniert. Als nächstes such ich dann erst mal was es mit dieser Version auf sich hat :)

cosinus 04.10.2012 14:53

ja wer hat dir das denn installiert? Oder hast du den Rechner so gekauft? mit Ultimate?

Heistmer 04.10.2012 15:13

Den hab ich so gekauft.

cosinus 04.10.2012 15:33

Du hast den mit Ultimate-Editition Lizenz gekauft, wo das auch schon vorinstalliert war? Klingt etwas ungewöhnlich

Heistmer 04.10.2012 15:44

es war ein Leasingrückläufer 2 jahre alt, also ein "gebrauchter" ohne irgendwas.
Aufpreis war dann das Betriebsystem. Da gab es verschiedene zur auswahl. Auch noch XP. Nach Beratungen mit Freunden hies es dann nimm gleich was richtiges nicht nur das einfache. Preislich war das ja nicht der riesen unterschied. Zusätzlich gab es dann den Service Ready to Use. Für eine kleinigkeit oben drauf.


Aber um was geht es jetzt genau?

cosinus 04.10.2012 15:47

Ich geh halt solchen ungewöhnlichen Dingen nach weil wir hier bestimmte Regeln einhalten müssen.



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset



Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Heistmer 05.10.2012 09:28

Moin,

hier der Eset Log

Code:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-10-04 10:22:43
# local_time=2012-10-05 12:22:43 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1792 16777215 100 0 26972636 26972636 0 0
# compatibility_mode=5892 16776573 100 56 113683 186887327 0 0
# compatibility_mode=8192 67108863 100 0 159 159 0 0
# scanned=638296
# found=5
# cleaned=0
# scan_time=26038
C:\Program Files (x86)\DAEMON Tools Lite\uninst.exe        Win32/Adware.Toolbar.Shopper application (unable to clean)        00000000000000000000000000000000        I
C:\Program Files (x86)\Mozilla Firefox\plugins\npdlplug.dll        Win32/Adware.PluginDL application (unable to clean)        00000000000000000000000000000000        I
C:\Users\Heistmer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\1a48cd8c-7164adca        Java/Exploit.CVE-2012-4681.W trojan (unable to clean)        00000000000000000000000000000000        I
C:\Users\Heistmer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\67ffeaef-52c199f9        Java/Exploit.CVE-2012-1723.AT trojan (unable to clean)        00000000000000000000000000000000        I        I
J:\down\Defy\Motorola DEFY\Motorola DEFY_2012-08-06T19.46.06_Part00.cab        Android/Adware.BatteryDoctor.D application (unable to clean)        00000000000000000000000000000000        I

Der letzte Fund, stammt vermutlich aus einer Telefonsicherung (Handy) Dort hab ich mal ein App mit Namen Battery Doctor gehabt. Das könnte ich einfach so löschen. (glaub ich zumindest)

cosinus 05.10.2012 13:42

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop. Falls schon vorhanden, bitte die ältere vorhandene Datei durch die neu heruntergeladene Datei ersetzen, damit du auch wirklich mit einer aktuellen Version von OTL arbeitest.
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Heistmer 05.10.2012 16:19

So, hier dann der OTL Log

Code:

OTL logfile created on: 05.10.2012 15:18:42 - Run 3
OTL by OldTimer - Version 3.2.70.1    Folder = C:\Users\Heistmer\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 53,49% Memory free
6,71 Gb Paging File | 3,94 Gb Available in Paging File | 58,75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,11 Gb Total Space | 24,94 Gb Free Space | 5,53% Space Free | Partition Type: NTFS
Drive D: | 14,63 Gb Total Space | 10,08 Gb Free Space | 68,92% Space Free | Partition Type: FAT32
Drive J: | 931,50 Gb Total Space | 814,54 Gb Free Space | 87,44% Space Free | Partition Type: NTFS
 
Computer Name: Heistmer-ONE | User Name: Heistmer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC -  File not found
PRC - C:\Users\Heistmer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
PRC - C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Windows\SysWOW64\conime.exe (Microsoft Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Trillian\libspeex.dll ()
MOD - C:\Program Files (x86)\Trillian\libungif.dll ()
MOD - C:\Program Files (x86)\Trillian\zlib1.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\talk.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\events.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\toolkit.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\buddy.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\trillian.dll ()
MOD - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (StkSSrv) -- C:\Windows\SysNative\StkCSrv.exe (Syntek America Inc.)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (DeviceMonitorService) -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (MotoHelper) -- C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (mysql) -- C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
SRV - (Apache2.2) -- C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (FileZilla Server) -- C:\Users\Heistmer\Eigene Webs\xampp\FileZillaFTP\FileZillaServer.exe (FileZilla Project)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (FlipShare Service) -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (getPlusHelper) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (cjpcsc) -- C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (IGDCTRL) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (MagicTuneEngine) -- C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (Capture Device Service) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (x10nets) -- C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (motusbdevice) -- C:\Windows\SysNative\DRIVERS\motusbdevice.sys (Motorola Inc)
DRV:64bit: - (motccgp) -- C:\Windows\SysNative\DRIVERS\motccgp.sys (Motorola)
DRV:64bit: - (motmodem) -- C:\Windows\SysNative\DRIVERS\motmodem.sys (Motorola)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Motousbnet) -- C:\Windows\SysNative\DRIVERS\Motousbnet.sys (Motorola)
DRV:64bit: - (cmnsusbser) -- C:\Windows\SysNative\DRIVERS\cmnsusbser.sys (Mobile Connector)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (acedrv10) -- C:\Windows\SysNative\drivers\acedrv10.sys (Protect Software GmbH)
DRV:64bit: - (acehlp10) -- C:\Windows\SysNative\drivers\acehlp10.sys (Protect Software GmbH)
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (motccgpfl) -- C:\Windows\SysNative\DRIVERS\motccgpfl.sys (Motorola)
DRV:64bit: - (BTCFilterService) -- C:\Windows\SysNative\DRIVERS\motfilt.sys (Motorola Inc)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (IntelDH64) -- C:\Windows\SysNative\Drivers\IntelDH64.sys (Intel Corporation)
DRV:64bit: - (3xHybr64) -- C:\Windows\SysNative\DRIVERS\3xHybr64.sys (NXP Semiconductors Germany GmbH)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (L8042Kbd) -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV:64bit: - (MotoSwitchService) -- C:\Windows\SysNative\DRIVERS\motswch.sys (Motorola)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (sxuptp) -- C:\Windows\SysNative\DRIVERS\sxuptp.sys (silex technology, Inc.)
DRV:64bit: - (StkCMini) -- C:\Windows\SysNative\Drivers\StkCMini.sys (Syntek)
DRV:64bit: - (cjusb) -- C:\Windows\SysNative\DRIVERS\cjusb.sys (REINER SCT)
DRV:64bit: - (e1express) -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (XUIF) -- C:\Windows\SysNative\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV:64bit: - (X10Hid) -- C:\Windows\SysNative\Drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (TVICHW64) -- C:\Windows\SysWOW64\drivers\TVICHW64.SYS (EnTech Taiwan)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = hxxp://www.Google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}: "URL" = hxxp://www2.iesearch.com/s/?&q={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "FireSearch"
FF - prefs.js..browser.startup.homepage: "hxxp://www2.firesearch.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.0
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@innoplus.de/inoPanoViewer: C:\Program Files (x86)\innoPlus\Rundum-Betrachter-innoPlus\npirsviewer.dll (INNOVA-engineering GmbH)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.05 19:33:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.01.15 22:15:34 | 000,000,000 | ---D | M]
 
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Extensions
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions
[2010.05.19 23:02:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.08.26 21:16:36 | 000,000,000 | ---D | M] ("FireFTP") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2011.03.11 22:28:11 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.12.04 10:46:25 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.12.04 10:46:38 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\firebug@software.joehewitt.com
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.03.27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2008.06.18 09:47:34 | 000,397,312 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npdlplug.dll
[2011.10.26 20:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010.07.18 17:32:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.07.18 17:32:18 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.07.18 17:32:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.07.18 17:32:19 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.07.18 17:32:19 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.03.03 21:42:44 | 000,302,531 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.123topsearch.com
O1 - Hosts: 127.0.0.1        123topsearch.com
O1 - Hosts: 127.0.0.1        www.132.com
O1 - Hosts: 127.0.0.1        132.com
O1 - Hosts: 127.0.0.1        136136.net
O1 - Hosts: 127.0.0.1        www.136136.net
O1 - Hosts: 127.0.0.1        www.163ns.com
O1 - Hosts: 10430 more lines...
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [AVMFBoxMonitor] C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3066119559-789599144-109096739-1000..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil64_11_4_400_252_ActiveX.exe -update activex File not found
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk = C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIC273~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([global.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([www.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} hxxp://quickscan.bitdefender.com/qsax/qsax64.cab (Bitdefender QuickScan Control)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} Reg Error: Value error. (Reg Error: Unable to open value key)
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab (WebSDev Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Unable to open value key)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B63BB61-2F55-48CA-BA01-587CE776F4AC}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GR99D3~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O27:64bit: - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\itunes.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell\AutoRun\command - "" = J:\setup.exe -a
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell - "" = AutoRun
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell\AutoRun\command - "" = G:\pushinst.exe
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\AutoRun\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\configure\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\install\command - "" = F:\SETUP.EXE
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7070D8E0-650A-46b3-B03C-9497582E6A74} - %SystemRoot%\system32\soundschemes.exe /AddRegistration
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24} - %SystemRoot%\system32\soundschemes2.exe /AddRegistration
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.3IV2 - C:\Windows\SysWow64\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.05 11:16:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\L5 Software Group
[2012.10.05 11:16:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\L5 Software Group
[2012.10.04 17:06:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.02 23:00:30 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.02 20:51:43 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2012.10.02 20:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.02 20:51:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.02 20:51:26 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.02 20:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.22 23:57:59 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\NOS
[2012.09.15 19:55:10 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\Desktop\HeistMedia
[2012.09.15 19:48:27 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Artisteer 3
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\Xara
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2012.09.11 20:50:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2012.09.11 20:50:32 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
[2012.09.11 20:50:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo!
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.05 15:35:12 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.05 15:35:12 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.05 11:16:00 | 000,001,023 | ---- | M] () -- C:\Users\Heistmer\Desktop\Driver Manager W2K-XP.lnk
[2012.10.05 11:15:15 | 000,245,248 | ---- | M] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.10.04 15:35:44 | 000,002,305 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
[2012.10.04 15:35:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.03 23:51:51 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.10.03 18:10:26 | 000,000,020 | ---- | M] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:36 | 000,050,477 | ---- | M] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | M] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 23:07:26 | 000,513,501 | ---- | M] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.02 23:00:30 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.02 20:51:28 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 08:03:15 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.22 23:44:31 | 001,453,952 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.22 23:44:31 | 000,632,252 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.22 23:44:31 | 000,598,940 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.22 23:44:31 | 000,127,302 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.22 23:44:31 | 000,104,954 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.22 23:22:22 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.09.15 22:35:37 | 447,694,779 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.09.12 07:11:56 | 004,965,568 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.11 20:51:25 | 000,000,858 | ---- | M] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.05 11:16:00 | 000,001,023 | ---- | C] () -- C:\Users\Heistmer\Desktop\Driver Manager W2K-XP.lnk
[2012.10.03 18:10:26 | 000,000,020 | ---- | C] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:35 | 000,050,477 | ---- | C] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | C] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 23:07:26 | 000,513,501 | ---- | C] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.02 20:51:28 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 07:54:28 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.11 20:51:25 | 000,000,858 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[2012.06.07 21:24:07 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2011.10.16 11:51:19 | 000,000,430 | ---- | C] () -- C:\Windows\scummvm.ini
[2011.10.15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.26 07:31:00 | 000,169,757 | ---- | C] () -- C:\Users\Heistmer\fm_0911_34-35 (1).pdf
[2011.02.15 21:16:26 | 000,000,071 | ---- | C] () -- C:\Windows\wiso.ini
[2011.02.06 11:39:21 | 000,000,482 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\RAExpertHistory.xml
[2010.11.25 21:38:09 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2010.03.02 20:56:15 | 000,260,318 | ---- | C] () -- C:\Users\Heistmer\verzeichniss.jpg
[2010.03.02 20:54:29 | 000,276,485 | ---- | C] () -- C:\Users\Heistmer\filme.jpg
[2010.02.25 08:59:03 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2008.11.30 01:05:35 | 000,000,029 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\default.rss
[2008.11.30 01:05:35 | 000,000,000 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\downloads.m3u
[2008.10.23 20:15:43 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.twlsj
[2008.10.23 19:53:53 | 000,258,064 | ---- | C] () -- C:\ProgramData\bold flag flag.m89kbj
[2008.10.23 19:32:02 | 000,319,504 | ---- | C] () -- C:\ProgramData\bold flag flag.fddwg
[2008.10.23 19:10:12 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.zj2d1
[2008.10.23 18:48:21 | 000,348,176 | ---- | C] () -- C:\ProgramData\bold flag flag.0f3nl
[2008.10.23 18:26:31 | 000,311,312 | ---- | C] () -- C:\ProgramData\bold flag flag.6lzxdq1
[2008.10.23 18:04:41 | 000,122,896 | ---- | C] () -- C:\ProgramData\bold flag flag.tczrs2
[2008.10.23 17:42:50 | 000,036,880 | ---- | C] () -- C:\ProgramData\bold flag flag.a19t49
[2008.10.23 17:21:00 | 000,196,624 | ---- | C] () -- C:\ProgramData\bold flag flag.0ehold
[2008.10.23 16:59:09 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.qr8rj
[2008.10.23 16:37:19 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.b8af8
[2008.10.23 16:15:29 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.h3kwaw
[2008.10.23 15:53:38 | 000,090,128 | ---- | C] () -- C:\ProgramData\bold flag flag.6ze1fa
[2008.10.23 15:31:48 | 000,339,984 | ---- | C] () -- C:\ProgramData\bold flag flag.h5gwda
[2008.10.23 15:09:57 | 000,147,472 | ---- | C] () -- C:\ProgramData\bold flag flag.l5j7y
[2008.10.23 14:48:07 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.ps2k65
[2008.10.23 14:26:22 | 000,385,040 | ---- | C] () -- C:\ProgramData\loud flag cdrom.qxp4q
[2008.10.23 14:25:46 | 000,200,720 | ---- | C] () -- C:\ProgramData\bold flag flag.g7hex
[2008.10.23 14:25:46 | 000,159,760 | ---- | C] () -- C:\ProgramData\bold flag flag.zdmqfk
[2008.10.23 14:20:50 | 000,012,304 | ---- | C] () -- C:\ProgramData\bold flag flag.7376dv
[2008.08.27 19:54:45 | 000,024,226 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\UserTile.png
[2008.05.26 21:20:45 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.03.25 12:15:10 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.19 22:03:44 | 000,005,070 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2008.03.19 22:03:44 | 000,000,168 | RHS- | C] () -- C:\ProgramData\568DE542ED.sys
[2008.03.13 21:09:22 | 000,245,248 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.13 20:45:55 | 000,000,732 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\d3d9caps64.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 17:29:43 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 01:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.19 01:04:28 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2012.08.19 15:18:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2012.08.19 15:17:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.03 23:50:50 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.08.07 23:19:07 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Adobe
[2008.11.30 16:24:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ahead
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Apple Computer
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2011.11.27 13:50:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Avira
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2011.01.22 22:19:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Corel
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2008.08.27 07:27:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DivX
[2011.03.20 21:22:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\dvdcss
[2012.08.19 15:18:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2012.08.19 15:17:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.03 23:50:50 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.03.18 23:01:28 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Google
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2008.03.13 20:46:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Identities
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.03.14 00:31:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InstallShield
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2008.03.14 08:46:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Jasc Software Inc
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2008.03.15 19:17:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Logitech
[2008.03.20 21:38:49 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Macromedia
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.10.02 20:51:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2006.11.02 17:06:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Media Center Programs
[2010.08.15 21:43:50 | 000,000,000 | --SD | M] -- C:\Users\Heistmer\AppData\Roaming\Microsoft
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla
[2012.01.14 20:12:06 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla-Cache
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.07.03 20:37:23 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nero
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2012.06.27 19:53:45 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\NVIDIA
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2008.03.20 22:13:16 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Real
[2008.06.22 16:52:26 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\skypePM
[2008.03.16 01:22:08 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\SmartFTP
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2008.03.15 13:29:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Talkback
[2010.03.19 22:07:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\teamspeak2
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2008.08.18 23:36:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\vlc
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2011.11.05 20:03:29 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Winamp
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
[2008.03.14 22:39:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WinRAR
[2012.09.11 20:50:32 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
 
< %APPDATA%\*.exe /s >
[2010.07.19 18:49:04 | 000,010,134 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_24c89c8.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_39fe3610.exe
[2009.08.11 22:39:05 | 000,010,134 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{A2C60BF1-82E3-493C-911D-14AD50471F2F}\ARPPRODUCTICON.exe
[2007.10.08 01:57:52 | 000,307,200 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
[2007.12.28 11:15:38 | 000,172,032 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
[2012.01.07 17:57:55 | 003,703,176 | ---- | M] (WindSolutions) -- C:\Users\Heistmer\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2006.11.02 14:03:16 | 000,062,056 | ---- | M] (Microsoft Corporation) MD5=5CCDD13BC602AE33CD8B62D33C29AB72 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.19 01:07:48 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008.01.09 03:52:57 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=3927EB6EBFC77BA93481F440221D5252 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16584_none_371e04d9dcfdf69e\atapi.sys
[2008.01.09 03:52:56 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=48021EB810BF8FB6EBFA4569B95AAD5F -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20707_none_380123c8f5d8000c\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2009.12.20 00:00:00 | 000,037,520 | ---- | M] (perl.org) MD5=2852D57385C4709EAAE2F9DB01AD3672 -- C:\Users\Heistmer\Eigene Webs\xampp\perl\site\lib\auto\Win32\EventLog\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 01:11:32 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
[2006.11.02 13:51:48 | 000,280,680 | ---- | M] (Intel Corporation) MD5=72C3EE7EA3CD75A772E62AE0E5DF8B8C -- C:\Windows\SysNative\drivers\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.19 01:03:02 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.19 00:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
[2006.11.02 13:18:47 | 000,684,032 | ---- | M] (Microsoft Corporation) MD5=BFAB28B54DF41208CF3490FF26E53FD9 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_579f90caf36c48b9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 14:02:51 | 000,048,232 | ---- | M] (NVIDIA Corporation) MD5=94C5334040A5D500897F4C5FD12AEEDE -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.19 01:08:52 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 00:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006.11.02 13:19:09 | 000,239,616 | ---- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008.01.19 01:03:56 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2006.11.02 11:44:25 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=00B53DCA0408CCD8F6BAF13994F6E3A0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll
[2007.07.14 02:23:35 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=296BA70E2A302E639CBD9E2A32DC65C4 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll
[2008.01.19 01:04:24 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.19 00:32:20 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2007.07.14 02:23:36 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=437C1C0CB2A42EA20083F21E9CAEF461 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=707CD582A4F93DB789336A5CE9527970 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_275857df28a483b4\user32.dll
[2006.11.02 13:19:10 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=95D5555CC7BD8F520996E35D36491EEF -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_272045c928cedf94\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=E4E3ED1E0D1D8C33A9C94ABEA1C8BC96 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_27e0f46041c30a27\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
[2006.11.02 13:16:15 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
[2006.11.02 13:16:20 | 000,122,368 | ---- | M] (Microsoft Corporation) MD5=6F92CE5B50283B0C0A7A539ED552039A -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_8ada9256bfc30704\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.19 01:00:46 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 13:16:20 | 000,397,312 | ---- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 00:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
[2006.11.02 11:47:52 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=C4EE49DB7EADC812DBC0ECCF2E7FB929 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_a96e7a5c834006a3\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
[2006.11.02 17:40:34 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006.11.02 17:40:34 | 000,032,534 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 6281 bytes -> C:\Windows\pOOrGUI:Source Setup Log.txt
@Alternate Data Stream - 24 bytes -> C:\Windows:7E92895CF0C0E947
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 1192 bytes -> C:\ProgramData\Microsoft:GU20qEzkcvUPQnca2EoO96egmYBo7
@Alternate Data Stream - 1188 bytes -> C:\ProgramData\Microsoft:6UbkivR8LfAWeH3hD48xECCj6
@Alternate Data Stream - 1124 bytes -> C:\ProgramData\Microsoft:0gtbGQ5UBdBtGnl3ms7gN6CAa

< End of report >


Kleine Anmerkung, zwischenzeitlich gab mir OTL eine Fehlermeldung raus.
Zitat:

Es befindet sich kein Datenträger im Lauwerk. Legen Sie einen Datenträger in Laufwerk/Device/Harddisk/DR2 ein.
Das habe ich mehrmals mit Weiter bestätigt dann lief es wie gewollt weiter.
Was OTL da von mir gewünscht hat kann ich nicht Sagen.

cosinus 05.10.2012 18:11

Hm, da ist immer noch Toolbar-Müll drin
Bitte mal den aktuellen adwCleaner runterladen, also die alte adwcleaner löschen und neu runterladen

adwCleaner - Toolbars und ungewollte Start-/Suchseiten aufspüren

Downloade Dir bitte AdwCleaner auf deinen Desktop.

Falls der adwCleaner schon mal in der runtergeladen wurde, bitte die alte adwcleaner.exe löschen und neu runterladen!!
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Suche.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[Rx].txt. (x=fortlaufende Nummer)

Heistmer 05.10.2012 18:28

hier das log

Code:

# AdwCleaner v2.003 - Datei am 10/05/2012 um 19:15:50 erstellt
# Aktualisiert am 23/09/2012 von Xplode
# Betriebssystem : Windows (TM) Vista Ultimate Service Pack 2 (64 bits)
# Benutzer : Heistmer - Heistmer-ONE
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Heistmer\Desktop\adwcleaner.exe
# Option [Suche]


**** [Dienste] ****


***** [Dateien / Ordner] *****


***** [Registrierungsdatenbank] *****


***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Mozilla Firefox v3.6.6 (de)

Profilname : default
Datei : C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\prefs.js

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [2909 octets] - [02/10/2012 23:25:13]
AdwCleaner[R1].txt - [946 octets] - [02/10/2012 23:30:05]
AdwCleaner[R2].txt - [878 octets] - [05/10/2012 19:15:50]

########## EOF - C:\AdwCleaner[R2].txt - [937 octets] ##########


Toolbars nutz ich nicht, wenn sie mal wieder irgendwo mitinstaliert wurde versuch ich sie meist gleich wieder zu deinstalieren.

Die S1 und R1 evtl auch noch intressant, wo ich nun weiss wo sie steckt.

cosinus 05.10.2012 18:33

Code:

Version 3.2.70.1
hast du OTL vorhin nicht neu runtergeladen? Warum nicht? :wtf:

Heistmer 05.10.2012 18:39

doch war eigentlich der plan, bekahm auch die frage auf ersetzen. Vielleicht hätte ich vorher löschen sollen.
Vielleicht auch verklick. hmmm.

Noch mal?

cosinus 06.10.2012 18:31

Ja bitte nochmal mit der aktuellen Version

Heistmer 06.10.2012 21:26

Ich bin verwirt, gestern habe ich noch dann ja noch mal geschaut, bzw versucht nachzuvollziehen wo ich was falsch gemacht habe. Hatte dann letztendelich die 3.2.70.2

Wenn ich jetzt noch einmal aktuell herunterlade bekomm ich nur noch die 3.2.69.0 ??

Hier der Log von meiner gestern heruntergeladenen 3.2.70.2

Code:

OTL logfile created on: 06.10.2012 20:31:38 - Run 4
OTL by OldTimer - Version 3.2.70.2    Folder = C:\Users\Heistmer\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,51 Gb Available Physical Memory | 46,36% Memory free
6,71 Gb Paging File | 4,47 Gb Available in Paging File | 66,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,11 Gb Total Space | 24,05 Gb Free Space | 5,33% Space Free | Partition Type: NTFS
Drive D: | 14,63 Gb Total Space | 10,08 Gb Free Space | 68,92% Space Free | Partition Type: FAT32
Drive J: | 931,50 Gb Total Space | 814,54 Gb Free Space | 87,44% Space Free | Partition Type: NTFS
 
Computer Name: Heistmer-ONE | User Name: Heistmer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC -  File not found
PRC - C:\Users\Heistmer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
PRC - C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Trillian\libspeex.dll ()
MOD - C:\Program Files (x86)\Trillian\libungif.dll ()
MOD - C:\Program Files (x86)\Trillian\zlib1.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\talk.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\events.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\toolkit.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\buddy.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\trillian.dll ()
MOD - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (StkSSrv) -- C:\Windows\SysNative\StkCSrv.exe (Syntek America Inc.)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (DeviceMonitorService) -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (MotoHelper) -- C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (mysql) -- C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
SRV - (Apache2.2) -- C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (FileZilla Server) -- C:\Users\Heistmer\Eigene Webs\xampp\FileZillaFTP\FileZillaServer.exe (FileZilla Project)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (FlipShare Service) -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (getPlusHelper) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (cjpcsc) -- C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (IGDCTRL) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (MagicTuneEngine) -- C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (Capture Device Service) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (x10nets) -- C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (motusbdevice) -- C:\Windows\SysNative\DRIVERS\motusbdevice.sys (Motorola Inc)
DRV:64bit: - (motccgp) -- C:\Windows\SysNative\DRIVERS\motccgp.sys (Motorola)
DRV:64bit: - (motmodem) -- C:\Windows\SysNative\DRIVERS\motmodem.sys (Motorola)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Motousbnet) -- C:\Windows\SysNative\DRIVERS\Motousbnet.sys (Motorola)
DRV:64bit: - (cmnsusbser) -- C:\Windows\SysNative\DRIVERS\cmnsusbser.sys (Mobile Connector)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (acedrv10) -- C:\Windows\SysNative\drivers\acedrv10.sys (Protect Software GmbH)
DRV:64bit: - (acehlp10) -- C:\Windows\SysNative\drivers\acehlp10.sys (Protect Software GmbH)
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (motccgpfl) -- C:\Windows\SysNative\DRIVERS\motccgpfl.sys (Motorola)
DRV:64bit: - (BTCFilterService) -- C:\Windows\SysNative\DRIVERS\motfilt.sys (Motorola Inc)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (IntelDH64) -- C:\Windows\SysNative\Drivers\IntelDH64.sys (Intel Corporation)
DRV:64bit: - (3xHybr64) -- C:\Windows\SysNative\DRIVERS\3xHybr64.sys (NXP Semiconductors Germany GmbH)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (L8042Kbd) -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV:64bit: - (MotoSwitchService) -- C:\Windows\SysNative\DRIVERS\motswch.sys (Motorola)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (sxuptp) -- C:\Windows\SysNative\DRIVERS\sxuptp.sys (silex technology, Inc.)
DRV:64bit: - (StkCMini) -- C:\Windows\SysNative\Drivers\StkCMini.sys (Syntek)
DRV:64bit: - (cjusb) -- C:\Windows\SysNative\DRIVERS\cjusb.sys (REINER SCT)
DRV:64bit: - (e1express) -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (XUIF) -- C:\Windows\SysNative\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV:64bit: - (X10Hid) -- C:\Windows\SysNative\Drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (TVICHW64) -- C:\Windows\SysWOW64\drivers\TVICHW64.SYS (EnTech Taiwan)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = hxxp://www.Google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}: "URL" = hxxp://www2.iesearch.com/s/?&q={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "FireSearch"
FF - prefs.js..browser.startup.homepage: "hxxp://www2.firesearch.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.0
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@innoplus.de/inoPanoViewer: C:\Program Files (x86)\innoPlus\Rundum-Betrachter-innoPlus\npirsviewer.dll (INNOVA-engineering GmbH)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.05 19:33:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.01.15 22:15:34 | 000,000,000 | ---D | M]
 
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Extensions
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions
[2010.05.19 23:02:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.08.26 21:16:36 | 000,000,000 | ---D | M] ("FireFTP") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2011.03.11 22:28:11 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.12.04 10:46:25 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.12.04 10:46:38 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\firebug@software.joehewitt.com
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.03.27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2008.06.18 09:47:34 | 000,397,312 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npdlplug.dll
[2011.10.26 20:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010.07.18 17:32:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.07.18 17:32:18 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.07.18 17:32:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.07.18 17:32:19 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.07.18 17:32:19 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.03.03 21:42:44 | 000,302,531 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.123topsearch.com
O1 - Hosts: 127.0.0.1        123topsearch.com
O1 - Hosts: 127.0.0.1        www.132.com
O1 - Hosts: 127.0.0.1        132.com
O1 - Hosts: 127.0.0.1        136136.net
O1 - Hosts: 127.0.0.1        www.136136.net
O1 - Hosts: 127.0.0.1        www.163ns.com
O1 - Hosts: 10430 more lines...
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [AVMFBoxMonitor] C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk = C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIC273~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([global.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([www.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} hxxp://quickscan.bitdefender.com/qsax/qsax64.cab (Bitdefender QuickScan Control)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} Reg Error: Value error. (Reg Error: Unable to open value key)
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab (WebSDev Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Unable to open value key)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B63BB61-2F55-48CA-BA01-587CE776F4AC}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GR99D3~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O27:64bit: - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\itunes.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell\AutoRun\command - "" = J:\setup.exe -a
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell - "" = AutoRun
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell\AutoRun\command - "" = G:\pushinst.exe
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\AutoRun\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\configure\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\install\command - "" = F:\SETUP.EXE
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7070D8E0-650A-46b3-B03C-9497582E6A74} - %SystemRoot%\system32\soundschemes.exe /AddRegistration
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24} - %SystemRoot%\system32\soundschemes2.exe /AddRegistration
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.3IV2 - C:\Windows\SysWow64\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.05 19:37:10 | 000,601,088 | ---- | C] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.05 11:16:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\L5 Software Group
[2012.10.05 11:16:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\L5 Software Group
[2012.10.04 17:06:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.02 20:51:43 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2012.10.02 20:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.02 20:51:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.02 20:51:26 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.02 20:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.22 23:57:59 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\NOS
[2012.09.15 19:55:10 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\Desktop\HeistMedia
[2012.09.15 19:48:27 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Artisteer 3
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\Xara
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2012.09.11 20:50:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2012.09.11 20:50:32 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
[2012.09.11 20:50:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo!
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.06 09:16:37 | 000,002,305 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
[2012.10.06 09:15:24 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.06 09:15:23 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.06 09:15:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.05 23:40:29 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.10.05 19:37:10 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.05 19:15:12 | 000,513,501 | ---- | M] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.05 11:16:00 | 000,001,023 | ---- | M] () -- C:\Users\Heistmer\Desktop\Driver Manager W2K-XP.lnk
[2012.10.05 11:15:15 | 000,245,248 | ---- | M] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.10.03 18:10:26 | 000,000,020 | ---- | M] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:36 | 000,050,477 | ---- | M] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | M] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 20:51:28 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 08:03:15 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.22 23:44:31 | 001,453,952 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.22 23:44:31 | 000,632,252 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.22 23:44:31 | 000,598,940 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.22 23:44:31 | 000,127,302 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.22 23:44:31 | 000,104,954 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.22 23:22:22 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.09.12 07:11:56 | 004,965,568 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.11 20:51:25 | 000,000,858 | ---- | M] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.05 19:15:12 | 000,513,501 | ---- | C] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.05 11:16:00 | 000,001,023 | ---- | C] () -- C:\Users\Heistmer\Desktop\Driver Manager W2K-XP.lnk
[2012.10.03 18:10:26 | 000,000,020 | ---- | C] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:35 | 000,050,477 | ---- | C] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | C] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 20:51:28 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 07:54:28 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.11 20:51:25 | 000,000,858 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[2012.06.07 21:24:07 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2011.10.16 11:51:19 | 000,000,430 | ---- | C] () -- C:\Windows\scummvm.ini
[2011.10.15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.26 07:31:00 | 000,169,757 | ---- | C] () -- C:\Users\Heistmer\fm_0911_34-35 (1).pdf
[2011.02.15 21:16:26 | 000,000,071 | ---- | C] () -- C:\Windows\wiso.ini
[2011.02.06 11:39:21 | 000,000,482 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\RAExpertHistory.xml
[2010.11.25 21:38:09 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2010.03.02 20:56:15 | 000,260,318 | ---- | C] () -- C:\Users\Heistmer\verzeichniss.jpg
[2010.03.02 20:54:29 | 000,276,485 | ---- | C] () -- C:\Users\Heistmer\filme.jpg
[2010.02.25 08:59:03 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2008.11.30 01:05:35 | 000,000,029 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\default.rss
[2008.11.30 01:05:35 | 000,000,000 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\downloads.m3u
[2008.10.23 20:15:43 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.twlsj
[2008.10.23 19:53:53 | 000,258,064 | ---- | C] () -- C:\ProgramData\bold flag flag.m89kbj
[2008.10.23 19:32:02 | 000,319,504 | ---- | C] () -- C:\ProgramData\bold flag flag.fddwg
[2008.10.23 19:10:12 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.zj2d1
[2008.10.23 18:48:21 | 000,348,176 | ---- | C] () -- C:\ProgramData\bold flag flag.0f3nl
[2008.10.23 18:26:31 | 000,311,312 | ---- | C] () -- C:\ProgramData\bold flag flag.6lzxdq1
[2008.10.23 18:04:41 | 000,122,896 | ---- | C] () -- C:\ProgramData\bold flag flag.tczrs2
[2008.10.23 17:42:50 | 000,036,880 | ---- | C] () -- C:\ProgramData\bold flag flag.a19t49
[2008.10.23 17:21:00 | 000,196,624 | ---- | C] () -- C:\ProgramData\bold flag flag.0ehold
[2008.10.23 16:59:09 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.qr8rj
[2008.10.23 16:37:19 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.b8af8
[2008.10.23 16:15:29 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.h3kwaw
[2008.10.23 15:53:38 | 000,090,128 | ---- | C] () -- C:\ProgramData\bold flag flag.6ze1fa
[2008.10.23 15:31:48 | 000,339,984 | ---- | C] () -- C:\ProgramData\bold flag flag.h5gwda
[2008.10.23 15:09:57 | 000,147,472 | ---- | C] () -- C:\ProgramData\bold flag flag.l5j7y
[2008.10.23 14:48:07 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.ps2k65
[2008.10.23 14:26:22 | 000,385,040 | ---- | C] () -- C:\ProgramData\loud flag cdrom.qxp4q
[2008.10.23 14:25:46 | 000,200,720 | ---- | C] () -- C:\ProgramData\bold flag flag.g7hex
[2008.10.23 14:25:46 | 000,159,760 | ---- | C] () -- C:\ProgramData\bold flag flag.zdmqfk
[2008.10.23 14:20:50 | 000,012,304 | ---- | C] () -- C:\ProgramData\bold flag flag.7376dv
[2008.08.27 19:54:45 | 000,024,226 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\UserTile.png
[2008.05.26 21:20:45 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.03.25 12:15:10 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.19 22:03:44 | 000,005,070 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2008.03.19 22:03:44 | 000,000,168 | RHS- | C] () -- C:\ProgramData\568DE542ED.sys
[2008.03.13 21:09:22 | 000,245,248 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.13 20:45:55 | 000,000,732 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\d3d9caps64.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 17:29:43 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 01:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.19 01:04:28 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2012.08.19 15:18:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2012.08.19 15:17:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.05 23:39:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.08.07 23:19:07 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Adobe
[2008.11.30 16:24:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ahead
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Apple Computer
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2011.11.27 13:50:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Avira
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2011.01.22 22:19:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Corel
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2008.08.27 07:27:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DivX
[2011.03.20 21:22:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\dvdcss
[2012.08.19 15:18:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2012.08.19 15:17:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.05 23:39:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.03.18 23:01:28 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Google
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2008.03.13 20:46:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Identities
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.03.14 00:31:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InstallShield
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2008.03.14 08:46:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Jasc Software Inc
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2008.03.15 19:17:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Logitech
[2008.03.20 21:38:49 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Macromedia
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.10.02 20:51:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2006.11.02 17:06:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Media Center Programs
[2010.08.15 21:43:50 | 000,000,000 | --SD | M] -- C:\Users\Heistmer\AppData\Roaming\Microsoft
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla
[2012.01.14 20:12:06 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla-Cache
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.07.03 20:37:23 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nero
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2012.06.27 19:53:45 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\NVIDIA
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2008.03.20 22:13:16 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Real
[2008.06.22 16:52:26 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\skypePM
[2008.03.16 01:22:08 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\SmartFTP
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2008.03.15 13:29:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Talkback
[2010.03.19 22:07:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\teamspeak2
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2008.08.18 23:36:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\vlc
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2011.11.05 20:03:29 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Winamp
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
[2008.03.14 22:39:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WinRAR
[2012.09.11 20:50:32 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
 
< %APPDATA%\*.exe /s >
[2010.07.19 18:49:04 | 000,010,134 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_24c89c8.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_39fe3610.exe
[2009.08.11 22:39:05 | 000,010,134 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{A2C60BF1-82E3-493C-911D-14AD50471F2F}\ARPPRODUCTICON.exe
[2007.10.08 01:57:52 | 000,307,200 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
[2007.12.28 11:15:38 | 000,172,032 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
[2012.01.07 17:57:55 | 003,703,176 | ---- | M] (WindSolutions) -- C:\Users\Heistmer\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2006.11.02 14:03:16 | 000,062,056 | ---- | M] (Microsoft Corporation) MD5=5CCDD13BC602AE33CD8B62D33C29AB72 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.19 01:07:48 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008.01.09 03:52:57 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=3927EB6EBFC77BA93481F440221D5252 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16584_none_371e04d9dcfdf69e\atapi.sys
[2008.01.09 03:52:56 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=48021EB810BF8FB6EBFA4569B95AAD5F -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20707_none_380123c8f5d8000c\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2009.12.20 00:00:00 | 000,037,520 | ---- | M] (perl.org) MD5=2852D57385C4709EAAE2F9DB01AD3672 -- C:\Users\Heistmer\Eigene Webs\xampp\perl\site\lib\auto\Win32\EventLog\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 01:11:32 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
[2006.11.02 13:51:48 | 000,280,680 | ---- | M] (Intel Corporation) MD5=72C3EE7EA3CD75A772E62AE0E5DF8B8C -- C:\Windows\SysNative\drivers\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.19 01:03:02 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.19 00:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
[2006.11.02 13:18:47 | 000,684,032 | ---- | M] (Microsoft Corporation) MD5=BFAB28B54DF41208CF3490FF26E53FD9 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_579f90caf36c48b9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 14:02:51 | 000,048,232 | ---- | M] (NVIDIA Corporation) MD5=94C5334040A5D500897F4C5FD12AEEDE -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.19 01:08:52 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 00:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006.11.02 13:19:09 | 000,239,616 | ---- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008.01.19 01:03:56 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2006.11.02 11:44:25 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=00B53DCA0408CCD8F6BAF13994F6E3A0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll
[2007.07.14 02:23:35 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=296BA70E2A302E639CBD9E2A32DC65C4 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll
[2008.01.19 01:04:24 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.19 00:32:20 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2007.07.14 02:23:36 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=437C1C0CB2A42EA20083F21E9CAEF461 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=707CD582A4F93DB789336A5CE9527970 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_275857df28a483b4\user32.dll
[2006.11.02 13:19:10 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=95D5555CC7BD8F520996E35D36491EEF -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_272045c928cedf94\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=E4E3ED1E0D1D8C33A9C94ABEA1C8BC96 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_27e0f46041c30a27\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
[2006.11.02 13:16:15 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
[2006.11.02 13:16:20 | 000,122,368 | ---- | M] (Microsoft Corporation) MD5=6F92CE5B50283B0C0A7A539ED552039A -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_8ada9256bfc30704\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.19 01:00:46 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 13:16:20 | 000,397,312 | ---- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 00:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
[2006.11.02 11:47:52 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=C4EE49DB7EADC812DBC0ECCF2E7FB929 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_a96e7a5c834006a3\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 6281 bytes -> C:\Windows\pOOrGUI:Source Setup Log.txt
@Alternate Data Stream - 24 bytes -> C:\Windows:7E92895CF0C0E947
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 1192 bytes -> C:\ProgramData\Microsoft:GU20qEzkcvUPQnca2EoO96egmYBo7
@Alternate Data Stream - 1188 bytes -> C:\ProgramData\Microsoft:6UbkivR8LfAWeH3hD48xECCj6
@Alternate Data Stream - 1124 bytes -> C:\ProgramData\Microsoft:0gtbGQ5UBdBtGnl3ms7gN6CAa

< End of report >

Wir auch noch ein Log von der 3.2.69.0 benötigt?

cosinus 07.10.2012 07:32

Zitat:

Wenn ich jetzt noch einmal aktuell herunterlade bekomm ich nur noch die 3.2.69.0 ??
Ja die ist richtig :o
Der Rückschritt ist notwenig weil die 3.2.70er-Versionen wohl einige Bug haben
Mach es bitte nochmal mit der 3.2.69er Version, die offensichtlich fehlerfrei ist

Heistmer 07.10.2012 09:49

Hier dann jetzt das nächste Log.

OTL Logfile:
Code:

OTL logfile created on: 07.10.2012 10:08:55 - Run 5
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Heistmer\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,59 Gb Available Physical Memory | 49,09% Memory free
6,71 Gb Paging File | 4,68 Gb Available in Paging File | 69,73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,11 Gb Total Space | 18,92 Gb Free Space | 4,19% Space Free | Partition Type: NTFS
Drive D: | 14,63 Gb Total Space | 10,08 Gb Free Space | 68,92% Space Free | Partition Type: FAT32
Drive J: | 931,50 Gb Total Space | 809,09 Gb Free Space | 86,86% Space Free | Partition Type: NTFS
 
Computer Name: Heistmer-ONE | User Name: Heistmer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC -  File not found
PRC - C:\Users\Heistmer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
PRC - C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (StkSSrv) -- C:\Windows\SysNative\StkCSrv.exe (Syntek America Inc.)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (DeviceMonitorService) -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (MotoHelper) -- C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (mysql) -- C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
SRV - (Apache2.2) -- C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (FileZilla Server) -- C:\Users\Heistmer\Eigene Webs\xampp\FileZillaFTP\FileZillaServer.exe (FileZilla Project)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (FlipShare Service) -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (getPlusHelper) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (cjpcsc) -- C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (IGDCTRL) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (MagicTuneEngine) -- C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (Capture Device Service) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (x10nets) -- C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (motusbdevice) -- C:\Windows\SysNative\DRIVERS\motusbdevice.sys (Motorola Inc)
DRV:64bit: - (motccgp) -- C:\Windows\SysNative\DRIVERS\motccgp.sys (Motorola)
DRV:64bit: - (motmodem) -- C:\Windows\SysNative\DRIVERS\motmodem.sys (Motorola)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Motousbnet) -- C:\Windows\SysNative\DRIVERS\Motousbnet.sys (Motorola)
DRV:64bit: - (cmnsusbser) -- C:\Windows\SysNative\DRIVERS\cmnsusbser.sys (Mobile Connector)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (acedrv10) -- C:\Windows\SysNative\drivers\acedrv10.sys (Protect Software GmbH)
DRV:64bit: - (acehlp10) -- C:\Windows\SysNative\drivers\acehlp10.sys (Protect Software GmbH)
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (motccgpfl) -- C:\Windows\SysNative\DRIVERS\motccgpfl.sys (Motorola)
DRV:64bit: - (BTCFilterService) -- C:\Windows\SysNative\DRIVERS\motfilt.sys (Motorola Inc)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (IntelDH64) -- C:\Windows\SysNative\Drivers\IntelDH64.sys (Intel Corporation)
DRV:64bit: - (3xHybr64) -- C:\Windows\SysNative\DRIVERS\3xHybr64.sys (NXP Semiconductors Germany GmbH)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (L8042Kbd) -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV:64bit: - (MotoSwitchService) -- C:\Windows\SysNative\DRIVERS\motswch.sys (Motorola)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (sxuptp) -- C:\Windows\SysNative\DRIVERS\sxuptp.sys (silex technology, Inc.)
DRV:64bit: - (StkCMini) -- C:\Windows\SysNative\Drivers\StkCMini.sys (Syntek)
DRV:64bit: - (cjusb) -- C:\Windows\SysNative\DRIVERS\cjusb.sys (REINER SCT)
DRV:64bit: - (e1express) -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (XUIF) -- C:\Windows\SysNative\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV:64bit: - (X10Hid) -- C:\Windows\SysNative\Drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (TVICHW64) -- C:\Windows\SysWOW64\drivers\TVICHW64.SYS (EnTech Taiwan)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = Google
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Upgrade to Google Chrome
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}: "URL" = hxxp://www2.iesearch.com/s/?&q={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "FireSearch"
FF - prefs.js..browser.startup.homepage: "hxxp://www2.firesearch.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.0
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@innoplus.de/inoPanoViewer: C:\Program Files (x86)\innoPlus\Rundum-Betrachter-innoPlus\npirsviewer.dll (INNOVA-engineering GmbH)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.05 19:33:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.01.15 22:15:34 | 000,000,000 | ---D | M]
 
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Extensions
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions
[2010.05.19 23:02:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.08.26 21:16:36 | 000,000,000 | ---D | M] ("FireFTP") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2011.03.11 22:28:11 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010.12.04 10:46:25 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.12.04 10:46:38 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\firebug@software.joehewitt.com
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.03.27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2008.06.18 09:47:34 | 000,397,312 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npdlplug.dll
[2011.10.26 20:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010.07.18 17:32:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.07.18 17:32:18 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.07.18 17:32:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.07.18 17:32:19 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.07.18 17:32:19 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.03.03 21:42:44 | 000,302,531 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        ²©²Êͨ,²©²ÊÍø,½ð±¦²©188,²©²ÊͨÆÀ¼¶,°Ù¼ÒÀÖ,°ÂÃî°Ù¼ÒÀÖ
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        100sexlinks.com - Informationen zum Thema Sex links. Diese Website steht zum Verkauf!
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.123topsearch.com
O1 - Hosts: 127.0.0.1        123topsearch.com
O1 - Hosts: 127.0.0.1        ECSHOP
O1 - Hosts: 127.0.0.1        132.com
O1 - Hosts: 127.0.0.1        136136.net
O1 - Hosts: 127.0.0.1        www.136136.net
O1 - Hosts: 127.0.0.1        ,?,?,,,??,?,?
O1 - Hosts: 10430 more lines...
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [AVMFBoxMonitor] C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk = C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIC273~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([global.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([www.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} hxxp://quickscan.bitdefender.com/qsax/qsax64.cab (Bitdefender QuickScan Control)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab (WebSDev Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B63BB61-2F55-48CA-BA01-587CE776F4AC}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GR99D3~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O27:64bit: - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\itunes.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell\AutoRun\command - "" = J:\setup.exe -a
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell - "" = AutoRun
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell\AutoRun\command - "" = G:\pushinst.exe
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\AutoRun\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\configure\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\install\command - "" = F:\SETUP.EXE
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7070D8E0-650A-46b3-B03C-9497582E6A74} - %SystemRoot%\system32\soundschemes.exe /AddRegistration
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24} - %SystemRoot%\system32\soundschemes2.exe /AddRegistration
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.3IV2 - C:\Windows\SysWow64\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.07 10:05:48 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.05 11:16:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\L5 Software Group
[2012.10.05 11:16:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\L5 Software Group
[2012.10.04 17:06:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.02 20:51:43 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2012.10.02 20:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.02 20:51:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.02 20:51:26 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.02 20:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.22 23:57:59 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\NOS
[2012.09.15 19:55:10 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\Desktop\HeistMedia
[2012.09.15 19:48:27 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Artisteer 3
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\Xara
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2012.09.11 20:50:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2012.09.11 20:50:32 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
[2012.09.11 20:50:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo!
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.07 10:05:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.07 09:53:57 | 000,002,305 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
[2012.10.07 09:52:55 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 09:52:55 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.07 09:52:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.07 00:49:41 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.10.06 22:29:01 | 000,246,784 | ---- | M] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.10.06 10:16:06 | 000,566,764 | ---- | M] () -- C:\Users\Heistmer\Desktop\Sopoliste Acer PCs und Server.pdf
[2012.10.05 19:15:12 | 000,513,501 | ---- | M] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.05 11:16:00 | 000,001,023 | ---- | M] () -- C:\Users\Heistmer\Desktop\Driver Manager W2K-XP.lnk
[2012.10.03 18:10:26 | 000,000,020 | ---- | M] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:36 | 000,050,477 | ---- | M] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | M] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 20:51:28 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 08:03:15 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.22 23:44:31 | 001,453,952 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.22 23:44:31 | 000,632,252 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.22 23:44:31 | 000,598,940 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.22 23:44:31 | 000,127,302 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.22 23:44:31 | 000,104,954 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.22 23:22:22 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.09.12 07:11:56 | 004,965,568 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.09.11 20:51:25 | 000,000,858 | ---- | M] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[2012.09.07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.06 10:16:06 | 000,566,764 | ---- | C] () -- C:\Users\Heistmer\Desktop\Sopoliste Acer PCs und Server.pdf
[2012.10.05 19:15:12 | 000,513,501 | ---- | C] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.05 11:16:00 | 000,001,023 | ---- | C] () -- C:\Users\Heistmer\Desktop\Driver Manager W2K-XP.lnk
[2012.10.03 18:10:26 | 000,000,020 | ---- | C] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:35 | 000,050,477 | ---- | C] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | C] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 20:51:28 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 07:54:28 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.11 20:51:25 | 000,000,858 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[2012.06.07 21:24:07 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2011.10.16 11:51:19 | 000,000,430 | ---- | C] () -- C:\Windows\scummvm.ini
[2011.10.15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.26 07:31:00 | 000,169,757 | ---- | C] () -- C:\Users\Heistmer\fm_0911_34-35 (1).pdf
[2011.02.15 21:16:26 | 000,000,071 | ---- | C] () -- C:\Windows\wiso.ini
[2011.02.06 11:39:21 | 000,000,482 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\RAExpertHistory.xml
[2010.11.25 21:38:09 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2010.03.02 20:56:15 | 000,260,318 | ---- | C] () -- C:\Users\Heistmer\verzeichniss.jpg
[2010.03.02 20:54:29 | 000,276,485 | ---- | C] () -- C:\Users\Heistmer\filme.jpg
[2010.02.25 08:59:03 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2008.11.30 01:05:35 | 000,000,029 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\default.rss
[2008.11.30 01:05:35 | 000,000,000 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\downloads.m3u
[2008.10.23 20:15:43 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.twlsj
[2008.10.23 19:53:53 | 000,258,064 | ---- | C] () -- C:\ProgramData\bold flag flag.m89kbj
[2008.10.23 19:32:02 | 000,319,504 | ---- | C] () -- C:\ProgramData\bold flag flag.fddwg
[2008.10.23 19:10:12 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.zj2d1
[2008.10.23 18:48:21 | 000,348,176 | ---- | C] () -- C:\ProgramData\bold flag flag.0f3nl
[2008.10.23 18:26:31 | 000,311,312 | ---- | C] () -- C:\ProgramData\bold flag flag.6lzxdq1
[2008.10.23 18:04:41 | 000,122,896 | ---- | C] () -- C:\ProgramData\bold flag flag.tczrs2
[2008.10.23 17:42:50 | 000,036,880 | ---- | C] () -- C:\ProgramData\bold flag flag.a19t49
[2008.10.23 17:21:00 | 000,196,624 | ---- | C] () -- C:\ProgramData\bold flag flag.0ehold
[2008.10.23 16:59:09 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.qr8rj
[2008.10.23 16:37:19 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.b8af8
[2008.10.23 16:15:29 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.h3kwaw
[2008.10.23 15:53:38 | 000,090,128 | ---- | C] () -- C:\ProgramData\bold flag flag.6ze1fa
[2008.10.23 15:31:48 | 000,339,984 | ---- | C] () -- C:\ProgramData\bold flag flag.h5gwda
[2008.10.23 15:09:57 | 000,147,472 | ---- | C] () -- C:\ProgramData\bold flag flag.l5j7y
[2008.10.23 14:48:07 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.ps2k65
[2008.10.23 14:26:22 | 000,385,040 | ---- | C] () -- C:\ProgramData\loud flag cdrom.qxp4q
[2008.10.23 14:25:46 | 000,200,720 | ---- | C] () -- C:\ProgramData\bold flag flag.g7hex
[2008.10.23 14:25:46 | 000,159,760 | ---- | C] () -- C:\ProgramData\bold flag flag.zdmqfk
[2008.10.23 14:20:50 | 000,012,304 | ---- | C] () -- C:\ProgramData\bold flag flag.7376dv
[2008.08.27 19:54:45 | 000,024,226 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\UserTile.png
[2008.05.26 21:20:45 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.03.25 12:15:10 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.19 22:03:44 | 000,005,070 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2008.03.19 22:03:44 | 000,000,168 | RHS- | C] () -- C:\ProgramData\568DE542ED.sys
[2008.03.13 21:09:22 | 000,246,784 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.13 20:45:55 | 000,000,732 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\d3d9caps64.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 17:29:43 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 01:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.19 01:04:28 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2012.08.19 15:18:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2012.08.19 15:17:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.05 23:39:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.08.07 23:19:07 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Adobe
[2008.11.30 16:24:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ahead
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Apple Computer
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2011.11.27 13:50:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Avira
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2011.01.22 22:19:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Corel
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2008.08.27 07:27:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DivX
[2011.03.20 21:22:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\dvdcss
[2012.08.19 15:18:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2012.08.19 15:17:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.05 23:39:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.03.18 23:01:28 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Google
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2008.03.13 20:46:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Identities
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.03.14 00:31:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InstallShield
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2008.03.14 08:46:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Jasc Software Inc
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2008.03.15 19:17:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Logitech
[2008.03.20 21:38:49 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Macromedia
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.10.02 20:51:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2006.11.02 17:06:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Media Center Programs
[2010.08.15 21:43:50 | 000,000,000 | --SD | M] -- C:\Users\Heistmer\AppData\Roaming\Microsoft
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla
[2012.01.14 20:12:06 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla-Cache
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.07.03 20:37:23 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nero
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2012.06.27 19:53:45 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\NVIDIA
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2008.03.20 22:13:16 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Real
[2008.06.22 16:52:26 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\skypePM
[2008.03.16 01:22:08 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\SmartFTP
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2008.03.15 13:29:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Talkback
[2010.03.19 22:07:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\teamspeak2
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2008.08.18 23:36:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\vlc
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2011.11.05 20:03:29 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Winamp
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
[2008.03.14 22:39:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WinRAR
[2012.09.11 20:50:32 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
 
< %APPDATA%\*.exe /s >
[2010.07.19 18:49:04 | 000,010,134 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_24c89c8.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_39fe3610.exe
[2009.08.11 22:39:05 | 000,010,134 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{A2C60BF1-82E3-493C-911D-14AD50471F2F}\ARPPRODUCTICON.exe
[2007.10.08 01:57:52 | 000,307,200 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
[2007.12.28 11:15:38 | 000,172,032 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
[2012.01.07 17:57:55 | 003,703,176 | ---- | M] (WindSolutions) -- C:\Users\Heistmer\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2006.11.02 14:03:16 | 000,062,056 | ---- | M] (Microsoft Corporation) MD5=5CCDD13BC602AE33CD8B62D33C29AB72 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.19 01:07:48 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008.01.09 03:52:57 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=3927EB6EBFC77BA93481F440221D5252 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16584_none_371e04d9dcfdf69e\atapi.sys
[2008.01.09 03:52:56 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=48021EB810BF8FB6EBFA4569B95AAD5F -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20707_none_380123c8f5d8000c\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2009.12.20 00:00:00 | 000,037,520 | ---- | M] (perl.org) MD5=2852D57385C4709EAAE2F9DB01AD3672 -- C:\Users\Heistmer\Eigene Webs\xampp\perl\site\lib\auto\Win32\EventLog\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 01:11:32 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
[2006.11.02 13:51:48 | 000,280,680 | ---- | M] (Intel Corporation) MD5=72C3EE7EA3CD75A772E62AE0E5DF8B8C -- C:\Windows\SysNative\drivers\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.19 01:03:02 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.19 00:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
[2006.11.02 13:18:47 | 000,684,032 | ---- | M] (Microsoft Corporation) MD5=BFAB28B54DF41208CF3490FF26E53FD9 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_579f90caf36c48b9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 14:02:51 | 000,048,232 | ---- | M] (NVIDIA Corporation) MD5=94C5334040A5D500897F4C5FD12AEEDE -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.19 01:08:52 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 00:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006.11.02 13:19:09 | 000,239,616 | ---- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008.01.19 01:03:56 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2006.11.02 11:44:25 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=00B53DCA0408CCD8F6BAF13994F6E3A0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll
[2007.07.14 02:23:35 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=296BA70E2A302E639CBD9E2A32DC65C4 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll
[2008.01.19 01:04:24 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.19 00:32:20 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2007.07.14 02:23:36 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=437C1C0CB2A42EA20083F21E9CAEF461 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=707CD582A4F93DB789336A5CE9527970 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_275857df28a483b4\user32.dll
[2006.11.02 13:19:10 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=95D5555CC7BD8F520996E35D36491EEF -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_272045c928cedf94\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=E4E3ED1E0D1D8C33A9C94ABEA1C8BC96 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_27e0f46041c30a27\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
[2006.11.02 13:16:15 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
[2006.11.02 13:16:20 | 000,122,368 | ---- | M] (Microsoft Corporation) MD5=6F92CE5B50283B0C0A7A539ED552039A -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_8ada9256bfc30704\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.19 01:00:46 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 13:16:20 | 000,397,312 | ---- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 00:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
[2006.11.02 11:47:52 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=C4EE49DB7EADC812DBC0ECCF2E7FB929 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_a96e7a5c834006a3\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
[2006.11.02 17:40:34 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006.11.02 17:40:34 | 000,032,534 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 6281 bytes -> C:\Windows\pOOrGUI:Source Setup Log.txt
@Alternate Data Stream - 24 bytes -> C:\Windows:7E92895CF0C0E947
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 1192 bytes -> C:\ProgramData\Microsoft:GU20qEzkcvUPQnca2EoO96egmYBo7
@Alternate Data Stream - 1188 bytes -> C:\ProgramData\Microsoft:6UbkivR8LfAWeH3hD48xECCj6
@Alternate Data Stream - 1124 bytes -> C:\ProgramData\Microsoft:0gtbGQ5UBdBtGnl3ms7gN6CAa

< End of report >

--- --- ---

cosinus 07.10.2012 18:03

Code:

PRC - C:\Users\Heistmer\Eigene Webs\xampp\mysql\bin\mysqld.exe ()
PRC - C:\Users\Heistmer\Eigene Webs\xampp\apache\bin\httpd.exe (Apache Software Foundation)

Das ist so bekannt und auch gewollt mit dem xampp?

Heistmer 07.10.2012 19:10

Ich glaub das war mal irgend ein Baustein um eine Hompage zu erstellen, das hab ich dann aber auch schnell wieder augegeben.

Kann grundsätzlich wech. Kann so wie es aussieht auch über den Pogrammanager deinstaliert werden.

cosinus 07.10.2012 20:24

Dann deinstallier das mal und bei Gelegenheit auch alles andere was du nicht mehr brauchst. Hält das Log kurz und man sieht dann den Wald wegen weniger Bäume etwas besser :blabla:

Also mach danach wie o.g. bitte ein neues OTL-Log :)

Heistmer 08.10.2012 19:13

und ein neues Log :)

Code:

OTL logfile created on: 08.10.2012 19:25:13 - Run 6
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Heistmer\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,25 Gb Total Physical Memory | 1,82 Gb Available Physical Memory | 56,12% Memory free
6,71 Gb Paging File | 4,90 Gb Available in Paging File | 72,94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,11 Gb Total Space | 26,06 Gb Free Space | 5,78% Space Free | Partition Type: NTFS
Drive D: | 14,63 Gb Total Space | 10,08 Gb Free Space | 68,92% Space Free | Partition Type: FAT32
Drive J: | 931,50 Gb Total Space | 810,36 Gb Free Space | 87,00% Space Free | Partition Type: NTFS
 
Computer Name: Heistmer-ONE | User Name: Heistmer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC -  File not found
PRC - C:\Users\Heistmer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\FRITZ!DSL\StCenter.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
PRC - C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
PRC - C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Trillian\libungif.dll ()
MOD - C:\Program Files (x86)\Trillian\zlib1.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\talk.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\events.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\toolkit.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\buddy.dll ()
MOD - c:\users\Heistmer\appdata\roaming\trillian\languages\de\trillian.dll ()
MOD - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (StkSSrv) -- C:\Windows\SysNative\StkCSrv.exe (Syntek America Inc.)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (DeviceMonitorService) -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (FlipShare Service) -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (getPlusHelper) -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cjpcsc) -- C:\Windows\SysWOW64\cjpcsc.exe (REINER SCT)
SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (IGDCTRL) -- C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE (AVM Berlin)
SRV - (MagicTuneEngine) -- C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe ()
SRV - (Capture Device Service) -- C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (x10nets) -- C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe (X10)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira GmbH)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (cmnsusbser) -- C:\Windows\SysNative\DRIVERS\cmnsusbser.sys (Mobile Connector)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (acedrv10) -- C:\Windows\SysNative\drivers\acedrv10.sys (Protect Software GmbH)
DRV:64bit: - (acehlp10) -- C:\Windows\SysNative\drivers\acehlp10.sys (Protect Software GmbH)
DRV:64bit: - (atksgt) -- C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:64bit: - (lirsgt) -- C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\DRIVERS\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (IntelDH64) -- C:\Windows\SysNative\Drivers\IntelDH64.sys (Intel Corporation)
DRV:64bit: - (3xHybr64) -- C:\Windows\SysNative\DRIVERS\3xHybr64.sys (NXP Semiconductors Germany GmbH)
DRV:64bit: - (LUsbFilt) -- C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (L8042Kbd) -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (sxuptp) -- C:\Windows\SysNative\DRIVERS\sxuptp.sys (silex technology, Inc.)
DRV:64bit: - (StkCMini) -- C:\Windows\SysNative\Drivers\StkCMini.sys (Syntek)
DRV:64bit: - (cjusb) -- C:\Windows\SysNative\DRIVERS\cjusb.sys (REINER SCT)
DRV:64bit: - (e1express) -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (XUIF) -- C:\Windows\SysNative\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
DRV:64bit: - (X10Hid) -- C:\Windows\SysNative\Drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (TVICHW64) -- C:\Windows\SysWOW64\drivers\TVICHW64.SYS (EnTech Taiwan)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = hxxp://www.Google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}: "URL" = hxxp://www2.iesearch.com/s/?&q={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
 
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "FireSearch"
FF - prefs.js..browser.startup.homepage: "hxxp://www2.firesearch.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.0
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0:  File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.11.05 19:33:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.01.15 22:15:34 | 000,000,000 | ---D | M]
 
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Extensions
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions
[2010.05.19 23:02:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.08.26 21:16:36 | 000,000,000 | ---D | M] ("FireFTP") -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010.12.04 10:46:25 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.12.04 10:46:38 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Heistmer\AppData\Roaming\mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\firebug@software.joehewitt.com
[2012.10.04 15:48:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
File not found (No name found) -- C:\USERS\Heistmer\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\7EW9DMKC.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
[2010.03.27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2008.06.18 09:47:34 | 000,397,312 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npdlplug.dll
[2011.10.26 20:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010.07.18 17:32:18 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.07.18 17:32:18 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.07.18 17:32:18 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.07.18 17:32:19 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.07.18 17:32:19 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.03.03 21:42:44 | 000,302,531 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        www.123topsearch.com
O1 - Hosts: 127.0.0.1        123topsearch.com
O1 - Hosts: 127.0.0.1        www.132.com
O1 - Hosts: 127.0.0.1        132.com
O1 - Hosts: 127.0.0.1        136136.net
O1 - Hosts: 127.0.0.1        www.136136.net
O1 - Hosts: 127.0.0.1        www.163ns.com
O1 - Hosts: 10430 more lines...
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [AVMFBoxMonitor] C:\Program Files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe (AVM Berlin)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Protect.lnk = C:\Program Files (x86)\FRITZ!DSL\FwebProt.exe (AVM Berlin)
O4 - Startup: C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk = C:\Program Files (x86)\Trillian\trillian.exe (Cerulean Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8:64bit: - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIC273~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Heistmer\Desktop\PartyPoker.lnk ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\FRITZ!DSL\\sarah.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\FRITZ!DSL\sarah.dll (AVM Berlin)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([global.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: com.tw ([www.msi] http in Trusted sites)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-3066119559-789599144-109096739-1000\..Trusted Ranges: Range1 ([*] in Lokales Intranet)
O16:64bit: - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} hxxp://quickscan.bitdefender.com/qsax/qsax64.cab (Bitdefender QuickScan Control)
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab (WebSDev Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B63BB61-2F55-48CA-BA01-587CE776F4AC}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GR99D3~1.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg
O27:64bit: - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\itunes.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27:64bit: - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\acrord32.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\afterfx.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\exprwd.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\filezilla.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_install_win_ax64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flashplayer11-2_p2_uninstall_win_64_112211.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\flipshare.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\magictune.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mml.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mmlupdate.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\msoxmled.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\mstore.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\presentationhost.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\switchboard.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe (TuneUp Software)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{03941441-e1ec-11de-af2d-806e6f6e6963}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{73c27794-a33c-11e0-bab9-001d9204693f}\Shell\AutoRun\command - "" = J:\setup.exe -a
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell - "" = AutoRun
O33 - MountPoints2\{89f70bcf-e347-11de-9c6a-00f1d000f1d0}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{9be9d8f9-48c9-11df-bf43-001d9204693f}\Shell\AutoRun\command - "" = G:\pushinst.exe
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell - "" = AutoRun
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\AutoRun\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\configure\command - "" = F:\SETUP.EXE
O33 - MountPoints2\{f07e3d91-0280-11dd-b8d7-001d9204693f}\Shell\install\command - "" = F:\SETUP.EXE
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
 
 
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7070D8E0-650A-46b3-B03C-9497582E6A74} - %SystemRoot%\system32\soundschemes.exe /AddRegistration
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24} - %SystemRoot%\system32\soundschemes2.exe /AddRegistration
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.3IV2 - C:\Windows\SysWow64\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.10.08 19:22:44 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.04 17:06:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012.10.02 20:51:43 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2012.10.02 20:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.10.02 20:51:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.10.02 20:51:26 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012.10.02 20:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.09.22 23:57:59 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\NOS
[2012.09.15 19:55:10 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\Desktop\HeistMedia
[2012.09.15 19:48:27 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Artisteer 3
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Local\Xara
[2012.09.11 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2012.09.11 20:51:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MAGIX
[2012.09.11 20:50:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2012.09.11 20:50:32 | 000,000,000 | ---D | C] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
[2012.09.11 20:50:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo!
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.10.08 19:22:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Heistmer\Desktop\OTL.exe
[2012.10.08 18:54:36 | 000,002,305 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FRITZ!DSL Startcenter.lnk
[2012.10.08 18:53:56 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.10.08 18:53:55 | 000,003,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.10.08 18:53:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.10.08 08:01:37 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.10.08 07:07:57 | 004,965,768 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.10.06 22:29:01 | 000,246,784 | ---- | M] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.10.05 19:15:12 | 000,513,501 | ---- | M] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.03 18:10:26 | 000,000,020 | ---- | M] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:36 | 000,050,477 | ---- | M] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | M] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 20:51:28 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 08:03:15 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.22 23:44:31 | 001,453,952 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.09.22 23:44:31 | 000,632,252 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.09.22 23:44:31 | 000,598,940 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.09.22 23:44:31 | 000,127,302 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.09.22 23:44:31 | 000,104,954 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.09.22 23:22:22 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012.09.11 20:51:25 | 000,000,858 | ---- | M] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.10.05 19:15:12 | 000,513,501 | ---- | C] () -- C:\Users\Heistmer\Desktop\adwcleaner.exe
[2012.10.03 18:10:26 | 000,000,020 | ---- | C] () -- C:\Users\Heistmer\defogger_reenable
[2012.10.03 18:09:35 | 000,050,477 | ---- | C] () -- C:\Users\Heistmer\Desktop\Defogger.exe
[2012.10.03 17:37:00 | 000,543,455 | ---- | C] () -- C:\Users\Heistmer\Desktop\trojaner.jpg
[2012.10.02 20:51:28 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.10.02 07:54:28 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.09.11 20:51:25 | 000,000,858 | ---- | C] () -- C:\Users\Public\Desktop\MAGIX 3D Maker 7 Download-Version.lnk
[2012.06.07 21:24:07 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2011.10.16 11:51:19 | 000,000,430 | ---- | C] () -- C:\Windows\scummvm.ini
[2011.10.15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011.08.26 07:31:00 | 000,169,757 | ---- | C] () -- C:\Users\Heistmer\fm_0911_34-35 (1).pdf
[2011.02.15 21:16:26 | 000,000,071 | ---- | C] () -- C:\Windows\wiso.ini
[2011.02.06 11:39:21 | 000,000,482 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\RAExpertHistory.xml
[2010.11.25 21:38:09 | 000,000,032 | ---- | C] () -- C:\Windows\Menu.INI
[2010.03.02 20:56:15 | 000,260,318 | ---- | C] () -- C:\Users\Heistmer\verzeichniss.jpg
[2010.03.02 20:54:29 | 000,276,485 | ---- | C] () -- C:\Users\Heistmer\filme.jpg
[2010.02.25 08:59:03 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2008.11.30 01:05:35 | 000,000,029 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\default.rss
[2008.11.30 01:05:35 | 000,000,000 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\downloads.m3u
[2008.10.23 20:15:43 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.twlsj
[2008.10.23 19:53:53 | 000,258,064 | ---- | C] () -- C:\ProgramData\bold flag flag.m89kbj
[2008.10.23 19:32:02 | 000,319,504 | ---- | C] () -- C:\ProgramData\bold flag flag.fddwg
[2008.10.23 19:10:12 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.zj2d1
[2008.10.23 18:48:21 | 000,348,176 | ---- | C] () -- C:\ProgramData\bold flag flag.0f3nl
[2008.10.23 18:26:31 | 000,311,312 | ---- | C] () -- C:\ProgramData\bold flag flag.6lzxdq1
[2008.10.23 18:04:41 | 000,122,896 | ---- | C] () -- C:\ProgramData\bold flag flag.tczrs2
[2008.10.23 17:42:50 | 000,036,880 | ---- | C] () -- C:\ProgramData\bold flag flag.a19t49
[2008.10.23 17:21:00 | 000,196,624 | ---- | C] () -- C:\ProgramData\bold flag flag.0ehold
[2008.10.23 16:59:09 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.qr8rj
[2008.10.23 16:37:19 | 000,008,208 | ---- | C] () -- C:\ProgramData\bold flag flag.b8af8
[2008.10.23 16:15:29 | 000,110,608 | ---- | C] () -- C:\ProgramData\bold flag flag.h3kwaw
[2008.10.23 15:53:38 | 000,090,128 | ---- | C] () -- C:\ProgramData\bold flag flag.6ze1fa
[2008.10.23 15:31:48 | 000,339,984 | ---- | C] () -- C:\ProgramData\bold flag flag.h5gwda
[2008.10.23 15:09:57 | 000,147,472 | ---- | C] () -- C:\ProgramData\bold flag flag.l5j7y
[2008.10.23 14:48:07 | 000,303,120 | ---- | C] () -- C:\ProgramData\bold flag flag.ps2k65
[2008.10.23 14:26:22 | 000,385,040 | ---- | C] () -- C:\ProgramData\loud flag cdrom.qxp4q
[2008.10.23 14:25:46 | 000,200,720 | ---- | C] () -- C:\ProgramData\bold flag flag.g7hex
[2008.10.23 14:25:46 | 000,159,760 | ---- | C] () -- C:\ProgramData\bold flag flag.zdmqfk
[2008.10.23 14:20:50 | 000,012,304 | ---- | C] () -- C:\ProgramData\bold flag flag.7376dv
[2008.08.27 19:54:45 | 000,024,226 | ---- | C] () -- C:\Users\Heistmer\AppData\Roaming\UserTile.png
[2008.05.26 21:20:45 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2008.03.25 12:15:10 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2008.03.19 22:03:44 | 000,005,070 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2008.03.19 22:03:44 | 000,000,168 | RHS- | C] () -- C:\ProgramData\568DE542ED.sys
[2008.03.13 21:09:22 | 000,246,784 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.13 20:45:55 | 000,000,732 | ---- | C] () -- C:\Users\Heistmer\AppData\Local\d3d9caps64.dat
 
========== ZeroAccess Check ==========
 
[2006.11.02 17:29:43 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.08 19:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.04.11 01:11:16 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 00:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008.01.19 01:04:28 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2012.10.08 07:20:51 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.07 23:25:53 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.08.07 23:19:07 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Adobe
[2008.11.30 16:24:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ahead
[2010.10.21 11:11:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Any Video Converter
[2012.01.26 23:28:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Apple Computer
[2012.01.26 23:28:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Artisteer
[2011.11.27 13:50:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Avira
[2008.06.29 17:49:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\BlackBean
[2011.07.02 20:51:27 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Canneverbe Limited
[2011.01.22 22:19:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Corel
[2008.04.04 21:52:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DAEMON Tools
[2008.08.27 07:27:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DivX
[2011.03.20 21:22:56 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\dvdcss
[2012.10.08 07:20:51 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\DVDVideoSoft
[2011.02.13 16:56:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\elsterformular
[2012.09.14 20:17:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FileZilla
[2012.10.07 23:25:53 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\FRITZ!
[2008.03.18 23:01:28 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Google
[2008.12.09 22:24:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Haufe
[2008.03.13 20:46:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Identities
[2011.03.20 21:11:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\ImTOO
[2008.03.14 00:31:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InstallShield
[2008.08.21 22:26:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\InterVideo
[2008.03.14 08:46:48 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Jasc Software Inc
[2012.09.27 19:52:12 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\KeePass
[2008.12.15 22:04:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Leadertech
[2008.12.09 22:01:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Lexware
[2008.03.15 19:17:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Logitech
[2008.03.20 21:38:49 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Macromedia
[2012.09.11 20:53:47 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MAGIX
[2012.10.02 20:51:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Malwarebytes
[2006.11.02 17:06:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Media Center Programs
[2010.08.15 21:43:50 | 000,000,000 | --SD | M] -- C:\Users\Heistmer\AppData\Roaming\Microsoft
[2011.06.30 21:45:22 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\motorola
[2008.08.26 21:11:41 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla
[2012.01.14 20:12:06 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Mozilla-Cache
[2009.02.01 23:33:54 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Musicmatch
[2012.08.27 19:12:02 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\MyPhoneExplorer
[2012.10.02 23:29:35 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nayfo
[2011.07.03 20:37:23 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nero
[2011.06.26 00:08:39 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Nokia
[2012.06.27 19:53:45 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\NVIDIA
[2010.07.20 07:36:11 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PACE Anti-Piracy
[2008.05.08 19:51:09 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PC Suite
[2008.08.27 19:54:43 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\PeerNetworking
[2012.06.07 19:10:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\QuickScan
[2008.03.20 22:13:16 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Real
[2008.06.22 16:52:26 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\skypePM
[2008.03.16 01:22:08 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\SmartFTP
[2010.07.19 20:54:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2008.03.15 13:29:24 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Talkback
[2010.03.19 22:07:33 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\teamspeak2
[2011.03.08 08:28:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Transcend
[2010.09.09 07:49:55 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Trillian
[2012.08.10 20:20:05 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TS3Client
[2011.11.20 15:37:03 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\TuneUp Software
[2012.09.22 23:23:15 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Ulead Systems
[2008.08.18 23:36:46 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\vlc
[2012.09.14 07:47:20 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\VSO
[2010.04.21 22:37:31 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\wds.NET
[2011.11.05 20:03:29 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Winamp
[2012.01.07 18:07:17 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WindSolutions
[2008.03.14 22:39:38 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\WinRAR
[2012.09.11 20:50:32 | 000,000,000 | ---D | M] -- C:\Users\Heistmer\AppData\Roaming\Yahoo!
 
< %APPDATA%\*.exe /s >
[2010.07.19 18:49:04 | 000,010,134 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_24c89c8.exe
[2009.05.19 21:35:06 | 000,007,358 | R--- | M] () -- C:\Users\Heistmer\AppData\Roaming\Microsoft\Installer\{5C79D312-F68F-4B04-8A4F-E28A0AE1ECBB}\_39fe3610.exe
[2007.10.08 01:57:52 | 000,307,200 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
[2007.12.28 11:15:38 | 000,172,032 | ---- | M] (Simon Tatham) -- C:\Users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
[2012.01.07 17:57:55 | 003,703,176 | ---- | M] (WindSolutions) -- C:\Users\Heistmer\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2006.11.02 14:03:16 | 000,062,056 | ---- | M] (Microsoft Corporation) MD5=5CCDD13BC602AE33CD8B62D33C29AB72 -- C:\Windows\SysNative\drivers\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008.01.19 01:09:10 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2008.01.19 01:07:48 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008.01.09 03:52:57 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=3927EB6EBFC77BA93481F440221D5252 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16584_none_371e04d9dcfdf69e\atapi.sys
[2008.01.09 03:52:56 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=48021EB810BF8FB6EBFA4569B95AAD5F -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20707_none_380123c8f5d8000c\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SysNative\drivers\atapi.sys
[2009.04.11 01:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\SysNative\cngaudit.dll
[2006.11.02 13:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 01:11:32 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
[2006.11.02 13:51:48 | 000,280,680 | ---- | M] (Intel Corporation) MD5=72C3EE7EA3CD75A772E62AE0E5DF8B8C -- C:\Windows\SysNative\drivers\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2008.01.19 01:03:02 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SysWOW64\netlogon.dll
[2009.04.11 00:28:24 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SysNative\netlogon.dll
[2009.04.11 01:11:18 | 000,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008.01.19 00:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
[2006.11.02 13:18:47 | 000,684,032 | ---- | M] (Microsoft Corporation) MD5=BFAB28B54DF41208CF3490FF26E53FD9 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_579f90caf36c48b9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 14:02:51 | 000,048,232 | ---- | M] (NVIDIA Corporation) MD5=94C5334040A5D500897F4C5FD12AEEDE -- C:\Windows\SysNative\drivers\nvstor.sys
[2008.01.19 01:08:52 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 00:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006.11.02 13:19:09 | 000,239,616 | ---- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008.01.19 01:03:56 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SysWOW64\scecli.dll
[2009.04.11 00:28:26 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SysNative\scecli.dll
[2009.04.11 01:11:24 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
 
< MD5 for: USER32.DLL  >
[2006.11.02 11:44:25 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=00B53DCA0408CCD8F6BAF13994F6E3A0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_3174f01b5d2fa18f\user32.dll
[2007.07.14 02:23:35 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=296BA70E2A302E639CBD9E2A32DC65C4 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_31ad02315d0545af\user32.dll
[2008.01.19 01:04:24 | 000,820,224 | ---- | M] (Microsoft Corporation) MD5=32B87D215905F648EBE36A621978442C -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_295707c525b9f068\user32.dll
[2008.01.19 00:32:20 | 000,648,192 | ---- | M] (Microsoft Corporation) MD5=3D691030DBD3BD75DE1501BE54F0D425 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_33abb2175a1ab263\user32.dll
[2007.07.14 02:23:36 | 000,646,656 | ---- | M] (Microsoft Corporation) MD5=437C1C0CB2A42EA20083F21E9CAEF461 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_32359eb27623cc22\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=707CD582A4F93DB789336A5CE9527970 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_275857df28a483b4\user32.dll
[2006.11.02 13:19:10 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=95D5555CC7BD8F520996E35D36491EEF -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_272045c928cedf94\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\SysWOW64\user32.dll
[2009.04.11 00:26:46 | 000,648,704 | ---- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_35972b23573c7daf\user32.dll
[2007.07.14 02:23:36 | 000,810,496 | ---- | M] (Microsoft Corporation) MD5=E4E3ED1E0D1D8C33A9C94ABEA1C8BC96 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_27e0f46041c30a27\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysNative\user32.dll
[2009.04.11 01:11:28 | 000,820,224 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_2b4280d122dbbbb4\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\SysWOW64\userinit.exe
[2008.01.19 00:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 11:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
[2006.11.02 13:16:15 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\SysNative\userinit.exe
[2008.01.19 01:00:42 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\SysWOW64\wininit.exe
[2008.01.19 00:33:38 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\SysNative\wininit.exe
[2008.01.19 01:00:46 | 000,123,904 | ---- | M] (Microsoft Corporation) MD5=117EA87DF785CA1B9D821F6F213DCE07 -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_8d115452bcae17d8\wininit.exe
[2006.11.02 13:16:20 | 000,122,368 | ---- | M] (Microsoft Corporation) MD5=6F92CE5B50283B0C0A7A539ED552039A -- C:\Windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_8ada9256bfc30704\wininit.exe
[2006.11.02 11:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.09.07 17:04:42 | 000,218,696 | ---- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\SysNative\winlogon.exe
[2009.04.11 01:11:10 | 000,405,504 | ---- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008.01.19 01:00:46 | 000,406,016 | ---- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SysWOW64\winlogon.exe
[2009.04.11 00:28:14 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 13:16:20 | 000,397,312 | ---- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2006.11.02 11:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008.01.19 00:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2008.01.18 23:37:48 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=8A900348370E359B6BFF6A550E4649E1 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_aba53c58802b1777\ws2ifsl.sys
[2006.11.02 11:47:52 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=C4EE49DB7EADC812DBC0ECCF2E7FB929 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_a96e7a5c834006a3\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >
[2006.11.02 17:40:34 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006.11.02 17:40:34 | 000,032,534 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 6281 bytes -> C:\Windows\pOOrGUI:Source Setup Log.txt
@Alternate Data Stream - 24 bytes -> C:\Windows:7E92895CF0C0E947
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 1192 bytes -> C:\ProgramData\Microsoft:GU20qEzkcvUPQnca2EoO96egmYBo7
@Alternate Data Stream - 1188 bytes -> C:\ProgramData\Microsoft:6UbkivR8LfAWeH3hD48xECCj6
@Alternate Data Stream - 1124 bytes -> C:\ProgramData\Microsoft:0gtbGQ5UBdBtGnl3ms7gN6CAa

< End of report >


Alles was nun noch da ist benutz ich entweder, bzw. meine Frau. Oder was auch bei vielem zutrifft, hab ich einfach keine Ahnung wozu es gehört.

Ich habe auch versucht Avira zu deinstalieren, da ich ja derzeit das AntiMaleware Pogramm am laufen habe, allerding bekomm ich dann auch wieder die Meldung mit der falschen Gruppenrichline.

Auch den Fehler welchen OTL immer mal wieder ausgibt ist noch da. Aber das nur am Rande fals es von bedeutung ist.

Zitat:

Es befindet sich kein Datenträger im Lauwerk. Legen Sie einen Datenträger in Laufwerk/Device/Harddisk/DR2 ein.

cosinus 09.10.2012 10:50

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKLM\..\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}: "URL" = http://www2.iesearch.com/s/?&q={searchTerms}
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
@Alternate Data Stream - 6281 bytes -> C:\Windows\pOOrGUI:Source Setup Log.txt
@Alternate Data Stream - 24 bytes -> C:\Windows:7E92895CF0C0E947
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 1192 bytes -> C:\ProgramData\Microsoft:GU20qEzkcvUPQnca2EoO96egmYBo7
@Alternate Data Stream - 1188 bytes -> C:\ProgramData\Microsoft:6UbkivR8LfAWeH3hD48xECCj6
@Alternate Data Stream - 1124 bytes -> C:\ProgramData\Microsoft:0gtbGQ5UBdBtGnl3ms7gN6CAa
:Files
C:\Windows\pOOrGUI
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Heistmer 09.10.2012 13:45

Hallo,

hier das Fix Log.

Code:

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4327FABE-3C21-4689-8DBE-D226CF777FE9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4327FABE-3C21-4689-8DBE-D226CF777FE9}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA deleted successfully.
ADS C:\Windows\pOOrGUI:Source Setup Log.txt deleted successfully.
ADS C:\Windows:7E92895CF0C0E947 deleted successfully.
ADS C:\ProgramData\TEMP:CB0AACC9 deleted successfully.
ADS C:\ProgramData\Microsoft:GU20qEzkcvUPQnca2EoO96egmYBo7 deleted successfully.
ADS C:\ProgramData\Microsoft:6UbkivR8LfAWeH3hD48xECCj6 deleted successfully.
ADS C:\ProgramData\Microsoft:0gtbGQ5UBdBtGnl3ms7gN6CAa deleted successfully.
========== FILES ==========
C:\Windows\pOOrGUI moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Heistmer\Desktop\cmd.bat deleted successfully.
C:\Users\Heistmer\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Heistmer
->Temp folder emptied: 6080208 bytes
->Temporary Internet Files folder emptied: 1289520574 bytes
->Java cache emptied: 8125001 bytes
->FireFox cache emptied: 68287063 bytes
->Flash cache emptied: 154928 bytes
 
User: Public
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41661 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 35648 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1061934 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1.310,00 mb
 
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Error: Unble to create default HOSTS file!
 
OTL by OldTimer - Version 3.2.69.0 log created on 10092012_133009

Files\Folders moved on Reboot...
C:\Users\Heistmer\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Heistmer\AppData\Local\Temp\REG58DA.tmp moved successfully.
C:\Users\Heistmer\AppData\Local\Temp\REG75A3.tmp moved successfully.
File move failed. C:\Windows\SysNative\uxtF565.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


cosinus 09.10.2012 15:21

Ich brauch den Quarantäneordner von OTL. Bitte folgendes machen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinflussen!
2.) Ordner MovedFiles in C:\_OTL in eine Datei zippen
3.) Die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten!

4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

Heistmer 09.10.2012 20:44

Datei: MovedFiles.zip_1 empfangen

Vorgang erfolgreich abgeschlossen.

cosinus 10.10.2012 10:18

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

Heistmer 10.10.2012 11:58

Hier das TDSS Log

Code:

12:51:46.0018 5700  TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
12:51:48.0020 5700  ============================================================
12:51:48.0020 5700  Current date / time: 2012/10/10 12:51:48.0020
12:51:48.0020 5700  SystemInfo:
12:51:48.0021 5700 
12:51:48.0021 5700  OS Version: 6.0.6002 ServicePack: 2.0
12:51:48.0021 5700  Product type: Workstation
12:51:48.0021 5700  ComputerName: Heistmer-ONE
12:51:48.0021 5700  UserName: Heistmer
12:51:48.0021 5700  Windows directory: C:\Windows
12:51:48.0021 5700  System windows directory: C:\Windows
12:51:48.0021 5700  Running under WOW64
12:51:48.0021 5700  Processor architecture: Intel x64
12:51:48.0021 5700  Number of processors: 4
12:51:48.0021 5700  Page size: 0x1000
12:51:48.0021 5700  Boot type: Normal boot
12:51:48.0021 5700  ============================================================
12:51:57.0320 5700  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:51:57.0355 5700  Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:51:57.0387 5700  ============================================================
12:51:57.0387 5700  \Device\Harddisk0\DR0:
12:51:57.0387 5700  MBR partitions:
12:51:57.0387 5700  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x74701AC1
12:51:57.0387 5700  \Device\Harddisk1\DR1:
12:51:57.0388 5700  MBR partitions:
12:51:57.0388 5700  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3863A000
12:51:57.0408 5700  \Device\Harddisk1\DR1\Partition2: MBR, Type 0xB, StartLBA 0x3863B000, BlocksNum 0x1D4A800
12:51:57.0408 5700  ============================================================
12:51:57.0448 5700  C: <-> \Device\Harddisk1\DR1\Partition1
12:51:57.0467 5700  D: <-> \Device\Harddisk1\DR1\Partition2
12:51:57.0474 5700  J: <-> \Device\Harddisk0\DR0\Partition1
12:51:57.0474 5700  ============================================================
12:51:57.0474 5700  Initialize success
12:51:57.0474 5700  ============================================================
12:52:53.0223 5396  ============================================================
12:52:53.0223 5396  Scan started
12:52:53.0223 5396  Mode: Manual; SigCheck; TDLFS;
12:52:53.0223 5396  ============================================================
12:52:54.0402 5396  ================ Scan system memory ========================
12:52:54.0402 5396  System memory - ok
12:52:54.0403 5396  ================ Scan services =============================
12:52:54.0484 5396  !SASCORE - ok
12:52:54.0621 5396  [ 48D4EA83CA0A1285ECA3D6AFA780D93D ] 3xHybr64        C:\Windows\system32\DRIVERS\3xHybr64.sys
12:52:54.0901 5396  3xHybr64 - ok
12:52:54.0925 5396  [ 156BC3F91DCF43510C28E75CC5CEE3C7 ] acedrv10        C:\Windows\system32\drivers\acedrv10.sys
12:52:54.0949 5396  acedrv10 - ok
12:52:54.0960 5396  [ 1AFE4120F70962B4A773008557F660CD ] acehlp10        C:\Windows\system32\drivers\acehlp10.sys
12:52:54.0982 5396  acehlp10 - ok
12:52:55.0007 5396  [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI            C:\Windows\system32\drivers\acpi.sys
12:52:55.0029 5396  ACPI - ok
12:52:55.0050 5396  [ 9137451D37BA1C325CD6C2DEF3D2D692 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
12:52:55.0081 5396  adp94xx - ok
12:52:55.0107 5396  [ 01F80898DF5CC7DF19B3B11351846263 ] adpahci        C:\Windows\system32\drivers\adpahci.sys
12:52:55.0132 5396  adpahci - ok
12:52:55.0155 5396  [ DA001DB13FFF45DFE9109936E265B7CC ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
12:52:55.0192 5396  adpu160m - ok
12:52:55.0218 5396  [ 2B10C35C5B7C5C0C28F572E035319602 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
12:52:55.0248 5396  adpu320 - ok
12:52:55.0269 5396  [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
12:52:55.0425 5396  AeLookupSvc - ok
12:52:55.0450 5396  [ C4F6CE6087760AD70960C9EB130E7943 ] AFD            C:\Windows\system32\drivers\afd.sys
12:52:55.0509 5396  AFD - ok
12:52:55.0526 5396  [ 5CCDD13BC602AE33CD8B62D33C29AB72 ] agp440          C:\Windows\system32\drivers\agp440.sys
12:52:55.0543 5396  agp440 - ok
12:52:55.0560 5396  [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
12:52:55.0578 5396  aic78xx - ok
12:52:55.0600 5396  [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG            C:\Windows\System32\alg.exe
12:52:55.0787 5396  ALG - ok
12:52:55.0805 5396  [ BFE5E136EDC48F8ED2386639CA3BC687 ] aliide          C:\Windows\system32\drivers\aliide.sys
12:52:55.0822 5396  aliide - ok
12:52:55.0832 5396  [ 9C5C3109E07C8A9F5D63F4C6171B9587 ] amdide          C:\Windows\system32\drivers\amdide.sys
12:52:55.0848 5396  amdide - ok
12:52:55.0858 5396  [ DE55DC52F7CEB89A967572D6B491ADA2 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
12:52:56.0005 5396  AmdK8 - ok
12:52:56.0079 5396  [ 466A0D95960DAD3222C896D2CEA99993 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
12:52:56.0207 5396  AntiVirSchedulerService - ok
12:52:56.0230 5396  [ A489BE6BB0AA1FF406B488B60542314B ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
12:52:56.0241 5396  AntiVirService - ok
12:52:56.0257 5396  [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo        C:\Windows\System32\appinfo.dll
12:52:56.0287 5396  Appinfo - ok
12:52:56.0341 5396  [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:52:56.0380 5396  Apple Mobile Device - ok
12:52:56.0409 5396  [ 3DA98C07B18A676180FE7EED924D1673 ] AppMgmt        C:\Windows\System32\appmgmts.dll
12:52:56.0447 5396  AppMgmt - ok
12:52:56.0456 5396  [ 2E8623F2FED998A97129A3DB919551C8 ] arc            C:\Windows\system32\drivers\arc.sys
12:52:56.0474 5396  arc - ok
12:52:56.0486 5396  [ 741A003C041A3EC480A2E71AF71E9654 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
12:52:56.0503 5396  arcsas - ok
12:52:56.0521 5396  [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
12:52:56.0565 5396  AsyncMac - ok
12:52:56.0588 5396  [ E68D9B3A3905619732F7FE039466A623 ] atapi          C:\Windows\system32\drivers\atapi.sys
12:52:56.0600 5396  atapi - ok
12:52:56.0626 5396  [ FC0E8778C000291CAF60EB88C011E931 ] atksgt          C:\Windows\system32\DRIVERS\atksgt.sys
12:52:56.0673 5396  atksgt - ok
12:52:56.0709 5396  [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:52:56.0742 5396  AudioEndpointBuilder - ok
12:52:56.0750 5396  [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
12:52:56.0777 5396  AudioSrv - ok
12:52:56.0783 5396  [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
12:52:56.0794 5396  avgntflt - ok
12:52:56.0822 5396  [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
12:52:56.0851 5396  avipbb - ok
12:52:56.0865 5396  [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
12:52:56.0907 5396  avkmgr - ok
12:52:56.0941 5396  [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE            C:\Windows\System32\bfe.dll
12:52:56.0987 5396  BFE - ok
12:52:57.0025 5396  [ 6D316F4859634071CC25C4FD4589AD2C ] BITS            C:\Windows\System32\qmgr.dll
12:52:57.0110 5396  BITS - ok
12:52:57.0114 5396  blbdrive - ok
12:52:57.0155 5396  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
12:52:57.0205 5396  Bonjour Service - ok
12:52:57.0249 5396  [ 2348447A80920B2493A9B582A23E81E1 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
12:52:57.0274 5396  bowser - ok
12:52:57.0293 5396  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
12:52:57.0335 5396  BrFiltLo - ok
12:52:57.0348 5396  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
12:52:57.0388 5396  BrFiltUp - ok
12:52:57.0409 5396  [ A1B39DE453433B115B4EA69EE0343816 ] Browser        C:\Windows\System32\browser.dll
12:52:57.0447 5396  Browser - ok
12:52:57.0456 5396  [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid        C:\Windows\system32\drivers\brserid.sys
12:52:57.0510 5396  Brserid - ok
12:52:57.0520 5396  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
12:52:57.0612 5396  BrSerWdm - ok
12:52:57.0624 5396  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
12:52:57.0678 5396  BrUsbMdm - ok
12:52:57.0693 5396  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
12:52:57.0761 5396  BrUsbSer - ok
12:52:57.0764 5396  BTCFilterService - ok
12:52:57.0783 5396  [ 09F926A0D9C0BAFD8417A4307D2ED13C ] BthEnum        C:\Windows\system32\DRIVERS\BthEnum.sys
12:52:57.0819 5396  BthEnum - ok
12:52:57.0832 5396  [ 72F70A38BB15252EB7C4DA7BA3BD4ED1 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
12:52:57.0866 5396  BTHMODEM - ok
12:52:57.0886 5396  [ BEFC5311736B475AC5B60C14FF7C775A ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
12:52:57.0923 5396  BthPan - ok
12:52:57.0959 5396  [ E1466882252FF51EDDE48C3F7EDA2591 ] BTHPORT        C:\Windows\system32\Drivers\BTHport.sys
12:52:58.0047 5396  BTHPORT - ok
12:52:58.0095 5396  [ 22E65FFD640F16968F855F5B3528D366 ] BthServ        C:\Windows\System32\bthserv.dll
12:52:58.0131 5396  BthServ - ok
12:52:58.0148 5396  [ 970192CDED77A128E7E30722E5EE6B9C ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
12:52:58.0177 5396  BTHUSB - ok
12:52:58.0195 5396  [ 1778EBA872274C1226D869CD9486847E ] Capture Device Service C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
12:52:58.0231 5396  Capture Device Service - ok
12:52:58.0257 5396  [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
12:52:58.0289 5396  cdfs - ok
12:52:58.0303 5396  [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
12:52:58.0344 5396  cdrom - ok
12:52:58.0373 5396  [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc    C:\Windows\System32\certprop.dll
12:52:58.0407 5396  CertPropSvc - ok
12:52:58.0417 5396  [ F28F00596824058BC61D5EDF434C9B82 ] circlass        C:\Windows\system32\drivers\circlass.sys
12:52:58.0468 5396  circlass - ok
12:52:58.0527 5396  [ 7DB47DA3A831A330FCF6E6C77849744B ] cjpcsc          C:\Windows\SysWOW64\cjpcsc.exe
12:52:58.0562 5396  cjpcsc - ok
12:52:58.0603 5396  [ B16DA6F151CD7FA0D58F82AC884D5039 ] cjusb          C:\Windows\system32\DRIVERS\cjusb.sys
12:52:58.0618 5396  cjusb - ok
12:52:58.0636 5396  [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS            C:\Windows\system32\CLFS.sys
12:52:58.0659 5396  CLFS - ok
12:52:58.0712 5396  [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:52:58.0724 5396  clr_optimization_v2.0.50727_32 - ok
12:52:58.0756 5396  [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:52:58.0772 5396  clr_optimization_v2.0.50727_64 - ok
12:52:58.0804 5396  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:52:58.0819 5396  clr_optimization_v4.0.30319_32 - ok
12:52:58.0843 5396  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:52:58.0858 5396  clr_optimization_v4.0.30319_64 - ok
12:52:58.0880 5396  [ 689630948F770D4462B04B69D28CD5A1 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
12:52:58.0895 5396  cmdide - ok
12:52:58.0917 5396  [ 2B3B8CBEA1BA1BCE5700607FBDB31034 ] cmnsusbser      C:\Windows\system32\DRIVERS\cmnsusbser.sys
12:52:58.0938 5396  cmnsusbser ( UnsignedFile.Multi.Generic ) - warning
12:52:58.0938 5396  cmnsusbser - detected UnsignedFile.Multi.Generic (1)
12:52:58.0947 5396  [ 0E77A445640BF310817F60941C50560C ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
12:52:58.0962 5396  Compbatt - ok
12:52:58.0966 5396  COMSysApp - ok
12:52:58.0971 5396  [ B1192DCD5B9CF46BEED0E2A9E5BCF59A ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
12:52:58.0982 5396  crcdisk - ok
12:52:59.0007 5396  [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
12:52:59.0050 5396  CryptSvc - ok
12:52:59.0067 5396  [ F60F50C8ED3FCBE358430B95FE27D09C ] CSC            C:\Windows\system32\drivers\csc.sys
12:52:59.0155 5396  CSC - ok
12:52:59.0192 5396  [ 1B5F256D31836ED2BA60B3A6C800200C ] CscService      C:\Windows\System32\cscsvc.dll
12:52:59.0226 5396  CscService - ok
12:52:59.0256 5396  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch      C:\Windows\system32\rpcss.dll
12:52:59.0323 5396  DcomLaunch - ok
12:52:59.0372 5396  [ 0259948FFE5F7E69CD1D8A8E74E0547C ] DeviceMonitorService C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
12:52:59.0398 5396  DeviceMonitorService - ok
12:52:59.0411 5396  [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
12:52:59.0455 5396  DfsC - ok
12:52:59.0544 5396  [ C647F468F7DE343DF8C143655C5557D4 ] DFSR            C:\Windows\system32\DFSR.exe
12:52:59.0733 5396  DFSR - ok
12:52:59.0754 5396  [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
12:52:59.0804 5396  Dhcp - ok
12:52:59.0830 5396  [ B0107E40ECDB5FA692EBF832F295D905 ] disk            C:\Windows\system32\drivers\disk.sys
12:52:59.0844 5396  disk - ok
12:52:59.0871 5396  [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
12:52:59.0899 5396  Dnscache - ok
12:52:59.0914 5396  [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc        C:\Windows\System32\dot3svc.dll
12:52:59.0939 5396  dot3svc - ok
12:52:59.0963 5396  [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS            C:\Windows\system32\dps.dll
12:52:59.0998 5396  DPS - ok
12:53:00.0010 5396  [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
12:53:00.0035 5396  drmkaud - ok
12:53:00.0067 5396  [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
12:53:00.0112 5396  DXGKrnl - ok
12:53:00.0151 5396  [ 6130D06A3D41AC5DC67E9D4513239125 ] e1express      C:\Windows\system32\DRIVERS\e1e6032e.sys
12:53:00.0174 5396  e1express - ok
12:53:00.0190 5396  [ D57FE09B575545738A73A0C193D0616A ] E1G60          C:\Windows\system32\DRIVERS\E1G6032E.sys
12:53:00.0243 5396  E1G60 - ok
12:53:00.0255 5396  [ C2303883FD9BE49DC36A6400643002EA ] EapHost        C:\Windows\System32\eapsvc.dll
12:53:00.0292 5396  EapHost - ok
12:53:00.0308 5396  [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache          C:\Windows\system32\drivers\ecache.sys
12:53:00.0324 5396  Ecache - ok
12:53:00.0359 5396  [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
12:53:00.0394 5396  ehRecvr - ok
12:53:00.0419 5396  [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched        C:\Windows\ehome\ehsched.exe
12:53:00.0448 5396  ehSched - ok
12:53:00.0475 5396  [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart        C:\Windows\ehome\ehstart.dll
12:53:00.0514 5396  ehstart - ok
12:53:00.0553 5396  [ 3D6298AFF3FE06C0616CE5D090A3EEAA ] elxstor        C:\Windows\system32\drivers\elxstor.sys
12:53:00.0578 5396  elxstor - ok
12:53:00.0617 5396  [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
12:53:00.0685 5396  EMDMgmt - ok
12:53:00.0710 5396  [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem    C:\Windows\system32\es.dll
12:53:00.0748 5396  EventSystem - ok
12:53:00.0767 5396  [ 486844F47B6636044A42454614ED4523 ] exfat          C:\Windows\system32\drivers\exfat.sys
12:53:00.0805 5396  exfat - ok
12:53:00.0828 5396  [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
12:53:00.0866 5396  fastfat - ok
12:53:00.0891 5396  [ 989A776A2FF32A148FCF15C44058B129 ] Fax            C:\Windows\system32\fxssvc.exe
12:53:01.0008 5396  Fax - ok
12:53:01.0023 5396  [ 61B6DBD1AD1143F008364D4E9A96B224 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
12:53:01.0073 5396  fdc - ok
12:53:01.0092 5396  [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost        C:\Windows\system32\fdPHost.dll
12:53:01.0133 5396  fdPHost - ok
12:53:01.0148 5396  [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub        C:\Windows\system32\fdrespub.dll
12:53:01.0196 5396  FDResPub - ok
12:53:01.0216 5396  [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
12:53:01.0231 5396  FileInfo - ok
12:53:01.0259 5396  [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
12:53:01.0376 5396  Filetrace - ok
12:53:01.0430 5396  [ 7A7F1D1C598C5C8B21CEAAAB892B9FB8 ] FlipShare Service C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
12:53:01.0452 5396  FlipShare Service - ok
12:53:01.0472 5396  [ 12C3D1B4D0CE49E1CE343BA2F22F15E0 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
12:53:01.0523 5396  flpydisk - ok
12:53:01.0542 5396  [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
12:53:01.0561 5396  FltMgr - ok
12:53:01.0595 5396  [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache      C:\Windows\system32\FntCache.dll
12:53:01.0718 5396  FontCache - ok
12:53:01.0745 5396  [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:53:01.0756 5396  FontCache3.0.0.0 - ok
12:53:01.0770 5396  [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
12:53:01.0801 5396  Fs_Rec - ok
12:53:01.0822 5396  [ 849E38DB7D829962D0233A0A252B60C3 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
12:53:01.0838 5396  fvevol - ok
12:53:01.0856 5396  [ B54520CC7B4B55134D7527B1CD3FC1F2 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
12:53:01.0873 5396  gagp30kx - ok
12:53:01.0894 5396  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
12:53:01.0908 5396  GEARAspiWDM - ok
12:53:01.0934 5396  [ 360FC9E29EBCD7CB75320E2663EBA0F2 ] getPlusHelper  C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll
12:53:01.0943 5396  getPlusHelper - ok
12:53:02.0022 5396  [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc          C:\Windows\System32\gpsvc.dll
12:53:02.0104 5396  gpsvc - ok
12:53:02.0132 5396  [ DF45F8142DC6DF9D18C39B3EFFBD0409 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:53:02.0210 5396  HdAudAddService - ok
12:53:02.0255 5396  [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
12:53:02.0410 5396  HDAudBus - ok
12:53:02.0422 5396  [ B4881C84A180E75B8C25DC1D726C375F ] HidBth          C:\Windows\system32\drivers\hidbth.sys
12:53:02.0485 5396  HidBth - ok
12:53:02.0495 5396  [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr          C:\Windows\system32\drivers\hidir.sys
12:53:02.0544 5396  HidIr - ok
12:53:02.0564 5396  [ 59361D38A297755D46A540E450202B2A ] hidserv        C:\Windows\system32\hidserv.dll
12:53:02.0588 5396  hidserv - ok
12:53:02.0607 5396  [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
12:53:02.0643 5396  HidUsb - ok
12:53:02.0662 5396  [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc          C:\Windows\system32\kmsvc.dll
12:53:02.0696 5396  hkmsvc - ok
12:53:02.0713 5396  [ 8EDC820115DF1E04763B2923676EA5B2 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
12:53:02.0729 5396  HpCISSs - ok
12:53:02.0761 5396  [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
12:53:02.0845 5396  HTTP - ok
12:53:02.0863 5396  [ F2901763845570ECAC48E6A50EC50812 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
12:53:02.0878 5396  i2omp - ok
12:53:02.0903 5396  [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
12:53:02.0943 5396  i8042prt - ok
12:53:02.0959 5396  [ 72C3EE7EA3CD75A772E62AE0E5DF8B8C ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
12:53:02.0981 5396  iaStorV - ok
12:53:03.0031 5396  [ 6F95324909B502E2651442C1548AB12F ] IDriverT        C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
12:53:03.0066 5396  IDriverT ( UnsignedFile.Multi.Generic ) - warning
12:53:03.0066 5396  IDriverT - detected UnsignedFile.Multi.Generic (1)
12:53:03.0103 5396  [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:53:03.0178 5396  idsvc - ok
12:53:03.0245 5396  [ E28602C9E17B0DDCE9F5DEB3B3E2A635 ] IGDCTRL        C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE
12:53:03.0256 5396  IGDCTRL - ok
12:53:03.0267 5396  [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
12:53:03.0284 5396  iirsp - ok
12:53:03.0315 5396  [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT          C:\Windows\System32\ikeext.dll
12:53:03.0378 5396  IKEEXT - ok
12:53:03.0444 5396  [ BC64B75E8E0A0B8982AB773483164E72 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
12:53:03.0547 5396  IntcAzAudAddService - ok
12:53:03.0590 5396  [ 2B6EBA0D1588AA45C505DB4974DFDE9B ] IntelDH64      C:\Windows\system32\Drivers\IntelDH64.sys
12:53:03.0617 5396  IntelDH64 - ok
12:53:03.0638 5396  [ D61A91BC967937EC9CA81632BC12593E ] intelide        C:\Windows\system32\drivers\intelide.sys
12:53:03.0654 5396  intelide - ok
12:53:03.0674 5396  [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
12:53:03.0706 5396  intelppm - ok
12:53:03.0725 5396  [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
12:53:03.0758 5396  IPBusEnum - ok
12:53:03.0774 5396  [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:53:03.0816 5396  IpFilterDriver - ok
12:53:03.0833 5396  [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
12:53:03.0877 5396  iphlpsvc - ok
12:53:03.0881 5396  IpInIp - ok
12:53:03.0897 5396  [ EACDBBE429C6D170BDEEE0EFFCBC317B ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
12:53:03.0950 5396  IPMIDRV - ok
12:53:03.0962 5396  [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
12:53:04.0004 5396  IPNAT - ok
12:53:04.0048 5396  [ 46D249F9DB7844CC01050A9345F0F61B ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
12:53:04.0119 5396  iPod Service - ok
12:53:04.0167 5396  [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
12:53:04.0201 5396  IRENUM - ok
12:53:04.0215 5396  [ D3BB520B31F28C1A065CD058E762EE73 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
12:53:04.0230 5396  isapnp - ok
12:53:04.0252 5396  [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
12:53:04.0269 5396  iScsiPrt - ok
12:53:04.0279 5396  [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
12:53:04.0295 5396  iteatapi - ok
12:53:04.0305 5396  [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid        C:\Windows\system32\drivers\iteraid.sys
12:53:04.0340 5396  iteraid - ok
12:53:04.0370 5396  [ 423696F3BA6472DD17699209B933BC26 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
12:53:04.0387 5396  kbdclass - ok
12:53:04.0408 5396  [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
12:53:04.0439 5396  kbdhid - ok
12:53:04.0472 5396  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso          C:\Windows\system32\lsass.exe
12:53:04.0518 5396  KeyIso - ok
12:53:04.0556 5396  [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
12:53:04.0598 5396  KSecDD - ok
12:53:04.0653 5396  [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
12:53:04.0695 5396  ksthunk - ok
12:53:04.0734 5396  [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm          C:\Windows\system32\msdtckrm.dll
12:53:04.0794 5396  KtmRm - ok
12:53:04.0821 5396  [ BBD9BBED0DE036B2297E6434B26D1AE9 ] L8042Kbd        C:\Windows\system32\DRIVERS\L8042Kbd.sys
12:53:04.0835 5396  L8042Kbd - ok
12:53:04.0858 5396  [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer    C:\Windows\system32\srvsvc.dll
12:53:04.0895 5396  LanmanServer - ok
12:53:04.0924 5396  [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:53:04.0960 5396  LanmanWorkstation - ok
12:53:05.0005 5396  [ 4D25A79A9F67A7E2D8D5382E75FCB124 ] LBTServ        C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
12:53:05.0015 5396  LBTServ - ok
12:53:05.0033 5396  [ AA3D903C5A7538803F2400A8391F1881 ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
12:53:05.0047 5396  LHidFilt - ok
12:53:05.0072 5396  [ 156AB2E56DC3CA0B582E3362E07CDED7 ] lirsgt          C:\Windows\system32\DRIVERS\lirsgt.sys
12:53:05.0087 5396  lirsgt - ok
12:53:05.0097 5396  [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
12:53:05.0141 5396  lltdio - ok
12:53:05.0157 5396  [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
12:53:05.0210 5396  lltdsvc - ok
12:53:05.0220 5396  [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts        C:\Windows\System32\lmhsvc.dll
12:53:05.0253 5396  lmhosts - ok
12:53:05.0265 5396  [ 90B4B2B0B5F05ABB9FB365405A7B825B ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
12:53:05.0280 5396  LMouFilt - ok
12:53:05.0295 5396  [ 1572F8D999C0AB4376AFDCE058A78DF9 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
12:53:05.0312 5396  LSI_FC - ok
12:53:05.0321 5396  [ 64470979C3E3C9FF60EDFB5230C56E0E ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
12:53:05.0338 5396  LSI_SAS - ok
12:53:05.0350 5396  [ 4CED7D3B54BFC5BBAE75C4A73C7F7428 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
12:53:05.0368 5396  LSI_SCSI - ok
12:53:05.0389 5396  [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv          C:\Windows\system32\drivers\luafv.sys
12:53:05.0426 5396  luafv - ok
12:53:05.0446 5396  [ 4EB7886F6223F68CA855730A96D6110C ] LUsbFilt        C:\Windows\system32\Drivers\LUsbFilt.Sys
12:53:05.0461 5396  LUsbFilt - ok
12:53:05.0493 5396  [ 86504FE0759D4DCE38E997921062DF6B ] MagicTuneEngine C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe
12:53:05.0514 5396  MagicTuneEngine ( UnsignedFile.Multi.Generic ) - warning
12:53:05.0514 5396  MagicTuneEngine - detected UnsignedFile.Multi.Generic (1)
12:53:05.0531 5396  [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
12:53:05.0543 5396  MBAMProtector - ok
12:53:05.0561 5396  [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
12:53:05.0601 5396  MBAMScheduler - ok
12:53:05.0653 5396  [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
12:53:05.0705 5396  MBAMService - ok
12:53:05.0734 5396  [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
12:53:05.0772 5396  Mcx2Svc - ok
12:53:05.0788 5396  [ 2F631C2939D5F2E8958935EE701D70D7 ] megasas        C:\Windows\system32\drivers\megasas.sys
12:53:05.0804 5396  megasas - ok
12:53:05.0853 5396  [ FAFE367D032ED82E9332B4C741A20216 ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
12:53:05.0885 5396  Microsoft Office Groove Audit Service - ok
12:53:05.0912 5396  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS          C:\Windows\system32\mmcss.dll
12:53:05.0953 5396  MMCSS - ok
12:53:05.0963 5396  [ 59848D5CC74606F0EE7557983BB73C2E ] Modem          C:\Windows\system32\drivers\modem.sys
12:53:05.0998 5396  Modem - ok
12:53:06.0024 5396  [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
12:53:06.0065 5396  monitor - ok
12:53:06.0069 5396  motccgp - ok
12:53:06.0072 5396  motccgpfl - ok
12:53:06.0077 5396  motmodem - ok
12:53:06.0080 5396  MotoSwitchService - ok
12:53:06.0084 5396  Motousbnet - ok
12:53:06.0087 5396  motusbdevice - ok
12:53:06.0109 5396  [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
12:53:06.0126 5396  mouclass - ok
12:53:06.0135 5396  [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
12:53:06.0178 5396  mouhid - ok
12:53:06.0193 5396  [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
12:53:06.0206 5396  MountMgr - ok
12:53:06.0224 5396  [ ED48EAC719EE28DB773359EB1B06E2B5 ] mpio            C:\Windows\system32\drivers\mpio.sys
12:53:06.0258 5396  mpio - ok
12:53:06.0285 5396  [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
12:53:06.0318 5396  mpsdrv - ok
12:53:06.0343 5396  [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc          C:\Windows\system32\mpssvc.dll
12:53:06.0401 5396  MpsSvc - ok
12:53:06.0412 5396  [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
12:53:06.0428 5396  Mraid35x - ok
12:53:06.0441 5396  [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
12:53:06.0463 5396  MRxDAV - ok
12:53:06.0485 5396  [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
12:53:06.0519 5396  mrxsmb - ok
12:53:06.0550 5396  [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:53:06.0568 5396  mrxsmb10 - ok
12:53:06.0582 5396  [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:53:06.0604 5396  mrxsmb20 - ok
12:53:06.0615 5396  [ AA459F2AB3AB603C357FF117CAE3D818 ] msahci          C:\Windows\system32\drivers\msahci.sys
12:53:06.0628 5396  msahci - ok
12:53:06.0637 5396  [ 96D7C0A1B98434C6E4FF0C2E26A0E20A ] msdsm          C:\Windows\system32\drivers\msdsm.sys
12:53:06.0655 5396  msdsm - ok
12:53:06.0686 5396  [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC          C:\Windows\System32\msdtc.exe
12:53:06.0725 5396  MSDTC - ok
12:53:06.0732 5396  [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs            C:\Windows\system32\drivers\Msfs.sys
12:53:06.0764 5396  Msfs - ok
12:53:06.0785 5396  [ 00EBC952961664780D43DCA157E79B27 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
12:53:06.0796 5396  msisadrv - ok
12:53:06.0808 5396  [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
12:53:06.0847 5396  MSiSCSI - ok
12:53:06.0850 5396  msiserver - ok
12:53:06.0862 5396  [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
12:53:06.0900 5396  MSKSSRV - ok
12:53:06.0910 5396  [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
12:53:06.0944 5396  MSPCLOCK - ok
12:53:06.0956 5396  [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
12:53:06.0988 5396  MSPQM - ok
12:53:07.0012 5396  [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
12:53:07.0032 5396  MsRPC - ok
12:53:07.0048 5396  [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
12:53:07.0061 5396  mssmbios - ok
12:53:07.0077 5396  [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
12:53:07.0117 5396  MSTEE - ok
12:53:07.0142 5396  [ 0CC49F78D8ACA0877D885F149084E543 ] Mup            C:\Windows\system32\Drivers\mup.sys
12:53:07.0155 5396  Mup - ok
12:53:07.0181 5396  [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent        C:\Windows\system32\qagentRT.dll
12:53:07.0215 5396  napagent - ok
12:53:07.0234 5396  [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
12:53:07.0258 5396  NativeWifiP - ok
12:53:07.0279 5396  [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS            C:\Windows\system32\drivers\ndis.sys
12:53:07.0340 5396  NDIS - ok
12:53:07.0361 5396  [ 64DF698A425478E321981431AC171334 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
12:53:07.0427 5396  NdisTapi - ok
12:53:07.0442 5396  [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
12:53:07.0487 5396  Ndisuio - ok
12:53:07.0507 5396  [ F8158771905260982CE724076419EF19 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
12:53:07.0545 5396  NdisWan - ok
12:53:07.0557 5396  [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
12:53:07.0584 5396  NDProxy - ok
12:53:07.0638 5396  [ 27FE4B70C12A2C67A58D799B9A4E8D81 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
12:53:07.0699 5396  Nero BackItUp Scheduler 4.0 - ok
12:53:07.0739 5396  [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
12:53:07.0770 5396  NetBIOS - ok
12:53:07.0784 5396  [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
12:53:07.0819 5396  netbt - ok
12:53:07.0828 5396  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon        C:\Windows\system32\lsass.exe
12:53:07.0840 5396  Netlogon - ok
12:53:07.0862 5396  [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman          C:\Windows\System32\netman.dll
12:53:07.0918 5396  Netman - ok
12:53:07.0942 5396  [ 7846D0136CC2B264926A73047BA7688A ] netprofm        C:\Windows\System32\netprofm.dll
12:53:07.0987 5396  netprofm - ok
12:53:08.0017 5396  [ 74751DDA198165947FD7454D83F49825 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:53:08.0053 5396  NetTcpPortSharing - ok
12:53:08.0069 5396  [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
12:53:08.0089 5396  nfrd960 - ok
12:53:08.0110 5396  [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc          C:\Windows\System32\nlasvc.dll
12:53:08.0147 5396  NlaSvc - ok
12:53:08.0166 5396  [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
12:53:08.0191 5396  Npfs - ok
12:53:08.0196 5396  [ ACB62BAA1C319B17752553DF3026EEEB ] nsi            C:\Windows\system32\nsisvc.dll
12:53:08.0238 5396  nsi - ok
12:53:08.0251 5396  [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
12:53:08.0286 5396  nsiproxy - ok
12:53:08.0321 5396  [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
12:53:08.0382 5396  Ntfs - ok
12:53:08.0417 5396  [ DD5D684975352B85B52E3FD5347C20CB ] Null            C:\Windows\system32\drivers\Null.sys
12:53:08.0456 5396  Null - ok
12:53:08.0768 5396  [ 9C1996DD3C0469BC8933321F15709F5A ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
12:53:09.0534 5396  nvlddmkm - ok
12:53:09.0548 5396  [ 840EEB44DC49317A6161961F7682CD99 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
12:53:09.0566 5396  nvraid - ok
12:53:09.0576 5396  [ 94C5334040A5D500897F4C5FD12AEEDE ] nvstor          C:\Windows\system32\drivers\nvstor.sys
12:53:09.0593 5396  nvstor - ok
12:53:09.0633 5396  [ 2D7092FEC9BD2ACA199673BBA2BA9277 ] nvsvc          C:\Windows\system32\nvvsvc.exe
12:53:09.0719 5396  nvsvc - ok
12:53:09.0821 5396  [ 7E22DE30E222BFDFCEC7E77032BAF3CD ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
12:53:09.0905 5396  nvUpdatusService - ok
12:53:09.0936 5396  [ AA1B6C86A4763502E20B65C025F39BAD ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
12:53:09.0955 5396  nv_agp - ok
12:53:09.0959 5396  NwlnkFlt - ok
12:53:09.0963 5396  NwlnkFwd - ok
12:53:10.0014 5396  [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
12:53:10.0064 5396  odserv - ok
12:53:10.0092 5396  [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
12:53:10.0129 5396  ohci1394 - ok
12:53:10.0159 5396  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:53:10.0197 5396  ose - ok
12:53:10.0238 5396  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc        C:\Windows\system32\p2psvc.dll
12:53:10.0287 5396  p2pimsvc - ok
12:53:10.0321 5396  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc          C:\Windows\system32\p2psvc.dll
12:53:10.0358 5396  p2psvc - ok
12:53:10.0411 5396  [ AECD57F94C887F58919F307C35498EA0 ] Parport        C:\Windows\system32\drivers\parport.sys
12:53:10.0470 5396  Parport - ok
12:53:10.0485 5396  [ B43751085E2ABE389DA466BC62A4B987 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
12:53:10.0499 5396  partmgr - ok
12:53:10.0516 5396  [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc          C:\Windows\System32\pcasvc.dll
12:53:10.0562 5396  PcaSvc - ok
12:53:10.0578 5396  [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
12:53:10.0609 5396  pccsmcfd - ok
12:53:10.0621 5396  [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci            C:\Windows\system32\drivers\pci.sys
12:53:10.0638 5396  pci - ok
12:53:10.0644 5396  [ 2657F6C0B78C36D95034BE109336E382 ] pciide          C:\Windows\system32\drivers\pciide.sys
12:53:10.0656 5396  pciide - ok
12:53:10.0686 5396  [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
12:53:10.0709 5396  pcmcia - ok
12:53:10.0732 5396  [ 58865916F53592A61549B04941BFD80D ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
12:53:10.0825 5396  PEAUTH - ok
12:53:10.0866 5396  [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
12:53:10.0896 5396  PerfHost - ok
12:53:10.0940 5396  [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla            C:\Windows\system32\pla.dll
12:53:11.0006 5396  pla - ok
12:53:11.0035 5396  [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
12:53:11.0073 5396  PlugPlay - ok
12:53:11.0104 5396  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
12:53:11.0147 5396  PNRPAutoReg - ok
12:53:11.0204 5396  [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc        C:\Windows\system32\p2psvc.dll
12:53:11.0228 5396  PNRPsvc - ok
12:53:11.0276 5396  [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
12:53:11.0331 5396  PolicyAgent - ok
12:53:11.0359 5396  [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
12:53:11.0388 5396  PptpMiniport - ok
12:53:11.0402 5396  [ 6BC78E5F12CBB74E7930AAAA4A0DB387 ] Processor      C:\Windows\system32\drivers\processr.sys
12:53:11.0469 5396  Processor - ok
12:53:11.0565 5396  [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc        C:\Windows\system32\profsvc.dll
12:53:11.0607 5396  ProfSvc - ok
12:53:11.0618 5396  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
12:53:11.0645 5396  ProtectedStorage - ok
12:53:11.0660 5396  [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
12:53:11.0684 5396  PSched - ok
12:53:11.0704 5396  [ 543A4EF0923BF70D126625B034EF25AF ] PSI_SVC_2      c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
12:53:11.0717 5396  PSI_SVC_2 - ok
12:53:11.0742 5396  [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64        C:\Windows\system32\Drivers\PxHlpa64.sys
12:53:11.0752 5396  PxHlpa64 - ok
12:53:11.0787 5396  [ 4A29D25704917161BAD9B4659A248DFD ] ql2300          C:\Windows\system32\drivers\ql2300.sys
12:53:11.0852 5396  ql2300 - ok
12:53:11.0874 5396  [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
12:53:11.0893 5396  ql40xx - ok
12:53:11.0918 5396  [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE          C:\Windows\system32\qwave.dll
12:53:11.0937 5396  QWAVE - ok
12:53:11.0947 5396  [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
12:53:11.0974 5396  QWAVEdrv - ok
12:53:12.0008 5396  [ ED4E69C31EF566266BE13638EBE9DA56 ] RapiMgr        C:\Windows\WindowsMobile\rapimgr.dll
12:53:12.0040 5396  RapiMgr - ok
12:53:12.0051 5396  [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
12:53:12.0085 5396  RasAcd - ok
12:53:12.0110 5396  [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto        C:\Windows\System32\rasauto.dll
12:53:12.0150 5396  RasAuto - ok
12:53:12.0177 5396  [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
12:53:12.0207 5396  Rasl2tp - ok
12:53:12.0228 5396  [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan          C:\Windows\System32\rasmans.dll
12:53:12.0258 5396  RasMan - ok
12:53:12.0274 5396  [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
12:53:12.0310 5396  RasPppoe - ok
12:53:12.0324 5396  [ C6A593B51F34C33E5474539544072527 ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
12:53:12.0355 5396  RasSstp - ok
12:53:12.0363 5396  [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
12:53:12.0393 5396  rdbss - ok
12:53:12.0404 5396  [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
12:53:12.0438 5396  RDPCDD - ok
12:53:12.0468 5396  [ AE23E79B13FEB62939E2CA1189E71735 ] rdpdr          C:\Windows\system32\DRIVERS\rdpdr.sys
12:53:12.0511 5396  rdpdr - ok
12:53:12.0524 5396  [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
12:53:12.0557 5396  RDPENCDD - ok
12:53:12.0583 5396  [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
12:53:12.0613 5396  RDPWD - ok
12:53:12.0634 5396  [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess    C:\Windows\System32\mprdim.dll
12:53:12.0667 5396  RemoteAccess - ok
12:53:12.0681 5396  [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
12:53:12.0721 5396  RemoteRegistry - ok
12:53:12.0741 5396  [ CD71E053D7260E4102D99A28F9196070 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
12:53:12.0781 5396  RFCOMM - ok
12:53:12.0797 5396  [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator      C:\Windows\system32\locator.exe
12:53:12.0821 5396  RpcLocator - ok
12:53:12.0840 5396  [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs          C:\Windows\system32\rpcss.dll
12:53:12.0886 5396  RpcSs - ok
12:53:12.0916 5396  [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
12:53:12.0953 5396  rspndr - ok
12:53:12.0972 5396  [ 3DA2CCA7206DB8D4CE234177A97A1B62 ] SaiMini        C:\Windows\system32\DRIVERS\SaiMini.sys
12:53:13.0003 5396  SaiMini - ok
12:53:13.0025 5396  [ 7DF4B3E55FF2540111E7E7AD3656A7C5 ] SaiNtBus        C:\Windows\system32\drivers\SaiBus.sys
12:53:13.0058 5396  SaiNtBus - ok
12:53:13.0084 5396  [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs          C:\Windows\system32\lsass.exe
12:53:13.0096 5396  SamSs - ok
12:53:13.0115 5396  [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
12:53:13.0134 5396  sbp2port - ok
12:53:13.0146 5396  [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr        C:\Windows\System32\SCardSvr.dll
12:53:13.0175 5396  SCardSvr - ok
12:53:13.0205 5396  [ 0F838C811AD295D2A4489B9993096C63 ] Schedule        C:\Windows\system32\schedsvc.dll
12:53:13.0295 5396  Schedule - ok
12:53:13.0315 5396  [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc    C:\Windows\System32\certprop.dll
12:53:13.0338 5396  SCPolicySvc - ok
12:53:13.0358 5396  [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
12:53:13.0387 5396  SDRSVC - ok
12:53:13.0402 5396  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
12:53:13.0453 5396  secdrv - ok
12:53:13.0466 5396  [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon        C:\Windows\system32\seclogon.dll
12:53:13.0509 5396  seclogon - ok
12:53:13.0524 5396  [ 90973A64B96CD647FF81C79443618EED ] SENS            C:\Windows\System32\sens.dll
12:53:13.0561 5396  SENS - ok
12:53:13.0578 5396  [ 2449316316411D65BD2C761A6FFB2CE2 ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
12:53:13.0623 5396  Serenum - ok
12:53:13.0637 5396  [ 4B438170BE2FC8E0BD35EE87A960F84F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
12:53:13.0683 5396  Serial - ok
12:53:13.0703 5396  [ A842F04833684BCEEA7336211BE478DF ] sermouse        C:\Windows\system32\drivers\sermouse.sys
12:53:13.0744 5396  sermouse - ok
12:53:13.0760 5396  [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv      C:\Windows\system32\sessenv.dll
12:53:13.0801 5396  SessionEnv - ok
12:53:13.0821 5396  [ 18C056B109DA7CD823BFAE223818EB2E ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
12:53:13.0845 5396  sffdisk - ok
12:53:13.0859 5396  [ B387781EA1A47BBE08A6E4CBD82F9790 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
12:53:13.0884 5396  sffp_mmc - ok
12:53:13.0896 5396  [ 4E6B82359DFBD84E914B4D01256EF3BF ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
12:53:13.0911 5396  sffp_sd - ok
12:53:13.0921 5396  [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
12:53:13.0971 5396  sfloppy - ok
12:53:13.0987 5396  [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
12:53:14.0030 5396  SharedAccess - ok
12:53:14.0072 5396  [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:53:14.0143 5396  ShellHWDetection - ok
12:53:14.0169 5396  [ 08DDA16573FA44F8B13AFE74597AD2E5 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
12:53:14.0186 5396  SiSRaid2 - ok
12:53:14.0196 5396  [ C52259E9DAAF3890D572D87FFEE0979E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
12:53:14.0212 5396  SiSRaid4 - ok
12:53:14.0275 5396  [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc          C:\Windows\system32\SLsvc.exe
12:53:14.0380 5396  slsvc - ok
12:53:14.0422 5396  [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify      C:\Windows\system32\SLUINotify.dll
12:53:14.0452 5396  SLUINotify - ok
12:53:14.0469 5396  [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
12:53:14.0513 5396  Smb - ok
12:53:14.0532 5396  [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
12:53:14.0555 5396  SNMPTRAP - ok
12:53:14.0572 5396  [ 386C3C63F00A7040C7EC5E384217E89D ] spldr          C:\Windows\system32\drivers\spldr.sys
12:53:14.0585 5396  spldr - ok
12:53:14.0612 5396  [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler        C:\Windows\System32\spoolsv.exe
12:53:14.0643 5396  Spooler - ok
12:53:14.0685 5396  [ 9AB59CF736981ED1F83C6AB5FAA8BA5C ] sptd            C:\Windows\System32\Drivers\sptd.sys
12:53:14.0743 5396  sptd - ok
12:53:14.0789 5396  [ 880A57FCCB571EBD063D4DD50E93E46D ] srv            C:\Windows\system32\DRIVERS\srv.sys
12:53:14.0849 5396  srv - ok
12:53:14.0870 5396  [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
12:53:14.0926 5396  srv2 - ok
12:53:14.0955 5396  [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
12:53:14.0971 5396  srvnet - ok
12:53:14.0988 5396  [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
12:53:15.0033 5396  SSDPSRV - ok
12:53:15.0044 5396  [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc        C:\Windows\system32\sstpsvc.dll
12:53:15.0068 5396  SstpSvc - ok
12:53:15.0081 5396  Steam Client Service - ok
12:53:15.0097 5396  [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc          C:\Windows\System32\wiaservc.dll
12:53:15.0139 5396  stisvc - ok
12:53:15.0182 5396  [ D2FBE517D8FE03552E9C6CF91C1540D2 ] StkCMini        C:\Windows\system32\Drivers\StkCMini.sys
12:53:15.0273 5396  StkCMini ( UnsignedFile.Multi.Generic ) - warning
12:53:15.0273 5396  StkCMini - detected UnsignedFile.Multi.Generic (1)
12:53:15.0283 5396  [ 0E447EF3CC90B32BA478093B998C48FD ] StkSSrv        C:\Windows\System32\StkCSrv.exe
12:53:15.0291 5396  StkSSrv ( UnsignedFile.Multi.Generic ) - warning
12:53:15.0291 5396  StkSSrv - detected UnsignedFile.Multi.Generic (1)
12:53:15.0312 5396  [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
12:53:15.0327 5396  swenum - ok
12:53:15.0366 5396  [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard    C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
12:53:15.0385 5396  SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
12:53:15.0385 5396  SwitchBoard - detected UnsignedFile.Multi.Generic (1)
12:53:15.0410 5396  [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv          C:\Windows\System32\swprv.dll
12:53:15.0462 5396  swprv - ok
12:53:15.0488 5396  [ E4154C5CE666B713DE9398C053D8FB7E ] sxuptp          C:\Windows\system32\DRIVERS\sxuptp.sys
12:53:15.0515 5396  sxuptp - ok
12:53:15.0527 5396  [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
12:53:15.0544 5396  Symc8xx - ok
12:53:15.0550 5396  [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
12:53:15.0566 5396  Sym_hi - ok
12:53:15.0582 5396  [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
12:53:15.0599 5396  Sym_u3 - ok
12:53:15.0626 5396  [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain        C:\Windows\system32\sysmain.dll
12:53:15.0690 5396  SysMain - ok
12:53:15.0727 5396  [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:53:15.0754 5396  TabletInputService - ok
12:53:15.0783 5396  [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv        C:\Windows\System32\tapisrv.dll
12:53:15.0824 5396  TapiSrv - ok
12:53:15.0833 5396  [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS            C:\Windows\System32\tbssvc.dll
12:53:15.0866 5396  TBS - ok
12:53:15.0899 5396  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
12:53:15.0958 5396  Tcpip - ok
12:53:15.0991 5396  [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
12:53:16.0038 5396  Tcpip6 - ok
12:53:16.0074 5396  [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
12:53:16.0112 5396  tcpipreg - ok
12:53:16.0131 5396  [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
12:53:16.0165 5396  TDPIPE - ok
12:53:16.0189 5396  [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
12:53:16.0223 5396  TDTCP - ok
12:53:16.0233 5396  [ 458919C8C42E398DC4802178D5FFEE27 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
12:53:16.0277 5396  tdx - ok
12:53:16.0293 5396  [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
12:53:16.0311 5396  TermDD - ok
12:53:16.0331 5396  [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService    C:\Windows\System32\termsrv.dll
12:53:16.0379 5396  TermService - ok
12:53:16.0404 5396  [ 56793271ECDEDD350C5ADD305603E963 ] Themes          C:\Windows\system32\shsvcs.dll
12:53:16.0420 5396  Themes - ok
12:53:16.0431 5396  [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER    C:\Windows\system32\mmcss.dll
12:53:16.0463 5396  THREADORDER - ok
12:53:16.0477 5396  [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks          C:\Windows\System32\trkwks.dll
12:53:16.0512 5396  TrkWks - ok
12:53:16.0536 5396  [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:53:16.0565 5396  TrustedInstaller - ok
12:53:16.0575 5396  [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
12:53:16.0609 5396  tssecsrv - ok
12:53:16.0674 5396  [ C7935E1E4025CDD62F9806CAEEF86086 ] TuneUp.UtilitiesSvc C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
12:53:16.0726 5396  TuneUp.UtilitiesSvc - ok
12:53:16.0767 5396  [ DCC94C51D27C7EC0DADECA8F64C94FCF ] TuneUpUtilitiesDrv C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys
12:53:16.0779 5396  TuneUpUtilitiesDrv - ok
12:53:16.0790 5396  [ 89EC74A9E602D16A75A4170511029B3C ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
12:53:16.0807 5396  tunmp - ok
12:53:16.0829 5396  [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
12:53:16.0845 5396  tunnel - ok
12:53:16.0884 5396  [ 1A006963644C7FDE5BE60036F3A43E68 ] TVICHW64        C:\Windows\SysWOW64\Drivers\TVICHW64.SYS
12:53:16.0898 5396  TVICHW64 - ok
12:53:16.0922 5396  [ E4722DFBD6232ACF17543EF2C2DCE8D2 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
12:53:16.0939 5396  uagp35 - ok
12:53:16.0969 5396  [ FAF2640A2A76ED03D449E443194C4C34 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
12:53:17.0014 5396  udfs - ok
12:53:17.0028 5396  [ 060507C4113391394478F6953A79EEDC ] UI0Detect      C:\Windows\system32\UI0Detect.exe
12:53:17.0067 5396  UI0Detect - ok
12:53:17.0084 5396  [ 5663D7696ABBE71F8C9D915C5374118A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
12:53:17.0102 5396  uliagpkx - ok
12:53:17.0118 5396  [ 6030B68E86A30D1B315B51C4D7778B16 ] uliahci        C:\Windows\system32\drivers\uliahci.sys
12:53:17.0141 5396  uliahci - ok
12:53:17.0157 5396  [ 31707F09846056651EA2C37858F5DDB0 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
12:53:17.0176 5396  UlSata - ok
12:53:17.0192 5396  [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
12:53:17.0213 5396  ulsata2 - ok
12:53:17.0238 5396  [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
12:53:17.0273 5396  umbus - ok
12:53:17.0289 5396  [ 01ABE05C401E70795B43A8933B44831E ] UMPass          C:\Windows\system32\DRIVERS\umpass.sys
12:53:17.0323 5396  UMPass - ok
12:53:17.0337 5396  [ DC5E34F189B827199B9CC8481C648269 ] UmRdpService    C:\Windows\System32\umrdp.dll
12:53:17.0371 5396  UmRdpService - ok
12:53:17.0392 5396  [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost        C:\Windows\System32\upnphost.dll
12:53:17.0469 5396  upnphost - ok
12:53:17.0473 5396  upperdev - ok
12:53:17.0507 5396  [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64      C:\Windows\system32\Drivers\usbaapl64.sys
12:53:17.0536 5396  USBAAPL64 - ok
12:53:17.0557 5396  [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
12:53:17.0596 5396  usbaudio - ok
12:53:17.0622 5396  [ 07E3498FC60834219D2356293DA0FECC ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
12:53:17.0656 5396  usbccgp - ok
12:53:17.0691 5396  [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
12:53:17.0761 5396  usbcir - ok
12:53:17.0782 5396  [ 827E44DE934A736EA31E91D353EB126F ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
12:53:17.0809 5396  usbehci - ok
12:53:17.0839 5396  [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
12:53:17.0881 5396  usbhub - ok
12:53:17.0897 5396  [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
12:53:17.0960 5396  usbohci - ok
12:53:17.0977 5396  [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
12:53:18.0012 5396  usbprint - ok
12:53:18.0039 5396  [ F7386007FB19E7685FC7B298560AA81F ] usbser          C:\Windows\system32\drivers\usbser.sys
12:53:18.0065 5396  usbser - ok
12:53:18.0069 5396  UsbserFilt - ok
12:53:18.0084 5396  [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:53:18.0114 5396  USBSTOR - ok
12:53:18.0128 5396  [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
12:53:18.0159 5396  usbuhci - ok
12:53:18.0171 5396  [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms          C:\Windows\System32\uxsms.dll
12:53:18.0197 5396  UxSms - ok
12:53:18.0212 5396  [ 294945381DFA7CE58CECF0A9896AF327 ] vds            C:\Windows\System32\vds.exe
12:53:18.0246 5396  vds - ok
12:53:18.0262 5396  [ 2998DC48905E9B4821AD8FD75B3E070C ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
12:53:18.0312 5396  vga - ok
12:53:18.0324 5396  [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave        C:\Windows\System32\drivers\vga.sys
12:53:18.0366 5396  VgaSave - ok
12:53:18.0383 5396  [ 9978DA36FF889A28B590E74BF11B4764 ] viaide          C:\Windows\system32\drivers\viaide.sys
12:53:18.0399 5396  viaide - ok
12:53:18.0417 5396  [ 2B7E885ED951519A12C450D24535DFCA ] volmgr          C:\Windows\system32\drivers\volmgr.sys
12:53:18.0431 5396  volmgr - ok
12:53:18.0453 5396  [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
12:53:18.0476 5396  volmgrx - ok
12:53:18.0508 5396  [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap        C:\Windows\system32\drivers\volsnap.sys
12:53:18.0527 5396  volsnap - ok
12:53:18.0543 5396  [ 410AE2C141142C58BC617FC2C677F8B0 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
12:53:18.0561 5396  vsmraid - ok
12:53:18.0593 5396  [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS            C:\Windows\system32\vssvc.exe
12:53:18.0680 5396  VSS - ok
12:53:18.0705 5396  [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time        C:\Windows\system32\w32time.dll
12:53:18.0767 5396  W32Time - ok
12:53:18.0799 5396  [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
12:53:18.0855 5396  WacomPen - ok
12:53:18.0868 5396  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
12:53:18.0909 5396  Wanarp - ok
12:53:18.0913 5396  [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
12:53:18.0935 5396  Wanarpv6 - ok
12:53:18.0968 5396  [ 48EEE289DF9E4989128B2283F3EEACC6 ] wbengine        C:\Windows\system32\wbengine.exe
12:53:19.0031 5396  wbengine - ok
12:53:19.0078 5396  [ 382A7B0B632EC98DE5F0658DA9DE6159 ] WcesComm        C:\Windows\WindowsMobile\wcescomm.dll
12:53:19.0119 5396  WcesComm - ok
12:53:19.0144 5396  [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
12:53:19.0178 5396  wcncsvc - ok
12:53:19.0214 5396  [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:53:19.0243 5396  WcsPlugInService - ok
12:53:19.0255 5396  [ 59B501B0A04C9672142B7FFA2BDBF663 ] Wd              C:\Windows\system32\drivers\wd.sys
12:53:19.0270 5396  Wd - ok
12:53:19.0299 5396  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
12:53:19.0336 5396  Wdf01000 - ok
12:53:19.0364 5396  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost  C:\Windows\system32\wdi.dll
12:53:19.0402 5396  WdiServiceHost - ok
12:53:19.0405 5396  [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost  C:\Windows\system32\wdi.dll
12:53:19.0437 5396  WdiSystemHost - ok
12:53:19.0459 5396  [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient      C:\Windows\System32\webclnt.dll
12:53:19.0479 5396  WebClient - ok
12:53:19.0483 5396  WEBNTACCESS - ok
12:53:19.0502 5396  [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc          C:\Windows\system32\wecsvc.dll
12:53:19.0541 5396  Wecsvc - ok
12:53:19.0556 5396  [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
12:53:19.0581 5396  wercplsupport - ok
12:53:19.0589 5396  [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc          C:\Windows\System32\WerSvc.dll
12:53:19.0616 5396  WerSvc - ok
12:53:19.0632 5396  WinDefend - ok
12:53:19.0637 5396  WinHttpAutoProxySvc - ok
12:53:19.0670 5396  [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
12:53:19.0696 5396  Winmgmt - ok
12:53:19.0746 5396  [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM          C:\Windows\system32\WsmSvc.dll
12:53:19.0859 5396  WinRM - ok
12:53:19.0883 5396  [ 7F2F9E48566B2087F2AAAD258CB2A8D4 ] winusb          C:\Windows\system32\DRIVERS\winusb.sys
12:53:19.0912 5396  winusb - ok
12:53:19.0941 5396  [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc        C:\Windows\System32\wlansvc.dll
12:53:19.0989 5396  Wlansvc - ok
12:53:20.0004 5396  [ AE34218455D5DC12D1E45DE85F160346 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
12:53:20.0053 5396  WmiAcpi - ok
12:53:20.0069 5396  [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
12:53:20.0108 5396  wmiApSrv - ok
12:53:20.0114 5396  WMPNetworkSvc - ok
12:53:20.0127 5396  [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
12:53:20.0163 5396  WPCSvc - ok
12:53:20.0178 5396  [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
12:53:20.0204 5396  WPDBusEnum - ok
12:53:20.0230 5396  [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
12:53:20.0248 5396  WpdUsb - ok
12:53:20.0321 5396  [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:53:20.0381 5396  WPFFontCache_v0400 - ok
12:53:20.0431 5396  [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
12:53:20.0470 5396  ws2ifsl - ok
12:53:20.0487 5396  [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc          C:\Windows\System32\wscsvc.dll
12:53:20.0512 5396  wscsvc - ok
12:53:20.0515 5396  WSearch - ok
12:53:20.0576 5396  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
12:53:20.0669 5396  wuauserv - ok
12:53:20.0711 5396  [ 7CADC74271DD6461C452C271B30BD378 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
12:53:20.0737 5396  WudfPf - ok
12:53:20.0757 5396  [ 3B197AF0FFF08AA66B6B2241CA538D64 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
12:53:20.0779 5396  WUDFRd - ok
12:53:20.0791 5396  [ 3DCC7BF5AFA921B479E622BD999121F3 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
12:53:20.0815 5396  wudfsvc - ok
12:53:20.0836 5396  [ EC760BEE30B167A04A246C29F1A8E120 ] X10Hid          C:\Windows\system32\Drivers\x10hid.sys
12:53:20.0850 5396  X10Hid - ok
12:53:20.0875 5396  [ 5A0C788C5BC5F2C993CB60940ADCF95E ] x10nets        C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe
12:53:20.0885 5396  x10nets ( UnsignedFile.Multi.Generic ) - warning
12:53:20.0885 5396  x10nets - detected UnsignedFile.Multi.Generic (1)
12:53:20.0908 5396  [ 6533F30045B0A234783BD8B4069F0433 ] XUIF            C:\Windows\system32\Drivers\x10ufx2.sys
12:53:20.0918 5396  XUIF - ok
12:53:20.0928 5396  ================ Scan global ===============================
12:53:20.0957 5396  [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
12:53:20.0980 5396  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
12:53:20.0997 5396  [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
12:53:21.0023 5396  [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe
12:53:21.0030 5396  [Global] - ok
12:53:21.0031 5396  ================ Scan MBR ==================================
12:53:21.0033 5396  [ DD46BDBDC677798D42CCB057D4BDFC92 ] \Device\Harddisk0\DR0
12:53:21.0247 5396  \Device\Harddisk0\DR0 - ok
12:53:21.0259 5396  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk1\DR1
12:53:21.0508 5396  \Device\Harddisk1\DR1 - ok
12:53:21.0509 5396  ================ Scan VBR ==================================
12:53:21.0511 5396  [ FAC856C5AC26EFEEB504A5FC82AC8DD9 ] \Device\Harddisk0\DR0\Partition1
12:53:21.0512 5396  \Device\Harddisk0\DR0\Partition1 - ok
12:53:21.0515 5396  [ AD5BB688BBFAFDC2E7AC44E19A00F31A ] \Device\Harddisk1\DR1\Partition1
12:53:21.0516 5396  \Device\Harddisk1\DR1\Partition1 - ok
12:53:21.0530 5396  [ F2274E9CC0F31EBDC4DA3846BBF057E0 ] \Device\Harddisk1\DR1\Partition2
12:53:21.0531 5396  \Device\Harddisk1\DR1\Partition2 - ok
12:53:21.0532 5396  ============================================================
12:53:21.0532 5396  Scan finished
12:53:21.0532 5396  ============================================================
12:53:21.0542 6108  Detected object count: 7
12:53:21.0542 6108  Actual detected object count: 7
12:53:48.0812 6108  cmnsusbser ( UnsignedFile.Multi.Generic ) - skipped by user
12:53:48.0812 6108  cmnsusbser ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:53:48.0815 6108  IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
12:53:48.0815 6108  IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:53:48.0817 6108  MagicTuneEngine ( UnsignedFile.Multi.Generic ) - skipped by user
12:53:48.0817 6108  MagicTuneEngine ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:53:48.0818 6108  StkCMini ( UnsignedFile.Multi.Generic ) - skipped by user
12:53:48.0818 6108  StkCMini ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:53:48.0819 6108  StkSSrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:53:48.0819 6108  StkSSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:53:48.0820 6108  SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
12:53:48.0820 6108  SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:53:48.0822 6108  x10nets ( UnsignedFile.Multi.Generic ) - skipped by user
12:53:48.0822 6108  x10nets ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 10.10.2012 13:51

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Heistmer 11.10.2012 10:03

Das hab ich nun auch geschafft,

Probleme gab es dabei Combofix zu starten. Das System ist immer bei ca der Hälfte bei verzeichniss C:/32788R22FWJFW hängen geblieben.

Nach mehrfachen versuchen, und zwischenzeitlichen Löschens des Ordners hat es dann geklappt.
Leider bekahm ich dann die Meldung das Avira noch im Hintergrund läuft. Über den Taskmanager habe ich es dann auch gefunden konnte aber auf Grund der Gruppenrichtlinie es nicht deaktivieren. Ich habe dann mittels AutoRuns es deaktiviert bekommen, und dann sogar deinstaliren können.
Danach konte ich Kombofix wieder starten und es gab keine Fehlermeldung

Hier nun das Kombofix Log.

Code:

ComboFix 12-10-11.01 - Heistmer 11.10.2012  10:17:58.1.4 - x64
Microsoft® Windows Vista™ Ultimate  6.0.6002.2.1252.49.1031.18.3325.1856 [GMT 2:00]
ausgeführt von:: c:\users\Heistmer\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\index.htm
c:\program files (x86)\PluginDL
c:\program files (x86)\PluginDL\axdlplug.inf
c:\program files (x86)\PluginDL\PluginDL.url
c:\program files (x86)\xp-AntiSpy
c:\program files (x86)\xp-AntiSpy\Uninstall.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.chm
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.exe
c:\program files (x86)\xp-AntiSpy\xp-AntiSpy.url
c:\programdata\568DE542ED.sys
c:\programdata\dsgsdgdsgdsgw.pad
c:\users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PluginDL
c:\users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PluginDL\HomePage.lnk
c:\windows\Installer\$PatchCache$\Managed\6D79387323DF29048A45A657BCE7AD64\1.5.2060\pst.ini2
c:\windows\IsUn0407.exe
c:\windows\UA000107.DLL
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-09-11 bis 2012-10-11  ))))))))))))))))))))))))))))))
.
.
2012-10-11 08:29 . 2012-10-11 08:29        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2012-10-11 08:29 . 2012-10-11 08:29        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-10-11 06:06 . 2012-09-13 13:45        2048        ----a-w-        c:\windows\system32\tzres.dll
2012-10-11 06:06 . 2012-09-13 13:28        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
2012-10-11 06:06 . 2012-08-24 16:07        218624        ----a-w-        c:\windows\system32\wintrust.dll
2012-10-11 06:06 . 2012-08-24 15:53        172544        ----a-w-        c:\windows\SysWow64\wintrust.dll
2012-10-11 06:06 . 2012-06-02 00:20        1268736        ----a-w-        c:\windows\system32\crypt32.dll
2012-10-11 06:06 . 2012-06-02 00:20        174592        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-10-11 06:06 . 2012-06-02 00:20        132096        ----a-w-        c:\windows\system32\cryptnet.dll
2012-10-11 06:06 . 2012-06-02 00:02        985088        ----a-w-        c:\windows\SysWow64\crypt32.dll
2012-10-11 06:06 . 2012-06-02 00:02        98304        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2012-10-11 06:06 . 2012-06-02 00:02        133120        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2012-10-11 06:05 . 2012-08-29 11:40        4699520        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-10-09 11:58 . 2012-08-30 07:27        9308616        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{D5E27317-FF4E-48ED-B38E-F479CE507871}\mpengine.dll
2012-10-09 11:30 . 2012-10-09 20:43        --------        d-----w-        C:\_OTL
2012-10-04 15:06 . 2012-10-04 15:06        --------        d-----w-        c:\program files (x86)\ESET
2012-10-02 18:51 . 2012-10-02 18:51        --------        d-----w-        c:\users\Heistmer\AppData\Roaming\Malwarebytes
2012-10-02 18:51 . 2012-10-02 18:51        --------        d-----w-        c:\programdata\Malwarebytes
2012-10-02 18:51 . 2012-10-02 18:51        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-02 18:51 . 2012-09-07 15:04        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-09-22 21:57 . 2012-09-22 21:57        --------        d-----w-        c:\users\Heistmer\AppData\Local\NOS
2012-09-11 18:53 . 2012-09-11 18:53        --------        d-----w-        c:\users\Heistmer\AppData\Roaming\MAGIX
2012-09-11 18:53 . 2012-09-11 18:53        --------        d-----w-        c:\users\Heistmer\AppData\Local\Xara
2012-09-11 18:51 . 2012-09-11 18:53        --------        d-----w-        c:\programdata\MAGIX
2012-09-11 18:51 . 2012-09-11 18:51        --------        d-----w-        c:\program files (x86)\MAGIX
2012-09-11 18:50 . 2012-10-02 21:42        --------        d-----w-        c:\programdata\Yahoo!
2012-09-11 18:50 . 2012-09-11 18:50        --------        d-----w-        c:\users\Heistmer\AppData\Roaming\Yahoo!
2012-09-11 18:50 . 2012-09-11 18:50        --------        d-----w-        c:\program files (x86)\Yahoo!
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-08 20:10 . 2012-08-08 20:10        73416        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-08 20:10 . 2012-08-08 20:10        696520        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoStart-Manager"="c:\program files (x86)\Tools&More\Autostart-Manager\AutoStart-Manager.exe" [2012-02-29 401408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVMFBoxMonitor"="c:\program files (x86)\FRITZ!Box Monitor\FRITZBoxMonitor.exe" [2008-06-03 1508656]
.
c:\users\Heistmer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FRITZ!DSL Protect.lnk - c:\program files (x86)\FRITZ!DSL\FwebProt.exe [2007-9-7 1070384]
Trillian.lnk - c:\program files (x86)\Trillian\trillian.exe [2012-7-2 2298320]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FRITZ!DSL Startcenter.lnk - c:\windows\Installer\{2457326B-C110-40C3-89B0-889CC913871A}\Icon2457326B4.exe [2008-6-14 29184]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-7-19 1196048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\acrord32.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\afterfx.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\exprwd.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\filezilla.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\flashplayer11-2_p2_install_win_ax64_112211.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\flashplayer11-2_p2_uninstall_win_64_112211.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\flipshare.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\magictune.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\mml.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\mmlupdate.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\msoxmled.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\mstore.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\presentationhost.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\switchboard.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\uninstall.exe]
"Debugger"="c:\program files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
.
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 acedrv10;acedrv10;c:\windows\system32\drivers\acedrv10.sys [2009-08-18 277904]
S2 acehlp10;acehlp10;c:\windows\system32\drivers\acehlp10.sys [2009-08-18 228000]
S3 3xHybr64;Philips SAA713x PCI Card;c:\windows\system32\DRIVERS\3xHybr64.sys [2008-03-13 1607392]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
getPlusHelper        REG_MULTI_SZ          getPlusHelper
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 242192]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;192.168.*.*
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\FRITZ!DSL\\sarah.dll
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
TCP: DhcpNameServer = 192.168.178.1
DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3}
FF - ProfilePath - c:\users\Heistmer\AppData\Roaming\Mozilla\Firefox\Profiles\7ew9dmkc.default\
FF - prefs.js: browser.search.selectedEngine - FireSearch
FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-TAPI - c:\windows\IsUn0407.exe
AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe
AddRemove-bleh eggs link - c:\progra~4\PROXYM~1\AntiPlus.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êÖtêÖt¾Z¾Zuw&]
@Allowed: (Read) (RestrictedCode)
"0"=hex:56,00,31,00,00,00,00,00,3b,41,58,98,10,00,48,45,49,53,54,4d,7e,31,00,
  00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,3b,41,58,98,26,00,00,00,48,a3,07,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:56,00,31,00,00,00,00,00,3b,41,e0,9b,10,00,48,45,49,53,54,4d,7e,31,00,
  00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,3b,41,e0,9b,26,00,00,00,48,a3,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê
v¾ZƒZbÙžYš7*\À7*Е7*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,fd,40,bc,6b,10,00,44,45,52,54,4f,49,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,f5,40,62,99,fd,40,bc,6b,26,00,00,00,f1,45,00,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê1vê1v¾Zž`£Ä"]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,c6,40,f6,9a,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,c6,40,f6,9a,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê8vê8v¾ZF_Ú¬kÃ]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,b9,40,20,8e,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,b9,40,20,8e,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png êpvêpv¾ZX_
°rC]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,b6,40,0f,a0,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,b6,40,0f,a0,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*ê›vê›v¾Zæa        Äâ]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ef,40,56,43,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ef,40,56,43,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êœvêœv¾Zbén¢]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,3f,40,1b,ad,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,3f,40,1b,ad,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,41,40,07,a8,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,41,40,07,a8,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êžv¾ZÈf*œÁ*X”+*œº+*+*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,9a,40,d7,a5,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,9a,40,d7,a5,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êñvêñv¾ZOW늌û]
@Allowed: (Read) (RestrictedCode)
"0"=hex:56,00,31,00,00,00,00,00,2f,41,29,93,10,00,48,45,49,53,54,4d,7e,31,00,
  00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,2f,41,29,93,26,00,00,00,48,a3,07,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:56,00,31,00,00,00,00,00,2f,41,47,93,10,00,48,45,49,53,54,4d,7e,31,00,
  00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,2f,41,47,93,26,00,00,00,48,a3,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*êwêw¾Z[?àó1]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,a2,40,cb,9e,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,a2,40,cb,9e,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:66,00,31,00,00,00,00,00,a2,40,2b,9f,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,a2,40,2b,9f,26,00,00,00,23,72,07,00,\
"2"=hex:66,00,31,00,00,00,00,00,a2,40,83,a0,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,a2,40,83,a0,26,00,00,00,23,72,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾ZƒZÞÅžY]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,fd,40,e1,54,10,00,44,45,52,54,4f,49,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,f5,40,62,99,fd,40,e1,54,26,00,00,00,f1,45,00,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:66,00,31,00,00,00,00,00,fd,40,ac,76,10,00,44,45,52,54,4f,49,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,f5,40,62,99,fd,40,ac,76,26,00,00,00,f1,45,00,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾Z ]’*Æ]
@Allowed: (Read) (RestrictedCode)
"0"=hex:56,00,31,00,00,00,00,00,30,41,dd,4a,10,00,48,45,49,53,54,4d,7e,31,00,
  00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,30,41,dd,4a,26,00,00,00,48,a3,07,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:56,00,31,00,00,00,00,00,32,41,43,a2,10,00,48,45,49,53,54,4d,7e,31,00,
  00,3e,00,07,00,04,00,ef,be,2f,41,e6,8e,32,41,43,a2,26,00,00,00,48,a3,07,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾Z…cKù&¢]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,bf,40,46,87,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,bf,40,46,87,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png*¾ZÈfÁ*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,9a,40,14,a3,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,9a,40,14,a3,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*êÌuêÌu¾Z2_2î£]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff,
  ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"3"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
"4"=hex:52,00,31,00,00,00,00,00,ba,40,1a,a2,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ba,40,1a,a2,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*ê*vê*v¾Zò^ÓŽù>]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,35,40,80,a6,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,80,a6,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,35,40,47,ac,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,47,ac,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,35,40,64,af,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,64,af,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Zú`ÚÄ;]
@Allowed: (Read) (RestrictedCode)
"0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
  00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Za[2bF]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,47,40,e1,ae,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,47,40,e1,ae,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Z”j>{ßb]
@Allowed: (Read) (RestrictedCode)
"0"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
  00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
"MRUListEx"=hex:02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
  00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
"2"=hex:14,00,1f,44,47,1a,03,59,72,3f,a7,44,89,c5,55,95,fe,6b,30,ee,20,00,00,
  00,1a,00,ee,bb,fe,23,00,00,10,00,30,81,e2,33,1e,4e,76,46,83,5a,98,39,5c,3b,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\jpg*¾Z·pR \³]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ec,40,f2,9e,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ec,40,f2,9e,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage*›vê›v¾ZæaªÄâ`š]*¤À]*–]*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,ef,40,56,43,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,ef,40,56,43,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage*}-Bþÿÿÿêžvêžv¾ZÈf*œÁ*X”+*œº+*+*]
@Allowed: (Read) (RestrictedCode)
"0"=hex:66,00,31,00,00,00,00,00,9a,40,8a,a3,10,00,54,4f,57,45,52,2d,7e,31,00,
  00,4e,00,07,00,04,00,ef,be,96,40,ee,5e,9a,40,8a,a3,26,00,00,00,23,72,07,00,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage*ø¯uÀõþÿÿÿê¥uê¥u¾ZDaa—Ê]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,51,40,cd,b0,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,51,40,cd,b0,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:0e,00,00,00,0d,00,00,00,0c,00,00,00,0b,00,00,00,0a,00,00,00,09,
  00,00,00,08,00,00,00,07,00,00,00,06,00,00,00,05,00,00,00,04,00,00,00,03,00,\
"1"=hex:52,00,31,00,00,00,00,00,54,40,4e,98,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,4e,98,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,54,40,73,98,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,73,98,26,00,00,00,fe,a1,03,00,\
"3"=hex:52,00,31,00,00,00,00,00,54,40,92,98,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,92,98,26,00,00,00,fe,a1,03,00,\
"4"=hex:52,00,31,00,00,00,00,00,54,40,ac,98,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,ac,98,26,00,00,00,fe,a1,03,00,\
"5"=hex:52,00,31,00,00,00,00,00,54,40,ca,98,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,ca,98,26,00,00,00,fe,a1,03,00,\
"6"=hex:52,00,31,00,00,00,00,00,54,40,e5,98,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,e5,98,26,00,00,00,fe,a1,03,00,\
"7"=hex:52,00,31,00,00,00,00,00,54,40,02,99,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,02,99,26,00,00,00,fe,a1,03,00,\
"8"=hex:52,00,31,00,00,00,00,00,54,40,19,99,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,19,99,26,00,00,00,fe,a1,03,00,\
"9"=hex:52,00,31,00,00,00,00,00,54,40,36,99,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,36,99,26,00,00,00,fe,a1,03,00,\
"10"=hex:52,00,31,00,00,00,00,00,54,40,74,99,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,74,99,26,00,00,00,fe,a1,03,00,\
"11"=hex:52,00,31,00,00,00,00,00,54,40,b9,99,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,b9,99,26,00,00,00,fe,a1,03,00,\
"12"=hex:52,00,31,00,00,00,00,00,54,40,80,9a,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,80,9a,26,00,00,00,fe,a1,03,00,\
"13"=hex:52,00,31,00,00,00,00,00,54,40,ca,9a,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,ca,9a,26,00,00,00,fe,a1,03,00,\
"14"=hex:52,00,31,00,00,00,00,00,54,40,eb,9a,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,eb,9a,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage ø¯uÀõþÿÿÿê¥uê¥u¾ZDaá
—Ê]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,54,40,0b,9b,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,0b,9b,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:0a,00,00,00,09,00,00,00,08,00,00,00,07,00,00,00,06,00,00,00,05,
  00,00,00,04,00,00,00,03,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,ff,ff,\
"1"=hex:52,00,31,00,00,00,00,00,54,40,b8,9d,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,b8,9d,26,00,00,00,fe,a1,03,00,\
"2"=hex:52,00,31,00,00,00,00,00,54,40,8c,a6,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,8c,a6,26,00,00,00,fe,a1,03,00,\
"3"=hex:52,00,31,00,00,00,00,00,54,40,d8,a6,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,d8,a6,26,00,00,00,fe,a1,03,00,\
"4"=hex:52,00,31,00,00,00,00,00,54,40,46,a7,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,46,a7,26,00,00,00,fe,a1,03,00,\
"5"=hex:52,00,31,00,00,00,00,00,54,40,4a,a7,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,4a,a7,26,00,00,00,fe,a1,03,00,\
"6"=hex:52,00,31,00,00,00,00,00,54,40,5d,a7,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,5d,a7,26,00,00,00,fe,a1,03,00,\
"7"=hex:52,00,31,00,00,00,00,00,54,40,0f,a8,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,0f,a8,26,00,00,00,fe,a1,03,00,\
"8"=hex:52,00,31,00,00,00,00,00,54,40,21,a8,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,21,a8,26,00,00,00,fe,a1,03,00,\
"9"=hex:52,00,31,00,00,00,00,00,54,40,37,a8,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,37,a8,26,00,00,00,fe,a1,03,00,\
"10"=hex:52,00,31,00,00,00,00,00,54,40,49,a8,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,54,40,49,a8,26,00,00,00,fe,a1,03,00,\
.
[HKEY_USERS\S-1-5-21-3066119559-789599144-109096739-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\pspimage ø
v,ßPTþÿÿÿê vê v¾Zò^ÓŽù>]
@Allowed: (Read) (RestrictedCode)
"0"=hex:52,00,31,00,00,00,00,00,35,40,e3,bc,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,e3,bc,26,00,00,00,fe,a1,03,00,\
"MRUListEx"=hex:01,00,00,00,00,00,00,00,ff,ff,ff,ff
"1"=hex:52,00,31,00,00,00,00,00,35,40,7a,be,10,00,68,6f,63,68,7a,65,69,74,00,
  00,3a,00,07,00,04,00,ef,be,35,40,b8,a4,35,40,7a,be,26,00,00,00,fe,a1,03,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_400_252_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_400_252_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:b5,58,57,e5,b4,98,13,5e,68,e9,00,b7,64,94,bb,28,9f,7f,e7,a7,f3,
  09,ab,5a,37,76,eb,9d,e0,6e,51,aa,0b,a7,21,cc,f1,30,44,f7,c5,c7,8a,40,6c,d7,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_400_252_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_400_252_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_400_252.ocx"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\FLAGS]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\HELPDIR]
@="c:\\Windows\\system32\\Macromed\\Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\FLAGS]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\HELPDIR]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_400_252_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
"RasTimeoutResponseWait"=dword:00000032
"RasTimeoutPause"=dword:00000005
"ConnectTypesAllowed"=dword:0000000a
"CheckPasswordTimeoutSeconds"=dword:00000014
"WaitV2TimeoutSeconds"=dword:00000004
"SerialPort"="Bluetooth"
"HasUsbDevice"=dword:00000000
"SerialBaudRate"=dword:0001c200
"DeviceType"=""
"DeviceOemInfo"=""
"DeviceVersion"=dword:04401504
"DeviceProcessorType"=dword:00000000
"DeviceProcessor"=""
"DTPTNetworkType"="{0}"
"DisableIr"=dword:00000000
"GuestOnly"=dword:00000000
"MajorVersion"=dword:00000006
"MinorVersion"=dword:00000000
"InstalledDir"=expand:"%windir%\\WindowsMobile"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:b5,58,57,e5,b4,98,13,5e,68,e9,00,b7,64,94,bb,28,9f,7f,e7,a7,f3,
  09,ab,5a,37,76,eb,9d,e0,6e,51,aa,0b,a7,21,cc,f1,30,44,f7,c5,c7,8a,40,6c,d7,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
  00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2012-10-11  10:34:27
ComboFix-quarantined-files.txt  2012-10-11 08:34
.
Vor Suchlauf: 16 Verzeichnis(se), 29.150.113.792 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 28.972.433.408 Bytes frei
.
- - End Of File - - FAC62B0F29F3CB50D64FEB2D16B49A6A


cosinus 11.10.2012 14:07

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Heistmer 11.10.2012 18:19

Liste der Anhänge anzeigen (Anzahl: 1)
GMER lief ohne Probleme.

Bei Osam finde ich leider das LOG nicht. In der Anleitung ist ja beschrieben das ich auf Save Log klicken soll. Wenn ich das mache bekomm ich aber keinen speicher unter bildschim. Ich habe auch mit der Windows Suche nach neuen Dateien gesucht, aber nix gefunden.
Ich habe jetzt erst mal ein JPG mit angehängt vielleicht reicht das ja.

ASW ist auch durch.



Hier die LOG's

Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-10-11 16:23:05
Windows 6.0.6002 Service Pack 2
Running: 1circqqp.exe


---- Registry - GMER 1.0.15 ----

Reg  HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016930002a5                                         
Reg  HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016930002a5@00188d74fb1d                            0x31 0xCF 0xCC 0x2A ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                   
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                  C:\Program Files (x86)\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                  0
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                              0xD1 0x94 0xEA 0x82 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001                           
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                        0x20 0x01 0x00 0x00 ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                      0x75 0x1A 0xE6 0x2C ...
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40                     
Reg  HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                0xF8 0xFF 0xE1 0x5D ...
Reg  HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0016930002a5 (not active ControlSet)                     
Reg  HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0016930002a5@00188d74fb1d                                0x31 0xCF 0xCC 0x2A ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)               
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                      C:\Program Files (x86)\DAEMON Tools Lite\
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                      0
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                  0xD1 0x94 0xEA 0x82 ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)       
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                            0x20 0x01 0x00 0x00 ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                          0x75 0x1A 0xE6 0x2C ...
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) 
Reg  HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                    0xF8 0xFF 0xE1 0x5D ...

---- EOF - GMER 1.0.15 ----


Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-11 18:04:59
-----------------------------
18:04:59.079    OS Version: Windows x64 6.0.6002 Service Pack 2
18:04:59.079    Number of processors: 4 586 0xF0B
18:04:59.080    ComputerName: Heistmer-ONE  UserName: Heistmer
18:05:01.724    Initialize success
18:06:51.059    AVAST engine defs: 12101100
18:07:23.325    Disk 0  \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
18:07:23.327    Disk 0 Vendor: SAMSUNG_HD103SJ 1AJ10001 Size: 953869MB BusType: 3
18:07:23.329    Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP4T0L0-6
18:07:23.331    Disk 1 Vendor: ST3500320AS SD15 Size: 476940MB BusType: 3
18:07:23.336    Disk 1 MBR read successfully
18:07:23.338    Disk 1 MBR scan
18:07:23.348    Disk 1 Windows VISTA default MBR code
18:07:23.360    Disk 1 Partition 1 80 (A) 07    HPFS/NTFS NTFS      461940 MB offset 2048
18:07:23.364    Disk 1 Partition - 00    0F Extended LBA            14998 MB offset 946055168
18:07:23.398    Disk 1 Partition 2 00    0B        FAT32 MSDOS5.0    14997 MB offset 946057216
18:07:23.434    Disk 1 scanning C:\Windows\system32\drivers
18:07:33.574    Service scanning
18:07:51.743    Modules scanning
18:07:51.749    Disk 1 trace - called modules:
18:07:51.795    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
18:07:51.799    1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa8004fd5060]
18:07:51.802    3 CLASSPNP.SYS[fffffa6000b56c33] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-6[0xfffffa800383d940]
18:07:54.026    AVAST engine scan C:\Windows
18:07:59.826    AVAST engine scan C:\Windows\system32
18:11:38.062    AVAST engine scan C:\Windows\system32\drivers
18:12:00.765    AVAST engine scan C:\Users\Heistmer
18:53:46.716    Disk 1 MBR has been saved successfully to "C:\Users\Heistmer\Desktop\MBR.dat"
18:53:46.721    The log file has been saved successfully to "C:\Users\Heistmer\Desktop\aswMBR.txt"


cosinus 12.10.2012 09:32

Ist schon ok, OSAM funktioniert nicht immter auf einem 64-Bit-Vista

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Heistmer 12.10.2012 20:13

Sooo, die Scans sind durch,

Malware:

Code:

Malwarebytes Anti-Malware (Test) 1.65.0.1400
www.malwarebytes.org

Datenbank Version: v2012.10.12.03

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Heistmer :: Heistmer-ONE [Administrator]

Schutz: Aktiviert

12.10.2012 15:19:54
mbam-log-2012-10-12 (18-54-49).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|J:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 816316
Laufzeit: 2 Stunde(n), 19 Minute(n), 57 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0


(Ende)

Und Super Antispyware

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/12/2012 at 08:41 PM

Application Version : 5.6.1010

Core Rules Database Version : 9394
Trace Rules Database Version: 7206

Scan type      : Complete Scan
Total Scan Time : 01:37:35

Operating System Information
Windows Vista Ultimate 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User

Memory items scanned      : 330
Memory threats detected  : 0
Registry items scanned    : 73482
Registry threats detected : 30
File items scanned        : 171081
File threats detected    : 138

Security.HiJack[ImageFileExecutionOptions]
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ACRORD32.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ACRORD32.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AFTERFX.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AFTERFX.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPRWD.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPRWD.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FILEZILLA.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FILEZILLA.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_INSTALL_WIN_AX64_112211.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_INSTALL_WIN_AX64_112211.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_UNINSTALL_WIN_64_112211.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_UNINSTALL_WIN_64_112211.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLIPSHARE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLIPSHARE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MAGICTUNE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MAGICTUNE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MML.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MML.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MMLUPDATE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MMLUPDATE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSOXMLED.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSOXMLED.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSTORE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSTORE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PRESENTATIONHOST.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PRESENTATIONHOST.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SWITCHBOARD.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SWITCHBOARD.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UNINSTALL.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UNINSTALL.EXE#Debugger

Adware.Tracking Cookie
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\H9REJC93.txt [ /smartadserver.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\9SW4DVEG.txt [ /ad3.adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2PC6SPWV.txt [ /ad.360yield.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2PA1EOMX.txt [ /webmasterplan.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\M3DP8J0H.txt [ /revsci.net ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\SE1X7PT1.txt [ /server.adformdsp.net ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\YJ98HIGN.txt [ /de.sitestat.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TSBX45HM.txt [ /ad.zanox.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\MSNXW35C.txt [ /ads.verticalscope.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\W0TEL8PU.txt [ /zanox.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\JHN46Q3Q.txt [ /adbrite.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2KUVBYQ6.txt [ /serving-sys.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\Z8D0T2QC.txt [ /bs.serving-sys.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\3B7SGKCZ.txt [ /adx2.chip.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\0CYUK3GB.txt [ /stat.dealtime.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\V6QX6E7M.txt [ /edates.traffective-tracking.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\O3MW8204.txt [ /de.sitestat.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\Q0AEM54X.txt [ /xiti.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\PCTWOYQ6.txt [ /ad4.adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TNEXPOCN.txt [ /at.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\X80Z9N80.txt [ /adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\QPUODD2R.txt [ /tracker.vinsight.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TBL4015A.txt [ /ru4.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\53S0SWXF.txt [ /ad.ad-srv.net ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\IXHLO1XA.txt [ /amazon-adsystem.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\00AQJO3G.txt [ /clickfuse.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\JYDPFUYL.txt [ /www.googleadservices.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\MX4C4S53.txt [ /ad.yieldmanager.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\B5ZRO0BC.txt [ /invitemedia.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\WTNN4HFD.txt [ /tracking.mobile.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\1BSUM3RG.txt [ /ec-track.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\JFJ1PQ9O.txt [ /ar.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\DAWRBYIN.txt [ /eas.apm.emediate.eu ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\6HKB0JSJ.txt [ /de.sitestat.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\YR6QYNDX.txt [ /ads.creative-serving.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\MHPDVD0X.txt [ /uk.at.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\RX22PSP2.txt [ /tacoda.at.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\ANZ2A4PZ.txt [ /stats.deka.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\Q25NNMHI.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\K4TU3X4S.txt [ /www.etracker.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TL2AXY93.txt [ /atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\26I6D3CZ.txt [ /adx.chip.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\4U5KNPUU.txt [ /adtech.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\L1K914P0.txt [ /ad.lokalisten.de ]
        C:\USERS\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\NEMYJ8LK.txt [ Cookie:Heistmer@www.tomtom.com/livetraffic ]
        C:\USERS\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2LDZT3EC.txt [ Cookie:Heistmer@adsonar.com/adserving ]
        C:\USERS\Heistmer\Cookies\H9REJC93.txt [ Cookie:Heistmer@smartadserver.com/ ]
        C:\USERS\Heistmer\Cookies\9SW4DVEG.txt [ Cookie:Heistmer@ad3.adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\NEMYJ8LK.txt [ Cookie:Heistmer@www.tomtom.com/livetraffic ]
        C:\USERS\Heistmer\Cookies\M3DP8J0H.txt [ Cookie:Heistmer@revsci.net/ ]
        C:\USERS\Heistmer\Cookies\SE1X7PT1.txt [ Cookie:Heistmer@server.adformdsp.net/ ]
        C:\USERS\Heistmer\Cookies\YJ98HIGN.txt [ Cookie:Heistmer@de.sitestat.com/is24-mail/is24-mail/ ]
        C:\USERS\Heistmer\Cookies\W0TEL8PU.txt [ Cookie:Heistmer@zanox.com/ ]
        C:\USERS\Heistmer\Cookies\2KUVBYQ6.txt [ Cookie:Heistmer@serving-sys.com/ ]
        C:\USERS\Heistmer\Cookies\Z8D0T2QC.txt [ Cookie:Heistmer@bs.serving-sys.com/ ]
        C:\USERS\Heistmer\Cookies\3B7SGKCZ.txt [ Cookie:Heistmer@adx2.chip.de/ ]
        C:\USERS\Heistmer\Cookies\V6QX6E7M.txt [ Cookie:Heistmer@edates.traffective-tracking.com/ ]
        C:\USERS\Heistmer\Cookies\O3MW8204.txt [ Cookie:Heistmer@de.sitestat.com/sport1/ ]
        C:\USERS\Heistmer\Cookies\Q0AEM54X.txt [ Cookie:Heistmer@xiti.com/ ]
        C:\USERS\Heistmer\Cookies\PCTWOYQ6.txt [ Cookie:Heistmer@ad4.adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\TNEXPOCN.txt [ Cookie:Heistmer@at.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\X80Z9N80.txt [ Cookie:Heistmer@adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\TBL4015A.txt [ Cookie:Heistmer@ru4.com/ ]
        C:\USERS\Heistmer\Cookies\IXHLO1XA.txt [ Cookie:Heistmer@amazon-adsystem.com/ ]
        C:\USERS\Heistmer\Cookies\00AQJO3G.txt [ Cookie:Heistmer@clickfuse.com/ ]
        C:\USERS\Heistmer\Cookies\MX4C4S53.txt [ Cookie:Heistmer@ad.yieldmanager.com/ ]
        C:\USERS\Heistmer\Cookies\B5ZRO0BC.txt [ Cookie:Heistmer@invitemedia.com/ ]
        C:\USERS\Heistmer\Cookies\WTNN4HFD.txt [ Cookie:Heistmer@tracking.mobile.de/ ]
        C:\USERS\Heistmer\Cookies\JFJ1PQ9O.txt [ Cookie:Heistmer@ar.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\DAWRBYIN.txt [ Cookie:Heistmer@eas.apm.emediate.eu/ ]
        C:\USERS\Heistmer\Cookies\6HKB0JSJ.txt [ Cookie:Heistmer@de.sitestat.com/sport1/sport1-de/ ]
        C:\USERS\Heistmer\Cookies\MHPDVD0X.txt [ Cookie:Heistmer@uk.at.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\2LDZT3EC.txt [ Cookie:Heistmer@adsonar.com/adserving ]
        C:\USERS\Heistmer\Cookies\RX22PSP2.txt [ Cookie:Heistmer@tacoda.at.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\ANZ2A4PZ.txt [ Cookie:Heistmer@stats.deka.de/track/ ]
        C:\USERS\Heistmer\Cookies\Q25NNMHI.txt [ Cookie:Heistmer@ad2.adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\K4TU3X4S.txt [ Cookie:Heistmer@www.etracker.de/ ]
        C:\USERS\Heistmer\Cookies\TL2AXY93.txt [ Cookie:Heistmer@atwola.com/ ]
        C:\USERS\Heistmer\Cookies\4U5KNPUU.txt [ Cookie:Heistmer@adtech.de/ ]
        s0.2mdn.net [ C:\USERS\Heistmer\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\F6ZMF8VW ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD-HOC-NEWS[2].TXT [ /AD-HOC-NEWS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.71I[1].TXT [ /AD.71I ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.ADNET[3].TXT [ /AD.ADNET ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.BEEPWORLD[1].TXT [ /AD.BEEPWORLD ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.IEUROP[2].TXT [ /AD.IEUROP ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.ZANOX[1].TXT [ /AD.ZANOX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADBRITE[1].TXT [ /ADBRITE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADINTERAX[1].TXT [ /ADINTERAX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADREVOLVER[2].TXT [ /ADREVOLVER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.ADSHOPPING[2].TXT [ /ADS.ADSHOPPING ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.FETTSPIELEN[2].TXT [ /ADS.FETTSPIELEN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.HEIAS[1].TXT [ /ADS.HEIAS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.JINKADS[1].TXT [ /ADS.JINKADS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.KOMPLADS[2].TXT [ /ADS.KOMPLADS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.ONTECNIA[2].TXT [ /ADS.ONTECNIA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.POINTROLL[2].TXT [ /ADS.POINTROLL ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.REVSCI[1].TXT [ /ADS.REVSCI ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.SUN[1].TXT [ /ADS.SUN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.TOOSHOCKING[1].TXT [ /ADS.TOOSHOCKING ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.TUNINGSUCHE[1].TXT [ /ADS.TUNINGSUCHE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS3.EXP[2].TXT [ /ADS3.EXP ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADSERVER.FILEFRONT[1].TXT [ /ADSERVER.FILEFRONT ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADULTFRIENDFINDER[1].TXT [ /ADULTFRIENDFINDER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADVIVA[2].TXT [ /ADVIVA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AUTOSCOUT24.112.2O7[1].TXT [ /AUTOSCOUT24.112.2O7 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@CASALEMEDIA[2].TXT [ /CASALEMEDIA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@DE2.KOMTRACK[2].TXT [ /DE2.KOMTRACK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@DISCOUNT24.QUARTERSERVER[1].TXT [ /DISCOUNT24.QUARTERSERVER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@E-2DJ6WGKYQJD5MAP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WGKYQJD5MAP.STATS.ESOMNITURE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@E-2DJ6WJK4UICZMDP.STATS.ESOMNITURE[1].TXT [ /E-2DJ6WJK4UICZMDP.STATS.ESOMNITURE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@FASTCLICK[1].TXT [ /FASTCLICK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@FILEUPLOADX[1].TXT [ /FILEUPLOADX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@GOSTATS[1].TXT [ /GOSTATS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@HITBOX[1].TXT [ /HITBOX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@INDEXTOOLS[1].TXT [ /INDEXTOOLS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@KOMTRACK[1].TXT [ /KOMTRACK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@KUNDEN.WUNDERMEDIA[1].TXT [ /KUNDEN.WUNDERMEDIA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@LOCALPORTAL24DE.112.2O7[1].TXT [ /LOCALPORTAL24DE.112.2O7 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@MEDIA.FUNPIC[1].TXT [ /MEDIA.FUNPIC ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@MEDIA.MTVNSERVICES[1].TXT [ /MEDIA.MTVNSERVICES ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@PARTNERS.WEBMASTERPLAN[1].TXT [ /PARTNERS.WEBMASTERPLAN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@PORNTUBE[2].TXT [ /PORNTUBE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@RICHMEDIA.YAHOO[2].TXT [ /RICHMEDIA.YAHOO ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@S2.TRAFFICMAXX[1].TXT [ /S2.TRAFFICMAXX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@SALES.LIVEPERSON[3].TXT [ /SALES.LIVEPERSON ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@SEXYJODHPURS[2].TXT [ /SEXYJODHPURS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@SOFTONIC.112.2O7[1].TXT [ /SOFTONIC.112.2O7 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@STAT.DEALTIME[2].TXT [ /STAT.DEALTIME ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@STATSE.WEBTRENDSLIVE[1].TXT [ /STATSE.WEBTRENDSLIVE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@TACODA[2].TXT [ /TACODA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@TTO2.TRAFFICTRACK[1].TXT [ /TTO2.TRAFFICTRACK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WEBMASTERPLAN[1].TXT [ /WEBMASTERPLAN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WEBORAMA[1].TXT [ /WEBORAMA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WWW.DISCOUNT24[1].TXT [ /WWW.DISCOUNT24 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WWW.DISCOUNT24[2].TXT [ /WWW.DISCOUNT24 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WWW.GAMESBANNER[1].TXT [ /WWW.GAMESBANNER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@YADRO[2].TXT [ /YADRO ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ZBOX.ZANOX[2].TXT [ /ZBOX.ZANOX ]


cosinus 12.10.2012 21:02

Code:

UAC On - Limited User
Wie hast du sasw gestartet? Einfach per Doppelklick?

Bitte so wie es in der Anleitung steht auch ausführen!

Zitat:

Zitat von cosinus (Beitrag 324870)
Teil 2: Programm ausführen
Das Programm wurde nun installiert, eine Verknüpfung auf dem Desktop sollte erstellt worden sein. Nachdem du es gestartet hast, wird es sich erstmalig beim Updateserver nach neuen Schädlingssignaturen umsehen und Updates installieren. Diesen Vorgang NICHT abbrechen!

Benutzer mit Windows Vista und Windows 7 starten das Tool bitte wieder per Rechtsklick => als Administrator ausführen!


Heistmer 13.10.2012 14:18

Hallo, das kann ich nicht ausschliessen. Da muss ich mich immer zu zwingen, und bin mich auch zuvor schon immer ein paar mal erwischt das ich das wie gewohnt mit dem Doppelklick gemacht habe. Es ist irgendwie so drinn.

Neues Log

Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 10/13/2012 at 03:01 PM

Application Version : 5.6.1010

Core Rules Database Version : 9398
Trace Rules Database Version: 7210

Scan type      : Complete Scan
Total Scan Time : 04:58:45

Operating System Information
Windows Vista Ultimate 64-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 670
Memory threats detected  : 0
Registry items scanned    : 74377
Registry threats detected : 30
File items scanned        : 471607
File threats detected    : 139

Security.HiJack[ImageFileExecutionOptions]
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ACRORD32.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ACRORD32.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AFTERFX.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AFTERFX.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPRWD.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPRWD.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FILEZILLA.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FILEZILLA.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_INSTALL_WIN_AX64_112211.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_INSTALL_WIN_AX64_112211.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_UNINSTALL_WIN_64_112211.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLASHPLAYER11-2_P2_UNINSTALL_WIN_64_112211.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLIPSHARE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FLIPSHARE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MAGICTUNE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MAGICTUNE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MML.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MML.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MMLUPDATE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MMLUPDATE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSOXMLED.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSOXMLED.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSTORE.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSTORE.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PRESENTATIONHOST.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PRESENTATIONHOST.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SWITCHBOARD.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SWITCHBOARD.EXE#Debugger
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UNINSTALL.EXE
        (x86) HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UNINSTALL.EXE#Debugger

Adware.Tracking Cookie
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\H9REJC93.txt [ /smartadserver.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\9SW4DVEG.txt [ /ad3.adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2PC6SPWV.txt [ /ad.360yield.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2PA1EOMX.txt [ /webmasterplan.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\M3DP8J0H.txt [ /revsci.net ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\SE1X7PT1.txt [ /server.adformdsp.net ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\YJ98HIGN.txt [ /de.sitestat.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TSBX45HM.txt [ /ad.zanox.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\MSNXW35C.txt [ /ads.verticalscope.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\W0TEL8PU.txt [ /zanox.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\JHN46Q3Q.txt [ /adbrite.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2KUVBYQ6.txt [ /serving-sys.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\Z8D0T2QC.txt [ /bs.serving-sys.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\3B7SGKCZ.txt [ /adx2.chip.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\0CYUK3GB.txt [ /stat.dealtime.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\V6QX6E7M.txt [ /edates.traffective-tracking.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\O3MW8204.txt [ /de.sitestat.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\Q0AEM54X.txt [ /xiti.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\PCTWOYQ6.txt [ /ad4.adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TNEXPOCN.txt [ /at.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\X80Z9N80.txt [ /adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\QPUODD2R.txt [ /tracker.vinsight.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TBL4015A.txt [ /ru4.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\53S0SWXF.txt [ /ad.ad-srv.net ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\IXHLO1XA.txt [ /amazon-adsystem.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\00AQJO3G.txt [ /clickfuse.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\JYDPFUYL.txt [ /www.googleadservices.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\MX4C4S53.txt [ /ad.yieldmanager.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\B5ZRO0BC.txt [ /invitemedia.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\WTNN4HFD.txt [ /tracking.mobile.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\1BSUM3RG.txt [ /ec-track.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\JFJ1PQ9O.txt [ /ar.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\DAWRBYIN.txt [ /eas.apm.emediate.eu ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\6HKB0JSJ.txt [ /de.sitestat.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\YR6QYNDX.txt [ /ads.creative-serving.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\MHPDVD0X.txt [ /uk.at.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\RX22PSP2.txt [ /tacoda.at.atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\ANZ2A4PZ.txt [ /stats.deka.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\Q25NNMHI.txt [ /ad2.adfarm1.adition.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\K4TU3X4S.txt [ /www.etracker.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\TL2AXY93.txt [ /atwola.com ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\26I6D3CZ.txt [ /adx.chip.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\4U5KNPUU.txt [ /adtech.de ]
        C:\Users\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\L1K914P0.txt [ /ad.lokalisten.de ]
        C:\USERS\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\NEMYJ8LK.txt [ Cookie:Heistmer@www.tomtom.com/livetraffic ]
        C:\USERS\Heistmer\AppData\Roaming\Microsoft\Windows\Cookies\2LDZT3EC.txt [ Cookie:Heistmer@adsonar.com/adserving ]
        C:\USERS\Heistmer\Cookies\H9REJC93.txt [ Cookie:Heistmer@smartadserver.com/ ]
        C:\USERS\Heistmer\Cookies\9SW4DVEG.txt [ Cookie:Heistmer@ad3.adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\NEMYJ8LK.txt [ Cookie:Heistmer@www.tomtom.com/livetraffic ]
        C:\USERS\Heistmer\Cookies\M3DP8J0H.txt [ Cookie:Heistmer@revsci.net/ ]
        C:\USERS\Heistmer\Cookies\SE1X7PT1.txt [ Cookie:Heistmer@server.adformdsp.net/ ]
        C:\USERS\Heistmer\Cookies\YJ98HIGN.txt [ Cookie:Heistmer@de.sitestat.com/is24-mail/is24-mail/ ]
        C:\USERS\Heistmer\Cookies\W0TEL8PU.txt [ Cookie:Heistmer@zanox.com/ ]
        C:\USERS\Heistmer\Cookies\2KUVBYQ6.txt [ Cookie:Heistmer@serving-sys.com/ ]
        C:\USERS\Heistmer\Cookies\Z8D0T2QC.txt [ Cookie:Heistmer@bs.serving-sys.com/ ]
        C:\USERS\Heistmer\Cookies\3B7SGKCZ.txt [ Cookie:Heistmer@adx2.chip.de/ ]
        C:\USERS\Heistmer\Cookies\V6QX6E7M.txt [ Cookie:Heistmer@edates.traffective-tracking.com/ ]
        C:\USERS\Heistmer\Cookies\O3MW8204.txt [ Cookie:Heistmer@de.sitestat.com/sport1/ ]
        C:\USERS\Heistmer\Cookies\Q0AEM54X.txt [ Cookie:Heistmer@xiti.com/ ]
        C:\USERS\Heistmer\Cookies\PCTWOYQ6.txt [ Cookie:Heistmer@ad4.adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\TNEXPOCN.txt [ Cookie:Heistmer@at.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\X80Z9N80.txt [ Cookie:Heistmer@adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\TBL4015A.txt [ Cookie:Heistmer@ru4.com/ ]
        C:\USERS\Heistmer\Cookies\IXHLO1XA.txt [ Cookie:Heistmer@amazon-adsystem.com/ ]
        C:\USERS\Heistmer\Cookies\00AQJO3G.txt [ Cookie:Heistmer@clickfuse.com/ ]
        C:\USERS\Heistmer\Cookies\MX4C4S53.txt [ Cookie:Heistmer@ad.yieldmanager.com/ ]
        C:\USERS\Heistmer\Cookies\B5ZRO0BC.txt [ Cookie:Heistmer@invitemedia.com/ ]
        C:\USERS\Heistmer\Cookies\WTNN4HFD.txt [ Cookie:Heistmer@tracking.mobile.de/ ]
        C:\USERS\Heistmer\Cookies\JFJ1PQ9O.txt [ Cookie:Heistmer@ar.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\DAWRBYIN.txt [ Cookie:Heistmer@eas.apm.emediate.eu/ ]
        C:\USERS\Heistmer\Cookies\6HKB0JSJ.txt [ Cookie:Heistmer@de.sitestat.com/sport1/sport1-de/ ]
        C:\USERS\Heistmer\Cookies\MHPDVD0X.txt [ Cookie:Heistmer@uk.at.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\2LDZT3EC.txt [ Cookie:Heistmer@adsonar.com/adserving ]
        C:\USERS\Heistmer\Cookies\RX22PSP2.txt [ Cookie:Heistmer@tacoda.at.atwola.com/ ]
        C:\USERS\Heistmer\Cookies\ANZ2A4PZ.txt [ Cookie:Heistmer@stats.deka.de/track/ ]
        C:\USERS\Heistmer\Cookies\Q25NNMHI.txt [ Cookie:Heistmer@ad2.adfarm1.adition.com/ ]
        C:\USERS\Heistmer\Cookies\K4TU3X4S.txt [ Cookie:Heistmer@www.etracker.de/ ]
        C:\USERS\Heistmer\Cookies\TL2AXY93.txt [ Cookie:Heistmer@atwola.com/ ]
        C:\USERS\Heistmer\Cookies\4U5KNPUU.txt [ Cookie:Heistmer@adtech.de/ ]
        s0.2mdn.net [ C:\USERS\Heistmer\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\F6ZMF8VW ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@MEDIA.FUNPIC[1].TXT [ /MEDIA.FUNPIC ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD-HOC-NEWS[2].TXT [ /AD-HOC-NEWS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@CASALEMEDIA[2].TXT [ /CASALEMEDIA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@LOCALPORTAL24DE.112.2O7[1].TXT [ /LOCALPORTAL24DE.112.2O7 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@S2.TRAFFICMAXX[1].TXT [ /S2.TRAFFICMAXX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@SOFTONIC.112.2O7[1].TXT [ /SOFTONIC.112.2O7 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@FASTCLICK[1].TXT [ /FASTCLICK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.TOOSHOCKING[1].TXT [ /ADS.TOOSHOCKING ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@SEXYJODHPURS[2].TXT [ /SEXYJODHPURS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@FILEUPLOADX[1].TXT [ /FILEUPLOADX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@PARTNERS.WEBMASTERPLAN[1].TXT [ /PARTNERS.WEBMASTERPLAN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.ZANOX[1].TXT [ /AD.ZANOX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@E-2DJ6WJK4UICZMDP.STATS.ESOMNITURE[1].TXT [ /E-2DJ6WJK4UICZMDP.STATS.ESOMNITURE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.SUN[1].TXT [ /ADS.SUN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@RICHMEDIA.YAHOO[2].TXT [ /RICHMEDIA.YAHOO ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WWW.GAMESBANNER[1].TXT [ /WWW.GAMESBANNER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AUTOSCOUT24.112.2O7[1].TXT [ /AUTOSCOUT24.112.2O7 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WEBORAMA[1].TXT [ /WEBORAMA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADSERVER.FILEFRONT[1].TXT [ /ADSERVER.FILEFRONT ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.IEUROP[2].TXT [ /AD.IEUROP ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.ONTECNIA[2].TXT [ /ADS.ONTECNIA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@TTO2.TRAFFICTRACK[1].TXT [ /TTO2.TRAFFICTRACK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ZBOX.ZANOX[2].TXT [ /ZBOX.ZANOX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.POINTROLL[2].TXT [ /ADS.POINTROLL ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@HITBOX[1].TXT [ /HITBOX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@INDEXTOOLS[1].TXT [ /INDEXTOOLS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@STATSE.WEBTRENDSLIVE[1].TXT [ /STATSE.WEBTRENDSLIVE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.71I[1].TXT [ /AD.71I ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADVIVA[2].TXT [ /ADVIVA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.ADSHOPPING[2].TXT [ /ADS.ADSHOPPING ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADINTERAX[1].TXT [ /ADINTERAX ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@PORNTUBE[2].TXT [ /PORNTUBE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.TUNINGSUCHE[1].TXT [ /ADS.TUNINGSUCHE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.KOMPLADS[2].TXT [ /ADS.KOMPLADS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.FETTSPIELEN[2].TXT [ /ADS.FETTSPIELEN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@E-2DJ6WGKYQJD5MAP.STATS.ESOMNITURE[2].TXT [ /E-2DJ6WGKYQJD5MAP.STATS.ESOMNITURE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADULTFRIENDFINDER[1].TXT [ /ADULTFRIENDFINDER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@STAT.DEALTIME[2].TXT [ /STAT.DEALTIME ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.ADNET[3].TXT [ /AD.ADNET ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@KOMTRACK[1].TXT [ /KOMTRACK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@DE2.KOMTRACK[2].TXT [ /DE2.KOMTRACK ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@SALES.LIVEPERSON[3].TXT [ /SALES.LIVEPERSON ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@YADRO[2].TXT [ /YADRO ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@MEDIA.MTVNSERVICES[1].TXT [ /MEDIA.MTVNSERVICES ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADREVOLVER[2].TXT [ /ADREVOLVER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.REVSCI[1].TXT [ /ADS.REVSCI ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@AD.BEEPWORLD[1].TXT [ /AD.BEEPWORLD ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS3.EXP[2].TXT [ /ADS3.EXP ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@GOSTATS[1].TXT [ /GOSTATS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADBRITE[1].TXT [ /ADBRITE ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@TACODA[2].TXT [ /TACODA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@DISCOUNT24.QUARTERSERVER[1].TXT [ /DISCOUNT24.QUARTERSERVER ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.JINKADS[1].TXT [ /ADS.JINKADS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@KUNDEN.WUNDERMEDIA[1].TXT [ /KUNDEN.WUNDERMEDIA ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WEBMASTERPLAN[1].TXT [ /WEBMASTERPLAN ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@ADS.HEIAS[1].TXT [ /ADS.HEIAS ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WWW.DISCOUNT24[2].TXT [ /WWW.DISCOUNT24 ]
        C:\USERS\Heistmer\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\Heistmer@WWW.DISCOUNT24[1].TXT [ /WWW.DISCOUNT24 ]


Trojan.Agent/Gen-Malintent
        C:\PROGRAM FILES (X86)\WINRAR\DEFAULT.SFX


cosinus 13.10.2012 17:05

Sieht ok aus, da wurden nur Cookies und Überreste gefunden, die können alle weg.
Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Heistmer 13.10.2012 20:19

Hab ich gelöscht.

Ja ich denke ich muss mal umdenken. Bisher hab ich Bisher hab ich den Rechner eingeschaltet gnutzt und ausgeschaltet. Pflege und Wartung kommt da auch mangels Zeit, bzw. einem bisher zu niedrigem Stellenwert viel zu kurz.
Nach dem Einschalten hat der Rechner bevor die ganzen Sachen durchgefürt wurden gute 5-8 min zum hochfahren gebraucht. Runter das gleiche noch mal. Das ist nun auf gut die hälfte geschrumpft :)
Ansonnsten alles wieder wie gewohnt möchte ich behaupten.

Vielen Dank.
Ich bin beindruckt von so viel Geduld, Hilfsbereitschaft und Arbeit mit Leuten wie mir, die trotz toller Anleitung immernoch blöde Fehler machen.

Meinen Respect muss ich auch für das Durcharbeiten seitenweiser Log's und vorallem dem dazugehörigem Wissen was es mit den Einträgen auf sich hat aussprechen.

Absolut Top.

cosinus 13.10.2012 21:54

Danke für die lobenden Worte! :daumenhoc

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 23:43 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131