Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme (https://www.trojaner-board.de/126563-habe-virus-weiss-ihn-weg-bekomme.html)

pkhoschi 05.11.2012 20:25

Ich habe einen Virus und weiss nicht wie ich Ihn weg bekomme
 
Hey zusammen. Ich habe ESET Smart Security 4 und mein Programm hat 4 Viren gefunden, jedoch bekomme ich die nicht weg. Gemerkt habe ich es, weil die Internet Browser total verlangsamt arbeiten.Bitte um Hilfe. Was braucht ihr für Angaben von mir um mir helfen zu können?Bin leider recht unerfahren was das an geht.

markusg 05.11.2012 20:33

hi
warum eset 4, aktuell ist eset 5 und es kommt bald version 6.
was hat eset wo gefunden, meldunge n als text posten.
danach bitte:
Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

pkhoschi 05.11.2012 20:37

Not Found

The requested URL /OTL.exe<br /> <br /> was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.


wird angezeigt

markusg 05.11.2012 20:38

nimm den link darunter bitte

pkhoschi 05.11.2012 20:40

ok...wird gemacht

sorry, bin ich zu blöd? Wie bekomme ich den Text aus dem Kasten in das vorgesehende Feld??

so, habe es hin bekommen...nun wird unten immer angezeigt: Pattern search-looking at file.....

wo finde ich otl.txt und extra.txt???

Zitat:

Zitat von markusg (Beitrag 950967)
nimm den link darunter bitte

bist du noch da und kannst du mir folgen?

markusg 05.11.2012 21:19

hi
das log sollte nach beendigung automatisch geöffnet werden, ist der scan denn schon durch?

pkhoschi 05.11.2012 21:20

hmmm?bitte um antwort

oh sorry, bin wohl zu ungeduldig...nein, läuft noch immer

markusg 05.11.2012 21:23

und bitte hör auf, dauernd solche posts wie "bitte um antwort" zu schreiben, du bist hier nicht der einzige

pkhoschi 05.11.2012 21:36

OTL EXTRAS Logfile:
Code:

OTL Extras logfile created on: 05.11.2012 20:56:58 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Krause\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 1,96 Gb Available Physical Memory | 50,61% Memory free
7,73 Gb Paging File | 5,68 Gb Available in Paging File | 73,55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,66 Gb Total Space | 15,35 Gb Free Space | 15,72% Space Free | Partition Type: NTFS
Drive E: | 354,82 Gb Total Space | 343,96 Gb Free Space | 96,94% Space Free | Partition Type: NTFS
 
Computer Name: KRAUSE-PC | User Name: Krause | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08684E36-85DA-468A-8814-C075D67F07A6}" = rport=137 | protocol=17 | dir=out | app=system |
"{142FEB28-227A-4E2D-B317-E43A8D8D28DD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1F005242-78D2-45E7-840F-8CD1C33FF7AF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{214310DF-113D-40F7-B35A-15FF17F23EE0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{24084DBF-B02E-4B92-B788-6AFB1A40D1D3}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3285E9FB-79C7-4B6A-BB8E-6D7ACA97985A}" = lport=139 | protocol=6 | dir=in | app=system |
"{3C4BCB6E-55CB-459E-BBD4-454B302BD245}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3CF1542A-4107-45E8-B535-2C4A9DEEC371}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4728117D-3CF5-4FD7-BA07-6C495333A245}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4C75F24A-DA1C-4241-9CC1-3183370D62F8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5096A66A-4350-4A94-A493-53FF8E3C9ED9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{52A61B78-74ED-446B-B7E0-0DA37A2D8BA9}" = rport=445 | protocol=6 | dir=out | app=system |
"{74B76843-1EBF-47F3-B722-6D50CB7C4821}" = rport=138 | protocol=17 | dir=out | app=system |
"{7D497508-EFF2-453D-8EFE-B0D730E3418A}" = rport=139 | protocol=6 | dir=out | app=system |
"{915C12EE-2E7A-4272-8299-0D96B953D0D9}" = lport=138 | protocol=17 | dir=in | app=system |
"{94BFFB5A-AD8B-44B2-9FE9-77DDB3063390}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9569EB65-0D16-4F58-945B-9E618A670396}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A172365D-7CC5-4A99-9811-D6C5063BF916}" = lport=445 | protocol=6 | dir=in | app=system |
"{A8048B73-E26E-4D15-8157-9407ED87C586}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A805E2CC-1BB0-4B11-947B-BC6EFA6A18DC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B8DE7CFB-665D-4F8B-A03A-3F6D31EB251B}" = lport=137 | protocol=17 | dir=in | app=system |
"{C013D6A8-90D2-4773-B7DE-704FF606C3B1}" = lport=10243 | protocol=6 | dir=in | app=system |
"{CC523978-3273-4441-975A-12C704AA6F53}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CCCF472B-40DF-4D41-A3D7-CB7F6366BAD5}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D2E24EBF-B1AE-412D-94C2-9BB9DFF6E5B6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02860ABA-C631-4F30-B93C-035D5D4E4C79}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{02D7460E-A7D8-4A2A-A18C-B5E78A4128BF}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{0BC4A608-501F-4E4F-9CEF-5FB9C99937BA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe |
"{12D04386-11B0-48AF-8CB0-2FC180F3BD4C}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{1EB3A79B-C27D-4B34-9374-23F46679F230}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{1FF9C696-E8BB-4F2A-B88B-FFC8C6AECC30}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqnrs08.exe |
"{2210BAB7-CA55-4DC1-AE29-2E1BCF543781}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe |
"{265961A2-1A33-4AAA-94CE-C9A4ECCAF275}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{290E0AA1-E9E1-4BBC-919C-A8A776C56E98}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{29C54221-6271-45D3-925F-55F1E1AFD1D1}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{2C94EE21-8F21-4D64-8802-6DBD96630572}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{35330B7B-BE70-41F6-9EF5-D67BA1849C8E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{359BA13E-B907-4BD7-B22B-DD47FAD13F00}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe |
"{38A11AC4-6E6F-45DD-95AB-4CAD6CC53F97}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |
"{3F0B93E4-0721-43D1-B476-F46F8D0F3D51}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{50743285-74B2-4B34-B5A2-D0F547873388}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{54673332-8659-48D0-A035-0F51C1EFFCCB}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{54ED9F68-160C-4558-A52D-1239B71AB697}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{55355A7D-3937-46FF-8AC3-484172BDA0E7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{57F35274-64B1-4873-A57D-611BE588EEA0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{580335E0-9BE5-4915-98C8-B3D30B0DB299}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5857A0C9-22E8-4E56-B21E-C6C5A7AAE293}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{5DCE8FD3-43D2-4938-8DA6-AFCC3CD80A8D}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{6372FA66-7E8F-4ACB-8610-BF54DCC355F6}" = protocol=6 | dir=in | app=c:\program files (x86)\sony ericsson\update service\update service.exe |
"{65679E58-F2CD-41F1-9F35-E4C360CCACE4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6ABF5604-EBCE-40BC-8E15-A1A4BDAC8FE8}" = protocol=17 | dir=in | app=c:\program files (x86)\sony ericsson\update service\update service.exe |
"{76B27807-A6F0-4AF5-A585-4002FC935E7D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
"{7806BDC5-B6C5-4134-87CC-9B5AADD5C521}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{7F145FF4-EAEF-4A13-B494-BB6067D4DCB7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{880290FB-9F8D-4CB9-AFD0-159001A0234F}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{897CA531-67D2-403B-A968-68FAFE5F3EC1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8A0E3D7B-1E63-4B00-A94F-D04C2D2AD080}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8C636446-98DE-440F-A638-B0B07DC284B4}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{8C7B7E33-E446-4DFA-AE71-D5CF81EE33C9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{8E3E128C-58B0-4E59-979B-F14E62A8EA21}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe |
"{942D5A7A-7074-4261-AC9A-1F2A857F1F06}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{9506BE76-5977-44D4-8614-6B8C4D427202}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{98BB1C66-DBE3-41AB-9CB1-C9162429DFDC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{99DC64AA-4424-42D9-9459-AB550159C2B6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{B0889D33-1398-4808-9219-24F960EB032C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{B2673B8B-4F0C-404A-9BC0-6FEC42841716}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{B42F98A0-5F02-4C17-847C-91CEDF489ED7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{B5738367-D299-4C56-8963-9EEAB294CD11}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{B7A08A26-5500-4DD4-9248-A7B341ED6DD6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BDE8709D-F138-4D51-8BB7-27C961EA78F2}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C0E2A896-EBED-44FB-8BBD-C2702271651F}" = protocol=6 | dir=out | app=system |
"{C2E717FC-FBCD-471A-A6C4-EC79FC5EDA81}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C724984E-B571-4846-9AE4-69F21D415005}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CD7D2A51-BB64-4AB6-9F07-29BF69C3979E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D14F0FDD-CF70-4BF0-B87C-249084C3939A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{D28BD9FE-7CF9-45A6-B998-DEE52D4F02F8}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{D8914F91-1602-44CB-9D7F-252B2DDD7342}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D9C3A163-3BB5-478F-8E9B-1197C847FEDF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DE81790A-B8F0-4CD0-8CF5-D61923388FDC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe |
"{F17B5892-19A8-4541-8D50-145BADAC73B0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F3C26471-889B-403D-B222-E60C0002F3AE}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F5C54985-1C10-473C-A4C2-F20763683483}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{F5FC2307-9240-4AE2-B716-5003164BEFED}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{F8F7647D-6E22-4AB3-B869-3D21D3799F8C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64726C2C-0B39-5D87-3117-E11F59C9460D}" = ccc-utility64
"{75FDB05A-C1C2-CD17-35CE-3C1A454CC79F}" = ATI Catalyst Install Manager
"{7810E7AD-E3ED-4967-809B-3AED87079723}" = 3D XML Player
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90140000-006D-0407-1000-0000000FF1CE}" = Microsoft Office Klick-und-Los 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D34D4CB-AF07-47AC-8A26-0AC085A4D8B5}" = ESET Smart Security
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{F2D07826-C7FD-4371-85CC-4923E13F26B8}" = Nitro Reader 2
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Shop for HP Supplies" = Shop for HP Supplies
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{098426AB-AF12-F225-15E1-0A6B5CB44625}" = CCC Help Spanish
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F32914F-A633-4516-B531-7084C8F19F93}" = Haufe iDesk-Browser
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{15B2BC56-D179-4450-84B9-7A8D7F4CE1B9}" = Lexware Info Service
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1AE3E621-E0C0-4aa1-B10B-B3E353A8D110}" = c3100_Help
"{1B192700-C368-49C1-BF81-D2F9BA065534}" = Catalyst Control Center - Branding
"{1DE498F3-1516-20E5-97A6-825B1B4C550A}" = CCC Help Korean
"{1DE4A2D1-BB3B-8AAB-85FA-950C2CC43D04}" = CCC Help Dutch
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{240FC90F-1CB2-4F34-9551-580B297EB4D7}" = Steuererklärung 2010
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{244E0BD1-F718-CAE3-CF72-AC80E14D0F00}" = CCC Help Japanese
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{27F10580-E040-11DF-8C28-005056B12123}" = Haufe iDesk-Service
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{300DFCBA-348B-4FD6-AE50-1D3CDFEE6314}" = MAGIX Speed burnR (MSI)
"{305D864B-2F21-63F0-19DC-407FCA0D57EC}" = PX Profile Update
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}" = Firebird SQL Server - MAGIX Edition
"{354038F6-0A35-4C55-A80B-F86C4C1A6D38}" = C3100
"{39C14B42-C152-8714-2AD5-181AB0552B94}" = CCC Help Finnish
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{43002AB2-B693-6BE0-C503-F4A65663D4DE}" = Catalyst Control Center Graphics Previews Vista
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{5645FB61-898F-4F59-AF80-52FEF3D63A64}" = HTC Sync
"{571B550F-C377-7C28-14C2-F53E0559C9F9}" = Catalyst Control Center InstallProxy
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1" = Acer GameZone Console
"{5C5A944F-096E-4ADD-B8E8-887F18BA6228}" = LEGO® Harry Potter™: Die Jahre 5-7
"{5E43F665-AA84-A378-2F47-CA68AAE8816C}" = CCC Help Czech
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F7ED0CD-E04E-4441-9E03-10AFDB654E96}_is1" = Werksfeuerwehr-Simulator Version 1.0
"{63F043DB-8643-AA02-7A4E-D319AC0B7EDE}" = CCC Help Swedish
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{68B3611D-CBF5-19E0-038F-C2B9CA8E741C}" = CCC Help Chinese Traditional
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{811E44BF-DD4F-859E-1ACA-CC5C8B2D1A4D}" = CCC Help Danish
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}" = Spin & Win
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}" = Poker Pop
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}" = Amazonia
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}" = Heroes of Hellas
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11505173}" = Airport Mania First Flight
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2
"{850C7BD3-9F3F-46AD-9396-E7985B38C55E}" = Windows Live Fotogalerie
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8861494F-7030-9F2E-6E4D-DD04F5D5589A}" = CCC Help Russian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140011-0066-0407-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - Deutsch
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-00AF-0407-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet-TV für Windows Media Center
"{A7496F46-78AE-4DB2-BCF5-95F210FA6F96}" = Windows Live Movie Maker
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A7BC15A6-FD50-5B42-6DDC-1E8FCEF4D5EF}" = CCC Help Norwegian
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A8B92DB3-B481-35C2-2A38-D2EF946DCE6B}" = Catalyst Control Center Localization All
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{ACA4DE44-9531-EF98-A1DB-9B81C0C5552C}" = CCC Help Greek
"{AED2DD42-9853-407E-A6BC-8A1D6B715909}" = Windows Live Messenger
"{B29F0C92-D258-60E1-CDCD-98B2426A849F}" = CCC Help German
"{B5ABE1F0-5F38-4EA6-BEAC-87EAC4D2FBD5}" = Steuer Hilfesammlung 2010
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C010177E-FBE7-8F26-73CA-9AB66F53D521}" = CCC Help Chinese Standard
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C44AA0C1-3D87-F8A5-D779-40925F7CF38B}" = CCC Help Italian
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{C6C7C290-9E0A-377B-BEBA-0BB556D5B6AD}" = CCC Help Turkish
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAFA57E8-8927-4912-AFCF-B0AA3837E989}" = Windows Live Essentials
"{CE68968C-6298-6DDA-7298-3439457A9AA2}" = CCC Help Polish
"{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}" = Acer Crystal Eye webcam Ver:1.1.192.810
"{D2041A37-5FEC-49F0-AE5C-3F2FFDFAA4F4}" = Windows Live Call
"{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}" = Bing Bar
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{DA236B20-EE6D-015F-1DB7-4885F558C859}" = ccc-core-static
"{DB85A80F-3A68-8C88-93E3-A3EDEE8F065E}" = CCC Help Thai
"{DC4E398E-6994-5657-E02E-88DDBE49FDD9}" = CCC Help French
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader
"{DDD2A0FD-BBB4-F996-CE0D-800859DDEE23}" = CCC Help English
"{DE42DFC0-1297-41D8-CFDC-A1779D400CF1}" = CCC Help Hungarian
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{ECEDCC15-9E49-8B32-CF40-3592FDF8F68C}" = CCC Help Portuguese
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Diashow XL_is1" = Diashow XL
"DivX Setup.divx.com" = DivX-Setup
"ElsterFormular 13.2.0.8623p" = ElsterFormular
"eMule" = eMule
"Glary Utilities_is1" = Glary Utilities 2.49.0.1600
"Identity Card" = Identity Card
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Acer Backup Manager
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"InstallShield_{DD89CE29-BC88-40C6-A845-E2548682C5D6}" = Alcor Micro USB Card Reader
"KeyFinder_is1" = Magical Jelly Bean KeyFinder
"LManager" = Launch Manager
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Mozilla Thunderbird 14.0 (x86 de)" = Mozilla Thunderbird 14.0 (x86 de)
"Office14.Click2Run" = Microsoft Office Klick-und-Los 2010
"RealPlayer 12.0" = RealPlayer
"Update Service" = Sony Ericsson Update Service
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite_Wave3" = Windows Live Essentials
"Zahlenbuch 3" = Zahlenbuch 3
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{206a7328-437f-4bd9-b53e-12bfee24d588}" = G-Filter
"Spotify" = Spotify
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 04.03.2012 14:02:02 | Computer Name = Krause-PC | Source = SideBySide | ID = 16842787
Description = Fehler beim Generieren des Aktivierungskontextes für "c:\program files
 (x86)\windows live\photo gallery\MovieMaker.Exe". Fehler in Manifest- oder Richtliniendatei
 "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" in Zeile  8.  Die
im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente
 überein.  Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition:
 WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Verwenden Sie
 das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
Error - 09.03.2012 14:15:01 | Computer Name = Krause-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version: 1.9.2.3989,
 Zeitstempel: 0x4cf928fc  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000222b2  ID des fehlerhaften
 Prozesses: 0xe5c  Startzeit der fehlerhaften Anwendung: 0x01ccfe20864b82bb  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Pfad
 des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: c920f246-6a13-11e1-9c45-206a8a1c4ea5
 
Error - 09.03.2012 14:17:50 | Computer Name = Krause-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: notepad.exe, Version: 6.1.7600.16385,
 Zeitstempel: 0x4a5bc60f  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000374  Fehleroffset: 0x000ce6c3  ID des fehlerhaften
 Prozesses: 0xe2c  Startzeit der fehlerhaften Anwendung: 0x01ccfe20d916fc57  Pfad der
 fehlerhaften Anwendung: C:\Windows\SysWOW64\notepad.exe  Pfad des fehlerhaften Moduls:
 C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: 2de23d61-6a14-11e1-8a6d-2a7c8f270689
 
Error - 09.03.2012 16:32:45 | Computer Name = Krause-PC | Source = Application Hang | ID = 1002
Description = Programm OneClick.exe, Version 10.0.4500.49 kann nicht mehr unter
Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in
 der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
zu suchen.    Prozess-ID: e70    Startzeit: 01ccfe32284f59e5    Endzeit: 92    Anwendungspfad: C:\Program
 Files (x86)\TuneUp Utilities 2011\OneClick.exe    Berichts-ID: f988594b-6a26-11e1-9a20-206a8a1c4ea5

 
Error - 10.03.2012 20:17:26 | Computer Name = Krause-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 1.9.2.3989 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 810    Startzeit:
01ccff14a4161faf    Endzeit: 31    Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID:
 8eb0f52c-6b0f-11e1-8456-206a8a1c4ea5 
 
Error - 10.03.2012 20:18:02 | Computer Name = Krause-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 1.9.2.3989 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 538    Startzeit:
01ccff1c57d6e609    Endzeit: 32    Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID:
 a715c85e-6b0f-11e1-8456-206a8a1c4ea5 
 
Error - 10.03.2012 20:18:02 | Computer Name = Krause-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: plugin-container.exe, Version: 1.9.2.3989,
 Zeitstempel: 0x4cf928fc  Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.17725,
 Zeitstempel: 0x4ec49b8f  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000222b2  ID des fehlerhaften
 Prozesses: 0xec8  Startzeit der fehlerhaften Anwendung: 0x01ccff1c5b8a70c7  Pfad der
 fehlerhaften Anwendung: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Pfad
 des fehlerhaften Moduls: C:\Windows\SysWOW64\ntdll.dll  Berichtskennung: a9deb6ce-6b0f-11e1-8456-206a8a1c4ea5
 
Error - 10.03.2012 20:20:15 | Computer Name = Krause-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 1.9.2.3989 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 67c    Startzeit:
01ccff1c6d54a786    Endzeit: 21    Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID:
 f545dc7b-6b0f-11e1-8456-206a8a1c4ea5 
 
Error - 10.03.2012 20:23:32 | Computer Name = Krause-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 1.9.2.3989 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 8f8    Startzeit:
01ccff1cbc72f3b7    Endzeit: 15    Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID:
 6b9cd36e-6b10-11e1-8456-206a8a1c4ea5 
 
Error - 10.03.2012 20:33:02 | Computer Name = Krause-PC | Source = Application Hang | ID = 1002
Description = Programm firefox.exe, Version 1.9.2.3989 kann nicht mehr unter Windows
 ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung,
 um nach weiteren Informationen zum Problem zu suchen.    Prozess-ID: 45c    Startzeit:
01ccff1d31a9ef6c    Endzeit: 24    Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID:
 be87423a-6b11-11e1-8456-206a8a1c4ea5 
 
[ Media Center Events ]
Error - 20.12.2010 16:09:17 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 21:09:17 - Fehler beim Herstellen der Internetverbindung.  21:09:17
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 20.12.2010 16:09:51 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 21:09:23 - Fehler beim Herstellen der Internetverbindung.  21:09:23
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 21.12.2010 09:43:23 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 14:43:19 - Fehler beim Herstellen der Internetverbindung.  14:43:19
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 06.01.2011 19:01:56 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 00:01:56 - Fehler beim Herstellen der Internetverbindung.  00:01:56
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 06.01.2011 19:02:08 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 00:02:04 - Fehler beim Herstellen der Internetverbindung.  00:02:04
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 12.01.2011 16:06:35 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 21:06:35 - Fehler beim Herstellen der Internetverbindung.  21:06:35
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 12.01.2011 16:06:42 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 21:06:40 - Fehler beim Herstellen der Internetverbindung.  21:06:40
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 22.01.2011 14:30:21 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 19:30:21 - Fehler beim Herstellen der Internetverbindung.  19:30:21
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 22.01.2011 14:30:56 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 19:30:50 - Fehler beim Herstellen der Internetverbindung.  19:30:50
-    Serververbindung konnte nicht hergestellt werden.. 
 
Error - 10.02.2011 16:09:09 | Computer Name = Krause-PC | Source = MCUpdate | ID = 0
Description = 21:09:09 - Directory konnte nicht abgerufen werden (Fehler: Die zugrunde
 liegende Verbindung wurde geschlossen: Unbekannter Fehler beim Empfangen..) 
 
[ System Events ]
Error - 28.10.2012 11:59:35 | Computer Name = Krause-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 28.10.2012 11:59:35 | Computer Name = Krause-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 28.10.2012 11:59:36 | Computer Name = Krause-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 28.10.2012 11:59:36 | Computer Name = Krause-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR3 gefunden.
 
Error - 30.10.2012 16:37:53 | Computer Name = Krause-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "dgderdrv" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 30.10.2012 16:40:36 | Computer Name = Krause-PC | Source = Service Control Manager | ID = 7000
Description = Der Dienst "dgderdrv" wurde aufgrund folgenden Fehlers nicht gestartet:
  %%2
 
Error - 03.11.2012 13:21:33 | Computer Name = Krause-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installationsfehler: Die Installation des folgenden Updates ist mit
 Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597
 (Definition 1.139.1150.0)
 
Error - 04.11.2012 09:36:28 | Computer Name = Krause-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 04.11.2012 09:36:35 | Computer Name = Krause-PC | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
 
Error - 04.11.2012 10:03:59 | Computer Name = Krause-PC | Source = DCOM | ID = 10010
Description =
 
 
< End of report >

--- --- ---

pkhoschi 05.11.2012 21:37

OTL Logfile:
Code:

OTL logfile created on: 05.11.2012 20:56:58 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Krause\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,86 Gb Total Physical Memory | 1,96 Gb Available Physical Memory | 50,61% Memory free
7,73 Gb Paging File | 5,68 Gb Available in Paging File | 73,55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,66 Gb Total Space | 15,35 Gb Free Space | 15,72% Space Free | Partition Type: NTFS
Drive E: | 354,82 Gb Total Space | 343,96 Gb Free Space | 96,94% Space Free | Partition Type: NTFS
 
Computer Name: KRAUSE-PC | User Name: Krause | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.11.05 20:38:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Krause\Desktop\OTL.exe
PRC - [2012.10.30 21:35:48 | 000,843,208 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2012.10.11 01:33:54 | 000,309,688 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2012.10.11 01:33:52 | 000,966,072 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2012.10.09 01:17:54 | 000,580,096 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe
PRC - [2012.08.13 12:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012.05.26 09:44:19 | 000,932,528 | ---- | M] () -- C:\Users\Krause\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2012.03.23 13:25:24 | 000,087,040 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2012.02.10 10:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe
PRC - [2012.01.18 13:02:04 | 000,508,136 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2011.10.01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011.10.01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011.01.07 22:09:32 | 000,585,728 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
PRC - [2011.01.06 16:01:31 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010.12.09 11:45:58 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winampa.exe
PRC - [2010.12.08 22:15:44 | 000,063,360 | ---- | M] (DivX, LLC) -- C:\Program Files (x86)\DivX\DivX Plus Web Player\DDMService.exe
PRC - [2010.11.04 17:15:50 | 000,810,144 | ---- | M] (ESET) -- C:\Programme\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2010.10.10 22:42:43 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2010.08.11 02:06:16 | 000,975,952 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010.08.11 02:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010.08.11 02:06:16 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010.06.28 23:23:12 | 000,265,984 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2010.06.28 23:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2010.05.27 03:41:24 | 000,349,552 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
PRC - [2010.05.27 03:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
PRC - [2010.03.11 06:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
PRC - [2010.03.11 06:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
PRC - [2010.03.03 13:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010.03.03 13:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010.01.29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Programme\Acer\Acer Updater\UpdaterService.exe
PRC - [2010.01.08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.10.30 21:24:26 | 000,221,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\26e0457a9776a0e9f23e3986686d90a5\System.ServiceProcess.ni.dll
MOD - [2012.10.30 21:22:39 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\b68bee05c7e518172982cc92059c3315\System.Xaml.ni.dll
MOD - [2012.10.30 21:17:06 | 018,019,840 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\d239f585ee55f833dbe21e897e1265ac\PresentationFramework.ni.dll
MOD - [2012.10.30 21:16:52 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\00a4922fbf869a79c043b665035516b6\System.Windows.Forms.ni.dll
MOD - [2012.10.30 21:16:52 | 011,522,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b7de318e9fd1ef519ca6c1f3b5dba8e0\PresentationCore.ni.dll
MOD - [2012.10.30 21:16:45 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\09bd2126bba2ab4f29ed52afde1470d7\System.Core.ni.dll
MOD - [2012.10.30 21:16:40 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9abe44a0f82070ead5f1256683a4d25a\System.Xml.ni.dll
MOD - [2012.10.30 21:16:39 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\a84262e1224189f93e10cd3c403a9527\System.Configuration.ni.dll
MOD - [2012.10.30 21:16:38 | 003,881,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a6e37a05b8d0cedbc5c3ea266ae3fc31\WindowsBase.ni.dll
MOD - [2012.10.30 21:16:36 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\4230ed1c7990e4ee8352baf67a2a85fa\System.Drawing.ni.dll
MOD - [2012.10.30 21:16:34 | 009,092,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\a6be120e49f895ef6b00e9918402395b\System.ni.dll
MOD - [2012.10.30 21:16:28 | 014,414,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\c1af4ec9a36f671617a8ecaec00373f4\mscorlib.ni.dll
MOD - [2012.09.16 18:19:18 | 006,277,832 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2012.05.26 09:44:19 | 000,932,528 | ---- | M] () -- C:\Users\Krause\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
MOD - [2011.01.07 22:09:34 | 000,516,599 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll
MOD - [2011.01.07 22:09:32 | 000,585,728 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
MOD - [2011.01.07 22:09:32 | 000,352,256 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\HtcDetect.dll
MOD - [2011.01.07 22:09:32 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll
MOD - [2011.01.07 22:09:32 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll
MOD - [2011.01.07 22:09:32 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll
MOD - [2011.01.06 16:01:31 | 001,017,304 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
MOD - [2010.10.10 22:42:43 | 000,206,208 | ---- | M] () -- C:\Windows\PLFSetI.exe
MOD - [2010.06.28 23:20:54 | 000,465,576 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
MOD - [2009.05.20 23:02:04 | 000,072,200 | ---- | M] () -- C:\Program Files (x86)\Launch Manager\CdDirIo.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2012.10.30 20:59:52 | 000,119,808 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\GFilterSvc.exe -- (GFilterSvc)
SRV:64bit: - [2012.10.30 20:59:47 | 000,111,616 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\actjveds.exe -- (SndVol64)
SRV:64bit: - [2010.08.26 07:41:16 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.08.13 12:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.25 18:59:16 | 000,204,304 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Programme\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe -- (NitroReaderDriverReadSpool2)
SRV - [2012.03.23 13:25:24 | 000,087,040 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2012.02.10 10:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe -- (BBUpdate)
SRV - [2012.02.10 10:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe -- (BBSvc)
SRV - [2011.10.01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011.10.01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010.11.04 17:18:12 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Programme\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010.11.04 17:15:50 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Programme\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV - [2010.08.11 02:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010.06.28 23:23:06 | 000,255,744 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010.06.11 13:27:26 | 000,868,896 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2010.06.01 23:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010.05.27 03:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [Auto | Running] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.03 13:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010.03.03 13:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010.01.29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Programme\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010.01.08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009.09.20 11:55:20 | 001,037,824 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2009.08.27 16:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.08.07 10:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2012.09.20 05:35:36 | 000,203,104 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012.09.20 05:35:36 | 000,102,368 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.10.01 08:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011.10.01 08:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011.10.01 08:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011.10.01 08:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.02.22 19:26:54 | 000,034,032 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\seehcri.sys -- (seehcri)
DRV:64bit: - [2011.02.22 19:26:39 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
DRV:64bit: - [2011.02.22 19:26:39 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
DRV:64bit: - [2011.02.18 15:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.09.03 06:13:46 | 000,170,104 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2010.08.26 09:50:48 | 006,856,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.08.26 07:05:44 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.08.16 15:42:00 | 000,116,240 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010.07.29 12:31:26 | 000,171,152 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:64bit: - [2010.07.29 12:31:26 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2010.07.29 12:31:26 | 000,050,624 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:64bit: - [2010.07.29 12:31:26 | 000,033,632 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\epfwndis.sys -- (Epfwndis)
DRV:64bit: - [2010.06.25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2010.06.10 21:57:20 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2010.06.08 03:36:18 | 000,406,056 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
DRV:64bit: - [2010.05.12 03:11:38 | 002,229,608 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2010.04.28 23:21:38 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2010.04.28 23:21:38 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2010.03.04 03:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.11.01 19:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009.10.22 05:55:06 | 000,272,432 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2009.09.17 11:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2009.06.20 03:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E)
DRV:64bit: - [2009.06.10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009.06.10 21:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.03 03:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009.06.03 03:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009.06.03 03:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Hotmail, Skype Download und Messenger sowie Nachrichten, Unterhaltung, Video, Sport, Lifestyle, Finanzen, Auto uvm. bei MSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Babylon Search
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=109958&tt=4412_5&babsrc=SP_ss&mntrId=c6d7688e0000000000002a7c8f270689
IE - HKCU\..\SearchScopes\{3EFBD2C2-B971-47B5-9DC7-7F74EC77F047}: "URL" = hxxp://www.google.de/search?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: "Productivity 2.1 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2903600&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Productivity 2.1 Customized Web Search"
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.51
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {c44f9e21-d93f-490c-b41c-b3548bdd19fc}:3.8.0.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:6.2.0.10687
FF - prefs.js..network.proxy.type: 0
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@3ds.com/3dxml: C:\Program Files\Dassault Systemes\3D XML Player\win_b64\code\bin\NP3DXMLPlugin.dll ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@3ds.com/3dxml: C:\Program Files\Dassault Systemes\3D XML Player\win_b64\code\bin32\NP3DXMLPlugin.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.11.27 14:10:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.12.10 17:10:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2010.12.23 19:10:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2010.12.23 19:10:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.04.14 16:51:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.04.14 16:51:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012.09.13 19:54:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2011.04.14 16:51:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.11.26 19:08:36 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.11.27 14:10:01 | 000,000,000 | ---D | M]
 
[2011.03.31 14:56:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krause\AppData\Roaming\mozilla\Extensions
[2010.12.09 20:20:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krause\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.03.31 14:56:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krause\AppData\Roaming\mozilla\Extensions\ideskbrowser@haufe.de
[2012.11.04 20:54:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krause\AppData\Roaming\mozilla\Firefox\Profiles\dj5w8jkh.default\extensions
[2011.11.28 21:24:09 | 000,000,000 | ---D | M] (Productivity 2.1 Community Toolbar) -- C:\Users\Krause\AppData\Roaming\mozilla\Firefox\Profiles\dj5w8jkh.default\extensions\{c44f9e21-d93f-490c-b41c-b3548bdd19fc}
[2011.11.12 14:41:24 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Krause\AppData\Roaming\mozilla\Firefox\Profiles\dj5w8jkh.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2012.10.30 21:00:17 | 000,002,536 | ---- | M] () -- C:\Users\Krause\AppData\Roaming\mozilla\firefox\profiles\dj5w8jkh.default\searchplugins\browsemngr.xml
[2011.01.10 12:55:34 | 000,000,935 | ---- | M] () -- C:\Users\Krause\AppData\Roaming\mozilla\firefox\profiles\dj5w8jkh.default\searchplugins\conduit.xml
[2012.09.12 10:28:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.09.12 10:29:00 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.02.23 18:07:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2012.04.02 12:49:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2010.12.23 19:10:06 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO
[2010.12.23 19:10:06 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA
[2010.11.27 14:10:01 | 000,000,000 | ---D | M] (HP Smart Web Printing) -- C:\PROGRAM FILES (X86)\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON3
File not found (No name found) -- C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
[2012.04.02 12:49:19 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010.12.09 11:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010.10.27 06:44:13 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.10.30 20:59:54 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2010.10.27 06:44:13 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2010.10.27 06:44:13 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.10.27 06:44:13 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.10.27 06:44:13 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: Google
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: Google
CHR - Extension: DivX HiQ = C:\Users\Krause\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Krause\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0\
CHR - Extension: Skype Click to Call = C:\Users\Krause\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.2.0.10687_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Krause\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.0.900_0\
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Programme\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKCU..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Samsung Electronics)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Krause\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{398E2C31-F499-437E-B290-953A2DB48003}: NameServer = 62.109.123.7 213.191.92.86
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF75B72D-7840-42BB-A6CA-C93297F7E0B1}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\haufereader - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\haufereader - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
 
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.11.05 20:38:07 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Krause\Desktop\OTL.exe
[2012.10.30 22:33:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump
[2012.10.30 21:44:10 | 000,000,000 | ---D | C] -- C:\Temp
[2012.10.30 21:41:42 | 000,203,104 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudmdm.sys
[2012.10.30 21:39:21 | 000,102,368 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2012.10.30 21:26:29 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\NativeFus_Log
[2012.10.30 21:26:23 | 000,000,000 | ---D | C] -- C:\Users\Krause\AppData\Local\Samsung
[2012.10.30 21:26:21 | 000,000,000 | ---D | C] -- C:\Users\Krause\AppData\Roaming\Samsung
[2012.10.30 21:26:16 | 000,000,000 | ---D | C] -- C:\Users\Krause\Documents\samsung
[2012.10.30 21:20:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2012.10.30 21:20:18 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll
[2012.10.30 21:20:11 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\SysWow64\dgderapi.dll
[2012.10.30 21:20:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2012.10.30 21:18:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2012.10.30 21:18:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung
[2012.10.30 21:03:30 | 000,000,000 | ---D | C] -- C:\Users\Krause\AppData\Local\InstallShare
[2012.10.30 21:00:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Browser Manager
[2012.10.30 21:00:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BabylonToolbar
[2012.10.30 20:59:34 | 000,000,000 | ---D | C] -- C:\Users\Krause\AppData\Roaming\Babylon
[2012.10.30 20:59:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012.10.22 18:35:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Werksfeuerwehr-Simulator
[2012.10.22 18:34:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Werksfeuerwehr-Simulator
 
========== Files - Modified Within 30 Days ==========
 
[2012.11.05 20:38:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Krause\Desktop\OTL.exe
[2012.11.05 20:37:12 | 000,001,110 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.11.05 19:57:53 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.11.05 19:57:53 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.11.05 19:56:05 | 001,500,294 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.11.05 19:56:05 | 000,654,852 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.11.05 19:56:05 | 000,616,694 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.11.05 19:56:05 | 000,130,434 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.11.05 19:56:05 | 000,106,816 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.11.05 19:50:42 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2012.11.05 19:50:41 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.11.05 19:50:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.11.05 19:50:18 | 3111,514,112 | -HS- | M] () -- C:\hiberfil.sys
[2012.10.30 21:26:15 | 000,001,996 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012.10.30 21:09:29 | 000,001,042 | ---- | M] () -- C:\Users\Krause\Desktop\Installation von Samsung Kies fortsetzen.lnk
[2012.10.30 20:59:52 | 000,119,808 | ---- | M] () -- C:\Windows\SysNative\GFilterSvc.exe
[2012.10.30 20:59:47 | 000,111,616 | ---- | M] () -- C:\Windows\SysNative\actjveds.exe
[2012.10.22 18:35:35 | 000,001,168 | ---- | M] () -- C:\Users\Public\Desktop\Werksfeuerwehr-Simulator.lnk
 
========== Files Created - No Company Name ==========
 
[2012.10.30 21:26:15 | 000,001,996 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012.10.30 21:03:30 | 000,001,042 | ---- | C] () -- C:\Users\Krause\Desktop\Installation von Samsung Kies fortsetzen.lnk
[2012.10.30 20:59:52 | 000,119,808 | ---- | C] () -- C:\Windows\SysNative\GFilterSvc.exe
[2012.10.30 20:59:47 | 000,111,616 | ---- | C] () -- C:\Windows\SysNative\actjveds.exe
[2012.10.22 18:35:35 | 000,001,168 | ---- | C] () -- C:\Users\Public\Desktop\Werksfeuerwehr-Simulator.lnk
[2012.09.26 20:57:16 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012.09.26 20:57:14 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012.09.26 20:57:14 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012.09.26 20:57:14 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012.09.26 20:57:14 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012.06.30 22:04:16 | 000,024,488 | ---- | C] () -- C:\Users\Krause\.recently-used.xbel
[2011.07.03 21:25:29 | 000,000,028 | ---- | C] () -- C:\Windows\Robota.INI
[2011.02.09 11:50:32 | 000,004,608 | ---- | C] () -- C:\Users\Krause\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.12.17 17:13:52 | 000,185,781 | ---- | C] () -- C:\Users\Krause\AppData\Roaming\UserTile.png
[2010.12.12 15:34:58 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.12.01 15:27:47 | 001,527,912 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.11.27 14:05:35 | 000,226,450 | ---- | C] () -- C:\Windows\hpoins18.dat
[2010.11.27 14:05:35 | 000,005,355 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2010.11.26 23:35:38 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.09.16 00:41:45 | 000,131,984 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.06.09 18:15:14 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\.minecraft
[2012.10.30 20:59:34 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Babylon
[2011.07.02 14:31:58 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Canneverbe Limited
[2012.03.05 19:54:08 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\DassaultSystemes
[2012.03.29 20:23:38 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Downloaded Installations
[2011.11.20 00:04:17 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Ebzu
[2012.04.23 16:59:06 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\elsterformular
[2010.11.26 19:09:54 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\ESET
[2012.09.16 15:50:48 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\GlarySoft
[2012.06.30 22:04:16 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\gtk-2.0
[2011.11.20 00:35:12 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Hafeuzb
[2011.03.31 14:56:37 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Haufe Mediengruppe
[2011.03.09 20:48:31 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\HTC
[2011.03.09 20:48:36 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012.06.02 19:40:44 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\IN-MEDIAKG
[2011.03.31 14:55:30 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Lexware
[2010.12.23 19:10:07 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Local
[2011.07.03 21:43:51 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\MAGIX
[2012.06.03 01:02:52 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\mresreg
[2012.06.02 23:44:39 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Nitro PDF
[2011.07.08 18:26:34 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\OpenCandy
[2012.04.26 19:01:37 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\pdfforge
[2012.10.30 21:26:29 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Samsung
[2012.11.03 21:39:54 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\SoftGrid Client
[2012.06.03 19:03:52 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Spotify
[2010.12.09 20:20:08 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\Thunderbird
[2010.12.01 15:28:16 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\TP
[2011.07.02 15:06:07 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\TuneUp Software
[2012.09.30 14:37:28 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\WB Games
[2010.12.27 23:51:43 | 000,000,000 | ---D | M] -- C:\Users\Krause\AppData\Roaming\{90140011-0066-0407-0000-0000000FF1CE}
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*. >
[2011.01.08 18:24:30 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2010.10.10 22:48:41 | 000,000,000 | ---D | M] -- C:\BOOK
[2012.10.30 21:20:08 | 000,000,000 | -H-D | M] -- C:\Config.Msi
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2010.11.25 19:17:46 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2010.11.25 19:19:13 | 000,000,000 | ---D | M] -- C:\elements
[2010.09.16 01:40:06 | 000,000,000 | ---D | M] -- C:\Intel
[2012.03.09 20:12:10 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2011.07.03 20:26:33 | 000,000,000 | -H-D | M] -- C:\MyWinLockerData
[2010.11.25 19:18:12 | 000,000,000 | -H-D | M] -- C:\oem
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2012.03.05 19:53:08 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.10.30 21:20:11 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2012.10.30 21:18:51 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2010.11.25 19:17:46 | 000,000,000 | -HSD | M] -- C:\Programme
[2010.11.25 19:17:46 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012.11.05 21:00:02 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2012.10.30 21:44:10 | 000,000,000 | ---D | M] -- C:\Temp
[2010.11.25 19:17:52 | 000,000,000 | R--D | M] -- C:\Users
[2012.11.04 15:33:13 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< C:\Windows\system32\*.tsp >
[2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 02:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.20 13:16:53 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010.12.06 18:49:31 | 000,001,106 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2010.12.06 18:49:31 | 000,001,110 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.09.10 16:36:21 | 000,000,328 | ---- | C] () -- C:\Windows\Tasks\GlaryInitialize.job
[2012.09.29 18:13:24 | 000,000,300 | ---- | C] () -- C:\Windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1227247490-993995614-759896167-1000.job
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010.09.16 01:25:38 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010.09.16 01:37:02 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.09.16 01:25:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010.09.16 01:37:02 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010.09.16 01:25:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010.09.16 01:37:02 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010.09.16 01:25:38 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010.09.16 01:37:02 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2010.03.04 04:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- C:\oem\Preload\Autorun\DRV\AHCI\F6\f6flpy-x86\iaStor.sys
[2010.03.04 04:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\oem\Preload\Autorun\DRV\AHCI\F6\f6flpy-x64\iaStor.sys
[2010.03.04 03:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.03.04 03:51:40 | 000,540,696 | ---- | M] (Intel Corporation) MD5=ABBF174CB394F5C437410A788B7E404A -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_78ebae21a80aa2b4\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010.09.16 01:25:38 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010.09.16 01:25:38 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %USERPROFILE%\*.* >
[2012.06.30 22:04:16 | 000,024,488 | ---- | M] () -- C:\Users\Krause\.recently-used.xbel
[2012.11.05 21:22:23 | 004,718,592 | -HS- | M] () -- C:\Users\Krause\ntuser.dat
[2012.11.05 21:22:23 | 000,262,144 | -HS- | M] () -- C:\Users\Krause\ntuser.dat.LOG1
[2010.11.25 19:17:52 | 000,000,000 | -HS- | M] () -- C:\Users\Krause\ntuser.dat.LOG2
[2010.11.25 21:00:50 | 000,065,536 | -HS- | M] () -- C:\Users\Krause\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010.11.25 21:00:50 | 000,524,288 | -HS- | M] () -- C:\Users\Krause\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010.11.25 21:00:50 | 000,524,288 | -HS- | M] () -- C:\Users\Krause\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010.12.20 21:00:15 | 000,065,536 | -HS- | M] () -- C:\Users\Krause\ntuser.dat{131139d0-0c6c-11e0-8d51-206a8a1c4ea5}.TM.blf
[2010.12.20 21:00:15 | 000,524,288 | -HS- | M] () -- C:\Users\Krause\ntuser.dat{131139d0-0c6c-11e0-8d51-206a8a1c4ea5}.TMContainer00000000000000000001.regtrans-ms
[2010.12.20 21:00:15 | 000,524,288 | -HS- | M] () -- C:\Users\Krause\ntuser.dat{131139d0-0c6c-11e0-8d51-206a8a1c4ea5}.TMContainer00000000000000000002.regtrans-ms
[2012.03.09 22:52:40 | 000,065,536 | -HS- | M] () -- C:\Users\Krause\ntuser.dat{4958247a-6a1b-11e1-a4ea-b006d0c6eee6}.TM.blf
[2012.03.09 22:52:40 | 000,524,288 | -HS- | M] () -- C:\Users\Krause\ntuser.dat{4958247a-6a1b-11e1-a4ea-b006d0c6eee6}.TMContainer00000000000000000001.regtrans-ms
[2012.03.09 22:52:40 | 000,524,288 | -HS- | M] () -- C:\Users\Krause\ntuser.dat{4958247a-6a1b-11e1-a4ea-b006d0c6eee6}.TMContainer00000000000000000002.regtrans-ms
[2010.11.25 19:17:53 | 000,000,020 | -HS- | M] () -- C:\Users\Krause\ntuser.ini
 
< %USERPROFILE%\Local Settings\Temp\*.exe >
 
< %USERPROFILE%\Local Settings\Temp\*.dll >
 
< %USERPROFILE%\Application Data\*.exe >
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:E3C56885

< End of report >

--- --- ---

markusg 05.11.2012 21:43

jetzt fehlen noch die eset fundmeldungen

pkhoschi 05.11.2012 21:46

C:\hiberfil.sys - Fehler beim Öffnen
C:\pagefile.sys - Fehler beim Öffnen
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.A1FFBB52_4F2E_44F1_8614_5D66C2EF43F0 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.03A77D79_488A_445D_B528_0E0089E3FCB3 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.D495C848_F235_46BF_A9A0_77D7C2120E3B = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.445237FC_7259_4EAD_ACEF_7ED7A95D32D7 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.79A89863_540B_470E_9C71_D57F22BFA44D = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.5ACB9F6A_C06C_4121_B854_7133C2ED29A8 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.15989D71_6BEB_424A_88DF_78A882081F91 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.1C571119_9D2B_4542_84BD_0CD3AA24E739 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.C4EB4D09_95BA_4DC2_9551_B6E637DA2230 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.C39C5B26_ED03_4B04_9CFD_166FDC7523D1 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.C05C46CB_E961_4BBA_86BE_4FE1A4426A32 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.87E45AFF_C0E7_4B6E_8E37_52EEB71BF5B7 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.E34CAC5A_4546_4E3A_BFFA_CE28E0CED140 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.14AFC4D4_5454_4AD5_B7FC_10D4FAB85CF3 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.B4924446_617C_4229_8C33_089CD780544D = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.F02247A4_BA3B_4A1D_B7EA_2CB2F17490B7 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.0F75E4D6_4C58_47F6_B626_BA408BA6F03B = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.B3E4ACDE_961E_474B_87CC_22A67A5E77CB = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.D8256176_51D5_41D4_B965_C7B0BC9E4A27 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht.D073AD43_9C5B_4759_A404_ED1717BEEAD7 = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\oem\Preload\Autorun\APP\NTI\Data1.cab = CAB = ls_hsi.msi = MSI = Data1.cab = CAB = Getting_Started.mht = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll = PECompact v2.xx - Fehler beim Entpacken
C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleUpdateHelper.msi = MSI = required.cab = CAB - Fehler beim Lesen des Archivs
C:\Program Files (x86)\Haufe\iDesk\iDeskService\Zope\lib\python\dateutil\zoneinfo\zoneinfo-2007k.tar.gz = GZIP = /home/niemeyer/src/dateutil/dateutil/zoneinfo/zoneinfo-2007k.tar = TAR = Atlantic/Faeroe = TAR = Atlantic/Jan_Mayen - Fehler beim Lesen des Archivs
C:\Program Files (x86)\Haufe\iDesk\iDeskService\Zope\lib\python\dateutil\zoneinfo\zoneinfo-2007k.tar.gz = GZIP = /home/niemeyer/src/dateutil/dateutil/zoneinfo/zoneinfo-2007k.tar = TAR = - Archiv beschädigt
C:\ProgramData\Microsoft\Application Virtualization Client\SoftGrid Client\sftfs.fsd - Fehler beim Öffnen
C:\ProgramData\Microsoft\Application Virtualization Client\SoftGrid Client\sftfs.fsG - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\Keys\82173eb19f3886440cb73f1e94145005_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\05760608a788c765386508dd5c30027f_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\083aba52a526842f081dcc478dcf2181_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0dbbdd9933966b373306ed21e72e6c52_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\56633099cb42473864b75f70107391b9_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a0b291ec3b42c1162a9dd38d0fdc8174_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ac4fbb3a904113d5fa9fb1a2688c5b54_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e2f355fbba0b3531bc5f2f83564c6ac3_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f5cdecc1f16454b2822dcca19dee6fdf_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\ProgramData\TuneUp Software\TuneUp Utilities 2011\TTUSvc.tt - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Application Virtualization Client\SoftGrid Client\sftfs.fsd - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Application Virtualization Client\SoftGrid Client\sftfs.fsG - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\Keys\82173eb19f3886440cb73f1e94145005_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\05760608a788c765386508dd5c30027f_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\083aba52a526842f081dcc478dcf2181_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0dbbdd9933966b373306ed21e72e6c52_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\56633099cb42473864b75f70107391b9_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a0b291ec3b42c1162a9dd38d0fdc8174_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ac4fbb3a904113d5fa9fb1a2688c5b54_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e2f355fbba0b3531bc5f2f83564c6ac3_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f5cdecc1f16454b2822dcca19dee6fdf_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_45c54437-7349-4636-bee7-85ad5158694c - Fehler beim Öffnen
C:\Users\All Users\TuneUp Software\TuneUp Utilities 2011\TTUSvc.tt - Fehler beim Öffnen
C:\Users\Krause\ntuser.dat - Fehler beim Öffnen
C:\Users\Krause\ntuser.dat.LOG1 - Fehler beim Öffnen
C:\Users\Krause\ntuser.dat.LOG2 - Fehler beim Öffnen
C:\Users\Krause\AppData\Local\InstallShare\11_264_installer.exe - Variante von Win32/InstallShare.A evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans
C:\Users\Krause\AppData\Local\Microsoft\Windows\UsrClass.dat - Fehler beim Öffnen
C:\Users\Krause\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - Fehler beim Öffnen
C:\Users\Krause\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - Fehler beim Öffnen
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MSETA2PY\flash_animation[1].swf = CWS = file.swf - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MEIRYOB.TTC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90chs.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90cht.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90deu.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90enu.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90esn.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90esp.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90fra.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90ita.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90jpn.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90kor.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90rus.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfc90u.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfcm90.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = mfcm90u.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MSO.DLL.x86 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MSOINTL.DLL.IDX_DLL.x86.1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MSOINTL.DLL.x86.1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MSOINTL.REST.IDX_DLL.x86.1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MSORES.DLL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MSOSHEXT.DLL.x86 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = MSPTLS.DLL_0001 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = msvcm90.dll.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = msvcp90.dll.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = msvcr90.dll.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_atl90.dll.0901F145_82C9_3BF6_A91B_31F6791950EA - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90.dll.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90chs.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90cht.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90deu.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90enu.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90esn.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90esp.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90fra.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90ita.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90jpn.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90kor.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90rus.dll.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfc90u.dll.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfcm90.dll.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_mfcm90u.dll.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_msvcm90.dll.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_msvcp90.dll.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = nosxs_msvcr90.dll.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = OART.DLL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = OFFICE.ODF - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = OGL.DLL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = OLBINTL.DLL_0001_1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = policy.30729.4148.policy_9_0_Microsoft_VC90_ATL_x86.QFE.36F772C3_DEA7_32C0_AD18_338903366207 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = policy.30729.4148.policy_9_0_Microsoft_VC90_CRT_x86.QFE.EB5BA578_FF7F_3863_8E53_7A003222B7FC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = policy.30729.4148.policy_9_0_Microsoft_VC90_MFC_x86.QFE.71F730CE_8B24_3BC2_83EA_36396DE29B9E - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = policy.30729.4148.policy_9_0_Microsoft_VC90_MFCLOC_x86.QFE.036BF802_B20B_38B9_9A44_2CF929804212 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = PPINTL.DLL.IDX_DLL_1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = PPINTL.DLL_1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = PPINTL.REST.IDX_DLL_1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = PPTVIEW.EXE_0001 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = PPTVIEW.MAN_0001 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = PVREADME.HTM_1031 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = RICHED20.DLL_0001 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = SAEXT.DLL - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_atl90.dll.30729.4148.Microsoft_VC90_ATL_x86.QFE.0901F145_82C9_3BF6_A91B_31F6791950EA - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.Microsoft_VC90_ATL_x86.QFE.0901F145_82C9_3BF6_A91B_31F6791950EA - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.policy_9_0_Microsoft_VC90_ATL_x86.QFE.36F772C3_DEA7_32C0_AD18_338903366207 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.policy_9_0_Microsoft_VC90_CRT_x86.QFE.EB5BA578_FF7F_3863_8E53_7A003222B7FC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.policy_9_0_Microsoft_VC90_MFC_x86.QFE.71F730CE_8B24_3BC2_83EA_36396DE29B9E - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_catalog.30729.4148.policy_9_0_Microsoft_VC90_MFCLOC_x86.QFE.036BF802_B20B_38B9_9A44_2CF929804212 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_manifest.30729.4148.Microsoft_VC90_ATL_x86.QFE.0901F145_82C9_3BF6_A91B_31F6791950EA - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_manifest.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_manifest.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_manifest.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90chs.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90cht.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90deu.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90enu.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90esn.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90esp.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90fra.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90ita.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90jpn.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90kor.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90rus.dll.30729.4148.Microsoft_VC90_MFCLOC_x86.QFE.1D3B0A01_2635_3323_932D_3D66D5C4B0FD - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfc90u.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfcm90.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_mfcm90u.dll.30729.4148.Microsoft_VC90_MFC_x86.QFE.1B1242B0_08E9_3D59_826D_ADAA4BB763B5 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_msvcm90.dll.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_msvcp90.dll.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_msvcr90.dll.30729.4148.Microsoft_VC90_CRT_x86.QFE.AA2EBBCC_4E3B_3442_865E_7BB3E9F45F0C - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_policy.30729.4148.policy_9_0_Microsoft_VC90_ATL_x86.QFE.36F772C3_DEA7_32C0_AD18_338903366207 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_policy.30729.4148.policy_9_0_Microsoft_VC90_CRT_x86.QFE.EB5BA578_FF7F_3863_8E53_7A003222B7FC - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_policy.30729.4148.policy_9_0_Microsoft_VC90_MFC_x86.QFE.71F730CE_8B24_3BC2_83EA_36396DE29B9E - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = ul_policy.30729.4148.policy_9_0_Microsoft_VC90_MFCLOC_x86.QFE.036BF802_B20B_38B9_9A44_2CF929804212 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.cab = CAB = USP10.DLL_0002 - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = ppviewer.msi - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OZFBKR15\PowerPointViewer[1].exe = CAB = files14.cat - Archiv beschädigt - Datei kann nicht extrahiert werden
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Sentinel\WLMailSearchSentinel.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Peters emails\26E901EB-00000001.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Sent Items\0F3E0099-00000005.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Sent Items\16496DF1-00000006.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Sent Items\26060184-00000003.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Sent Items\31264583-00000001.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Sent Items\5AF141BB-00000002.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Sent Items\7FBE3D21-00000004.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\11-28-2010 823\Freenet (pk a28\Posteingang\2CD672AE-0F9DAD4F.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\11-28-2010 823\Freenet (pk a28\Posteingang\4AE13D6C-EBEE1205.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\11-28-2010 823\Freenet (pk a28\Posteingang\69525F90-9EEE1658.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\12-02-2010 29\Outbox\18BE6784-E6BEE959.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\12-06-2010 29\Freenet (pk a28\Posteingang\67844AE1-2509DDF4.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\12-15-2010 1a9\Freenet (pk a28\Posteingang\329875C4-8F9ECB64.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\12-15-2010 1a9\Freenet (pk a28\Posteingang\75607A43-863F398A.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Live Mail\Storage Folders\Wiederherge 29\12-15-2010 1a9\Freenet (pk a28\Posteingang\78F763EA-C5D6902C.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\2C40303A-00000001.eml = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Local\Mozilla\Firefox\Profiles\dj5w8jkh.default\Cache\6B1D09BEd01 = GZIP = 6B1D09BEd01 - Archiv beschädigt
C:\Users\Krause\AppData\Local\Mozilla\Firefox\Profiles\dj5w8jkh.default\Cache\94D2ACE5d01 = GZIP = 94D2ACE5d01 - Archiv beschädigt
C:\Users\Krause\AppData\Local\Mozilla\Firefox\Profiles\dj5w8jkh.default\Cache\CCE1AC00d01 = GZIP = CCE1AC00d01 - Archiv beschädigt
C:\Users\Krause\AppData\Local\Mozilla\Firefox\Profiles\dj5w8jkh.default\Cache\EAA2710Ed01 = GZIP = EAA2710Ed01 - Archiv beschädigt
C:\Users\Krause\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\41792dcb-2783e8fe = ZIP = ER.class - Variante von Java/Exploit.Blacole.AN Trojaner
C:\Users\Krause\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\41792dcb-2783e8fe = ZIP = c.class - Java/Exploit.Blacole.EL Trojaner
C:\Users\Krause\AppData\Roaming\Apple Computer\MobileSync\Backup\cc7e173850ee4c4a21d6c874a15590ce4e87d3dd\b4a35db83c713b0c07735b1f85f7d320403e504e = MIME - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Mozilla\Firefox\Profiles\dj5w8jkh.default\parent.lock - Fehler beim Öffnen
C:\Users\Krause\AppData\Roaming\Mozilla\Firefox\Profiles\dj5w8jkh.default\conduitCommon\alert\Dialogs.zip = ZIP = Dialogs/AppNotificationDialog/Images/light/Next.png - Archiv beschädigt
C:\Users\Krause\AppData\Roaming\Skype\shared_dynco\dc.lock - Fehler beim Öffnen
C:\Users\Krause\AppData\Roaming\Skype\shared_httpfe\queue.lock - Fehler beim Öffnen
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\parent.lock - Fehler beim Öffnen
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\ImapMail\mx.freenet-3.de\INBOX = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\ImapMail\mx.freenet-4.de\INBOX = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\ImapMail\mx.freenet.de\INBOX = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\ImapMail\mx.freenet.de\INBOX.sbd\ESET Antispam = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\Local Folders\Drafts = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\mx.freenet-1.de\Drafts = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\mx.freenet-1.de\ESET Antispam = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\mx.freenet-1.de\Inbox = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\mx.freenet-1.de\Sent = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\mx.freenet-1.de\Trash = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\mx.freenet.de\Drafts = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\mx.freenet.de\Inbox = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\pop.mail.yahoo.com\Drafts = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\pop.mail.yahoo.com\ESET Antispam = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\pop.mail.yahoo.com\Inbox = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\pop.mail.yahoo.com\Sent = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\AppData\Roaming\Thunderbird\Profiles\y7gaawxf.default\Mail\pop.mail.yahoo.com\Trash = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\Desktop\ImapMail\mx.freenet.de\INBOX = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\Desktop\ImapMail\mx.freenet.de\INBOX.sbd\ESET Antispam = MBOX - - OK (eingebettete Archive NICHT geprüft)
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgBody.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgBodyLarge.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgButton.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgButtonFinished.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgCloseProgram.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgDownloadBarEmpty.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgDownloadBarError.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgDownloadBarFull.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgHeaderError.gif - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/bgListBullet.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/buttonCenter.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/buttonCenterHighlight.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/buttonLeft.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/buttonLeftHighlight.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/buttonRight.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/buttonRightHighlight.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/iconBlank.gif - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/iconComplete.gif - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/iconError.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/iconHeader.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/jspArrowDown.gif - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/jspArrowUp.gif - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/logoAdobe.gif - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = images/stencil.png - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _css/default.css - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _css/jquery.jscrollpane.css - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _css/openx.css - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/app.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/bundleloader.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/host.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/httpdownload.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/interop.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/jshelper.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/json2.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/oserror.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/skinwindow.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/skinwindowprompt.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/textfilereader.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _host/textfilewriter.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionairappexists.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionairappinstall.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionairruntimeexists.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actioncheckreaderversion.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actioncheckuninstall.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actiondiskspace.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actiondownload.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actiondownloadadobe.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actiongccheck.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actiongtbcheck.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionitem.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionlaunch.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionlaunchadobe.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionlaunchchrome.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionlaunchflashplayer.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionlaunchreader.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionlist.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionregistrykeypathcheck.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/actionregistryvaluecheck.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/adobe.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/authenticate.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/index.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/jquery.hasevent.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/jquery.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/jquery.jscrollpane.min.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/jquery.mousewheel.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-cs.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-da.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-de.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-es.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-fi.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-fr.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-it.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-ja.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-ko.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-nl.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-no.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-pl.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-pt.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-ru.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-sv.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-tr.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-zh-cn.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language-zh-tw.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/language.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/mwheelIntent.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/ping.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = _js/sitecatalyst.js - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = app.config.xml - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = bundles.json - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = download.solidconfig - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = downloader.bundle - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = gccheck.exe - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = language-zh-tw.xml - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = language.xml - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = launcher.bundle - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = logo.ico - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = openx.html - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\install_flashplayer10x32_mssd_aih.exe = ZIP = window.config.xml - Fehler - Datei ist passwortgeschützt
C:\Users\Krause\Downloads\Minecraft.exe = ZIP = - Archiv beschädigt
C:\Users\Krause\Downloads\TuneUp.Utilities.2012.v12.0.2160.11.German.Incl.Keymaker-CORE\TuneUp.Utilities.2012.v12.0.2160.11.German.Incl.Keymaker-CORE\setup.part1.rar = RAR = setup.exe - Teildatei des gesplitteten Archivs nicht gefunden
C:\Windows\Installer\6638b.msi = MSI = required.cab = CAB - Fehler beim Lesen des Archivs
C:\Windows\Logs\CBS\CBS.log - Fehler beim Öffnen
C:\Windows\Logs\DPX\setupact.log - Fehler beim Öffnen
C:\Windows\Logs\DPX\setuperr.log - Fehler beim Öffnen
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config - Fehler beim Öffnen
C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe.config - Fehler beim Öffnen
C:\Windows\Panther\UnattendGC\diagerr.xml - Fehler beim Öffnen
C:\Windows\Panther\UnattendGC\diagwrn.xml - Fehler beim Öffnen
C:\Windows\Panther\UnattendGC\setupact.log - Fehler beim Öffnen
C:\Windows\Panther\UnattendGC\setuperr.log - Fehler beim Öffnen
C:\Windows\PLA\System\System Diagnostics.xml - Fehler beim Öffnen
C:\Windows\PLA\System\System Performance.xml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\DeviceRedirection.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\EnhancedStorage.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\inetres.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\NCSI.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\RacWmiProv.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\ReAgent.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\sdiageng.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\sdiagschd.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\Search.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\ShapeCollector.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\WindowsMediaDRM.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\WindowsMediaPlayer.admx - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\DeviceRedirection.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\EnhancedStorage.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\InetRes.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\NCSI.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\RacWmiProv.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\ReAgent.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\sdiageng.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\sdiagschd.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\Search.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\ShapeCollector.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\WindowsMediaDRM.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\de-DE\WindowsMediaPlayer.adml - Fehler beim Öffnen
C:\Windows\PolicyDefinitions\en-US\InetRes.adml - Fehler beim Öffnen
C:\Windows\security\database\secedit.sdb - Fehler beim Öffnen
C:\Windows\System32\log.txt - Fehler beim Öffnen
C:\Windows\System32\catroot2\edb.log - Fehler beim Öffnen
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - Fehler beim Öffnen
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - Fehler beim Öffnen
C:\Windows\SysWOW64\log.txt - Fehler beim Öffnen
C:\Windows\Tasks\GlaryInitialize.job - Fehler beim Öffnen
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job - Fehler beim Öffnen
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job - Fehler beim Öffnen
C:\Windows\winsxs\amd64_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.1.7600.16385_none_2d2382534fb0bdfa\dnary.xsd - Fehler beim Öffnen
C:\Windows\winsxs\amd64_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.1.7601.17514_none_2f54961b4c9f4194\dnary.xsd - Fehler beim Öffnen
D:\ - Fehler beim Öffnen
E:\Eigene Bilder\37 Designs For Sony Ericsson k800I.exe = ZIP = 37 Designs for Sony Ericsson K800i/Miami Vice.thm = TAR = - Archiv beschädigt
E:\Eigene Bilder\Peter\htc\MP3_2011_9_27_8.apk = ZIP = classes.dex - Variante von Android/Adware.AirPush.C Anwendung
E:\Eigene Bilder\Peter\htc\WG_ Formeinlage J 191-194.msg = MIME - - OK (eingebettete Archive NICHT geprüft)

markusg 05.11.2012 21:50

ich sehe da nur zwei fundmeldungen, gabs noch weitere logs?

pkhoschi 05.11.2012 22:10

bei mir zeigt eset 4 meldungen an:
E:\Eigene Bilder\Peter\htc\MP3_2011_9_27_8.apk = ZIP = classes.dex - Variante von Android/Adware.AirPush.C Anwendung
C:\Users\Krause\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\41792dcb-2783e8fe = ZIP = c.class - Java/Exploit.Blacole.EL Trojaner
C:\Users\Krause\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\41792dcb-2783e8fe = ZIP = ER.class - Variante von Java/Exploit.Blacole.AN Trojaner
C:\Users\Krause\AppData\Local\InstallShare\11_264_installer.exe - Variante von Win32/InstallShare.A evtl. unerwünschte Anwendung - Aktionsauswahl aufgeschoben bis zum Abschluss des Scans

markusg 05.11.2012 22:11

ok das ist bisher nichts weiter tragisches
Combofix darf ausschließlich ausgeführt werden, wenn dies von einem Team Mitglied angewiesen wurde!
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich
ziehen und eine Bereinigung der Infektion noch erschweren.
Downloade dir bitte Combofix von einem dieser Downloadspiegel

Link 1
Link 2


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

pkhoschi 05.11.2012 22:20

soll ich die firewall während dessen auch deaktivieren?

markusg 05.11.2012 22:26

jepp, wenn möglich alle programme, die im hintergrund aktiev sind.
sollte combofix dann trotzdem anzeigen, dass antimalware software aktiv is, einfach weiter mit ok

pkhoschi 05.11.2012 22:36

Bin mal gespannt. Kann ich das Programm eigentlich immer wieder verwenden? Combofix?

markusg 05.11.2012 22:44

nein. steht ja auch in der anleitung

pkhoschi 05.11.2012 22:50

Wer lesen kann, ist klar im Vorteil. ..lach. Stufe 32. Wie viele stufen sind es? Eine Frage noch, meinst du eset ist eine gute software? Wieso konnte eset nicht das problem lösen?

markusg 05.11.2012 22:53

weil du zb eset 4 nutzt aktuell aber eset 5 ist.
malware software sollte sowieso immer die letzte möglichkeit sein, das dazugehörige system muss schon von sich aus gut konfiguriert sein, dazu später

pkhoschi 05.11.2012 22:57

Combofix Logfile:
Code:

ComboFix 12-11-05.03 - Krause 05.11.2012  22:24:14.1.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.3956.2087 [GMT 1:00]
ausgeführt von:: c:\users\Krause\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal Firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\10.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\11.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\2.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\3.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\4.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\5.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\596e0bd6255c81826771d599c49a9aeb.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\6.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\7.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\8.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\aoe-narnia_intro.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e07.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e08.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e10.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\deli-lostxvid-s06e11.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\FILE4CD3AF47E2FC5.plong.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\FILE8842594C04C27.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\kinowelt-sexcity2-xvid700.avi.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Post_Install_RB_HiQ_de.divx.ddr
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\596e0bd6255c81826771d599c49a9aeb.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\aoe-narnia_intro.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e07.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e08.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e10.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\deli-lostxvid-s06e11.avi
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\FILE4CD3AF47E2FC5.plong.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\FILE8842594C04C27.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\kinowelt-sexcity2-xvid.avi(2).ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\kinowelt-sexcity2-xvid.avi.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\kinowelt-sexcity2-xvid700.avi.ddp
c:\users\Krause\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Post_Install_RB_HiQ_de.divx
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\muzapp.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-10-05 bis 2012-11-05  ))))))))))))))))))))))))))))))
.
.
2012-11-05 21:52 . 2012-11-05 21:52        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-11-04 13:45 . 2012-11-05 19:38        69000        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{8F63BD03-D84B-4381-ACDA-EC883BB2EDE1}\offreg.dll
2012-11-03 17:24 . 2012-10-12 07:19        9291768        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{8F63BD03-D84B-4381-ACDA-EC883BB2EDE1}\mpengine.dll
2012-10-30 20:44 . 2012-10-30 20:44        --------        d-----w-        C:\Temp
2012-10-30 20:41 . 2012-09-20 04:35        203104        ----a-w-        c:\windows\system32\drivers\ssudmdm.sys
2012-10-30 20:39 . 2012-09-20 04:35        102368        ----a-w-        c:\windows\system32\drivers\ssudbus.sys
2012-10-30 20:26 . 2012-10-30 20:26        --------        d-----w-        c:\users\Krause\AppData\Local\Samsung
2012-10-30 20:26 . 2012-10-30 20:26        --------        d-----w-        c:\users\Krause\AppData\Roaming\Samsung
2012-10-30 20:20 . 2012-09-26 19:57        4659712        ----a-w-        c:\windows\SysWow64\Redemption.dll
2012-10-30 20:20 . 2012-10-30 20:20        --------        d-----w-        c:\program files (x86)\MarkAny
2012-10-30 20:20 . 2012-09-26 19:57        821824        ----a-w-        c:\windows\SysWow64\dgderapi.dll
2012-10-30 20:18 . 2012-10-30 20:21        --------        d-----w-        c:\program files (x86)\Samsung
2012-10-30 20:18 . 2012-10-30 20:20        --------        d-----w-        c:\programdata\Samsung
2012-10-30 20:03 . 2012-10-30 20:03        --------        d-----w-        c:\users\Krause\AppData\Local\InstallShare
2012-10-30 20:00 . 2012-10-30 20:00        --------        d-----w-        c:\programdata\Browser Manager
2012-10-30 20:00 . 2012-10-30 20:00        --------        d-----w-        c:\program files (x86)\BabylonToolbar
2012-10-30 19:59 . 2012-10-30 19:59        119808        ----a-w-        c:\windows\system32\GFilterSvc.exe
2012-10-30 19:59 . 2012-10-30 19:59        111616        ----a-w-        c:\windows\system32\actjveds.exe
2012-10-30 19:59 . 2012-10-30 19:59        --------        d-----w-        c:\users\Krause\AppData\Roaming\Babylon
2012-10-30 19:59 . 2012-10-30 19:59        --------        d-----w-        c:\programdata\Babylon
2012-10-22 17:34 . 2012-10-22 17:34        --------        d-----w-        c:\program files (x86)\Werksfeuerwehr-Simulator
2012-10-14 15:25 . 2012-10-14 15:27        696760        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-11 19:01 . 2012-08-31 18:19        1659760        ----a-w-        c:\windows\system32\drivers\ntfs.sys
2012-10-11 19:01 . 2012-08-30 18:03        5559664        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-10-11 19:01 . 2012-08-30 17:12        3914096        ----a-w-        c:\windows\SysWow64\ntoskrnl.exe
2012-10-11 19:01 . 2012-08-30 17:12        3968880        ----a-w-        c:\windows\SysWow64\ntkrnlpa.exe
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-14 15:27 . 2012-09-16 17:19        73656        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-12 09:32 . 2010-11-26 20:24        65309168        ----a-w-        c:\windows\system32\MRT.exe
2012-09-26 19:57 . 2012-09-26 19:57        90112        ----a-w-        c:\windows\MAMCityDownload.ocx
2012-09-26 19:57 . 2012-09-26 19:57        330240        ----a-w-        c:\windows\MASetupCaller.dll
2012-09-26 19:57 . 2012-09-26 19:57        30568        ----a-w-        c:\windows\MusiccityDownload.exe
2012-09-26 19:57 . 2012-09-26 19:57        974848        ----a-w-        c:\windows\SysWow64\cis-2.4.dll
2012-09-26 19:57 . 2012-09-26 19:57        81920        ----a-w-        c:\windows\SysWow64\issacapi_bs-2.3.dll
2012-09-26 19:57 . 2012-09-26 19:57        65536        ----a-w-        c:\windows\SysWow64\issacapi_pe-2.3.dll
2012-09-26 19:57 . 2012-09-26 19:57        57344        ----a-w-        c:\windows\SysWow64\MTXSYNCICON.dll
2012-09-26 19:57 . 2012-09-26 19:57        57344        ----a-w-        c:\windows\SysWow64\MK_Lyric.dll
2012-09-26 19:57 . 2012-09-26 19:57        57344        ----a-w-        c:\windows\SysWow64\issacapi_se-2.3.dll
2012-09-26 19:57 . 2012-09-26 19:57        569344        ----a-w-        c:\windows\SysWow64\muzdecode.ax
2012-09-26 19:57 . 2012-09-26 19:57        491520        ----a-w-        c:\windows\SysWow64\muzapp.dll
2012-09-26 19:57 . 2012-09-26 19:57        49152        ----a-w-        c:\windows\SysWow64\MaJGUILib.dll
2012-09-26 19:57 . 2012-09-26 19:57        45320        ----a-w-        c:\windows\SysWow64\MAMACExtract.dll
2012-09-26 19:57 . 2012-09-26 19:57        45056        ----a-w-        c:\windows\SysWow64\MaXMLProto.dll
2012-09-26 19:57 . 2012-09-26 19:57        45056        ----a-w-        c:\windows\SysWow64\MACXMLProto.dll
2012-09-26 19:57 . 2012-09-26 19:57        40960        ----a-w-        c:\windows\SysWow64\MTTELECHIP.dll
2012-09-26 19:57 . 2012-09-26 19:57        352256        ----a-w-        c:\windows\SysWow64\MSLUR71.dll
2012-09-26 19:57 . 2012-09-26 19:57        258048        ----a-w-        c:\windows\SysWow64\muzoggsp.ax
2012-09-26 19:57 . 2012-09-26 19:57        245760        ----a-w-        c:\windows\SysWow64\MSCLib.dll
2012-09-26 19:57 . 2012-09-26 19:57        24576        ----a-w-        c:\windows\SysWow64\MASetupCleaner.exe
2012-09-26 19:57 . 2012-09-26 19:57        200704        ----a-w-        c:\windows\SysWow64\muzwmts.dll
2012-09-26 19:57 . 2012-09-26 19:57        155648        ----a-w-        c:\windows\SysWow64\MSFLib.dll
2012-09-26 19:57 . 2012-09-26 19:57        143360        ----a-w-        c:\windows\SysWow64\3DAudio.ax
2012-09-26 19:57 . 2012-09-26 19:57        135168        ----a-w-        c:\windows\SysWow64\muzaf1.dll
2012-09-26 19:57 . 2012-09-26 19:57        131072        ----a-w-        c:\windows\SysWow64\muzmpgsp.ax
2012-09-26 19:57 . 2012-09-26 19:57        122880        ----a-w-        c:\windows\SysWow64\muzeffect.ax
2012-09-26 19:57 . 2012-09-26 19:57        118784        ----a-w-        c:\windows\SysWow64\MaDRM.dll
2012-09-26 19:57 . 2012-09-26 19:57        110592        ----a-w-        c:\windows\SysWow64\muzmp4sp.ax
2012-09-16 15:40 . 2012-09-16 15:40        9232584        ----a-w-        c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-08-24 11:15 . 2012-09-25 15:01        17810944        ----a-w-        c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-25 15:01        10925568        ----a-w-        c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-25 15:01        2312704        ----a-w-        c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-25 15:01        1346048        ----a-w-        c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-25 15:01        1392128        ----a-w-        c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-25 15:01        1494528        ----a-w-        c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-25 15:01        237056        ----a-w-        c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-25 15:01        85504        ----a-w-        c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-25 15:01        173056        ----a-w-        c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-25 15:01        816640        ----a-w-        c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-25 15:01        599040        ----a-w-        c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-25 15:01        2144768        ----a-w-        c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-25 15:01        729088        ----a-w-        c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-25 15:01        96768        ----a-w-        c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-25 15:01        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-25 15:01        248320        ----a-w-        c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-25 15:01        1800704        ----a-w-        c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-25 15:01        1129472        ----a-w-        c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-25 15:01        1427968        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-25 15:01        142848        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-25 15:01        420864        ----a-w-        c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-25 15:01        2382848        ----a-w-        c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 13:57        1913200        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 13:57        950128        ----a-w-        c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 13:57        376688        ----a-w-        c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 13:57        288624        ----a-w-        c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-27 19:49        245760        ----a-w-        c:\windows\system32\OxpsConverter.exe
2012-08-20 17:38 . 2012-10-11 19:00        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 02:40        120176        ----a-w-        c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"Spotify Web Helper"="c:\users\Krause\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-26 932528]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-10-11 966072]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-10-09 580096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-06-28 265984]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-25 98304]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-11 975952]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"DivX Download Manager"="c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-12-09 74752]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-07 585728]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-10-11 309688]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~3\BROWSE~1\23796~1.11\{16CDF~1\browsemngr.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"LexwareInfoService"=c:\program files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R2 SndVol64;Application Microsoft-Tunnelminiport-Adaptertreiber Shellhardwareerkennung;c:\windows\system32\actjveds.exe [2012-10-30 111616]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2010-06-10 40448]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-20 102368]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2011-02-22 13352]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-01 33736]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2010-04-17 50432]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-20 203104]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-02-18 51712]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-17 1255736]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-26 203264]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-11 321104]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-09-03 170104]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2010-11-04 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 50624]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 868896]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 GFilterSvc;G-Filter Service;c:\windows\System32\GFilterSvc.exe [2012-10-30 119808]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-03-25 204304]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-06-28 255744]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2010-04-17 144640]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-03-23 87040]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-08-16 116240]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2010-06-08 406056]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2011-02-22 34032]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt        REG_MULTI_SZ          hpqcxs08 hpqddsvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-11-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2012-09-10 19:59]
.
2012-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-06 17:49]
.
2012-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-06 17:49]
.
2012-09-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1227247490-993995614-759896167-1000.job
- c:\program files (x86)\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 02:42        137584        ----a-w-        c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-06-10 324608]
"mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-07-29 11101800]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-10-10 206208]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-10-22 325120]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 861216]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-11-04 2919168]
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://search.babylon.com/?affID=109958&tt=4412_5&babsrc=HP_ss&mntrId=c6d7688e0000000000002a7c8f270689
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://acer.msn.com
mStart Page = hxxp://acer.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{398E2C31-F499-437E-B290-953A2DB48003}: NameServer = 62.109.123.7 213.191.92.86
FF - ProfilePath - c:\users\Krause\AppData\Roaming\Mozilla\Firefox\Profiles\dj5w8jkh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2903600&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Productivity 2.1 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=c6d7688e0000000000002a7c8f270689&q=
FF - user.js: extensions.BabylonToolbar.id - c6d7688e0000000000002a7c8f270689
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15643
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.3.8
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.3.8
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.3.821:00
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109958&tt=4412_5
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2012-11-05  22:54:50
ComboFix-quarantined-files.txt  2012-11-05 21:54
.
Vor Suchlauf: 10 Verzeichnis(se), 16.234.598.400 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 15.779.516.416 Bytes frei
.
- - End Of File - - 1F79326DDCE577603F2D03F62B22EA29

--- --- ---


fertig...nun herunter fahren?

Keine Fehlermeldung erhalten. Und wie gehts weiter? Man, Respekt, ihr habt echt was drauf.

So, muss mich für heute verabschieden. Werde morgen wieder hier rein schauen um zu sehen wie wir weiter machen. Bis hierher schon mal schönen Dank.

Moin moin. Wo waren wir gestern stehen geblieben??

markusg 07.11.2012 00:32

download tdss killer:
http://www.trojaner-board.de/82358-t...entfernen.html
Klicke auf Change parameters
• Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system
• Klick auf OK und anschließend auf Start scan
- bei funden erst mal immer skip wählen, log posten

pkhoschi 07.11.2012 17:58

da sind einige Funde, aber ich bekomme die logs nicht kopiert um sie weiterzuleiten oder so.

markusg 07.11.2012 19:12

computer öffnen, c:
tdss-killer-datum-version.txt öffnen, log kopieren und posten

pkhoschi 07.11.2012 23:44

18:08:35.0863 3788 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
18:08:36.0129 3788 ============================================================
18:08:36.0129 3788 Current date / time: 2012/11/07 18:08:36.0129
18:08:36.0129 3788 SystemInfo:
18:08:36.0129 3788
18:08:36.0129 3788 OS Version: 6.1.7601 ServicePack: 1.0
18:08:36.0129 3788 Product type: Workstation
18:08:36.0129 3788 ComputerName: KRAUSE-PC
18:08:36.0129 3788 UserName: Krause
18:08:36.0129 3788 Windows directory: C:\Windows
18:08:36.0129 3788 System windows directory: C:\Windows
18:08:36.0129 3788 Running under WOW64
18:08:36.0129 3788 Processor architecture: Intel x64
18:08:36.0129 3788 Number of processors: 4
18:08:36.0129 3788 Page size: 0x1000
18:08:36.0129 3788 Boot type: Normal boot
18:08:36.0129 3788 ============================================================
18:08:36.0487 3788 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:08:36.0487 3788 ============================================================
18:08:36.0487 3788 \Device\Harddisk0\DR0:
18:08:36.0487 3788 MBR partitions:
18:08:36.0487 3788 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1A5E800, BlocksNum 0x32000
18:08:36.0487 3788 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1A90800, BlocksNum 0xC350030
18:08:36.0503 3788 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xDDE1800, BlocksNum 0x2C5A4000
18:08:36.0503 3788 ============================================================
18:08:36.0550 3788 C: <-> \Device\Harddisk0\DR0\Partition2
18:08:36.0581 3788 E: <-> \Device\Harddisk0\DR0\Partition3
18:08:36.0581 3788 ============================================================
18:08:36.0581 3788 Initialize success
18:08:36.0581 3788 ============================================================
18:09:03.0226 4732 ============================================================
18:09:03.0226 4732 Scan started
18:09:03.0226 4732 Mode: Manual; SigCheck; TDLFS;
18:09:03.0226 4732 ============================================================
18:09:03.0460 4732 ================ Scan system memory ========================
18:09:03.0460 4732 System memory - ok
18:09:03.0460 4732 ================ Scan services =============================
18:09:03.0616 4732 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:09:03.0709 4732 1394ohci - ok
18:09:03.0756 4732 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:09:03.0787 4732 ACPI - ok
18:09:03.0834 4732 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:09:03.0850 4732 AcpiPmi - ok
18:09:03.0912 4732 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:09:03.0959 4732 adp94xx - ok
18:09:03.0975 4732 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:09:04.0006 4732 adpahci - ok
18:09:04.0037 4732 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:09:04.0068 4732 adpu320 - ok
18:09:04.0115 4732 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:09:04.0193 4732 AeLookupSvc - ok
18:09:04.0255 4732 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
18:09:04.0287 4732 AFD - ok
18:09:04.0318 4732 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
18:09:04.0333 4732 agp440 - ok
18:09:04.0396 4732 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
18:09:04.0411 4732 ALG - ok
18:09:04.0458 4732 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
18:09:04.0474 4732 aliide - ok
18:09:04.0521 4732 [ FF779F9DE1CDF477033858B7681CEDA8 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
18:09:04.0536 4732 AMD External Events Utility - ok
18:09:04.0567 4732 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
18:09:04.0583 4732 amdide - ok
18:09:04.0614 4732 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
18:09:04.0630 4732 AmdK8 - ok
18:09:04.0817 4732 [ EF2B99DCEE397B45F50594696D7B5339 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:09:04.0911 4732 amdkmdag - ok
18:09:04.0926 4732 [ 239DCE60BEE6E1576C803948AB4D54C5 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
18:09:04.0942 4732 amdkmdap - ok
18:09:04.0973 4732 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
18:09:04.0989 4732 AmdPPM - ok
18:09:05.0020 4732 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
18:09:05.0035 4732 amdsata - ok
18:09:05.0067 4732 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
18:09:05.0129 4732 amdsbs - ok
18:09:05.0145 4732 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
18:09:05.0176 4732 amdxata - ok
18:09:05.0238 4732 [ 391887990CDAA83DE5C56C3FDE966DA1 ] AmUStor C:\Windows\system32\drivers\AmUStor.SYS
18:09:05.0254 4732 AmUStor - ok
18:09:05.0285 4732 [ FAB590E0FC28CB474B965F8267458E14 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
18:09:05.0363 4732 ApfiltrService - ok
18:09:05.0394 4732 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
18:09:05.0457 4732 AppID - ok
18:09:05.0488 4732 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
18:09:05.0581 4732 AppIDSvc - ok
18:09:05.0613 4732 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
18:09:05.0691 4732 Appinfo - ok
18:09:05.0784 4732 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:09:05.0800 4732 Apple Mobile Device - ok
18:09:05.0862 4732 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
18:09:05.0893 4732 arc - ok
18:09:05.0909 4732 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
18:09:05.0925 4732 arcsas - ok
18:09:05.0971 4732 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:09:06.0018 4732 AsyncMac - ok
18:09:06.0049 4732 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
18:09:06.0065 4732 atapi - ok
18:09:06.0159 4732 [ E642491F64E58CD5BC8FB8B347DCF65F ] athr C:\Windows\system32\DRIVERS\athrx.sys
18:09:06.0252 4732 athr - ok
18:09:06.0315 4732 [ FDA1E117A7E880BFF5540D180C06EA87 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
18:09:06.0330 4732 AtiHDAudioService - ok
18:09:06.0393 4732 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:09:06.0502 4732 AudioEndpointBuilder - ok
18:09:06.0517 4732 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
18:09:06.0595 4732 AudioSrv - ok
18:09:06.0642 4732 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
18:09:06.0673 4732 AxInstSV - ok
18:09:06.0736 4732 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
18:09:06.0767 4732 b06bdrv - ok
18:09:06.0814 4732 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
18:09:06.0845 4732 b57nd60a - ok
18:09:06.0970 4732 [ A2494901E7226B356B8C1005C45F1C5F ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe
18:09:06.0985 4732 BBSvc - ok
18:09:07.0048 4732 [ 63B1CBBAE4790B5BAC98F01BF9449722 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe
18:09:07.0079 4732 BBUpdate - ok
18:09:07.0141 4732 [ 9E84A931DBEE0292E38ED672F6293A99 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
18:09:07.0188 4732 BCM43XX - ok
18:09:07.0219 4732 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
18:09:07.0235 4732 BDESVC - ok
18:09:07.0282 4732 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
18:09:07.0329 4732 Beep - ok
18:09:07.0375 4732 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
18:09:07.0453 4732 BFE - ok
18:09:07.0485 4732 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
18:09:07.0531 4732 BITS - ok
18:09:07.0547 4732 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
18:09:07.0609 4732 blbdrive - ok
18:09:07.0656 4732 [ F2060A34C8A75BC24A9222EB4F8C07BD ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
18:09:07.0687 4732 Bonjour Service - ok
18:09:07.0719 4732 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:09:07.0734 4732 bowser - ok
18:09:07.0765 4732 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:09:07.0797 4732 BrFiltLo - ok
18:09:07.0828 4732 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:09:07.0843 4732 BrFiltUp - ok
18:09:07.0875 4732 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
18:09:07.0953 4732 BridgeMP - ok
18:09:07.0984 4732 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
18:09:08.0015 4732 Browser - ok
18:09:08.0046 4732 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
18:09:08.0077 4732 Brserid - ok
18:09:08.0093 4732 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
18:09:08.0140 4732 BrSerWdm - ok
18:09:08.0155 4732 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
18:09:08.0171 4732 BrUsbMdm - ok
18:09:08.0187 4732 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
18:09:08.0202 4732 BrUsbSer - ok
18:09:08.0218 4732 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
18:09:08.0265 4732 BTHMODEM - ok
18:09:08.0343 4732 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
18:09:08.0421 4732 bthserv - ok
18:09:08.0467 4732 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:09:08.0530 4732 cdfs - ok
18:09:08.0561 4732 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys
18:09:08.0592 4732 cdrom - ok
18:09:08.0623 4732 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
18:09:08.0701 4732 CertPropSvc - ok
18:09:08.0733 4732 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:09:08.0764 4732 circlass - ok
18:09:08.0811 4732 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
18:09:08.0842 4732 CLFS - ok
18:09:08.0904 4732 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:09:08.0920 4732 clr_optimization_v2.0.50727_32 - ok
18:09:08.0982 4732 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
18:09:09.0013 4732 clr_optimization_v2.0.50727_64 - ok
18:09:09.0123 4732 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:09:09.0154 4732 clr_optimization_v4.0.30319_32 - ok
18:09:09.0185 4732 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
18:09:09.0201 4732 clr_optimization_v4.0.30319_64 - ok
18:09:09.0232 4732 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:09:09.0247 4732 CmBatt - ok
18:09:09.0279 4732 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:09:09.0294 4732 cmdide - ok
18:09:09.0341 4732 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
18:09:09.0388 4732 CNG - ok
18:09:09.0419 4732 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:09:09.0450 4732 Compbatt - ok
18:09:09.0481 4732 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:09:09.0513 4732 CompositeBus - ok
18:09:09.0544 4732 COMSysApp - ok
18:09:09.0559 4732 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:09:09.0575 4732 crcdisk - ok
18:09:09.0622 4732 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:09:09.0653 4732 CryptSvc - ok
18:09:09.0762 4732 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
18:09:09.0793 4732 cvhsvc - ok
18:09:09.0856 4732 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
18:09:09.0934 4732 DcomLaunch - ok
18:09:09.0981 4732 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
18:09:10.0027 4732 defragsvc - ok
18:09:10.0059 4732 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:09:10.0090 4732 DfsC - ok
18:09:10.0121 4732 dgderdrv - ok
18:09:10.0168 4732 [ B9430166FEB246F6070A62B3554932C9 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
18:09:10.0183 4732 dg_ssudbus - ok
18:09:10.0230 4732 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
18:09:10.0308 4732 Dhcp - ok
18:09:10.0339 4732 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
18:09:10.0371 4732 discache - ok
18:09:10.0402 4732 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:09:10.0464 4732 Disk - ok
18:09:10.0480 4732 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:09:10.0495 4732 Dnscache - ok
18:09:10.0542 4732 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
18:09:10.0620 4732 dot3svc - ok
18:09:10.0667 4732 [ B42ED0320C6E41102FDE0005154849BB ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys
18:09:10.0698 4732 Dot4 - ok
18:09:10.0729 4732 [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print C:\Windows\system32\drivers\Dot4Prt.sys
18:09:10.0776 4732 Dot4Print - ok
18:09:10.0792 4732 [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
18:09:10.0823 4732 dot4usb - ok
18:09:10.0854 4732 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
18:09:10.0917 4732 DPS - ok
18:09:10.0948 4732 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:09:11.0010 4732 drmkaud - ok
18:09:11.0057 4732 [ 9CF46FDF163E06B83D03FF929EF2296C ] DsiWMIService C:\Program Files (x86)\Launch Manager\dsiwmis.exe
18:09:11.0088 4732 DsiWMIService - ok
18:09:11.0151 4732 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:09:11.0197 4732 DXGKrnl - ok
18:09:11.0260 4732 [ 72A1AA3C6C79B928D02A6FAD387B1349 ] eamonm C:\Windows\system32\DRIVERS\eamonm.sys
18:09:11.0291 4732 eamonm - ok
18:09:11.0322 4732 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
18:09:11.0400 4732 EapHost - ok
18:09:11.0494 4732 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
18:09:11.0587 4732 ebdrv - ok
18:09:11.0603 4732 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
18:09:11.0634 4732 EFS - ok
18:09:11.0681 4732 [ E99457900012B53B2226F146ECAF9136 ] ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys
18:09:11.0697 4732 ehdrv - ok
18:09:11.0775 4732 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:09:11.0821 4732 ehRecvr - ok
18:09:11.0853 4732 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
18:09:11.0868 4732 ehSched - ok
18:09:11.0962 4732 [ 0A38BD2C9589910C634B10E644D5759C ] EhttpSrv C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
18:09:11.0993 4732 EhttpSrv - ok
18:09:12.0040 4732 [ E6A6E6D58A8DCB64A0FFBC43863D0A80 ] ekrn C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
18:09:12.0087 4732 ekrn - ok
18:09:12.0133 4732 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:09:12.0165 4732 elxstor - ok
18:09:12.0227 4732 [ F9D0D6A7A6D48391BE1F314EF7669CE2 ] epfw C:\Windows\system32\DRIVERS\epfw.sys
18:09:12.0243 4732 epfw - ok
18:09:12.0258 4732 [ 96620AD728144D8E30A7BAEC9DDC811C ] Epfwndis C:\Windows\system32\DRIVERS\Epfwndis.sys
18:09:12.0274 4732 Epfwndis - ok
18:09:12.0321 4732 [ 16576F3A76F4D0DD83522D69B5EAFAA1 ] epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys
18:09:12.0336 4732 epfwwfp - ok
18:09:12.0414 4732 [ 3EA2C4F68A782839D97B3C83595575B6 ] ePowerSvc C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
18:09:12.0461 4732 ePowerSvc - ok
18:09:12.0492 4732 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:09:12.0508 4732 ErrDev - ok
18:09:12.0555 4732 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
18:09:12.0617 4732 EventSystem - ok
18:09:12.0648 4732 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
18:09:12.0679 4732 exfat - ok
18:09:12.0757 4732 Fabs - ok
18:09:12.0773 4732 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:09:12.0882 4732 fastfat - ok
18:09:12.0945 4732 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
18:09:12.0976 4732 Fax - ok
18:09:13.0023 4732 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:09:13.0054 4732 fdc - ok
18:09:13.0085 4732 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
18:09:13.0147 4732 fdPHost - ok
18:09:13.0163 4732 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
18:09:13.0225 4732 FDResPub - ok
18:09:13.0257 4732 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:09:13.0288 4732 FileInfo - ok
18:09:13.0319 4732 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:09:13.0366 4732 Filetrace - ok
18:09:13.0475 4732 [ FFF1130F7C9FA01D093A1EDFC5CCE8FC ] FirebirdServerMAGIXInstance C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
18:09:13.0569 4732 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - warning
18:09:13.0569 4732 FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic (1)
18:09:13.0600 4732 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:09:13.0615 4732 flpydisk - ok
18:09:13.0647 4732 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:09:13.0678 4732 FltMgr - ok
18:09:13.0740 4732 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
18:09:13.0787 4732 FontCache - ok
18:09:13.0818 4732 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
18:09:13.0834 4732 FontCache3.0.0.0 - ok
18:09:13.0865 4732 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:09:13.0881 4732 FsDepends - ok
18:09:13.0927 4732 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:09:13.0943 4732 Fs_Rec - ok
18:09:14.0005 4732 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:09:14.0052 4732 fvevol - ok
18:09:14.0083 4732 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:09:14.0193 4732 gagp30kx - ok
18:09:14.0224 4732 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
18:09:14.0239 4732 GEARAspiWDM - ok
18:09:14.0286 4732 [ 1017F2D3A4B90258CA730877D28B9FB1 ] GFilterSvc C:\Windows\System32\GFilterSvc.exe
18:09:14.0302 4732 GFilterSvc ( UnsignedFile.Multi.Generic ) - warning
18:09:14.0302 4732 GFilterSvc - detected UnsignedFile.Multi.Generic (1)
18:09:14.0349 4732 [ A4198F2BD8AA592CB90476277A81B5E1 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys
18:09:14.0364 4732 ggflt - ok
18:09:14.0380 4732 [ D266350BDAAB9EB6C1AEC370EEAAFF3A ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys
18:09:14.0380 4732 ggsemc - ok
18:09:14.0458 4732 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
18:09:14.0505 4732 gpsvc - ok
18:09:14.0567 4732 [ 0191DEE9B9EB7902AF2CF4F67301095D ] GREGService C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
18:09:14.0567 4732 GREGService - ok
18:09:14.0676 4732 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:09:14.0692 4732 gupdate - ok
18:09:14.0707 4732 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:09:14.0723 4732 gupdatem - ok
18:09:14.0754 4732 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:09:14.0770 4732 hcw85cir - ok
18:09:14.0801 4732 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:09:14.0817 4732 HdAudAddService - ok
18:09:14.0848 4732 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:09:14.0863 4732 HDAudBus - ok
18:09:14.0895 4732 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
18:09:14.0895 4732 HECIx64 - ok
18:09:14.0926 4732 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:09:14.0941 4732 HidBatt - ok
18:09:14.0941 4732 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:09:14.0973 4732 HidBth - ok
18:09:14.0988 4732 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:09:15.0004 4732 HidIr - ok
18:09:15.0035 4732 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
18:09:15.0066 4732 hidserv - ok
18:09:15.0113 4732 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:09:15.0129 4732 HidUsb - ok
18:09:15.0160 4732 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:09:15.0222 4732 hkmsvc - ok
18:09:15.0285 4732 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:09:15.0300 4732 HomeGroupListener - ok
18:09:15.0331 4732 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:09:15.0347 4732 HomeGroupProvider - ok
18:09:15.0456 4732 [ 1DAE5C46D42B02A6D5862E1482EFB390 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
18:09:15.0472 4732 hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning
18:09:15.0472 4732 hpqcxs08 - detected UnsignedFile.Multi.Generic (1)
18:09:15.0487 4732 [ 99E8EEF42FE2F4AF29B08C3355DD7685 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
18:09:15.0487 4732 hpqddsvc ( UnsignedFile.Multi.Generic ) - warning
18:09:15.0487 4732 hpqddsvc - detected UnsignedFile.Multi.Generic (1)
18:09:15.0534 4732 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:09:15.0550 4732 HpSAMD - ok
18:09:15.0597 4732 [ 7F57926169C1B8ABA9274EA7D4B70F18 ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
18:09:15.0628 4732 HPSLPSVC ( UnsignedFile.Multi.Generic ) - warning
18:09:15.0628 4732 HPSLPSVC - detected UnsignedFile.Multi.Generic (1)
18:09:15.0659 4732 [ F47CEC45FB85791D4AB237563AD0FA8F ] HTCAND64 C:\Windows\system32\Drivers\ANDROIDUSB.sys
18:09:15.0690 4732 HTCAND64 - ok
18:09:15.0737 4732 [ B8B1B284362E1D8135112573395D5DA5 ] htcnprot C:\Windows\system32\DRIVERS\htcnprot.sys
18:09:15.0753 4732 htcnprot - ok
18:09:15.0831 4732 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:09:15.0909 4732 HTTP - ok
18:09:15.0940 4732 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:09:15.0955 4732 hwpolicy - ok
18:09:15.0987 4732 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:09:16.0002 4732 i8042prt - ok
18:09:16.0033 4732 [ ABBF174CB394F5C437410A788B7E404A ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
18:09:16.0065 4732 iaStor - ok
18:09:16.0143 4732 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:09:16.0174 4732 iaStorV - ok
18:09:16.0236 4732 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
18:09:16.0252 4732 IDriverT ( UnsignedFile.Multi.Generic ) - warning
18:09:16.0252 4732 IDriverT - detected UnsignedFile.Multi.Generic (1)
18:09:16.0299 4732 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
18:09:16.0345 4732 idsvc - ok
18:09:16.0517 4732 [ A87261EF1546325B559374F5689CF5BC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
18:09:16.0642 4732 igfx - ok
18:09:16.0673 4732 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:09:16.0673 4732 iirsp - ok
18:09:16.0720 4732 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
18:09:16.0798 4732 IKEEXT - ok
18:09:16.0891 4732 [ E8017F1662D9142F45CEAB694D013C00 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
18:09:16.0954 4732 IntcAzAudAddService - ok
18:09:16.0969 4732 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
18:09:16.0985 4732 intelide - ok
18:09:17.0016 4732 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:09:17.0016 4732 intelppm - ok
18:09:17.0063 4732 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:09:17.0110 4732 IPBusEnum - ok
18:09:17.0157 4732 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:09:17.0188 4732 IpFilterDriver - ok
18:09:17.0250 4732 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:09:17.0313 4732 iphlpsvc - ok
18:09:17.0344 4732 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:09:17.0359 4732 IPMIDRV - ok
18:09:17.0391 4732 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:09:17.0453 4732 IPNAT - ok
18:09:17.0531 4732 [ A9E53E1A9C4274EEBC00D36AE5ED40DE ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
18:09:17.0562 4732 iPod Service - ok
18:09:17.0593 4732 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:09:17.0625 4732 IRENUM - ok
18:09:17.0640 4732 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:09:17.0656 4732 isapnp - ok
18:09:17.0687 4732 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:09:17.0703 4732 iScsiPrt - ok
18:09:17.0749 4732 [ 12E27942DBB7C91880163634B0D8A776 ] k57nd60a C:\Windows\system32\DRIVERS\k57nd60a.sys
18:09:17.0765 4732 k57nd60a - ok
18:09:17.0781 4732 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
18:09:17.0796 4732 kbdclass - ok
18:09:17.0827 4732 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
18:09:17.0843 4732 kbdhid - ok
18:09:17.0859 4732 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
18:09:17.0859 4732 KeyIso - ok
18:09:17.0890 4732 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:09:17.0890 4732 KSecDD - ok
18:09:17.0921 4732 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:09:17.0937 4732 KSecPkg - ok
18:09:17.0952 4732 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
18:09:17.0999 4732 ksthunk - ok
18:09:18.0046 4732 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
18:09:18.0124 4732 KtmRm - ok
18:09:18.0171 4732 [ 2AC603C3188C704CFCE353659AA7AD71 ] L1E C:\Windows\system32\DRIVERS\L1E62x64.sys
18:09:18.0202 4732 L1E - ok
18:09:18.0249 4732 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
18:09:18.0311 4732 LanmanServer - ok
18:09:18.0342 4732 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:09:18.0389 4732 LanmanWorkstation - ok
18:09:18.0436 4732 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:09:18.0498 4732 lltdio - ok
18:09:18.0545 4732 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:09:18.0623 4732 lltdsvc - ok
18:09:18.0654 4732 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
18:09:18.0701 4732 lmhosts - ok
18:09:18.0748 4732 [ 23DE5B62B0445A6F874BE633C95B483E ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
18:09:18.0763 4732 LMS - ok
18:09:18.0810 4732 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:09:18.0826 4732 LSI_FC - ok
18:09:18.0857 4732 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:09:18.0873 4732 LSI_SAS - ok
18:09:18.0888 4732 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:09:18.0888 4732 LSI_SAS2 - ok
18:09:18.0904 4732 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:09:18.0919 4732 LSI_SCSI - ok
18:09:18.0935 4732 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
18:09:18.0982 4732 luafv - ok
18:09:19.0044 4732 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:09:19.0060 4732 Mcx2Svc - ok
18:09:19.0075 4732 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:09:19.0091 4732 megasas - ok
18:09:19.0107 4732 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:09:19.0138 4732 MegaSR - ok
18:09:19.0169 4732 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
18:09:19.0216 4732 MMCSS - ok
18:09:19.0231 4732 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
18:09:19.0263 4732 Modem - ok
18:09:19.0294 4732 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:09:19.0309 4732 monitor - ok
18:09:19.0341 4732 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:09:19.0341 4732 mouclass - ok
18:09:19.0387 4732 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:09:19.0419 4732 mouhid - ok
18:09:19.0465 4732 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:09:19.0481 4732 mountmgr - ok
18:09:19.0528 4732 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
18:09:19.0543 4732 mpio - ok
18:09:19.0590 4732 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:09:19.0668 4732 mpsdrv - ok
18:09:19.0715 4732 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:09:19.0809 4732 MpsSvc - ok
18:09:19.0840 4732 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:09:19.0871 4732 MRxDAV - ok
18:09:19.0902 4732 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:09:19.0918 4732 mrxsmb - ok
18:09:19.0949 4732 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:09:19.0980 4732 mrxsmb10 - ok
18:09:19.0996 4732 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:09:20.0027 4732 mrxsmb20 - ok
18:09:20.0058 4732 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
18:09:20.0089 4732 msahci - ok
18:09:20.0105 4732 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:09:20.0136 4732 msdsm - ok
18:09:20.0152 4732 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
18:09:20.0167 4732 MSDTC - ok
18:09:20.0214 4732 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:09:20.0292 4732 Msfs - ok
18:09:20.0308 4732 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:09:20.0339 4732 mshidkmdf - ok
18:09:20.0370 4732 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:09:20.0370 4732 msisadrv - ok
18:09:20.0417 4732 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:09:20.0479 4732 MSiSCSI - ok
18:09:20.0495 4732 msiserver - ok
18:09:20.0511 4732 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:09:20.0557 4732 MSKSSRV - ok
18:09:20.0573 4732 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:09:20.0620 4732 MSPCLOCK - ok
18:09:20.0635 4732 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:09:20.0667 4732 MSPQM - ok
18:09:20.0698 4732 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:09:20.0713 4732 MsRPC - ok
18:09:20.0745 4732 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:09:20.0760 4732 mssmbios - ok
18:09:20.0791 4732 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:09:20.0854 4732 MSTEE - ok
18:09:20.0869 4732 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:09:20.0869 4732 MTConfig - ok
18:09:20.0885 4732 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
18:09:20.0901 4732 Mup - ok
18:09:20.0932 4732 [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
18:09:20.0963 4732 mwlPSDFilter - ok
18:09:20.0979 4732 [ 0BEFE32CA56D6EE89D58175725596A85 ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
18:09:20.0994 4732 mwlPSDNServ - ok
18:09:21.0010 4732 [ D43BC633B8660463E446E28E14A51262 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
18:09:21.0025 4732 mwlPSDVDisk - ok
18:09:21.0103 4732 [ 3E5E20817259F7328C8F3BE5421F35B9 ] MWLService C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
18:09:21.0119 4732 MWLService - ok
18:09:21.0166 4732 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
18:09:21.0244 4732 napagent - ok
18:09:21.0291 4732 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:09:21.0384 4732 NativeWifiP - ok
18:09:21.0431 4732 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:09:21.0493 4732 NDIS - ok
18:09:21.0509 4732 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:09:21.0571 4732 NdisCap - ok
18:09:21.0603 4732 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:09:21.0681 4732 NdisTapi - ok
18:09:21.0712 4732 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:09:21.0759 4732 Ndisuio - ok
18:09:21.0790 4732 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:09:21.0915 4732 NdisWan - ok
18:09:21.0946 4732 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:09:21.0993 4732 NDProxy - ok
18:09:22.0039 4732 [ D5AC41AE382738483FAFFBD7E373D49A ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
18:09:22.0039 4732 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
18:09:22.0039 4732 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
18:09:22.0086 4732 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:09:22.0117 4732 NetBIOS - ok
18:09:22.0149 4732 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:09:22.0180 4732 NetBT - ok
18:09:22.0227 4732 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
18:09:22.0258 4732 Netlogon - ok
18:09:22.0289 4732 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
18:09:22.0367 4732 Netman - ok
18:09:22.0383 4732 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
18:09:22.0429 4732 netprofm - ok
18:09:22.0445 4732 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:09:22.0461 4732 NetTcpPortSharing - ok
18:09:22.0492 4732 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:09:22.0507 4732 nfrd960 - ok
18:09:22.0617 4732 [ 1BF62D8130BEDBA41B18FC36C3E2B3B6 ] NitroReaderDriverReadSpool2 C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe
18:09:22.0632 4732 NitroReaderDriverReadSpool2 - ok
18:09:22.0679 4732 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:09:22.0757 4732 NlaSvc - ok
18:09:22.0897 4732 [ 5839A8027D6D324A7CD494051A96628C ] NOBU C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
18:09:23.0007 4732 NOBU - ok
18:09:23.0022 4732 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:09:23.0100 4732 Npfs - ok
18:09:23.0116 4732 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
18:09:23.0163 4732 nsi - ok
18:09:23.0178 4732 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:09:23.0225 4732 nsiproxy - ok
18:09:23.0287 4732 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:09:23.0334 4732 Ntfs - ok
18:09:23.0412 4732 [ 9A308FCDCCA98A15B6F62D36A272160E ] NTI IScheduleSvc C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
18:09:23.0428 4732 NTI IScheduleSvc - ok
18:09:23.0459 4732 [ 28C59F594044CBF8598B18C927097091 ] NTIBackupSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
18:09:23.0475 4732 NTIBackupSvc - ok
18:09:23.0506 4732 [ 710263B44C1D1AEE07525A53401FBE48 ] NTIDrvr C:\Windows\system32\drivers\NTIDrvr.sys
18:09:23.0537 4732 NTIDrvr - ok
18:09:23.0584 4732 [ B8D903B2894FF9AFBD99CA51C35590D7 ] NTISchedulerSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
18:09:23.0599 4732 NTISchedulerSvc - ok
18:09:23.0615 4732 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
18:09:23.0709 4732 Null - ok
18:09:23.0740 4732 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:09:23.0755 4732 nvraid - ok
18:09:23.0787 4732 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:09:23.0818 4732 nvstor - ok
18:09:23.0849 4732 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:09:23.0865 4732 nv_agp - ok
18:09:23.0896 4732 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:09:23.0927 4732 ohci1394 - ok
18:09:23.0989 4732 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:09:24.0021 4732 ose - ok
18:09:24.0177 4732 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
18:09:24.0286 4732 osppsvc - ok
18:09:24.0317 4732 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:09:24.0333 4732 p2pimsvc - ok
18:09:24.0364 4732 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
18:09:24.0379 4732 p2psvc - ok
18:09:24.0411 4732 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:09:24.0442 4732 Parport - ok
18:09:24.0504 4732 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:09:24.0520 4732 partmgr - ok
18:09:24.0582 4732 [ AFADA8B97BE3C9398DC6C770409C3544 ] PassThru Service C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
18:09:24.0598 4732 PassThru Service ( UnsignedFile.Multi.Generic ) - warning
18:09:24.0598 4732 PassThru Service - detected UnsignedFile.Multi.Generic (1)
18:09:24.0629 4732 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:09:24.0660 4732 PcaSvc - ok
18:09:24.0676 4732 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
18:09:24.0691 4732 pci - ok
18:09:24.0738 4732 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
18:09:24.0754 4732 pciide - ok
18:09:24.0769 4732 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:09:24.0816 4732 pcmcia - ok
18:09:24.0816 4732 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
18:09:24.0847 4732 pcw - ok
18:09:24.0863 4732 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:09:24.0910 4732 PEAUTH - ok
18:09:25.0003 4732 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
18:09:25.0019 4732 PerfHost - ok
18:09:25.0066 4732 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
18:09:25.0113 4732 pla - ok
18:09:25.0159 4732 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:09:25.0191 4732 PlugPlay - ok
18:09:25.0222 4732 [ 37F6046CDC630442D7DC087501FF6FC6 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
18:09:25.0237 4732 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
18:09:25.0237 4732 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
18:09:25.0253 4732 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:09:25.0269 4732 PNRPAutoReg - ok
18:09:25.0300 4732 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:09:25.0315 4732 PNRPsvc - ok
18:09:25.0347 4732 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:09:25.0456 4732 PolicyAgent - ok
18:09:25.0487 4732 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
18:09:25.0565 4732 Power - ok
18:09:25.0581 4732 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:09:25.0627 4732 PptpMiniport - ok
18:09:25.0659 4732 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:09:25.0674 4732 Processor - ok
18:09:25.0705 4732 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
18:09:25.0721 4732 ProfSvc - ok
18:09:25.0737 4732 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:09:25.0737 4732 ProtectedStorage - ok
18:09:25.0783 4732 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:09:25.0815 4732 Psched - ok
18:09:25.0861 4732 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:09:25.0893 4732 ql2300 - ok
18:09:25.0924 4732 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:09:25.0939 4732 ql40xx - ok
18:09:25.0971 4732 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
18:09:26.0002 4732 QWAVE - ok
18:09:26.0033 4732 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:09:26.0095 4732 QWAVEdrv - ok
18:09:26.0111 4732 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:09:26.0189 4732 RasAcd - ok
18:09:26.0251 4732 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:09:26.0283 4732 RasAgileVpn - ok
18:09:26.0314 4732 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
18:09:26.0345 4732 RasAuto - ok
18:09:26.0376 4732 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:09:26.0423 4732 Rasl2tp - ok
18:09:26.0470 4732 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
18:09:26.0548 4732 RasMan - ok
18:09:26.0579 4732 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:09:26.0610 4732 RasPppoe - ok
18:09:26.0610 4732 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:09:26.0673 4732 RasSstp - ok
18:09:26.0688 4732 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:09:26.0735 4732 rdbss - ok
18:09:26.0751 4732 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:09:26.0766 4732 rdpbus - ok
18:09:26.0782 4732 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:09:26.0829 4732 RDPCDD - ok
18:09:26.0829 4732 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:09:26.0875 4732 RDPENCDD - ok
18:09:26.0922 4732 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:09:27.0016 4732 RDPREFMP - ok
18:09:27.0063 4732 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:09:27.0078 4732 RDPWD - ok
18:09:27.0125 4732 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:09:27.0141 4732 rdyboost - ok
18:09:27.0172 4732 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
18:09:27.0203 4732 RemoteAccess - ok
18:09:27.0250 4732 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:09:27.0328 4732 RemoteRegistry - ok
18:09:27.0343 4732 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:09:27.0406 4732 RpcEptMapper - ok
18:09:27.0437 4732 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
18:09:27.0437 4732 RpcLocator - ok
18:09:27.0468 4732 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
18:09:27.0577 4732 RpcSs - ok
18:09:27.0609 4732 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:09:27.0671 4732 rspndr - ok
18:09:27.0687 4732 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
18:09:27.0702 4732 SamSs - ok
18:09:27.0733 4732 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:09:27.0765 4732 sbp2port - ok
18:09:27.0780 4732 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:09:27.0843 4732 SCardSvr - ok
18:09:27.0874 4732 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:09:27.0921 4732 scfilter - ok
18:09:27.0983 4732 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
18:09:28.0061 4732 Schedule - ok
18:09:28.0092 4732 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:09:28.0123 4732 SCPolicySvc - ok
18:09:28.0155 4732 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:09:28.0170 4732 SDRSVC - ok
18:09:28.0201 4732 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:09:28.0248 4732 secdrv - ok
18:09:28.0279 4732 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
18:09:28.0357 4732 seclogon - ok
18:09:28.0404 4732 [ EDE7A1D2715AAC2190D51DC07AFD44E3 ] seehcri C:\Windows\system32\DRIVERS\seehcri.sys
18:09:28.0420 4732 seehcri - ok
18:09:28.0451 4732 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
18:09:28.0498 4732 SENS - ok
18:09:28.0513 4732 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:09:28.0529 4732 SensrSvc - ok
18:09:28.0576 4732 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:09:28.0591 4732 Serenum - ok
18:09:28.0623 4732 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:09:28.0638 4732 Serial - ok
18:09:28.0669 4732 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:09:28.0701 4732 sermouse - ok
18:09:28.0732 4732 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
18:09:28.0794 4732 SessionEnv - ok
18:09:28.0825 4732 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:09:28.0841 4732 sffdisk - ok
18:09:28.0841 4732 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:09:28.0857 4732 sffp_mmc - ok
18:09:28.0872 4732 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:09:28.0888 4732 sffp_sd - ok
18:09:28.0919 4732 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:09:28.0935 4732 sfloppy - ok
18:09:28.0981 4732 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
18:09:29.0013 4732 Sftfs - ok
18:09:29.0075 4732 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
18:09:29.0106 4732 sftlist - ok
18:09:29.0122 4732 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
18:09:29.0137 4732 Sftplay - ok
18:09:29.0153 4732 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
18:09:29.0169 4732 Sftredir - ok
18:09:29.0200 4732 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
18:09:29.0215 4732 Sftvol - ok
18:09:29.0247 4732 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
18:09:29.0262 4732 sftvsa - ok
18:09:29.0325 4732 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:09:29.0403 4732 SharedAccess - ok
18:09:29.0434 4732 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:09:29.0512 4732 ShellHWDetection - ok
18:09:29.0543 4732 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:09:29.0559 4732 SiSRaid2 - ok
18:09:29.0574 4732 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:09:29.0590 4732 SiSRaid4 - ok
18:09:29.0761 4732 [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
18:09:29.0824 4732 Skype C2C Service - ok
18:09:29.0871 4732 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
18:09:29.0886 4732 SkypeUpdate - ok
18:09:29.0917 4732 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:09:29.0995 4732 Smb - ok
18:09:30.0089 4732 [ B24F7A40F2B4901DA7B76A88339553B8 ] SndVol64 C:\Windows\system32\actjveds.exe
18:09:30.0089 4732 SndVol64 ( UnsignedFile.Multi.Generic ) - warning
18:09:30.0089 4732 SndVol64 - detected UnsignedFile.Multi.Generic (1)
18:09:30.0136 4732 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:09:30.0167 4732 SNMPTRAP - ok
18:09:30.0198 4732 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
18:09:30.0245 4732 spldr - ok
18:09:30.0276 4732 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
18:09:30.0292 4732 Spooler - ok
18:09:30.0401 4732 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
18:09:30.0479 4732 sppsvc - ok
18:09:30.0510 4732 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:09:30.0541 4732 sppuinotify - ok
18:09:30.0588 4732 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
18:09:30.0666 4732 srv - ok
18:09:30.0682 4732 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:09:30.0697 4732 srv2 - ok
18:09:30.0697 4732 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:09:30.0713 4732 srvnet - ok
18:09:30.0744 4732 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:09:30.0791 4732 SSDPSRV - ok
18:09:30.0807 4732 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:09:30.0838 4732 SstpSvc - ok
18:09:30.0885 4732 [ C692C94FE55CAD0633440236022C27B3 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
18:09:30.0916 4732 ssudmdm - ok
18:09:30.0947 4732 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:09:30.0978 4732 stexstor - ok
18:09:31.0025 4732 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
18:09:31.0072 4732 stisvc - ok
18:09:31.0087 4732 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
18:09:31.0103 4732 swenum - ok
18:09:31.0150 4732 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
18:09:31.0243 4732 swprv - ok
18:09:31.0306 4732 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
18:09:31.0337 4732 SysMain - ok
18:09:31.0368 4732 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:09:31.0384 4732 TabletInputService - ok
18:09:31.0415 4732 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
18:09:31.0462 4732 TapiSrv - ok
18:09:31.0477 4732 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
18:09:31.0509 4732 TBS - ok
18:09:31.0587 4732 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:09:31.0649 4732 Tcpip - ok
18:09:31.0727 4732 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:09:31.0774 4732 TCPIP6 - ok
18:09:31.0805 4732 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:09:31.0836 4732 tcpipreg - ok
18:09:31.0867 4732 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:09:31.0883 4732 TDPIPE - ok
18:09:31.0930 4732 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:09:31.0945 4732 TDTCP - ok
18:09:31.0992 4732 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:09:32.0070 4732 tdx - ok
18:09:32.0101 4732 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:09:32.0117 4732 TermDD - ok
18:09:32.0164 4732 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
18:09:32.0257 4732 TermService - ok
18:09:32.0289 4732 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
18:09:32.0304 4732 Themes - ok
18:09:32.0335 4732 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
18:09:32.0413 4732 THREADORDER - ok
18:09:32.0429 4732 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
18:09:32.0491 4732 TrkWks - ok
18:09:32.0538 4732 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:09:32.0616 4732 TrustedInstaller - ok
18:09:32.0647 4732 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:09:32.0694 4732 tssecsrv - ok
18:09:32.0710 4732 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:09:32.0757 4732 TsUsbFlt - ok
18:09:32.0788 4732 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:09:32.0819 4732 tunnel - ok
18:09:32.0850 4732 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:09:32.0866 4732 uagp35 - ok
18:09:32.0897 4732 [ 40079B0B801C5432BA435B5AD61CE6E3 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys
18:09:32.0913 4732 UBHelper - ok
18:09:32.0944 4732 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:09:33.0006 4732 udfs - ok
18:09:33.0053 4732 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:09:33.0069 4732 UI0Detect - ok
18:09:33.0084 4732 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:09:33.0100 4732 uliagpkx - ok
18:09:33.0131 4732 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
18:09:33.0147 4732 umbus - ok
18:09:33.0178 4732 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:09:33.0209 4732 UmPass - ok
18:09:33.0349 4732 [ CC3775100ABA633984F73DFAE1F55CAE ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
18:09:33.0412 4732 UNS - ok
18:09:33.0490 4732 [ F9EC9ACD504D823D9B9CA98A4F8D3CA2 ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
18:09:33.0521 4732 Updater Service - ok
18:09:33.0552 4732 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
18:09:33.0630 4732 upnphost - ok
18:09:33.0661 4732 [ 54D4B48D443E7228BF64CF7CDC3118AC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
18:09:33.0677 4732 USBAAPL64 - ok
18:09:33.0708 4732 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:09:33.0724 4732 usbccgp - ok
18:09:33.0755 4732 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:09:33.0771 4732 usbcir - ok
18:09:33.0786 4732 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
18:09:33.0802 4732 usbehci - ok
18:09:33.0849 4732 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:09:33.0864 4732 usbhub - ok
18:09:33.0880 4732 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:09:33.0895 4732 usbohci - ok
18:09:33.0927 4732 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:09:33.0942 4732 usbprint - ok
18:09:33.0989 4732 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
18:09:34.0005 4732 usbscan - ok
18:09:34.0036 4732 [ 0F0C72A657C622286013788B886968AD ] usbser C:\Windows\system32\DRIVERS\usbser.sys
18:09:34.0051 4732 usbser - ok
18:09:34.0083 4732 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:09:34.0098 4732 USBSTOR - ok
18:09:34.0129 4732 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
18:09:34.0145 4732 usbuhci - ok
18:09:34.0176 4732 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
18:09:34.0192 4732 usbvideo - ok
18:09:34.0223 4732 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
18:09:34.0254 4732 UxSms - ok
18:09:34.0270 4732 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
18:09:34.0285 4732 VaultSvc - ok
18:09:34.0317 4732 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
18:09:34.0348 4732 vdrvroot - ok
18:09:34.0395 4732 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
18:09:34.0441 4732 vds - ok
18:09:34.0473 4732 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:09:34.0519 4732 vga - ok
18:09:34.0551 4732 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
18:09:34.0597 4732 VgaSave - ok
18:09:34.0629 4732 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
18:09:34.0644 4732 vhdmp - ok
18:09:34.0660 4732 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
18:09:34.0675 4732 viaide - ok
18:09:34.0691 4732 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:09:34.0738 4732 volmgr - ok
18:09:34.0753 4732 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:09:34.0769 4732 volmgrx - ok
18:09:34.0769 4732 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:09:34.0785 4732 volsnap - ok
18:09:34.0831 4732 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
18:09:34.0831 4732 vsmraid - ok
18:09:34.0894 4732 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
18:09:34.0941 4732 VSS - ok
18:09:34.0956 4732 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
18:09:34.0972 4732 vwifibus - ok
18:09:34.0987 4732 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
18:09:35.0003 4732 vwififlt - ok
18:09:35.0019 4732 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
18:09:35.0034 4732 vwifimp - ok
18:09:35.0081 4732 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
18:09:35.0128 4732 W32Time - ok
18:09:35.0159 4732 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
18:09:35.0159 4732 WacomPen - ok
18:09:35.0206 4732 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
18:09:35.0268 4732 WANARP - ok
18:09:35.0268 4732 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:09:35.0331 4732 Wanarpv6 - ok
18:09:35.0409 4732 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
18:09:35.0440 4732 WatAdminSvc - ok
18:09:35.0502 4732 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
18:09:35.0533 4732 wbengine - ok
18:09:35.0565 4732 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
18:09:35.0580 4732 WbioSrvc - ok
18:09:35.0627 4732 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:09:35.0643 4732 wcncsvc - ok
18:09:35.0658 4732 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:09:35.0674 4732 WcsPlugInService - ok
18:09:35.0705 4732 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
18:09:35.0705 4732 Wd - ok
18:09:35.0736 4732 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:09:35.0752 4732 Wdf01000 - ok
18:09:35.0783 4732 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:09:35.0799 4732 WdiServiceHost - ok
18:09:35.0799 4732 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:09:35.0814 4732 WdiSystemHost - ok
18:09:35.0845 4732 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
18:09:35.0861 4732 WebClient - ok
18:09:35.0892 4732 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:09:35.0939 4732 Wecsvc - ok
18:09:35.0970 4732 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:09:36.0001 4732 wercplsupport - ok
18:09:36.0033 4732 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
18:09:36.0095 4732 WerSvc - ok
18:09:36.0126 4732 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
18:09:36.0173 4732 WfpLwf - ok
18:09:36.0189 4732 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
18:09:36.0204 4732 WIMMount - ok
18:09:36.0220 4732 WinDefend - ok
18:09:36.0220 4732 WinHttpAutoProxySvc - ok
18:09:36.0282 4732 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:09:36.0313 4732 Winmgmt - ok
18:09:36.0376 4732 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
18:09:36.0438 4732 WinRM - ok
18:09:36.0485 4732 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
18:09:36.0501 4732 WinUsb - ok
18:09:36.0563 4732 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
18:09:36.0594 4732 Wlansvc - ok
18:09:36.0625 4732 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:09:36.0657 4732 WmiAcpi - ok
18:09:36.0672 4732 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:09:36.0703 4732 wmiApSrv - ok
18:09:36.0719 4732 WMPNetworkSvc - ok
18:09:36.0750 4732 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:09:36.0750 4732 WPCSvc - ok
18:09:36.0797 4732 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:09:36.0813 4732 WPDBusEnum - ok
18:09:36.0844 4732 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:09:36.0906 4732 ws2ifsl - ok
18:09:36.0937 4732 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
18:09:36.0953 4732 wscsvc - ok
18:09:36.0953 4732 WSearch - ok
18:09:37.0031 4732 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
18:09:37.0078 4732 wuauserv - ok
18:09:37.0093 4732 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:09:37.0140 4732 WudfPf - ok
18:09:37.0171 4732 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:09:37.0218 4732 WUDFRd - ok
18:09:37.0249 4732 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:09:37.0281 4732 wudfsvc - ok
18:09:37.0312 4732 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
18:09:37.0343 4732 WwanSvc - ok
18:09:37.0374 4732 ================ Scan global ===============================
18:09:37.0405 4732 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
18:09:37.0437 4732 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
18:09:37.0452 4732 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
18:09:37.0468 4732 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
18:09:37.0499 4732 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
18:09:37.0499 4732 [Global] - ok
18:09:37.0499 4732 ================ Scan MBR ==================================
18:09:37.0530 4732 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
18:09:37.0873 4732 \Device\Harddisk0\DR0 - ok
18:09:37.0873 4732 ================ Scan VBR ==================================
18:09:37.0889 4732 [ 95FBC11516C450CB1AABD87ACC9059F2 ] \Device\Harddisk0\DR0\Partition1
18:09:37.0889 4732 \Device\Harddisk0\DR0\Partition1 - ok
18:09:37.0905 4732 [ 46EA97EADE8EF6E83A3CABA9BB530D37 ] \Device\Harddisk0\DR0\Partition2
18:09:37.0905 4732 \Device\Harddisk0\DR0\Partition2 - ok
18:09:37.0920 4732 [ 69C4A2B68B1ED542E46588579E77DA99 ] \Device\Harddisk0\DR0\Partition3
18:09:37.0920 4732 \Device\Harddisk0\DR0\Partition3 - ok
18:09:37.0920 4732 ============================================================
18:09:37.0920 4732 Scan finished
18:09:37.0920 4732 ============================================================
18:09:37.0936 3752 Detected object count: 10
18:09:37.0936 3752 Actual detected object count: 10
18:15:53.0957 3752 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0957 3752 FirebirdServerMAGIXInstance ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0960 3752 GFilterSvc ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0960 3752 GFilterSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0963 3752 hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0963 3752 hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0966 3752 hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0966 3752 hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0969 3752 HPSLPSVC ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0969 3752 HPSLPSVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0972 3752 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0972 3752 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0974 3752 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0974 3752 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0976 3752 PassThru Service ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0976 3752 PassThru Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0978 3752 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0978 3752 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:15:53.0980 3752 SndVol64 ( UnsignedFile.Multi.Generic ) - skipped by user
18:15:53.0980 3752 SndVol64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:17:21.0603 4136 Deinitialize success

markusg 07.11.2012 23:45

gibts momentan noch probleme?
wenn ja, welche

pkhoschi 08.11.2012 09:33

Moin. Ja und zwar Mozilla stürzt immer nach ein paar Minuten ab. Beim Start des rechners keine Internet verbindung möglich.eset führt keine Überprüfung mehr durch und bricht immer bei der selben Datei ab. Internet sehr langsam.

markusg 08.11.2012 12:56

hi
gibt es noch weitere eset funde? dann poste diese mal bitte

pkhoschi 08.11.2012 17:12

Nein denn eset Prüfung bleibt ja immer bei der selben Datei hängen, wenn ich Prüfung gestartet hab

markusg 09.11.2012 16:02

ich meinte ältere, keine neuen.
wo bleibt eset hängen?


Alle Zeitangaben in WEZ +1. Es ist jetzt 23:46 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131