Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojan.Downloader in Registry Key (https://www.trojaner-board.de/117410-trojan-downloader-registry-key.html)

Hajaku 15.06.2012 22:29

Trojan.Downloader in Registry Key
 
Hallo,

auf meinem Rechner sind 5 infizierte Registrierungsschlüssel und eine infizierte Datei.
Ich habe es durch das Programm Malwarebytes Anti-Malware gefunden.
Bei der infizierten Datei habe ich den Inhalt in Quarantäne verschoben mittels Avira.
Nun benötige ich eure Hilfe, denn ich weiß nicht wie ich diese Viren entfernen kann.

Hier der Log
Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.14.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

15.06.2012 21:35:47
mbam-log-2012-06-15 (21-45-01).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 253017
Laufzeit: 7 Minute(n), 19 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 5
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Tuan\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Keine Aktion durchgeführt.

(Ende)

Gruß

cosinus 18.06.2012 13:32

Bitte erstmal routinemäßig einen Vollscan mit malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

Hajaku 20.06.2012 12:21

so geschafft
Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.14.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

19.06.2012 20:38:37
mbam-log-2012-06-19 (23-12-27).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 487834
Laufzeit: 2 Stunde(n), 33 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=1593b593cd52b846be5f07e71428a7f5
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-06-19 10:11:31
# local_time=2012-06-20 12:11:31 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 21528916 21528916 0 0
# compatibility_mode=4096 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776573 100 100 20831 177673409 0 0
# compatibility_mode=8192 67108863 100 0 99 99 0 0
# scanned=55294
# found=0
# cleaned=0
# scan_time=3209
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=1593b593cd52b846be5f07e71428a7f5
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-06-20 11:18:31
# local_time=2012-06-20 01:18:31 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1792 16777215 100 0 21568124 21568124 0 0
# compatibility_mode=4096 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776573 100 100 60039 177712617 0 0
# compatibility_mode=8192 67108863 100 0 39307 39307 0 0
# scanned=245034
# found=0


cosinus 20.06.2012 12:30

Code:

Datenbank Version: v2012.06.14.07
Du hast Malwarebytes vorher nicht aktualisiert. Bitte updaten und einen neuen Vollscan machen.

Hajaku 20.06.2012 19:43

und nochmal das Ganze ^^

Code:


Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.20.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

20.06.2012 18:18:57
mbam-log-2012-06-20 (20-39-47).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 486545
Laufzeit: 2 Stunde(n), 20 Minute(n), 43 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 21.06.2012 10:20

*hüstel*

Die Funde mit Malwarebytes bitte alle entfernen, sodass sie in der Quarantäne von Malwarebytes aufgehoben werden! NICHTS voreilig aus der Quarantäne entfernen!

Hajaku 21.06.2012 13:16

ich stelle mich gerade total dämlich an :headbang:
wie schicke ich diese Funde in die Quarantäne?

EDIT: habe es geschafft

cosinus 21.06.2012 14:59

Log dazu bitte posten :)

Hajaku 21.06.2012 22:22

Habe die Funde durch Quick-Scan in Quarantäne verschoben, aber sicherlich willst du einen vollständigen Scan. Also habe ich mir mal die Mühe gemacht. :)
Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.06.20.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

21.06.2012 20:49:37
mbam-log-2012-06-21 (20-49-37).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 486323
Laufzeit: 2 Stunde(n), 16 Minute(n), 6 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)


cosinus 22.06.2012 09:57

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


Hajaku 22.06.2012 18:08

OTL.txt

OTL Logfile:
Code:

OTL logfile created on: 22.06.2012 18:39:56 - Run 1
OTL by OldTimer - Version 3.2.51.0    Folder = C:\Users\Tuan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,32% Memory free
6,21 Gb Paging File | 4,76 Gb Available in Paging File | 76,76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 583,02 Gb Total Space | 310,66 Gb Free Space | 53,28% Space Free | Partition Type: NTFS
Drive D: | 13,15 Gb Total Space | 1,82 Gb Free Space | 13,85% Space Free | Partition Type: NTFS
 
Computer Name: TUAN-PC | User Name: Tuan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.06.22 18:37:50 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Tuan\Desktop\OTL.exe
PRC - [2012.05.08 16:01:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012.05.08 16:01:24 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2012.05.08 16:01:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012.05.08 16:01:22 | 000,348,624 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012.04.06 04:16:24 | 000,451,072 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2012.04.06 04:15:50 | 000,217,600 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2012.04.05 21:56:18 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.04.04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2009.07.24 15:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2009.06.26 17:21:00 | 000,757,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\vVX3000.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.02.23 15:05:34 | 000,111,856 | ---- | M] (Yahoo! Inc) -- C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
PRC - [2008.11.09 22:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008.05.02 02:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008.05.02 02:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2007.04.18 17:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012.06.17 13:29:41 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\9104e78d8897df008eed3a2af3bda6a2\WindowsFormsIntegration.ni.dll
MOD - [2012.06.15 22:12:01 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012.06.15 15:18:28 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012.06.15 15:18:18 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012.06.15 15:18:01 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012.06.15 15:16:08 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012.05.13 17:00:35 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5fd0071c259b92078ced7cd752a14730\UIAutomationProvider.ni.dll
MOD - [2012.05.13 16:58:25 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012.05.13 16:57:47 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012.05.11 18:45:08 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012.05.11 18:44:08 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012.05.11 18:44:02 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012.05.11 18:43:26 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012.05.11 18:43:21 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012.05.11 18:42:40 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012.04.06 03:09:10 | 000,037,376 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2012.04.05 22:00:20 | 000,369,152 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2012.04.05 21:56:24 | 000,095,232 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
MOD - [2011.07.29 01:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011.07.29 01:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2011.06.24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.05.28 22:04:56 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009.03.30 06:42:12 | 000,434,176 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009.03.30 06:42:12 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_de_b77a5c561934e089\System.resources.dll
MOD - [2009.03.30 06:42:11 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009.02.25 03:16:56 | 000,249,856 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_de_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2009.02.25 03:16:56 | 000,110,592 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationCore.resources\3.0.0.0_de_31bf3856ad364e35\PresentationCore.resources.dll
MOD - [2009.02.25 03:16:56 | 000,090,112 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\WindowsBase.resources\3.0.0.0_de_31bf3856ad364e35\WindowsBase.resources.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\G DATA InternetSecurity TotalCare\AVKTuner\AVKTunerService.exe -- (AVK Tuner Service)
SRV - [2012.06.18 13:50:45 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.06.15 15:18:24 | 000,257,224 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.05.08 16:01:33 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012.05.08 16:01:23 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012.04.06 04:15:50 | 000,217,600 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.04.05 21:56:18 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.04.02 19:44:32 | 000,489,256 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2009.07.24 15:05:24 | 000,139,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2008.11.09 22:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008.05.02 02:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008.02.03 13:00:00 | 000,129,992 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\Windows\System32\ezsvc7.dll -- (ezSharedSvc)
SRV - [2008.01.21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - [2012.05.08 16:01:35 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2012.05.08 16:01:35 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.04.06 07:21:10 | 009,334,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2012.04.06 07:21:10 | 009,334,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012.04.06 03:10:22 | 000,275,968 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.03.05 16:04:30 | 000,045,184 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\aoddriver2.sys -- (AODDriver4.1)
DRV - [2012.03.05 16:04:30 | 000,045,184 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\aoddriver2.sys -- (AODDriver4.01)
DRV - [2012.02.23 14:31:36 | 000,083,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2011.10.11 15:00:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010.06.17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.02.18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2010.02.02 23:39:43 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2010.02.02 23:39:42 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2010.02.02 23:39:42 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2009.10.08 19:08:47 | 000,271,360 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2009.10.08 19:08:36 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009.06.26 17:21:02 | 001,956,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VX3000.sys -- (VX3000)
DRV - [2008.06.11 22:32:34 | 000,061,424 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\HP\DVDPlay\000.fcl -- ({22D78859-9CE9-4B77-BF18-AC83E81A9263})
DRV - [2008.06.06 21:13:40 | 000,145,440 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2008.06.06 21:13:40 | 000,133,152 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2008.05.22 11:39:34 | 000,015,360 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008.05.21 13:44:10 | 001,049,760 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008.02.29 03:13:36 | 000,079,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2008.02.29 03:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008.02.29 03:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008.02.29 03:12:56 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007.01.23 16:44:00 | 000,020,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2005.12.12 19:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKLM\..\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com/?p=us
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&AF=109130&tt=261211_ctrl&babsrc=SP_ss&mntrId=5e90e91800000000000000ff9250e086
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.de/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_de
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}: "URL" = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}: "URL" = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-rog
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://de.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher@ea.com:5.0.31.0
FF - prefs.js..extensions.enabledItems: battlefieldplay4free@ea.com:1.0.53.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: screencaptureelite@plugin:2.0.0.20
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "hxxp://search.babylon.com/?AF=109130&tt=261211_ctrl&babsrc=adbartrp&mntrId=5e90e91800000000000000ff9250e086&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=0.80.0: C:\Program Files\Battlelog Web Plugins\0.80.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.7.1: C:\Users\Tuan\AppData\Local\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll (Yahoo! Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.12.18 15:14:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.06.18 13:50:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.16 17:20:30 | 000,000,000 | ---D | M]
 
[2010.07.13 16:07:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tuan\AppData\Roaming\mozilla\Extensions
[2012.06.13 15:56:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions
[2011.02.13 21:54:47 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.05.16 19:05:44 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.05.19 17:27:51 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012.06.13 15:56:59 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\battlefieldheroespatcher@ea.com
[2011.11.08 18:41:31 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\battlefieldplay4free@ea.com
[2012.05.24 18:42:05 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\ich@maltegoetz.de
[2011.03.18 17:31:45 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\personas@christopher.beard
[2011.12.30 18:25:13 | 000,000,000 | ---D | M] (Screen Capture Elite) -- C:\Users\Tuan\AppData\Roaming\mozilla\Firefox\Profiles\w97yn8xt.default\extensions\screencaptureelite@plugin
[2011.03.24 13:03:00 | 000,000,923 | ---- | M] () -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\conduit.xml
[2011.10.29 16:23:12 | 000,003,915 | ---- | M] () -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\sweetim.xml
[2012.05.02 18:01:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.12.18 15:14:16 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012.01.29 17:47:23 | 000,634,964 | ---- | M] () (No name found) -- C:\USERS\TUAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W97YN8XT.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2009.06.24 14:37:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.06.18 13:50:46 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.04.01 17:31:59 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.06.18 13:50:42 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.12.29 15:53:47 | 000,002,351 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012.06.18 13:50:42 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.18 13:50:42 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.18 13:50:42 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.18 13:50:42 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.18 13:50:42 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012.01.24 23:56:19 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2 - BHO: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) -  - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Media Finder] "C:\Program Files\Media Finder\Media Finder.exe" /opentotray File not found
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe File not found
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to iPhone Converter - C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoiphoneconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Save YouTube Video - Reg Error: Value error. File not found
O8 - Extra context menu item: Save YouTube Video as MP3 - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..Trusted Domains: fritz.box ([]* in Lokales Intranet)
O15 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..Trusted Ranges: Range2 ([*] in Lokales Intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.31.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.27.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{68FF45E2-D6D8-4607-9E46-7D06E815F2D9}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Tuan\Pictures\Bilder - Vietnam\fotolia_32611031_subscription_xl.jpg
O24 - Desktop BackupWallPaper: C:\Users\Tuan\Pictures\Bilder - Vietnam\fotolia_32611031_subscription_xl.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.10.27 17:51:08 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
NetSvcs: ezSharedSvc - C:\Windows\System32\ezsvc7.dll (EasyBits Sofware AS)
 
MsConfig - StartUpFolder: C:^Users^Tuan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MsConfig - StartUpReg: VirtualCloneDrive - hkey= - key= - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
 
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.06.22 18:37:49 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Tuan\Desktop\OTL.exe
[2012.06.22 16:04:59 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{11D8809E-9691-4963-BADB-4E5CF4616FEE}
[2012.06.22 16:04:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{676D2760-CE16-4F5C-B7C2-CA68D309DBEC}
[2012.06.21 14:00:12 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{04C6060E-4AA8-4C88-8E1B-827501C0824A}
[2012.06.21 13:59:44 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{602BC025-9956-42CF-9D59-BCB6E1CED67C}
[2012.06.20 09:59:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{C1EF38C1-416C-4844-8DEB-36EDE56809DB}
[2012.06.20 09:58:54 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{629806D2-B1DD-49BC-AF31-E906D34B3C03}
[2012.06.20 09:57:01 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{4326AE52-BCE3-4590-B9C6-74789DDCCE76}
[2012.06.20 09:56:22 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{19C742B3-19CE-4178-B059-E0708267510C}
[2012.06.19 23:16:22 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.06.19 17:19:15 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2FF460C1-5330-47ED-BB49-2A8B2A65A323}
[2012.06.19 17:18:49 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A8BE6743-DF47-4B30-95BE-0B46CC53BA76}
[2012.06.18 13:06:45 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A53F91B2-D669-4AD3-8FCD-32189F9EA9BF}
[2012.06.17 13:19:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{9CB88282-9BF4-41F6-B79C-DCF941D7EF5A}
[2012.06.16 15:17:42 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{951DFB62-ABC5-4807-8965-4EEF6741E7FB}
[2012.06.15 18:10:35 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\Macromedia
[2012.06.15 14:47:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{C11F68A2-E72E-4CA1-BD20-DA1628B143DB}
[2012.06.14 15:51:59 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{227DAF5C-8B85-462A-B235-1AB41F308B70}
[2012.06.14 15:51:48 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0EC1874F-3F88-468C-9EEC-E95D71CADA72}
[2012.06.13 15:29:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.13 15:27:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.13 15:27:20 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.13 15:09:26 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E4CBA780-7DFA-4A3E-BD97-FF9BFF825DD1}
[2012.06.13 15:09:10 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{96C92AAB-FF5B-4E5A-B7AE-3BFEB66889BB}
[2012.06.12 14:32:33 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{59B7EBF6-5D77-4DF8-85A6-E354F807EA53}
[2012.06.12 14:32:15 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F86B784C-B4B0-4441-9036-A094BD93CF6A}
[2012.06.11 14:14:14 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D43C751B-8152-4CFB-856A-347623986437}
[2012.06.11 14:14:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0672FFD9-669E-4705-AF2C-1DC9F5A06C5C}
[2012.06.10 17:00:10 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\Ubisoft Game Launcher
[2012.06.10 15:04:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{95F5C849-C0F9-464D-9D38-9E8F4AB04A44}
[2012.06.10 15:04:11 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A0486032-12BA-4030-AABF-6E196D1F6027}
[2012.06.10 15:03:20 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2EF6181B-F4A5-40C8-A3F6-26A2A5978AEC}
[2012.06.10 15:03:07 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F8122837-E91D-4E33-BFA7-87F0BDD161FE}
[2012.06.08 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{3C8C2B42-5AA4-447E-8F4B-FF5BA78F2A3A}
[2012.06.08 14:54:03 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0E6513F3-A8A4-49B4-BE8D-1D4CE4EB3D73}
[2012.06.07 13:53:52 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F815CABD-9229-4CF1-BB0C-BC293CFFC4E7}
[2012.06.07 13:53:40 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2C5A9D6C-B0F6-4C72-A6D5-B326CB01EA04}
[2012.06.07 13:53:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{64EB8058-BB79-4EEF-9070-6166A53D92C3}
[2012.06.06 15:11:23 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{463FDC6B-C84A-4145-9FCB-1470741B0E34}
[2012.06.06 15:11:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{CC906567-80FE-4CF6-8372-01F61041773B}
[2012.06.05 18:54:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
[2012.06.05 18:54:23 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Roaming\pdfforge
[2012.06.05 18:54:19 | 000,079,360 | ---- | C] (pdfforge GbR) -- C:\Windows\System32\pdfcmon.dll
[2012.06.05 18:54:17 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator
[2012.06.05 17:47:18 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F8B76F58-66C7-408A-8011-F111D812B869}
[2012.06.05 17:46:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{F96724CB-55DA-4F4B-B16B-DDEC5AF7AF07}
[2012.06.03 14:23:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A9700C93-2802-4A3E-A111-23D4AF778A6C}
[2012.06.03 14:23:11 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E2F9609D-6AB8-44C8-9549-2BB72A0EB964}
[2012.06.03 14:21:22 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{00591358-77C0-44C3-867D-CB35CAB3517D}
[2012.06.03 14:21:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D64B1FC5-0E7A-4C27-B468-96D6A30A3E45}
[2012.06.02 14:54:50 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{5949A055-418A-4771-A64A-524D91B5C3BD}
[2012.06.02 14:54:40 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{66BEB0F0-7061-41B6-BFAF-B2816BAD9A3D}
[2012.06.01 20:11:35 | 002,557,952 | ---- | C] (Nokia Corporation and/or its subsidiary(-ies)) -- C:\Windows\System32\QtCore4.dll
[2012.06.01 20:11:33 | 000,405,176 | ---- | C] (Newtonsoft) -- C:\Windows\System32\Newtonsoft.Json.Net20.dll
[2012.06.01 16:17:37 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{564D78B3-C966-4629-9118-5C8CBE911378}
[2012.06.01 16:17:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{8175111A-135F-4A46-AD89-C093B71ACEB9}
[2012.06.01 16:13:31 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D29C3E40-BCAF-4BAA-8967-AB453A1373A4}
[2012.05.31 14:47:27 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{17781506-E67D-4093-9374-E731701E85F7}
[2012.05.31 14:46:58 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{B4448378-CE32-4EE6-A685-098D2FF9087F}
[2012.05.30 13:53:53 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{332B615F-4970-47CE-AAE7-A6E9A87180FC}
[2012.05.30 13:53:43 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2DDE9AEB-7248-4C97-B659-A38F402EF2EA}
[2012.05.29 19:04:19 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Roaming\redsn0w
[2012.05.29 15:43:08 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{0D31CC38-7402-4E4D-8D0B-37AD8B42DC14}
[2012.05.29 15:42:48 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{717E5F3E-BAFC-4AD6-9FD1-0FBC3A0CDF46}
[2012.05.29 15:41:21 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D8FDE98E-D7BE-4319-93E1-D13D0F9A548B}
[2012.05.28 14:56:14 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{036024E5-8C55-4BFB-B14D-6ACE3A0DA12C}
[2012.05.28 14:56:04 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{14011417-E7C4-4E67-A9FC-AD01B1C25678}
[2012.05.28 14:54:13 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{D0997A7B-C99D-4D5A-8019-04F94F5EC1AD}
[2012.05.27 13:37:37 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{2E40EF69-C3AD-4B6D-80D7-C361BEAA80D6}
[2012.05.27 13:37:26 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{5C5B9595-BA96-4584-8E9D-CC685C27D250}
[2012.05.25 15:36:00 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E371F7FD-0D93-442A-B211-2B851D9F8F5E}
[2012.05.25 15:35:48 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{E492BBF1-1CAF-489B-9005-07E525A1D34B}
[2012.05.24 18:34:47 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{A369DB24-FC4D-4196-8FD4-706EB24D6A43}
[2012.05.24 18:34:31 | 000,000,000 | ---D | C] -- C:\Users\Tuan\AppData\Local\{5ACA2ACD-C8F4-4312-B33C-021EC1F56757}
 
========== Files - Modified Within 30 Days ==========
 
[2012.06.22 18:40:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.06.22 18:37:50 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Tuan\Desktop\OTL.exe
[2012.06.22 18:33:39 | 000,014,893 | ---- | M] () -- C:\Users\Tuan\Desktop\Lebenslauf.odt
[2012.06.22 18:13:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.22 18:03:49 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.06.22 18:03:49 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.06.22 16:03:57 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.06.22 16:03:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.06.21 14:07:53 | 000,021,459 | ---- | M] () -- C:\Users\Tuan\Desktop\TU Berlin.odt
[2012.06.20 21:24:32 | 000,671,212 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.06.20 21:24:32 | 000,631,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.20 21:24:32 | 000,144,380 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.06.20 21:24:32 | 000,118,568 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.20 13:44:54 | 000,139,048 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012.06.20 13:44:43 | 000,282,296 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2012.06.20 13:42:58 | 000,280,736 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2012.06.15 21:29:20 | 000,041,984 | ---- | M] () -- C:\Users\Tuan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.15 15:13:28 | 000,354,248 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.06.13 15:29:03 | 000,001,626 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.05 18:54:26 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\PDFArchitect.lnk
[2012.06.05 18:54:26 | 000,000,790 | ---- | M] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2012.05.29 19:20:05 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForTuan.job
 
========== Files Created - No Company Name ==========
 
[2012.06.21 00:30:30 | 000,014,893 | ---- | C] () -- C:\Users\Tuan\Desktop\Lebenslauf.odt
[2012.06.20 21:26:43 | 000,021,459 | ---- | C] () -- C:\Users\Tuan\Desktop\TU Berlin.odt
[2012.06.13 15:29:03 | 000,001,626 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.05 18:54:26 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\PDFArchitect.lnk
[2012.06.05 18:54:26 | 000,000,790 | ---- | C] () -- C:\Users\Public\Desktop\PDFCreator.lnk
[2012.04.13 18:47:51 | 000,000,023 | ---- | C] () -- C:\Windows\clofghls.dll
[2012.04.05 22:34:22 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012.02.24 15:02:07 | 000,000,680 | ---- | C] () -- C:\Users\Tuan\AppData\Local\d3d9caps.dat
[2012.01.24 20:02:15 | 000,000,000 | ---- | C] () -- C:\Users\Tuan\defogger_reenable
[2012.01.24 00:29:17 | 000,041,984 | ---- | C] () -- C:\Users\Tuan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.10 23:10:08 | 000,601,728 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\System32\OVDecoder.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011.07.03 15:49:14 | 000,001,449 | ---- | C] () -- C:\Windows\wininit.ini
[2011.07.03 15:48:24 | 000,040,960 | ---- | C] () -- C:\Windows\RAUNINST.EXE
[2011.06.28 18:57:29 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat
[2011.06.09 14:53:22 | 000,002,146 | ---- | C] () -- C:\Users\Tuan\.recently-used.xbel
[2011.06.03 17:01:06 | 000,000,479 | ---- | C] () -- C:\Windows\eReg.dat
[2010.10.19 18:18:44 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe
[2010.09.17 12:05:07 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2010.07.13 16:07:33 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009.06.21 20:24:31 | 000,023,888 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\UserTile.png
[2009.05.18 15:12:39 | 000,000,760 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\setup_ldm.iss
[2009.04.01 21:25:09 | 000,000,000 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\wklnhst.dat
[2009.04.01 17:24:34 | 000,139,152 | ---- | C] () -- C:\Users\Tuan\AppData\Roaming\PnkBstrK.sys
 
========== LOP Check ==========
 
[2011.05.14 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Ashampoo
[2011.07.03 20:35:32 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DisneyInteractiveStudios
[2012.06.20 10:01:58 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoft
[2011.02.13 21:54:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.08.06 19:05:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GetRightToGo
[2011.03.12 14:22:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GrabPro
[2011.05.24 18:08:51 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\gtk-2.0
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Image Zone Express
[2011.06.25 17:14:48 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Leadertech
[2011.12.29 16:21:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\LucasArts
[2010.02.10 21:39:19 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\muvee Technologies
[2010.12.08 23:50:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\OpenOffice.org
[2012.05.16 19:05:37 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Orbit
[2011.12.21 16:20:24 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Origin
[2012.06.05 19:04:45 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\pdfforge
[2009.06.21 20:24:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\PeerNetworking
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Printer Info Cache
[2010.11.01 20:25:49 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\ProgSense
[2012.06.01 20:33:09 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\redsn0w
[2011.12.23 23:49:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Syke
[2009.04.01 21:25:11 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Template
[2011.02.23 18:33:09 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\The Creative Assembly
[2012.06.10 16:59:11 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Ubisoft
[2010.10.02 15:59:36 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\WinBatch
[2012.04.13 18:04:24 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Windows Live Writer
[2009.09.28 13:59:51 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Zoner
[2012.06.21 23:23:45 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.12.04 22:53:12 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Adobe
[2011.11.19 21:07:10 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Apple Computer
[2011.05.14 16:14:34 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Ashampoo
[2009.03.23 18:38:41 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\ATI
[2011.10.14 19:03:36 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Avira
[2009.04.12 20:09:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\CyberLink
[2011.07.03 20:35:32 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DisneyInteractiveStudios
[2010.04.26 15:32:57 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DivX
[2012.06.20 10:01:58 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoft
[2011.02.13 21:54:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.08.06 19:05:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GetRightToGo
[2009.03.27 21:59:26 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Google
[2011.03.12 14:22:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\GrabPro
[2011.05.24 18:08:51 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\gtk-2.0
[2010.11.18 22:04:54 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Help
[2009.03.23 18:38:55 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Hewlett-Packard
[2010.09.25 22:12:16 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\HP
[2011.03.25 18:10:04 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\HpUpdate
[2009.03.23 18:38:10 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Identities
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Image Zone Express
[2009.04.04 20:49:56 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\InstallShield
[2011.06.25 17:14:48 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Leadertech
[2009.03.23 19:42:52 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Logitech
[2011.12.29 16:21:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\LucasArts
[2009.03.23 18:34:35 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Macromedia
[2012.01.23 22:39:20 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Malwarebytes
[2006.11.02 14:37:34 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Media Center Programs
[2011.04.11 21:16:39 | 000,000,000 | --SD | M] -- C:\Users\Tuan\AppData\Roaming\Microsoft
[2010.07.13 16:07:47 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Mozilla
[2010.02.10 21:39:19 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\muvee Technologies
[2010.12.08 23:50:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\OpenOffice.org
[2012.05.16 19:05:37 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Orbit
[2011.12.21 16:20:24 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Origin
[2012.06.05 19:04:45 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\pdfforge
[2009.06.21 20:24:31 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\PeerNetworking
[2010.09.26 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Printer Info Cache
[2010.11.01 20:25:49 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\ProgSense
[2012.06.01 20:33:09 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\redsn0w
[2010.10.19 18:40:38 | 000,000,000 | RH-D | M] -- C:\Users\Tuan\AppData\Roaming\SecuROM
[2012.05.31 15:02:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Skype
[2012.05.31 15:02:02 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\skypePM
[2011.12.23 23:49:14 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Syke
[2010.02.15 16:07:01 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\teamspeak2
[2009.04.01 21:25:11 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Template
[2011.02.23 18:33:09 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\The Creative Assembly
[2012.06.10 16:59:11 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Ubisoft
[2012.06.15 21:30:10 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\vlc
[2010.10.02 15:59:36 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\WinBatch
[2012.04.13 18:04:24 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Windows Live Writer
[2011.06.25 17:46:01 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\WinRAR
[2012.06.01 16:51:06 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\yahoo!
[2009.09.28 13:59:51 | 000,000,000 | ---D | M] -- C:\Users\Tuan\AppData\Roaming\Zoner
 
< %APPDATA%\*.exe /s >
[2010.09.26 17:24:24 | 000,010,134 | R--- | M] () -- C:\Users\Tuan\AppData\Roaming\Microsoft\Installer\{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}\ARPPRODUCTICON.exe
[2009.04.04 20:50:01 | 000,010,134 | R--- | M] () -- C:\Users\Tuan\AppData\Roaming\Microsoft\Installer\{3101CB58-3482-4D21-AF1A-7057FC935355}\ARPPRODUCTICON.exe
[2009.04.11 22:34:07 | 000,000,766 | R--- | M] () -- C:\Users\Tuan\AppData\Roaming\Microsoft\Installer\{E89B484C-B913-49A0-959B-89E836001658}\ARPPRODUCTICON.exe
[2012.06.07 14:53:32 | 001,361,896 | ---- | M] (EA Digital Illusions CE AB) -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\extensions\battlefieldheroespatcher@ea.com\plugins\BFHUpdater.exe
[2011.09.23 14:07:18 | 001,005,512 | ---- | M] (EA Digital Illusions CE AB) -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\extensions\battlefieldplay4free@ea.com\plugins\BP4FUpdater.exe
 
< %SYSTEMDRIVE%\*.exe >
 
< MD5 for: AGP440.SYS  >
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\ERDNT\cache\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.21 04:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\ERDNT\cache\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.21 04:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\ERDNT\cache\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: EVENTLOG.DLL  >
[2007.01.12 23:30:08 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\ERDNT\cache\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.21 04:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: NVSTOR32.SYS  >
[2008.06.06 21:13:10 | 000,145,440 | ---- | M] (NVIDIA Corporation) MD5=D05F6E26AC960474494356FE703D61BE -- C:\hp\DRIVERS\nvidia_storage\nvstor32.sys
[2008.06.06 21:13:40 | 000,145,440 | ---- | M] (NVIDIA Corporation) MD5=D7B213299852D2026DBC90DAB77EF06C -- C:\Windows\System32\drivers\nvstor32.sys
[2008.06.06 21:13:40 | 000,145,440 | ---- | M] (NVIDIA Corporation) MD5=D7B213299852D2026DBC90DAB77EF06C -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_5396a0ad\nvstor32.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.21 04:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\ERDNT\cache\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\ERDNT\cache\user32.dll
[2008.01.21 04:24:21 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 08:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\ERDNT\cache\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.21 04:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\ERDNT\cache\wininit.exe
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.21 04:23:42 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\ERDNT\cache\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 08:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008.01.21 04:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.21 04:24:47 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2008.01.21 05:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008.01.21 05:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008.01.21 05:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2012.04.06 04:16:52 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\Windows\system32\ATIDEMGX.dll
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:BD36345D

< End of report >

--- --- ---


und hier der Extra.txt

OTL EXTRAS Logfile:
OTL Logfile:
Code:

OTL Extras logfile created on: 22.06.2012 18:39:56 - Run 1
OTL by OldTimer - Version 3.2.51.0    Folder = C:\Users\Tuan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 63,32% Memory free
6,21 Gb Paging File | 4,76 Gb Available in Paging File | 76,76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 583,02 Gb Total Space | 310,66 Gb Free Space | 53,28% Space Free | Partition Type: NTFS
Drive D: | 13,15 Gb Total Space | 1,82 Gb Free Space | 13,85% Space Free | Partition Type: NTFS
 
Computer Name: TUAN-PC | User Name: Tuan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-449065279-793341504-1815772316-1000]
"EnableNotificationsRef" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03CA83AF-76E1-4A6A-BA87-8AF6E0A42463}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{0A71ECE8-9368-4174-B56E-F082A64BBD0E}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{104CF7CD-D0B6-449C-97DD-7735DB1E9256}" = rport=139 | protocol=6 | dir=out | app=system |
"{1C5E55EE-F9C2-4E85-AF5C-9AEC51272A57}" = lport=137 | protocol=17 | dir=in | app=system |
"{1CC3A897-1B00-4DF9-AA2E-CA5CCD431B2D}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{1DFCD8C5-31F5-4319-8709-E842CFD97625}" = lport=2869 | protocol=6 | dir=in | app=system |
"{200EC7A8-865B-4087-8C8F-318B52A90041}" = lport=6112 | protocol=6 | dir=in | name=wc3 |
"{26D406D3-8DD5-4BB5-BEA9-7033B4FD421D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{274A7816-06CC-42C3-BB68-73DD14C2CE2F}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{295FBD73-7DD5-46A7-920A-53C70C3A55B9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2BB1FC75-23FA-4860-9648-0047F1820C53}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{31E8B317-3C04-429C-831D-131CC5D1CCBB}" = lport=5358 | protocol=6 | dir=in | app=system |
"{35252EBE-6EC6-432C-91A2-273881939A4B}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{3867F7BF-2CB6-4497-B5F8-778A4CD2D664}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{42A24DDB-8F9D-4E30-826D-760C1FA240DC}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{4442B079-7923-4794-9257-372B8E8E1DF3}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{4776D466-3FFE-4B68-91AD-62EE117AC98D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{49DBD451-E09E-41FB-86CB-020232C4FF07}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4A5AA4CF-0CE9-4F8A-A2C0-6C7F2E59B2E4}" = rport=5358 | protocol=6 | dir=out | app=system |
"{4B326E58-050F-447E-B6D1-8D77EF6FEB4A}" = lport=5357 | protocol=6 | dir=in | app=system |
"{4D618B4F-98FA-4E82-AF7A-44612AEFF2E6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4FCC3A2C-7DFD-43E3-94FB-B9378A240D49}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{587A0DEF-24E8-466B-B92D-8DA10053E7F9}" = rport=445 | protocol=6 | dir=out | app=system |
"{5922EF2E-5BDF-4F46-AECD-53C7ADE04AEF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5E993312-4E9E-4F24-A286-A623AF353A0D}" = lport=139 | protocol=6 | dir=in | app=system |
"{6454D5C9-211C-4383-8C26-B6BFE6EECAA4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{65568F2F-BCF6-494B-AAD9-3CBEFDF018FC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{680B59F5-9F90-47F4-A894-238FC76861F3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{698439C6-4AD3-4EF4-A143-BF7A58733DAE}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{6BACF3CF-7CE8-4DAA-B96A-974909B20F8B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6D2C2271-CF71-48D5-99E7-7238D40CDD89}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{6FB909C0-A76F-44E5-B920-C32E212D1DE3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{72D114F1-32D2-4939-9855-342FED255F6C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{8168146A-FE66-44D8-8DFC-587201116DAF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{838B749D-9FE2-40A1-B928-076FEE33FFE5}" = lport=138 | protocol=17 | dir=in | app=system |
"{87942F3D-D06B-4BF3-BCEE-6A81F61156F7}" = rport=138 | protocol=17 | dir=out | app=system |
"{8C9E841C-C196-4512-A7D3-C453E8B18ECF}" = rport=137 | protocol=17 | dir=out | app=system |
"{90365249-1B88-475E-8D0C-04769AD27AA1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{987734FF-8F31-4424-9598-62E0EC23E8B0}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{9D181466-17B1-472E-B18F-5AF7057C8911}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{A6A0836B-522B-44AD-89B3-B72EBD5107AA}" = rport=5357 | protocol=6 | dir=out | app=system |
"{AFE3FF91-A8F0-416D-9211-D91EB5D560A9}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{B3B9580D-3202-4CF8-B674-12455586B889}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{B9DF5A48-DEDC-44C5-8B39-9735B294B1F7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B9E6B1B2-8D0C-4170-8C2B-2D42ACD48967}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BBDAFE76-2C3E-45E0-AF90-A2D1BDA0698B}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{BF7385AE-3EF4-447B-913C-C7EB57309F82}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{C6057DCA-4D6D-4378-8A04-6648DAB57A35}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{C6738888-86B9-4FA7-BBF0-C41508EA202B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C87D8B18-3186-4CC7-A13A-9646F4C5742B}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{CA7DA52E-BF9F-4BFF-8D98-6897C22AA453}" = lport=10243 | protocol=6 | dir=in | app=system |
"{CEF4F423-C6F9-428B-B61F-D86C67297D0C}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{D5FFE728-7E92-4E53-AA33-7BF5B0243196}" = lport=445 | protocol=6 | dir=in | app=system |
"{D6AA6B24-D14F-43F0-BB29-782F09916743}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{DC7E5988-9A0B-4DD9-8EAB-8A899BEFA8BE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{E08ED960-6ED1-4C76-8BE2-F75F6BBC2D04}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{E134DC62-855D-454B-8EA0-4C3B98608B0E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{E41D1E8C-CE68-46D3-B8CB-43D77948EF32}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EBDCEA3C-24AE-4CCC-97F3-855F1BCC8238}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{ECE149EF-15C7-404B-BF10-24F84CBD58B9}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{EE14078B-2EFF-46BA-89AC-0F40DA453A71}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EE43A508-A15B-40E2-87BD-68BAE92300DD}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{EE5982B8-9912-4579-A30F-094F9207F86D}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{F95F8EE4-69A5-42A0-BED8-88509376880E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01AFE317-1225-48BE-B54D-85A633031E5C}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreedii.exe |
"{07339EFC-41B7-4195-860D-7C9CA2009DE1}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{083285D2-7C01-4213-AE26-99E3FDA8755D}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{0AE8D622-201F-4EDA-BF1F-A374F0433CB0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\empire total war\empire.exe |
"{112025B5-3BBE-4AB0-82D2-44A71A1C4E29}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\uplaybrowser.exe |
"{119F6890-A4CC-45EC-8E41-9DBD47BB4D90}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{13A5E5CC-F3EC-422E-861B-AEEF187A8EBF}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{144EF265-1132-4E1B-9743-63B4E036F295}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{157FE4D7-7CE7-40FA-952B-2A2E7FE240EA}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{1E0B1293-F8F7-44A6-97D1-B9EF77ACB12E}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{1E9D533B-492C-4285-959C-B4F561953410}" = protocol=17 | dir=in | app=c:\program files\logitech touch mouse server\itouch-server-win.exe |
"{1F974071-2089-464A-92F0-EB1EC230CF5D}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{1FF62491-00A1-4666-847A-AA43F64CBCFB}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{2033363A-F8E0-4050-84F6-A7C9F60154FA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{225AB495-31C5-48F5-A4D0-4F6969CB8D64}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{22E5947F-8647-4124-8FAF-920F3B01F9F1}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{256F48E3-B598-433F-B0F8-096C9AB59D3D}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{276E5F1C-58C0-496F-83F7-C33AF33B76F5}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{27AD5108-7C66-46AC-8EC9-EB00D4E0DD02}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreedii.exe |
"{316BC786-8D6B-4865-9468-51D0AD2324F8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{32D5F70F-8007-4396-AEBC-59C77E60E991}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{33461631-47E2-4A41-9C08-EC0B10DD862F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{33572568-7BC9-45B3-92C0-06DCCFA271FD}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{33BB9A97-0E57-44B6-B74C-290D745F2523}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\uplaybrowser.exe |
"{377D2271-2555-4F71-92F0-DA2B8A0A5AA0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{38F47906-2507-448D-BF3A-36393AB43D46}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3AF84E87-07F8-47B6-8263-77B84519331D}" = protocol=17 | dir=in | app=c:\users\tuan\downloads\sweetimsetup.exe |
"{3E0524CE-C02A-46C8-8999-CF0B2E745F9D}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{3F012817-D384-472B-BD7D-5347D4A1EDDA}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{41DA0DFE-B660-4271-97DA-07C434C1DEB8}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{43A4E0FE-2059-44F9-BE74-3056E9F8C646}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{44195EF7-79B9-4DEB-A973-4CC1117FDAC7}" = protocol=6 | dir=out | app=system |
"{441EAD1D-C000-4481-9069-92ADFB2019D0}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{46689F67-A3F8-4A97-85EA-70BFF89D55BB}" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{4ABC2E31-486C-4DE6-BF17-813952310003}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{4C42EAF5-DF67-449B-A11C-18C6D69771A8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\amd driver updater, vista and 7, 32 bit\setup.exe |
"{4CE71511-654E-4AC0-84FD-800ECCB736B4}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{5029C933-C153-4957-9E7D-CAEA9D48566A}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{50A997B5-1DE0-4D70-A43C-D8ADBFEC76D4}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{5187FFA3-889D-4541-B2BB-57262FA522B4}" = protocol=6 | dir=in | app=c:\program files\avira\antivir desktop\avcenter.exe |
"{541B4969-0169-4BEE-AE6E-486FE02415F9}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{55AEF02F-B3AA-4BB6-8D73-02E5A2630F60}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{56E80A7D-DDE0-476C-9E74-47B75E4C8526}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifetray.exe |
"{58E5713A-1857-42C5-A769-9DECED7F0B56}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{5BE1FBE3-C8AB-4130-91B9-F313092F3C58}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{60100E0D-09BA-46B6-ABB3-2BDA634A5D7D}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{694FC2E2-C595-445E-B3A8-65D6FA7353B2}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{6DAD4258-D7A1-44CB-9B61-7D544A5F2821}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{6DD36D67-C434-4F04-96C7-63FF5960C26E}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{70163C9A-03B8-4EC9-8491-9897BCB1BE0D}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{7433F4AA-C514-4CD4-AB11-BA57CBC23AE5}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreediigame.exe |
"{7547926E-0DBA-4A6F-9780-F6E1D12FFEDB}" = protocol=6 | dir=out | app=%systemroot%\system32\netproj.exe |
"{7A87CBB5-397B-40AE-BB29-5DAC9376B84D}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{83B7E13A-B2BC-4E21-A2BF-DF89AE686C0F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8779801F-1EDB-4D3A-988E-940587D28041}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{8E1893B2-68FE-4A94-AE9D-7BF0B4A102C9}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{99A95C2D-06F7-4665-A850-D7534FA67002}" = protocol=6 | dir=in | app=c:\users\tuan\downloads\sweetimsetup.exe |
"{99ACA650-BDBA-47C3-9D69-57E0A90211D3}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{9BFB19CC-2D5A-4CEE-A243-71A4F99EF8FD}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{9C903254-DD7A-4381-833C-A937C04B1D8E}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeenc2.exe |
"{9CF358EC-6672-4A5A-89F6-D4800E16B9A1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{9D0CAB4D-20F4-4860-9B69-51DF29952B98}" = protocol=6 | dir=in | app=%systemroot%\system32\netproj.exe |
"{9E9606E9-58BD-44F2-BE96-A6462FE2C1C2}" = protocol=17 | dir=in | app=c:\program files\expressfiles\expressfiles.exe |
"{9FB81535-9835-41B6-AC57-B6ECBA88DCFD}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{A077F37F-2577-44AD-A708-D7EC6AEE8228}" = protocol=17 | dir=in | app=c:\program files\avira\antivir desktop\avcenter.exe |
"{A1B757BD-053D-4D18-B40A-B90DBA2D2D71}" = protocol=6 | dir=in | app=c:\program files\logitech touch mouse server\itouch-server-win.exe |
"{A3657604-124E-47F5-8D50-2ECB6D3ED96D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\empire total war\empire.exe |
"{A45BDE44-6065-48D3-8A3B-56F5AC3D0AAE}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{A4E90A5A-13DD-48E0-9637-400C03A0CFD8}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{A715B2C8-0694-48FB-8E9C-D7C769A89AA9}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{A71C4A8D-24F2-4332-819F-A778602FC749}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{A7936BD0-1018-4481-9C02-842E4A346197}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{A930D9EE-FB67-4EB7-AF3C-AB9252A049E1}" = dir=in | app=c:\program files\hp\dvdplay\dpservice.exe |
"{AD462B0F-324D-4A4D-9098-1E6B6769FA25}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{AE5384C1-5FB6-45C4-BFB5-51BCE24173BE}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{AEC9C685-3314-4C02-9E17-8A25DB7AFC3B}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{AFA98EDF-5E5B-474D-8C84-5E5AC9573846}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{B4866984-D73C-4930-B0F1-5696C08AFE0D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\america's army 3\binaries\aa3game.exe |
"{B67E6BD4-9DE2-4BC7-ADB7-F4AC7C6088D4}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{B99EEA81-500C-4EDC-97B6-F563B7836E8B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{BE909427-6A61-44B2-BEBF-74E49DA46E1D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\napoleon total war\napoleon.exe |
"{C71DF248-7E51-433D-9B40-ED09293D1C06}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{C8BE48D6-C424-4154-8EEA-DA228FCF14AD}" = dir=in | app=c:\program files\hp\dvdplay\dvdplay.exe |
"{C8E1D8B5-2783-4A45-B289-0759B4C05BBD}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{CAD4FF4B-CEFF-494D-BDF4-B33F5AB39615}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{CBFD354F-3CC7-43CE-A7D0-279F1CF29FF2}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{CEFD8C85-17F5-446C-BB84-99D9BABD2E00}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{D221F70E-7609-4C6A-B462-155C8DF77C2F}" = protocol=6 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.0\sonarhost.exe |
"{D282827D-97AB-4D0E-BF56-5A25FC85BA99}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{D5A11503-EFF0-4B68-9E0F-DB52A7E525C8}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{D78851BA-8249-4771-AC32-228391FBC878}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{D8542A74-4CC0-44E0-B0DD-490A0519019C}" = protocol=17 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.0\sonarhost.exe |
"{DA261475-BA47-4F2C-92D1-D9D538669B35}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{DB66D1D0-7A57-46C8-865B-558A01C558A4}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\amd driver updater, vista and 7, 32 bit\setup.exe |
"{DD26250F-1B8E-45C6-AA3A-686D8CDCB6CB}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{DDB00913-370D-4A8A-9EB9-ECB667A92061}" = protocol=6 | dir=out | app=system |
"{DE278405-42FB-4474-ACAE-EA511CD6AFEB}" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{E0BE78A4-4A40-4B89-9CEF-FF2C7A8D8D5A}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{E2298536-D4C0-4245-97D2-CA1E56BF14DB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\america's army 3\binaries\aa3game.exe |
"{E2C6C00B-E027-4662-8FCC-40DDBE10C7FA}" = protocol=6 | dir=in | app=c:\program files\expressfiles\expressfiles.exe |
"{E8313FBF-E708-4C16-B5A4-3C532ED75808}" = protocol=17 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{E8CF9801-177E-4599-8BDE-9B1F416813EE}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{ED188903-A491-4AD6-9A1D-38ED1014EBE0}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{F34B680F-74A7-4168-8B27-44DE73B478DF}" = protocol=6 | dir=in | app=c:\program files\expressfiles\expressdl.exe |
"{F46181DC-4ECA-4824-B5B9-71E23273DFA4}" = protocol=17 | dir=in | app=c:\program files\expressfiles\expressdl.exe |
"{F6A477A9-D632-45B2-BB24-8A3E406C00DC}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{F72D8D35-A5ED-4992-AA41-5AC84FA86B6B}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreediigame.exe |
"{FD253463-7D4F-42FA-8441-13C289A369D1}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{FDC04E51-C17E-4A2F-9EEC-644958893CCD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\napoleon total war\napoleon.exe |
"{FEF8F9C6-F336-40A8-9687-64B5AD945973}" = protocol=6 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"TCP Query User{00316C84-6B72-4B99-9502-C786818CC278}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{04441598-6DF3-467F-9EA0-1EA4894FFA62}C:\program files\anno 1701\anno1701.exe" = protocol=6 | dir=in | app=c:\program files\anno 1701\anno1701.exe |
"TCP Query User{1197861E-2BCF-4A30-8D52-2C70F879BFCC}C:\program files\ea games\battlefield 2\bf2_w32ded.exe" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 2\bf2_w32ded.exe |
"TCP Query User{150320AD-15D2-4D4A-85AC-14954BDC7FAE}C:\program files\ea sports\fifa 11\game\fifa.exe" = protocol=6 | dir=in | app=c:\program files\ea sports\fifa 11\game\fifa.exe |
"TCP Query User{2CD04F5C-429E-499F-A765-F9FC043D103F}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{2DD2DC2E-4CEE-41C9-926A-BE55CEEBC660}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{319A48E7-8836-4C79-81F0-80150AF06823}C:\program files\warcraft iii\pickup.listchecker.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\pickup.listchecker.exe |
"TCP Query User{367724CE-FB80-4BA3-93A6-F877973E2D3C}C:\users\tuan\appdata\local\temp\6341536c99024e45b83231740485442f\relicdownloader.exe" = protocol=6 | dir=in | app=c:\users\tuan\appdata\local\temp\6341536c99024e45b83231740485442f\relicdownloader.exe |
"TCP Query User{3757FE47-4728-447A-9C0D-968108CA2A01}C:\users\tuan\downloads\games\gb\gb mp\visualboyadvance.exe" = protocol=6 | dir=in | app=c:\users\tuan\downloads\games\gb\gb mp\visualboyadvance.exe |
"TCP Query User{3A9DF147-0045-4FA9-9F79-2A027929FFB0}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"TCP Query User{472E95D4-DB63-407E-A46E-16180C7E2BAF}C:\program files\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"TCP Query User{4CD803E7-EA2E-4CC3-8394-1D86DB7851E7}C:\program files\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{5660CC62-54FB-4BBA-BC34-C666B574A2F6}C:\program files\steam\steamapps\d_phan\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\d_phan\counter-strike source\hl2.exe |
"TCP Query User{5CE24C74-F3AA-462C-B0BC-B2600439650F}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{6A4297FE-1DED-4F2C-B81D-BDF21F0348A5}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{6CF53668-5E56-4FB2-8978-111BC559CB70}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{73FEB5D6-EFC6-437F-8165-8201CDDF0F44}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{A93087FF-FD22-4630-8CEC-2FBF1785C51A}C:\program files\ea sports\fifa 2003\fifa2003.exe" = protocol=6 | dir=in | app=c:\program files\ea sports\fifa 2003\fifa2003.exe |
"TCP Query User{B4BF4740-1854-4629-856A-F3B79D147F65}C:\users\tuan\downloads\games\snes\snes9x.exe" = protocol=6 | dir=in | app=c:\users\tuan\downloads\games\snes\snes9x.exe |
"TCP Query User{BB7FF89F-9855-4FC3-AA61-8674E8C43E88}C:\program files\american conquest - fight back\dmcr.exe" = protocol=6 | dir=in | app=c:\program files\american conquest - fight back\dmcr.exe |
"TCP Query User{CE8D4CC1-B381-40C1-8B1E-358E97783EC9}C:\program files\panzers - phase1\run\panzers.exe" = protocol=6 | dir=in | app=c:\program files\panzers - phase1\run\panzers.exe |
"TCP Query User{D22EBE74-0AB9-4771-A71E-3BCCFA4C4F52}C:\program files\ea games\battlefield play4free\bfp4f.exe" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield play4free\bfp4f.exe |
"TCP Query User{E5B4E554-99D5-4947-B3AC-9B2864F0B7A0}C:\program files\ea sports\fifa 11\game\fifa.exe" = protocol=6 | dir=in | app=c:\program files\ea sports\fifa 11\game\fifa.exe |
"TCP Query User{E601C8B6-6FD3-4826-A0B6-8D09625331D6}C:\program files\warcraft iii\listchecker\pickup.listchecker.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\listchecker\pickup.listchecker.exe |
"TCP Query User{F064F6C3-F4BA-4F89-ABF5-7EA0D3621189}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{01A58E33-BEED-4FC8-8780-A14E4638930A}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{27AB5D13-05AF-4145-8AA0-314F988039C7}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{42C1E6C0-3DCB-41DA-97F0-F7FDBB45CF01}C:\users\tuan\downloads\games\snes\snes9x.exe" = protocol=17 | dir=in | app=c:\users\tuan\downloads\games\snes\snes9x.exe |
"UDP Query User{46D24C6C-23FA-4ADC-8855-C46DCCD7099D}C:\users\tuan\downloads\games\gb\gb mp\visualboyadvance.exe" = protocol=17 | dir=in | app=c:\users\tuan\downloads\games\gb\gb mp\visualboyadvance.exe |
"UDP Query User{6845EFB0-2C85-410E-B4E0-3A2D77C508D3}C:\program files\ea sports\fifa 11\game\fifa.exe" = protocol=17 | dir=in | app=c:\program files\ea sports\fifa 11\game\fifa.exe |
"UDP Query User{6D9ABDEE-9B7F-4902-8A8F-6AC5E67D2C60}C:\users\tuan\appdata\local\temp\6341536c99024e45b83231740485442f\relicdownloader.exe" = protocol=17 | dir=in | app=c:\users\tuan\appdata\local\temp\6341536c99024e45b83231740485442f\relicdownloader.exe |
"UDP Query User{7313A7EB-A198-4C63-A4DF-EBE5D56371D4}C:\program files\panzers - phase1\run\panzers.exe" = protocol=17 | dir=in | app=c:\program files\panzers - phase1\run\panzers.exe |
"UDP Query User{738D9FFA-9B78-47E4-8831-7303805F58C4}C:\program files\ea sports\fifa 11\game\fifa.exe" = protocol=17 | dir=in | app=c:\program files\ea sports\fifa 11\game\fifa.exe |
"UDP Query User{76FD395E-C089-459E-B7BB-CB4659783C01}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{7C38298F-5832-4780-825B-C2BB5AE683E8}C:\program files\ea sports\fifa 2003\fifa2003.exe" = protocol=17 | dir=in | app=c:\program files\ea sports\fifa 2003\fifa2003.exe |
"UDP Query User{81A011D5-AE3C-4625-9DAD-85E751A09A24}C:\program files\anno 1701\anno1701.exe" = protocol=17 | dir=in | app=c:\program files\anno 1701\anno1701.exe |
"UDP Query User{88DF5D2E-488E-4EC9-80DC-243C85A7A555}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{8D222F70-C368-4632-AAF5-F63952D13DF5}C:\program files\steam\steamapps\d_phan\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\d_phan\counter-strike source\hl2.exe |
"UDP Query User{8E59D023-0FCA-4D91-B51E-DADB9435B868}C:\program files\ea games\battlefield 2\bf2_w32ded.exe" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 2\bf2_w32ded.exe |
"UDP Query User{954C302D-AF3A-4780-8933-F9EA9A4F5DAA}C:\program files\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{9915F5CD-8DA2-46D3-A829-45F0EC9EED08}C:\program files\warcraft iii\pickup.listchecker.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\pickup.listchecker.exe |
"UDP Query User{AF50138B-1FB8-4E07-AF7E-289BE0ED7160}C:\program files\warcraft iii\listchecker\pickup.listchecker.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\listchecker\pickup.listchecker.exe |
"UDP Query User{AFF34FEA-63DC-4C0B-98F0-0BE238C848B8}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{B4131824-B879-43EC-9AD5-8B7D68C13400}C:\program files\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{C4250DDB-F4BE-4959-BFE0-098DBD30ACCB}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{C5354FF1-A3F4-4727-800C-05C9654B9EC3}C:\program files\american conquest - fight back\dmcr.exe" = protocol=17 | dir=in | app=c:\program files\american conquest - fight back\dmcr.exe |
"UDP Query User{DA494E8E-BB6C-4984-BFB7-8ED05F3D335F}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{E3E57A2C-7A62-4AB7-8F95-5C8617E6BCB7}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{E69252DC-D227-4E9E-901B-3A0D386165AB}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{ECE758AD-A621-449A-863B-CD12B0B07FC9}C:\program files\ea games\battlefield play4free\bfp4f.exe" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield play4free\bfp4f.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03D4C700-2BFE-43E0-A0B4-9512B43C5B9F}" = Catalyst Control Center - Branding
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2(TM)
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0EC7C406-B592-4686-BAC1-AD29A85EAE6A}" = HP Driver Diagnostics
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{19D614EB-D62A-AEE7-2391-E74126601D59}" = CCC Help Italian
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1C373820-B9C8-0F7F-8F84-FC1B76A85F27}" = CCC Help Portuguese
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{26EC9601-D617-02AE-ABE1-F68B8560C408}" = Catalyst Control Center InstallProxy
"{2D35BC33-7D08-D529-DF91-8A15FBF2600E}" = CCC Help Polish
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{2FC92BF4-F8BB-755F-755C-D756383C4CF3}" = ccc-utility
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{337788D1-43D1-9A0F-9787-DD00DB512D41}" = Catalyst Control Center Localization All
"{36C97B5B-5593-45B8-B50E-DAD87036BD9D}" = Microsoft LifeCam
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{39D0E034-1042-4905-BECB-5502909FCB7C}" = Microsoft Works
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4286716B-1287-48E7-9078-3DC8248DBA96}" = OpenOffice.org 3.3
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = DVD Play BD
"{4725833D-4325-5C34-57D4-1FE23E5AE578}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B271648-43CB-DD31-FF24-E7B06D3EE72A}" = Catalyst Control Center InstallProxy
"{4DC37F33-7AEC-A4CB-56B1-69A402828763}" = CCC Help Japanese
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{50D4CB89-AF34-4978-96DC-C3034062E901}" = Battlefield 2: Special Forces
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{5710DAC2-8F2A-503C-CFC2-A973ADE0EA4C}" = CCC Help Czech
"{586509F0-350D-48B5-B763-9CC2F8D96C4C}" = Windows Live Sync
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5C763682-4C40-86DA-9C46-31924D7D2C34}" = CCC Help Thai
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{60E5022D-FA4B-C6A2-1E80-B46EC39096F3}" = CCC Help Chinese Traditional
"{60F34FDF-267C-408F-290E-EC90D841C8CB}" = CCC Help German
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66B79AE1-C6E2-B958-689C-D0812DE86BAB}" = CCC Help Greek
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6833245E-DD86-479A-882A-8360D62C8194}" = NVIDIA PhysX
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{6B39BE0F-0F5E-A8FA-33E4-8481AE39D96C}" = CCC Help Russian
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E19F2AF-7145-51DE-E395-7729A9374973}" = Catalyst Control Center Graphics Previews Common
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage
"{91CB5B8B-4EC8-DBA1-A88D-99FD480567B0}" = CCC Help English
"{924FBAC4-60D2-7981-3C3E-979DF9CBB346}" = CCC Help Finnish
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00AF-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (German)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9580813D-94B1-4C28-9426-A441E2BB29A5}" = Counter-Strike: Source
"{97ABD26A-3249-46CB-B2E2-F66E64B2E480}" = HP Demo
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{9DC939DC-B7A4-D0E2-C582-A442DF1B3EBE}" = CCC Help Spanish
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A1BD938B-F006-6E6D-70B2-47E1DD56F7DE}" = CCC Help Swedish
"{A2433A63-5F5D-40E5-B529-9123C2B3E734}" = Anno 1701
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Deutsch
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B9AB88D8-3A09-4A4A-8993-0E2F6F9F294B}" = muvee autoProducer 6.1
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{BABF7852-C2DD-6A8A-9956-101720C715C7}" = CCC Help Turkish
"{BB7C2A56-9706-43B8-5A8C-210AF5816106}" = CCC Help French
"{BF7E72DC-FD54-20A6-8F92-E6F27F1D579D}" = AMD Fuel
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C911A0C2-2236-3164-AA47-F2566C01AE5E}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{C9EAEE6B-741F-421D-B9CE-9FA300DA92AD}_is1" = Super Mario Bros. X version 1.3
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE3DF04B-D674-369C-8469-75285614A8C4}" = AMD Catalyst Install Manager
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFC2CB60-5654-05A7-4D30-C661800A3A92}" = CCC Help Korean
"{D04CE005-D1D2-80F3-84C8-B3524FCD39C3}" = CCC Help Norwegian
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{D544AE4C-4152-225B-A897-6756C8986B14}" = AMD VISION Engine Control Center
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D81E9069-3CCC-4405-3751-71E4AFEACC52}" = CCC Help Hungarian
"{DA9DAC64-C947-47BA-B411-8A1959B177CF}" = LightScribe System Software  1.14.25.1
"{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E89B484C-B913-49A0-959B-89E836001658}" = GEAR 32bit Driver Installer
"{E93FF166-DF14-2537-8FB4-96BB5810A96C}" = CCC Help Danish
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F405DC00-37F3-4A5F-97F4-C1310CCEE53A}" = HP Easy Setup - Frontend
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F750C986-5310-3A5A-95F8-4EC71C8AC01C}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"{FA9827E1-8A8E-C176-4923-0840A67ED4DE}" = CCC Help Dutch
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Ashampoo Burning Studio Elements_is1" = Ashampoo Burning Studio Elements 10.0.9
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira Free Antivirus
"AVMFBox" = AVM FRITZ!Box Dokumentation
"Battlelog Web Plugins" = Battlelog Web Plugins
"CCleaner" = CCleaner
"CCWORLD" = CCWORLD
"Company of Heroes" = Company of Heroes
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup" = DivX-Setup
"ESET Online Scanner" = ESET Online Scanner v3
"ESN Sonar-0.70.0" = ESN Sonar
"Forte Free" = Forte Free 2.0
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Audio Converter_is1" = Free Audio Converter version 2.2.12
"Free Disc Burner_is1" = Free Disc Burner version 3.0.1
"Free DVD Video Burner_is1" = Free DVD Video Burner version 3.0.1
"Free MP4 Video Converter_is1" = Free MP4 Video Converter version 5.0.11.508
"Free Studio_is1" = Free Studio version 5.0.3
"Free YouTube to iPhone Converter_is1" = Free YouTube to iPhone Converter version 2.10.34.517
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.24.608
"GeoGebra" = GeoGebra
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.0.4 (Basic)
"LEGO Star Wars III The Clone Wars" = LEGO Star Wars III The Clone Wars
"Logitech Touch Mouse Server" = Logitech Touch Mouse Server 1.0
"Logitech Unifying" = Logitech Unifying-Software 2.00
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.61.0.1400
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Mozilla Firefox 13.0.1 (x86 de)" = Mozilla Firefox 13.0.1 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Testversion von Microsoft Office Home and Student 2007
"OpenAL" = OpenAL
"Origin" = Origin
"PC-Doctor for Windows" = Hardware Diagnose Tools
"PunkBusterSvc" = PunkBuster Services
"Red Alert" = Red Alert Windows 95
"Red Alert Themes" = Red Alert Themes
"STARWARS: The Battle of Endor v2.1_is1" = STARWARS: The Battle of Endor version 2.1
"STARWARS: The Battle of Yavin v1.1_is1" = STARWARS: The Battle of Yavin version 1.1
"Steam App 22600" = Worms Reloaded
"Steam App 34030" = Napoleon: Total War
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Uninstall_is1" = Uninstall 1.0.0.1
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 2.0.1
"WChat" = Westwood Online
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.01 (32-Bit)
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Suche Schutzvorkehrung
"Yahoo! Software Update" = Yahoo! Software Update
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 05.11.2010 12:27:38 | Computer Name = Tuan-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 06.11.2010 08:33:38 | Computer Name = Tuan-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 06.11.2010 13:40:20 | Computer Name = Tuan-PC | Source = MsiInstaller | ID = 11312
Description =
 
Error - 07.11.2010 10:00:07 | Computer Name = Tuan-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 07.11.2010 14:02:19 | Computer Name = Tuan-PC | Source = Bonjour Service | ID = 100
Description = 404: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 08.11.2010 13:19:52 | Computer Name = Tuan-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 08.11.2010 16:35:40 | Computer Name = Tuan-PC | Source = Bonjour Service | ID = 100
Description = 404: ERROR: read_msg errno 10054 (Eine vorhandene Verbindung wurde
 vom Remotehost geschlossen.)
 
Error - 09.11.2010 08:57:07 | Computer Name = Tuan-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 09.11.2010 09:42:19 | Computer Name = Tuan-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 10.11.2010 08:59:55 | Computer Name = Tuan-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4385
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4385
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4385
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4385
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
 
Error - 22.06.2012 10:12:03 | Computer Name = Tuan-PC | Source = Microsoft-Windows-Servicing | ID = 4385
Description =
 
 
< End of report >

--- --- ---

--- --- ---

[/code]

cosinus 24.06.2012 15:42

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Code:

:OTL
IE - HKLM\..\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKLM\..\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=109130&tt=261211_ctrl&babsrc=SP_ss&mntrId=5e90e91800000000000000ff9250e086
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}: "URL" = http://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
IE - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://de.search.yahoo.com/search?p={searchTerms}&fr=chr-rog
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?AF=109130&tt=261211_ctrl&babsrc=adbartrp&mntrId=5e90e91800000000000000ff9250e086&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
[2011.03.24 13:03:00 | 000,000,923 | ---- | M] () -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\conduit.xml
[2011.10.29 16:23:12 | 000,003,915 | ---- | M] () -- C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\sweetim.xml
[2009.06.24 14:37:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.12.29 15:53:47 | 000,002,351 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) -  - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Media Finder] "C:\Program Files\Media Finder\Media Finder.exe" /opentotray File not found
O4 - HKU\S-1-5-21-449065279-793341504-1815772316-1000..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Save YouTube Video - Reg Error: Value error. File not found
O8 - Extra context menu item: Save YouTube Video as MP3 - Reg Error: Value error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.10.27 17:51:08 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
[2012.04.13 18:47:51 | 000,000,023 | ---- | C] () -- C:\Windows\clofghls.dll
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:BD36345D
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Hajaku 24.06.2012 17:41

Code:

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{879950C1-3353-486B-893E-6E23EE9D5329}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C0057537-1C1F-405C-B6EB-050826BA3A2A}\ not found.
Registry key HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\SearchScopes\{879950C1-3353-486B-893E-6E23EE9D5329}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{879950C1-3353-486B-893E-6E23EE9D5329}\ not found.
Registry key HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}\ not found.
Registry key HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C0057537-1C1F-405C-B6EB-050826BA3A2A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C0057537-1C1F-405C-B6EB-050826BA3A2A}\ not found.
Registry key HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ not found.
Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename
Prefs.js: "MyAshampoo Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1
Prefs.js: "hxxp://search.babylon.com/?AF=109130&tt=261211_ctrl&babsrc=adbartrp&mntrId=5e90e91800000000000000ff9250e086&q=" removed from keyword.URL
Prefs.js: "*.local" removed from network.proxy.no_proxies_on
C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\conduit.xml moved successfully.
C:\Users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\searchplugins\sweetim.xml moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\defaults\preferences folder moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\defaults folder moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\chrome folder moved successfully.
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION folder moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0124123D-61B4-456f-AF86-78C53A0790C5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0124123D-61B4-456f-AF86-78C53A0790C5}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0124123D-61B4-456f-AF86-78C53A0790C5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0124123D-61B4-456f-AF86-78C53A0790C5}\ not found.
Registry value HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C55BBCD6-41AD-48AD-9953-3609C48EACC7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}\ not found.
Registry value HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Media Finder deleted successfully.
Registry value HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Pando Media Booster deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Save YouTube Video\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Save YouTube Video as MP3\ deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
C:\Windows\clofghls.dll moved successfully.
ADS C:\ProgramData\TEMP:BD36345D deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Gast
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: Tran Trong Chinh
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Tuan
->Temp folder emptied: 12979702 bytes
->Temporary Internet Files folder emptied: 16679348 bytes
->Java cache emptied: 116773 bytes
->FireFox cache emptied: 168800143 bytes
->Flash cache emptied: 2513 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9146 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 189,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Gast
->Flash cache emptied: 0 bytes
 
User: Public
 
User: Tran Trong Chinh
->Flash cache emptied: 0 bytes
 
User: Tuan
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.51.0 log created on 06242012_183205

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


cosinus 24.06.2012 17:50

Ich brauch den Quarantäneordner von OTL. Bitte folgendes machen:

1.) GANZ WICHTIG!! Virenscanner deaktivieren, der darf das Packen nicht beeinflussen!
2.) Ordner MovedFiles in C:\_OTL in eine Datei zippen
3.) Die erstellte ZIP-Datei hier hochladen => http://www.trojaner-board.de/54791-a...ner-board.html

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang in den Thread posten!

4.) Wenns erfolgreich war Bescheid sagen
5.) Erst dann wieder den Virenscanner einschalten

Hajaku 24.06.2012 18:12

so hochgeladen

cosinus 24.06.2012 18:18

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg

Hajaku 25.06.2012 13:13

ich hoffe mal, dass es das richtige log ist
Code:

14:09:32.0888 5432        TDSS rootkit removing tool 2.7.41.0 Jun 20 2012 20:53:32
14:09:33.0060 5432        ============================================================
14:09:33.0060 5432        Current date / time: 2012/06/25 14:09:33.0060
14:09:33.0060 5432        SystemInfo:
14:09:33.0060 5432       
14:09:33.0060 5432        OS Version: 6.0.6002 ServicePack: 2.0
14:09:33.0060 5432        Product type: Workstation
14:09:33.0060 5432        ComputerName: TUAN-PC
14:09:33.0060 5432        UserName: Tuan
14:09:33.0060 5432        Windows directory: C:\Windows
14:09:33.0060 5432        System windows directory: C:\Windows
14:09:33.0060 5432        Processor architecture: Intel x86
14:09:33.0060 5432        Number of processors: 4
14:09:33.0060 5432        Page size: 0x1000
14:09:33.0060 5432        Boot type: Normal boot
14:09:33.0060 5432        ============================================================
14:09:33.0637 5432        Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:09:33.0637 5432        ============================================================
14:09:33.0637 5432        \Device\Harddisk0\DR0:
14:09:33.0637 5432        MBR partitions:
14:09:33.0637 5432        \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x48E08A0D
14:09:33.0637 5432        \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x48E08A4C, BlocksNum 0x1A4E475
14:09:33.0637 5432        ============================================================
14:09:33.0653 5432        C: <-> \Device\Harddisk0\DR0\Partition0
14:09:33.0715 5432        D: <-> \Device\Harddisk0\DR0\Partition1
14:09:33.0715 5432        ============================================================
14:09:33.0715 5432        Initialize success
14:09:33.0715 5432        ============================================================
14:10:33.0092 5220        ============================================================
14:10:33.0092 5220        Scan started
14:10:33.0092 5220        Mode: Manual; SigCheck; TDLFS;
14:10:33.0092 5220        ============================================================
14:10:33.0560 5220        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
14:10:33.0731 5220        ACPI - ok
14:10:33.0950 5220        AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
14:10:33.0965 5220        AdobeARMservice - ok
14:10:34.0012 5220        AdobeFlashPlayerUpdateSvc (990dc6edc9f933194d7cd4e65146bc94) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
14:10:34.0028 5220        AdobeFlashPlayerUpdateSvc - ok
14:10:34.0090 5220        adp94xx        (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
14:10:34.0168 5220        adp94xx - ok
14:10:34.0386 5220        adpahci        (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
14:10:34.0449 5220        adpahci - ok
14:10:34.0948 5220        adpu160m        (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
14:10:34.0964 5220        adpu160m - ok
14:10:34.0995 5220        adpu320        (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
14:10:35.0026 5220        adpu320 - ok
14:10:35.0057 5220        AeLookupSvc    (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
14:10:35.0198 5220        AeLookupSvc - ok
14:10:35.0603 5220        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
14:10:35.0712 5220        AFD - ok
14:10:35.0759 5220        agp440          (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
14:10:35.0790 5220        agp440 - ok
14:10:35.0837 5220        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
14:10:35.0853 5220        aic78xx - ok
14:10:35.0993 5220        ALG            (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
14:10:36.0102 5220        ALG - ok
14:10:36.0149 5220        aliide          (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
14:10:36.0180 5220        aliide - ok
14:10:36.0898 5220        AMD External Events Utility (50ebbb86e493bd9ab7ddf914a90eef8e) C:\Windows\system32\atiesrxx.exe
14:10:37.0007 5220        AMD External Events Utility - ok
14:10:37.0272 5220        AMD FUEL Service - ok
14:10:37.0335 5220        amdagp          (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
14:10:37.0350 5220        amdagp - ok
14:10:37.0366 5220        amdide          (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
14:10:37.0397 5220        amdide - ok
14:10:37.0428 5220        amdiox86        (ff258424f0b2ef25eb98f04ee386e6e3) C:\Windows\system32\DRIVERS\amdiox86.sys
14:10:37.0460 5220        amdiox86 - ok
14:10:37.0631 5220        AmdK7          (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
14:10:37.0725 5220        AmdK7 - ok
14:10:37.0740 5220        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
14:10:37.0787 5220        AmdK8 - ok
14:10:40.0283 5220        amdkmdag        (70eb74785ab7fc603fef19d87b7a7946) C:\Windows\system32\DRIVERS\atikmdag.sys
14:10:40.0954 5220        amdkmdag - ok
14:10:41.0110 5220        amdkmdap        (ba99833bbde9c4ff389fc8114fb14843) C:\Windows\system32\DRIVERS\atikmpag.sys
14:10:41.0328 5220        amdkmdap - ok
14:10:41.0438 5220        AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files\Avira\AntiVir Desktop\sched.exe
14:10:41.0453 5220        AntiVirSchedulerService - ok
14:10:41.0547 5220        AntiVirService  (a489be6bb0aa1ff406b488b60542314b) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
14:10:41.0562 5220        AntiVirService - ok
14:10:41.0625 5220        AODDriver4.01  (40c15ce1b832b78cc2a2f61807058763) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys
14:10:41.0640 5220        AODDriver4.01 - ok
14:10:41.0656 5220        AODDriver4.1    (40c15ce1b832b78cc2a2f61807058763) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys
14:10:41.0672 5220        AODDriver4.1 - ok
14:10:41.0703 5220        Appinfo        (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
14:10:41.0781 5220        Appinfo - ok
14:10:41.0843 5220        Apple Mobile Device (f401929ee0cc92bfe7f15161ca535383) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
14:10:41.0874 5220        Apple Mobile Device - ok
14:10:41.0937 5220        arc            (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
14:10:41.0952 5220        arc - ok
14:10:41.0999 5220        arcsas          (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
14:10:42.0030 5220        arcsas - ok
14:10:42.0140 5220        aspnet_state    (776acefa0ca9df0faa51a5fb2f435705) C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
14:10:42.0140 5220        aspnet_state - ok
14:10:42.0171 5220        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
14:10:42.0218 5220        AsyncMac - ok
14:10:42.0233 5220        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
14:10:42.0249 5220        atapi - ok
14:10:42.0311 5220        AtiHDAudioService (35290682dbdb9cede934b73369f3cede) C:\Windows\system32\drivers\AtihdLH3.sys
14:10:42.0327 5220        AtiHDAudioService - ok
14:10:43.0169 5220        atikmdag        (70eb74785ab7fc603fef19d87b7a7946) C:\Windows\system32\DRIVERS\atikmdag.sys
14:10:43.0778 5220        atikmdag - ok
14:10:43.0980 5220        atksgt          (6e996cf8459a2594e0e9609d0e34d41f) C:\Windows\system32\DRIVERS\atksgt.sys
14:10:44.0074 5220        atksgt ( UnsignedFile.Multi.Generic ) - warning
14:10:44.0074 5220        atksgt - detected UnsignedFile.Multi.Generic (1)
14:10:44.0121 5220        AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
14:10:44.0183 5220        AudioEndpointBuilder - ok
14:10:44.0183 5220        Audiosrv        (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
14:10:44.0230 5220        Audiosrv - ok
14:10:44.0261 5220        avgntflt        (d5541f0afb767e85fc412fc609d96a74) C:\Windows\system32\DRIVERS\avgntflt.sys
14:10:44.0277 5220        avgntflt - ok
14:10:44.0292 5220        avipbb          (7d967a682d4694df7fa57d63a2db01fe) C:\Windows\system32\DRIVERS\avipbb.sys
14:10:44.0324 5220        avipbb - ok
14:10:44.0370 5220        AVK Tuner Service - ok
14:10:44.0386 5220        avkmgr          (271cfd1a989209b1964e24d969552bf7) C:\Windows\system32\DRIVERS\avkmgr.sys
14:10:44.0402 5220        avkmgr - ok
14:10:44.0417 5220        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
14:10:44.0464 5220        Beep - ok
14:10:44.0511 5220        BFE            (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll
14:10:44.0573 5220        BFE - ok
14:10:44.0667 5220        BITS            (93952506c6d67330367f7e7934b6a02f) C:\Windows\system32\qmgr.dll
14:10:44.0792 5220        BITS - ok
14:10:44.0854 5220        blbdrive        (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
14:10:44.0901 5220        blbdrive - ok
14:10:44.0979 5220        Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
14:10:45.0010 5220        Bonjour Service - ok
14:10:45.0072 5220        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
14:10:45.0104 5220        bowser - ok
14:10:45.0135 5220        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
14:10:45.0182 5220        BrFiltLo - ok
14:10:45.0228 5220        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
14:10:45.0275 5220        BrFiltUp - ok
14:10:45.0306 5220        Browser        (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
14:10:45.0369 5220        Browser - ok
14:10:45.0416 5220        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
14:10:45.0603 5220        Brserid - ok
14:10:45.0618 5220        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
14:10:45.0728 5220        BrSerWdm - ok
14:10:45.0743 5220        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
14:10:45.0806 5220        BrUsbMdm - ok
14:10:45.0806 5220        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
14:10:45.0852 5220        BrUsbSer - ok
14:10:45.0884 5220        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
14:10:45.0930 5220        BTHMODEM - ok
14:10:45.0962 5220        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
14:10:46.0008 5220        cdfs - ok
14:10:46.0040 5220        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
14:10:46.0055 5220        cdrom - ok
14:10:46.0086 5220        CertPropSvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
14:10:46.0118 5220        CertPropSvc - ok
14:10:46.0149 5220        circlass        (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
14:10:46.0180 5220        circlass - ok
14:10:46.0211 5220        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
14:10:46.0242 5220        CLFS - ok
14:10:46.0289 5220        clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:10:46.0305 5220        clr_optimization_v2.0.50727_32 - ok
14:10:46.0398 5220        clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:10:46.0414 5220        clr_optimization_v4.0.30319_32 - ok
14:10:46.0430 5220        cmdide          (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
14:10:46.0461 5220        cmdide - ok
14:10:46.0476 5220        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
14:10:46.0492 5220        Compbatt - ok
14:10:46.0508 5220        COMSysApp - ok
14:10:46.0508 5220        crcdisk        (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
14:10:46.0539 5220        crcdisk - ok
14:10:46.0554 5220        Crusoe          (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
14:10:46.0601 5220        Crusoe - ok
14:10:46.0664 5220        CryptSvc        (75c6a297e364014840b48eccd7525e30) C:\Windows\system32\cryptsvc.dll
14:10:46.0742 5220        CryptSvc - ok
14:10:46.0788 5220        DcomLaunch      (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
14:10:46.0820 5220        DcomLaunch - ok
14:10:46.0882 5220        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
14:10:46.0929 5220        DfsC - ok
14:10:47.0085 5220        DFSR            (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe
14:10:47.0288 5220        DFSR - ok
14:10:47.0490 5220        Dhcp            (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll
14:10:47.0537 5220        Dhcp - ok
14:10:47.0568 5220        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
14:10:47.0600 5220        disk - ok
14:10:47.0662 5220        Dnscache        (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll
14:10:47.0724 5220        Dnscache - ok
14:10:47.0756 5220        dot3svc        (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll
14:10:47.0802 5220        dot3svc - ok
14:10:47.0834 5220        Dot4            (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
14:10:47.0912 5220        Dot4 - ok
14:10:47.0943 5220        Dot4Print      (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
14:10:48.0005 5220        Dot4Print - ok
14:10:48.0036 5220        dot4usb        (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
14:10:48.0114 5220        dot4usb - ok
14:10:48.0146 5220        DPS            (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
14:10:48.0192 5220        DPS - ok
14:10:48.0224 5220        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
14:10:48.0270 5220        drmkaud - ok
14:10:48.0333 5220        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
14:10:48.0395 5220        DXGKrnl - ok
14:10:48.0473 5220        E1G60          (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
14:10:48.0504 5220        E1G60 - ok
14:10:48.0504 5220        EagleNT - ok
14:10:48.0536 5220        EapHost        (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
14:10:48.0567 5220        EapHost - ok
14:10:48.0598 5220        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
14:10:48.0629 5220        Ecache - ok
14:10:48.0676 5220        ehRecvr        (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
14:10:48.0707 5220        ehRecvr - ok
14:10:48.0723 5220        ehSched        (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
14:10:48.0785 5220        ehSched - ok
14:10:48.0801 5220        ehstart        (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
14:10:48.0832 5220        ehstart - ok
14:10:48.0910 5220        ElbyCDIO        (d71233d7ccc2e64f8715a20428d5a33b) C:\Windows\system32\Drivers\ElbyCDIO.sys
14:10:48.0941 5220        ElbyCDIO - ok
14:10:48.0972 5220        elxstor        (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
14:10:49.0019 5220        elxstor - ok
14:10:49.0082 5220        EMDMgmt        (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll
14:10:49.0175 5220        EMDMgmt - ok
14:10:49.0191 5220        ErrDev          (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
14:10:49.0253 5220        ErrDev - ok
14:10:49.0284 5220        EventSystem    (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll
14:10:49.0362 5220        EventSystem - ok
14:10:49.0409 5220        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
14:10:49.0503 5220        exfat - ok
14:10:49.0550 5220        ezSharedSvc    (42f721c52eef2d6df9372a53813a83ef) C:\Windows\System32\ezsvc7.dll
14:10:49.0581 5220        ezSharedSvc ( UnsignedFile.Multi.Generic ) - warning
14:10:49.0581 5220        ezSharedSvc - detected UnsignedFile.Multi.Generic (1)
14:10:49.0612 5220        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
14:10:49.0674 5220        fastfat - ok
14:10:49.0706 5220        fdc            (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
14:10:49.0752 5220        fdc - ok
14:10:49.0768 5220        fdPHost        (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
14:10:49.0815 5220        fdPHost - ok
14:10:49.0830 5220        FDResPub        (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
14:10:49.0908 5220        FDResPub - ok
14:10:49.0940 5220        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
14:10:49.0955 5220        FileInfo - ok
14:10:49.0971 5220        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
14:10:50.0018 5220        Filetrace - ok
14:10:50.0033 5220        flpydisk        (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
14:10:50.0064 5220        flpydisk - ok
14:10:50.0080 5220        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
14:10:50.0096 5220        FltMgr - ok
14:10:50.0205 5220        FontCache      (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll
14:10:50.0267 5220        FontCache - ok
14:10:50.0330 5220        FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:10:50.0345 5220        FontCache3.0.0.0 - ok
14:10:50.0408 5220        Fs_Rec          (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys
14:10:50.0454 5220        Fs_Rec - ok
14:10:50.0470 5220        gagp30kx        (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
14:10:50.0486 5220        gagp30kx - ok
14:10:50.0501 5220        GEARAspiWDM    (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\Drivers\GEARAspiWDM.sys
14:10:50.0532 5220        GEARAspiWDM - ok
14:10:50.0564 5220        ggflt          (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys
14:10:50.0579 5220        ggflt - ok
14:10:50.0595 5220        ggsemc          (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys
14:10:50.0610 5220        ggsemc - ok
14:10:50.0673 5220        gpsvc          (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll
14:10:50.0751 5220        gpsvc - ok
14:10:50.0829 5220        gupdate        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
14:10:50.0844 5220        gupdate - ok
14:10:50.0860 5220        gupdatem        (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
14:10:50.0876 5220        gupdatem - ok
14:10:50.0922 5220        HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys
14:10:50.0985 5220        HdAudAddService - ok
14:10:51.0032 5220        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
14:10:51.0141 5220        HDAudBus - ok
14:10:51.0172 5220        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
14:10:51.0266 5220        HidBth - ok
14:10:51.0297 5220        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
14:10:51.0375 5220        HidIr - ok
14:10:51.0406 5220        hidserv        (84067081f3318162797385e11a8f0582) C:\Windows\System32\hidserv.dll
14:10:51.0437 5220        hidserv - ok
14:10:51.0453 5220        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
14:10:51.0484 5220        HidUsb - ok
14:10:51.0515 5220        hkmsvc          (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
14:10:51.0562 5220        hkmsvc - ok
14:10:51.0609 5220        HP Health Check Service (a3a30438c48d2d71556e120c9c7ba7a0) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
14:10:51.0609 5220        HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
14:10:51.0609 5220        HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
14:10:51.0640 5220        HpCISSs        (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
14:10:51.0656 5220        HpCISSs - ok
14:10:51.0718 5220        HTTP            (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
14:10:51.0827 5220        HTTP - ok
14:10:51.0890 5220        i2omp          (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
14:10:51.0921 5220        i2omp - ok
14:10:51.0952 5220        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
14:10:51.0999 5220        i8042prt - ok
14:10:52.0030 5220        iaStorV        (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
14:10:52.0077 5220        iaStorV - ok
14:10:52.0186 5220        IDriverT        (6f95324909b502e2651442c1548ab12f) C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
14:10:52.0202 5220        IDriverT ( UnsignedFile.Multi.Generic ) - warning
14:10:52.0202 5220        IDriverT - detected UnsignedFile.Multi.Generic (1)
14:10:52.0311 5220        idsvc          (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:10:52.0404 5220        idsvc - ok
14:10:52.0451 5220        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
14:10:52.0482 5220        iirsp - ok
14:10:52.0529 5220        IKEEXT          (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll
14:10:52.0638 5220        IKEEXT - ok
14:10:52.0826 5220        IntcAzAudAddService (3914ea9111dbeffaf1c68200817768ad) C:\Windows\system32\drivers\RTKVHDA.sys
14:10:53.0013 5220        IntcAzAudAddService - ok
14:10:53.0106 5220        intelide        (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
14:10:53.0122 5220        intelide - ok
14:10:53.0153 5220        intelppm        (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
14:10:53.0216 5220        intelppm - ok
14:10:53.0231 5220        IPBusEnum      (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
14:10:53.0294 5220        IPBusEnum - ok
14:10:53.0325 5220        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:10:53.0372 5220        IpFilterDriver - ok
14:10:53.0403 5220        iphlpsvc        (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll
14:10:53.0434 5220        iphlpsvc - ok
14:10:53.0450 5220        IpInIp - ok
14:10:53.0465 5220        IPMIDRV        (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
14:10:53.0481 5220        IPMIDRV - ok
14:10:53.0496 5220        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
14:10:53.0528 5220        IPNAT - ok
14:10:53.0668 5220        iPod Service    (e6be7a41a28d8f2db174957454d32448) C:\Program Files\iPod\bin\iPodService.exe
14:10:53.0730 5220        iPod Service - ok
14:10:53.0762 5220        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
14:10:53.0808 5220        IRENUM - ok
14:10:53.0824 5220        isapnp          (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
14:10:53.0855 5220        isapnp - ok
14:10:53.0886 5220        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
14:10:53.0918 5220        iScsiPrt - ok
14:10:53.0964 5220        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
14:10:53.0996 5220        iteatapi - ok
14:10:54.0011 5220        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
14:10:54.0042 5220        iteraid - ok
14:10:54.0058 5220        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
14:10:54.0074 5220        kbdclass - ok
14:10:54.0105 5220        kbdhid          (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
14:10:54.0152 5220        kbdhid - ok
14:10:54.0198 5220        KeyIso          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
14:10:54.0245 5220        KeyIso - ok
14:10:54.0292 5220        KSecDD          (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys
14:10:54.0354 5220        KSecDD - ok
14:10:54.0432 5220        KtmRm          (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
14:10:54.0510 5220        KtmRm - ok
14:10:54.0557 5220        L8042Kbd        (58759156a6918913edd368f995be3e53) C:\Windows\system32\DRIVERS\L8042Kbd.sys
14:10:54.0573 5220        L8042Kbd - ok
14:10:54.0588 5220        L8042mou        (d6fc755ff505d99e6cc73e83492310df) C:\Windows\system32\DRIVERS\L8042mou.Sys
14:10:54.0604 5220        L8042mou - ok
14:10:54.0635 5220        LanmanServer    (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\System32\srvsvc.dll
14:10:54.0698 5220        LanmanServer - ok
14:10:54.0729 5220        LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll
14:10:54.0760 5220        LanmanWorkstation - ok
14:10:54.0869 5220        LBTServ        (a0f7dc0080e4f97dc97de08b699e231b) C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
14:10:54.0900 5220        LBTServ - ok
14:10:54.0916 5220        LHidFilt        (24e0ddb99aeccf86bb37702611761459) C:\Windows\system32\DRIVERS\LHidFilt.Sys
14:10:54.0932 5220        LHidFilt - ok
14:10:54.0978 5220        LightScribeService (e75adcfafdef3f4c3af3332928d59926) c:\Program Files\Common Files\LightScribe\LSSrvc.exe
14:10:55.0010 5220        LightScribeService ( UnsignedFile.Multi.Generic ) - warning
14:10:55.0010 5220        LightScribeService - detected UnsignedFile.Multi.Generic (1)
14:10:55.0041 5220        lirsgt          (975b6cf65f44e95883f3855bae8cecaf) C:\Windows\system32\DRIVERS\lirsgt.sys
14:10:55.0072 5220        lirsgt ( UnsignedFile.Multi.Generic ) - warning
14:10:55.0072 5220        lirsgt - detected UnsignedFile.Multi.Generic (1)
14:10:55.0088 5220        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
14:10:55.0134 5220        lltdio - ok
14:10:55.0166 5220        lltdsvc        (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
14:10:55.0228 5220        lltdsvc - ok
14:10:55.0244 5220        lmhosts        (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
14:10:55.0322 5220        lmhosts - ok
14:10:55.0353 5220        LMouFilt        (d58b330d318361a66a9fe60d7c9b4951) C:\Windows\system32\DRIVERS\LMouFilt.Sys
14:10:55.0368 5220        LMouFilt - ok
14:10:55.0384 5220        LMouKE          (c149bdad13194df16ea33f9f601ed7bf) C:\Windows\system32\DRIVERS\LMouKE.Sys
14:10:55.0400 5220        LMouKE - ok
14:10:55.0415 5220        LSI_FC          (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
14:10:55.0431 5220        LSI_FC - ok
14:10:55.0446 5220        LSI_SAS        (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
14:10:55.0462 5220        LSI_SAS - ok
14:10:55.0478 5220        LSI_SCSI        (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
14:10:55.0493 5220        LSI_SCSI - ok
14:10:55.0524 5220        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
14:10:55.0540 5220        luafv - ok
14:10:55.0602 5220        MBAMProtector  (fb097bbc1a18f044bd17bd2fccf97865) C:\Windows\system32\drivers\mbam.sys
14:10:55.0602 5220        MBAMProtector - ok
14:10:55.0712 5220        MBAMService    (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
14:10:55.0790 5220        MBAMService - ok
14:10:55.0836 5220        Mcx2Svc        (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
14:10:55.0868 5220        Mcx2Svc - ok
14:10:55.0914 5220        megasas        (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
14:10:55.0930 5220        megasas - ok
14:10:55.0977 5220        MegaSR          (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
14:10:56.0024 5220        MegaSR - ok
14:10:56.0070 5220        MMCSS          (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
14:10:56.0117 5220        MMCSS - ok
14:10:56.0133 5220        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
14:10:56.0195 5220        Modem - ok
14:10:56.0211 5220        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
14:10:56.0242 5220        monitor - ok
14:10:56.0273 5220        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
14:10:56.0289 5220        mouclass - ok
14:10:56.0289 5220        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
14:10:56.0320 5220        mouhid - ok
14:10:56.0351 5220        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
14:10:56.0367 5220        MountMgr - ok
14:10:56.0460 5220        MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:10:56.0460 5220        MozillaMaintenance - ok
14:10:56.0507 5220        mpio            (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
14:10:56.0523 5220        mpio - ok
14:10:56.0538 5220        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
14:10:56.0585 5220        mpsdrv - ok
14:10:56.0616 5220        MpsSvc          (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll
14:10:56.0741 5220        MpsSvc - ok
14:10:56.0788 5220        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
14:10:56.0804 5220        Mraid35x - ok
14:10:56.0835 5220        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
14:10:56.0866 5220        MRxDAV - ok
14:10:56.0897 5220        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
14:10:56.0928 5220        mrxsmb - ok
14:10:56.0960 5220        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:10:57.0006 5220        mrxsmb10 - ok
14:10:57.0038 5220        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:10:57.0069 5220        mrxsmb20 - ok
14:10:57.0084 5220        msahci          (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
14:10:57.0116 5220        msahci - ok
14:10:57.0194 5220        MSCamSvc        (31e023681015c35ebfe1498b07813b87) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
14:10:57.0209 5220        MSCamSvc - ok
14:10:57.0240 5220        msdsm          (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
14:10:57.0256 5220        msdsm - ok
14:10:57.0303 5220        MSDTC          (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
14:10:57.0365 5220        MSDTC - ok
14:10:57.0381 5220        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
14:10:57.0443 5220        Msfs - ok
14:10:57.0459 5220        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
14:10:57.0459 5220        msisadrv - ok
14:10:57.0490 5220        MSiSCSI        (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
14:10:57.0552 5220        MSiSCSI - ok
14:10:57.0552 5220        msiserver - ok
14:10:57.0584 5220        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
14:10:57.0615 5220        MSKSSRV - ok
14:10:57.0646 5220        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
14:10:57.0677 5220        MSPCLOCK - ok
14:10:57.0693 5220        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
14:10:57.0724 5220        MSPQM - ok
14:10:57.0740 5220        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
14:10:57.0755 5220        MsRPC - ok
14:10:57.0771 5220        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
14:10:57.0786 5220        mssmbios - ok
14:10:57.0802 5220        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
14:10:57.0849 5220        MSTEE - ok
14:10:57.0864 5220        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
14:10:57.0880 5220        Mup - ok
14:10:57.0911 5220        napagent        (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll
14:10:57.0942 5220        napagent - ok
14:10:57.0989 5220        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
14:10:58.0020 5220        NativeWifiP - ok
14:10:58.0067 5220        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
14:10:58.0145 5220        NDIS - ok
14:10:58.0208 5220        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
14:10:58.0239 5220        NdisTapi - ok
14:10:58.0254 5220        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
14:10:58.0301 5220        Ndisuio - ok
14:10:58.0332 5220        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
14:10:58.0364 5220        NdisWan - ok
14:10:58.0364 5220        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
14:10:58.0379 5220        NDProxy - ok
14:10:58.0426 5220        Net Driver HPZ12 (2969d26eee289be7422aa46fc55f4e38) C:\Windows\system32\HPZinw12.dll
14:10:58.0442 5220        Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
14:10:58.0442 5220        Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
14:10:58.0457 5220        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
14:10:58.0488 5220        NetBIOS - ok
14:10:58.0520 5220        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
14:10:58.0566 5220        netbt - ok
14:10:58.0613 5220        Netlogon        (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
14:10:58.0629 5220        Netlogon - ok
14:10:58.0676 5220        Netman          (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
14:10:58.0722 5220        Netman - ok
14:10:58.0785 5220        NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:10:58.0816 5220        NetMsmqActivator - ok
14:10:58.0816 5220        NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:10:58.0847 5220        NetPipeActivator - ok
14:10:58.0863 5220        netprofm        (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
14:10:58.0925 5220        netprofm - ok
14:10:58.0941 5220        NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:10:58.0956 5220        NetTcpActivator - ok
14:10:58.0972 5220        NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
14:10:58.0972 5220        NetTcpPortSharing - ok
14:10:58.0988 5220        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
14:10:59.0003 5220        nfrd960 - ok
14:10:59.0019 5220        NlaSvc          (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
14:10:59.0050 5220        NlaSvc - ok
14:10:59.0066 5220        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
14:10:59.0097 5220        Npfs - ok
14:10:59.0097 5220        nsi            (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
14:10:59.0144 5220        nsi - ok
14:10:59.0175 5220        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
14:10:59.0237 5220        nsiproxy - ok
14:10:59.0315 5220        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
14:10:59.0424 5220        Ntfs - ok
14:10:59.0471 5220        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
14:10:59.0549 5220        ntrigdigi - ok
14:10:59.0565 5220        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
14:10:59.0612 5220        Null - ok
14:10:59.0721 5220        NVENETFD        (de3fcf6a5aaca198b22998330c3c64d9) C:\Windows\system32\DRIVERS\nvmfdx32.sys
14:10:59.0799 5220        NVENETFD - ok
14:10:59.0814 5220        nvraid          (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
14:10:59.0830 5220        nvraid - ok
14:10:59.0877 5220        nvrd32          (6934105ecc6a19570160d794e301e595) C:\Windows\system32\drivers\nvrd32.sys
14:10:59.0892 5220        nvrd32 - ok
14:10:59.0908 5220        nvsmu          (62754e376185eacbb73d06fea0ffc54a) C:\Windows\system32\drivers\nvsmu.sys
14:10:59.0939 5220        nvsmu - ok
14:10:59.0955 5220        nvstor          (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
14:10:59.0970 5220        nvstor - ok
14:10:59.0986 5220        nvstor32        (d7b213299852d2026dbc90dab77ef06c) C:\Windows\system32\drivers\nvstor32.sys
14:11:00.0002 5220        nvstor32 - ok
14:11:00.0017 5220        nv_agp          (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
14:11:00.0033 5220        nv_agp - ok
14:11:00.0033 5220        NwlnkFlt - ok
14:11:00.0048 5220        NwlnkFwd - ok
14:11:00.0095 5220        ohci1394        (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
14:11:00.0111 5220        ohci1394 - ok
14:11:00.0173 5220        p2pimsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
14:11:00.0251 5220        p2pimsvc - ok
14:11:00.0267 5220        p2psvc          (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
14:11:00.0329 5220        p2psvc - ok
14:11:00.0376 5220        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
14:11:00.0423 5220        Parport - ok
14:11:00.0485 5220        partmgr        (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys
14:11:00.0501 5220        partmgr - ok
14:11:00.0516 5220        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
14:11:00.0563 5220        Parvdm - ok
14:11:00.0594 5220        PcaSvc          (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
14:11:00.0626 5220        PcaSvc - ok
14:11:00.0641 5220        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
14:11:00.0657 5220        pci - ok
14:11:00.0688 5220        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
14:11:00.0704 5220        pciide - ok
14:11:00.0735 5220        pcmcia          (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
14:11:00.0750 5220        pcmcia - ok
14:11:00.0813 5220        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
14:11:00.0969 5220        PEAUTH - ok
14:11:01.0078 5220        pla            (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
14:11:01.0203 5220        pla - ok
14:11:01.0312 5220        PlugPlay        (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll
14:11:01.0343 5220        PlugPlay - ok
14:11:01.0359 5220        Pml Driver HPZ12 (bafc9706bdf425a02b66468ab2605c59) C:\Windows\system32\HPZipm12.dll
14:11:01.0390 5220        Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
14:11:01.0390 5220        Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
14:11:01.0421 5220        PnkBstrA        (205e1b699fd3f2f9b036eea2ec30c620) C:\Windows\system32\PnkBstrA.exe
14:11:01.0437 5220        PnkBstrA - ok
14:11:01.0484 5220        PNRPAutoReg    (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
14:11:01.0530 5220        PNRPAutoReg - ok
14:11:01.0546 5220        PNRPsvc        (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
14:11:01.0640 5220        PNRPsvc - ok
14:11:01.0702 5220        PolicyAgent    (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll
14:11:01.0811 5220        PolicyAgent - ok
14:11:01.0858 5220        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
14:11:01.0920 5220        PptpMiniport - ok
14:11:01.0936 5220        Processor      (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\DRIVERS\processr.sys
14:11:01.0967 5220        Processor - ok
14:11:01.0983 5220        ProfSvc        (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll
14:11:01.0998 5220        ProfSvc - ok
14:11:02.0045 5220        ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
14:11:02.0061 5220        ProtectedStorage - ok
14:11:02.0092 5220        Ps2            (390c204ced3785609ab24e9c52054a84) C:\Windows\system32\DRIVERS\PS2.sys
14:11:02.0123 5220        Ps2 - ok
14:11:02.0139 5220        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
14:11:02.0170 5220        PSched - ok
14:11:02.0248 5220        ql2300          (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
14:11:02.0342 5220        ql2300 - ok
14:11:02.0404 5220        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
14:11:02.0435 5220        ql40xx - ok
14:11:02.0498 5220        QWAVE          (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
14:11:02.0529 5220        QWAVE - ok
14:11:02.0544 5220        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
14:11:02.0560 5220        QWAVEdrv - ok
14:11:02.0576 5220        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
14:11:02.0622 5220        RasAcd - ok
14:11:02.0638 5220        RasAuto        (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
14:11:02.0716 5220        RasAuto - ok
14:11:02.0732 5220        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
14:11:02.0778 5220        Rasl2tp - ok
14:11:02.0825 5220        RasMan          (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll
14:11:02.0872 5220        RasMan - ok
14:11:02.0919 5220        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
14:11:02.0934 5220        RasPppoe - ok
14:11:02.0950 5220        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
14:11:02.0966 5220        RasSstp - ok
14:11:02.0981 5220        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
14:11:03.0012 5220        rdbss - ok
14:11:03.0028 5220        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
14:11:03.0059 5220        RDPCDD - ok
14:11:03.0106 5220        rdpdr          (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
14:11:03.0137 5220        rdpdr - ok
14:11:03.0137 5220        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
14:11:03.0168 5220        RDPENCDD - ok
14:11:03.0231 5220        RDPWD          (c127ebd5afab31524662c48dfceb773a) C:\Windows\system32\drivers\RDPWD.sys
14:11:03.0278 5220        RDPWD - ok
14:11:03.0324 5220        RemoteAccess    (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
14:11:03.0387 5220        RemoteAccess - ok
14:11:03.0418 5220        RemoteRegistry  (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll
14:11:03.0449 5220        RemoteRegistry - ok
14:11:03.0480 5220        RpcLocator      (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
14:11:03.0512 5220        RpcLocator - ok
14:11:03.0558 5220        RpcSs          (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
14:11:03.0590 5220        RpcSs - ok
14:11:03.0621 5220        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
14:11:03.0652 5220        rspndr - ok
14:11:03.0699 5220        RTSTOR          (52532a4ca8b251775decc87c4813abfb) C:\Windows\system32\drivers\RTSTOR.SYS
14:11:03.0730 5220        RTSTOR - ok
14:11:03.0777 5220        SamSs          (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
14:11:03.0792 5220        SamSs - ok
14:11:03.0824 5220        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
14:11:03.0839 5220        sbp2port - ok
14:11:03.0870 5220        SCardSvr        (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll
14:11:03.0886 5220        SCardSvr - ok
14:11:03.0933 5220        Schedule        (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll
14:11:04.0026 5220        Schedule - ok
14:11:04.0104 5220        SCPolicySvc    (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
14:11:04.0136 5220        SCPolicySvc - ok
14:11:04.0198 5220        SDRSVC          (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
14:11:04.0276 5220        SDRSVC - ok
14:11:04.0292 5220        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
14:11:04.0385 5220        secdrv - ok
14:11:04.0401 5220        seclogon        (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
14:11:04.0448 5220        seclogon - ok
14:11:04.0479 5220        seehcri        (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
14:11:04.0510 5220        seehcri - ok
14:11:04.0541 5220        SENS            (a9bbab5759771e523f55563d6cbe140f) C:\Windows\system32\sens.dll
14:11:04.0572 5220        SENS - ok
14:11:04.0588 5220        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
14:11:04.0635 5220        Serenum - ok
14:11:04.0650 5220        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
14:11:04.0713 5220        Serial - ok
14:11:04.0744 5220        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
14:11:04.0775 5220        sermouse - ok
14:11:04.0822 5220        SessionEnv      (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
14:11:04.0853 5220        SessionEnv - ok
14:11:04.0884 5220        sffdisk        (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
14:11:04.0916 5220        sffdisk - ok
14:11:04.0931 5220        sffp_mmc        (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
14:11:04.0978 5220        sffp_mmc - ok
14:11:04.0994 5220        sffp_sd        (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
14:11:05.0025 5220        sffp_sd - ok
14:11:05.0040 5220        sfloppy        (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
14:11:05.0103 5220        sfloppy - ok
14:11:05.0134 5220        SharedAccess    (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
14:11:05.0181 5220        SharedAccess - ok
14:11:05.0243 5220        ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll
14:11:05.0290 5220        ShellHWDetection - ok
14:11:05.0290 5220        sisagp          (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
14:11:05.0306 5220        sisagp - ok
14:11:05.0321 5220        SiSRaid2        (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
14:11:05.0352 5220        SiSRaid2 - ok
14:11:05.0384 5220        SiSRaid4        (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
14:11:05.0399 5220        SiSRaid4 - ok
14:11:05.0602 5220        slsvc          (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe
14:11:05.0836 5220        slsvc - ok
14:11:06.0008 5220        SLUINotify      (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll
14:11:06.0039 5220        SLUINotify - ok
14:11:06.0117 5220        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
14:11:06.0148 5220        Smb - ok
14:11:06.0179 5220        SNMPTRAP        (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
14:11:06.0210 5220        SNMPTRAP - ok
14:11:06.0242 5220        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
14:11:06.0242 5220        spldr - ok
14:11:06.0273 5220        Spooler        (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe
14:11:06.0320 5220        Spooler - ok
14:11:06.0382 5220        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
14:11:06.0413 5220        srv - ok
14:11:06.0429 5220        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
14:11:06.0460 5220        srv2 - ok
14:11:06.0507 5220        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
14:11:06.0538 5220        srvnet - ok
14:11:06.0569 5220        SSDPSRV        (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
14:11:06.0600 5220        SSDPSRV - ok
14:11:06.0616 5220        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
14:11:06.0632 5220        ssmdrv - ok
14:11:06.0678 5220        SstpSvc        (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
14:11:06.0678 5220        SstpSvc - ok
14:11:06.0741 5220        Steam Client Service - ok
14:11:06.0772 5220        StillCam        (ef70b3d22b4bffda6ea851ecb063efaa) C:\Windows\system32\DRIVERS\serscan.sys
14:11:06.0803 5220        StillCam - ok
14:11:06.0850 5220        stisvc          (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll
14:11:06.0912 5220        stisvc - ok
14:11:06.0959 5220        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
14:11:07.0006 5220        swenum - ok
14:11:07.0084 5220        swprv          (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll
14:11:07.0162 5220        swprv - ok
14:11:07.0178 5220        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
14:11:07.0193 5220        Symc8xx - ok
14:11:07.0209 5220        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
14:11:07.0240 5220        Sym_hi - ok
14:11:07.0256 5220        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
14:11:07.0271 5220        Sym_u3 - ok
14:11:07.0334 5220        SysMain        (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll
14:11:07.0380 5220        SysMain - ok
14:11:07.0427 5220        TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
14:11:07.0458 5220        TabletInputService - ok
14:11:07.0490 5220        TapiSrv        (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll
14:11:07.0568 5220        TapiSrv - ok
14:11:07.0599 5220        TBS            (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
14:11:07.0661 5220        TBS - ok
14:11:07.0786 5220        Tcpip          (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys
14:11:07.0848 5220        Tcpip - ok
14:11:07.0864 5220        Tcpip6          (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys
14:11:07.0911 5220        Tcpip6 - ok
14:11:07.0958 5220        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
14:11:08.0036 5220        tcpipreg - ok
14:11:08.0051 5220        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
14:11:08.0114 5220        TDPIPE - ok
14:11:08.0129 5220        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
14:11:08.0192 5220        TDTCP - ok
14:11:08.0254 5220        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
14:11:08.0332 5220        tdx - ok
14:11:08.0363 5220        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
14:11:08.0394 5220        TermDD - ok
14:11:08.0472 5220        TermService    (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll
14:11:08.0535 5220        TermService - ok
14:11:08.0613 5220        Themes          (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll
14:11:08.0644 5220        Themes - ok
14:11:08.0706 5220        THREADORDER    (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
14:11:08.0753 5220        THREADORDER - ok
14:11:08.0800 5220        TrkWks          (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
14:11:08.0847 5220        TrkWks - ok
14:11:08.0940 5220        TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe
14:11:08.0987 5220        TrustedInstaller - ok
14:11:09.0081 5220        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
14:11:09.0128 5220        tssecsrv - ok
14:11:09.0190 5220        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
14:11:09.0221 5220        tunmp - ok
14:11:09.0284 5220        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
14:11:09.0299 5220        tunnel - ok
14:11:09.0362 5220        uagp35          (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
14:11:09.0377 5220        uagp35 - ok
14:11:09.0408 5220        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
14:11:09.0455 5220        udfs - ok
14:11:09.0486 5220        UI0Detect      (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
14:11:09.0549 5220        UI0Detect - ok
14:11:09.0580 5220        uliagpkx        (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
14:11:09.0596 5220        uliagpkx - ok
14:11:09.0627 5220        uliahci        (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
14:11:09.0658 5220        uliahci - ok
14:11:09.0674 5220        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
14:11:09.0705 5220        UlSata - ok
14:11:09.0720 5220        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
14:11:09.0767 5220        ulsata2 - ok
14:11:09.0783 5220        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
14:11:09.0830 5220        umbus - ok
14:11:09.0861 5220        upnphost        (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
14:11:09.0923 5220        upnphost - ok
14:11:09.0970 5220        USBAAPL        (eafe1e00739afe6c51487a050e772e17) C:\Windows\system32\Drivers\usbaapl.sys
14:11:10.0032 5220        USBAAPL - ok
14:11:10.0079 5220        usbaudio        (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
14:11:10.0126 5220        usbaudio - ok
14:11:10.0173 5220        usbccgp        (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
14:11:10.0204 5220        usbccgp - ok
14:11:10.0235 5220        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
14:11:10.0344 5220        usbcir - ok
14:11:10.0376 5220        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
14:11:10.0407 5220        usbehci - ok
14:11:10.0454 5220        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
14:11:10.0500 5220        usbhub - ok
14:11:10.0500 5220        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
14:11:10.0547 5220        usbohci - ok
14:11:10.0594 5220        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
14:11:10.0641 5220        usbprint - ok
14:11:10.0688 5220        usbscan        (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
14:11:10.0719 5220        usbscan - ok
14:11:10.0750 5220        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:11:10.0797 5220        USBSTOR - ok
14:11:10.0812 5220        usbuhci        (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
14:11:10.0859 5220        usbuhci - ok
14:11:10.0890 5220        UxSms          (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll
14:11:10.0937 5220        UxSms - ok
14:11:11.0000 5220        VClone          (fce98c43b5c5db8e0da8ea0e2b45e044) C:\Windows\system32\DRIVERS\VClone.sys
14:11:11.0046 5220        VClone - ok
14:11:11.0078 5220        vds            (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe
14:11:11.0156 5220        vds - ok
14:11:11.0202 5220        vga            (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
14:11:11.0249 5220        vga - ok
14:11:11.0265 5220        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
14:11:11.0312 5220        VgaSave - ok
14:11:11.0327 5220        viaagp          (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
14:11:11.0343 5220        viaagp - ok
14:11:11.0358 5220        ViaC7          (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
14:11:11.0390 5220        ViaC7 - ok
14:11:11.0405 5220        viaide          (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
14:11:11.0421 5220        viaide - ok
14:11:11.0436 5220        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
14:11:11.0452 5220        volmgr - ok
14:11:11.0483 5220        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
14:11:11.0499 5220        volmgrx - ok
14:11:11.0530 5220        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
14:11:11.0546 5220        volsnap - ok
14:11:11.0608 5220        vsmraid        (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
14:11:11.0624 5220        vsmraid - ok
14:11:11.0686 5220        VSS            (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe
14:11:11.0733 5220        VSS - ok
14:11:11.0936 5220        VX3000          (42870675b4d84acd81a9da69b83f14c5) C:\Windows\system32\DRIVERS\VX3000.sys
14:11:12.0092 5220        VX3000 - ok
14:11:12.0216 5220        W32Time        (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll
14:11:12.0263 5220        W32Time - ok
14:11:12.0310 5220        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
14:11:12.0404 5220        WacomPen - ok
14:11:12.0419 5220        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
14:11:12.0466 5220        Wanarp - ok
14:11:12.0466 5220        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
14:11:12.0497 5220        Wanarpv6 - ok
14:11:12.0544 5220        wcncsvc        (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll
14:11:12.0606 5220        wcncsvc - ok
14:11:12.0669 5220        WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
14:11:12.0700 5220        WcsPlugInService - ok
14:11:12.0716 5220        Wd              (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
14:11:12.0747 5220        Wd - ok
14:11:12.0794 5220        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
14:11:12.0825 5220        Wdf01000 - ok
14:11:12.0856 5220        WdiServiceHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
14:11:12.0887 5220        WdiServiceHost - ok
14:11:12.0903 5220        WdiSystemHost  (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
14:11:12.0934 5220        WdiSystemHost - ok
14:11:12.0965 5220        WebClient      (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll
14:11:12.0996 5220        WebClient - ok
14:11:13.0028 5220        Wecsvc          (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
14:11:13.0074 5220        Wecsvc - ok
14:11:13.0106 5220        wercplsupport  (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
14:11:13.0152 5220        wercplsupport - ok
14:11:13.0184 5220        WerSvc          (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll
14:11:13.0230 5220        WerSvc - ok
14:11:13.0324 5220        WinDefend      (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
14:11:13.0340 5220        WinDefend - ok
14:11:13.0355 5220        WinHttpAutoProxySvc - ok
14:11:13.0402 5220        Winmgmt        (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll
14:11:13.0449 5220        Winmgmt - ok
14:11:13.0527 5220        WinRM          (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
14:11:13.0683 5220        WinRM - ok
14:11:13.0776 5220        Wlansvc        (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll
14:11:13.0901 5220        Wlansvc - ok
14:11:14.0151 5220        wlidsvc        (fb01d4ae207b9efdbabfc55dc95c7e31) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
14:11:14.0244 5220        wlidsvc - ok
14:11:14.0385 5220        WmiAcpi        (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
14:11:14.0416 5220        WmiAcpi - ok
14:11:14.0525 5220        wmiApSrv        (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe
14:11:14.0588 5220        wmiApSrv - ok
14:11:14.0712 5220        WMPNetworkSvc  (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
14:11:14.0837 5220        WMPNetworkSvc - ok
14:11:14.0900 5220        WPCSvc          (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll
14:11:14.0946 5220        WPCSvc - ok
14:11:14.0978 5220        WPDBusEnum      (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll
14:11:15.0024 5220        WPDBusEnum - ok
14:11:15.0071 5220        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
14:11:15.0087 5220        WpdUsb - ok
14:11:15.0212 5220        WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
14:11:15.0274 5220        WPFFontCache_v0400 - ok
14:11:15.0336 5220        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
14:11:15.0368 5220        ws2ifsl - ok
14:11:15.0399 5220        wscsvc          (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\system32\wscsvc.dll
14:11:15.0430 5220        wscsvc - ok
14:11:15.0430 5220        WSearch - ok
14:11:15.0602 5220        wuauserv        (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll
14:11:15.0804 5220        wuauserv - ok
14:11:15.0945 5220        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
14:11:16.0007 5220        WUDFRd - ok
14:11:16.0023 5220        wudfsvc        (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
14:11:16.0085 5220        wudfsvc - ok
14:11:16.0210 5220        YahooAUService  (dd0042f0c3b606a6a8b92d49afb18ad6) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
14:11:16.0288 5220        YahooAUService - ok
14:11:16.0350 5220        {22D78859-9CE9-4B77-BF18-AC83E81A9263} (4d840c6af3c020ed3a35efba9025cf4a) C:\Program Files\HP\DVDPlay\000.fcl
14:11:16.0366 5220        {22D78859-9CE9-4B77-BF18-AC83E81A9263} - ok
14:11:16.0382 5220        MBR (0x1B8)    (125a9efb00805296e689c06cf6020c43) \Device\Harddisk0\DR0
14:11:16.0662 5220        \Device\Harddisk0\DR0 - ok
14:11:16.0678 5220        Boot (0x1200)  (bf38b5bd45a4edbd65e5e3a98e0d0f32) \Device\Harddisk0\DR0\Partition0
14:11:16.0678 5220        \Device\Harddisk0\DR0\Partition0 - ok
14:11:16.0678 5220        Boot (0x1200)  (fe26d57e3d36bac50c8d2c4b4bcf6fd4) \Device\Harddisk0\DR0\Partition1
14:11:16.0694 5220        \Device\Harddisk0\DR0\Partition1 - ok
14:11:16.0694 5220        ============================================================
14:11:16.0694 5220        Scan finished
14:11:16.0694 5220        ============================================================
14:11:16.0709 3264        Detected object count: 8
14:11:16.0709 3264        Actual detected object count: 8
14:11:44.0524 3264        atksgt ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0524 3264        atksgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:11:44.0524 3264        ezSharedSvc ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0524 3264        ezSharedSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:11:44.0524 3264        HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0524 3264        HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:11:44.0524 3264        IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0524 3264        IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:11:44.0524 3264        LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0524 3264        LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:11:44.0524 3264        lirsgt ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0524 3264        lirsgt ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:11:44.0540 3264        Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0540 3264        Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:11:44.0540 3264        Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
14:11:44.0540 3264        Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 25.06.2012 14:46

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte combofix.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

Hajaku 25.06.2012 15:48

[code]
Combofix Logfile:
Code:

ComboFix 12-06-25.03 - Tuan 25.06.2012  16:19:30.1.4 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3070.1874 [GMT 2:00]
ausgeführt von:: c:\users\Tuan\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-05-25 bis 2012-06-25  ))))))))))))))))))))))))))))))
.
.
2012-06-25 14:32 . 2012-06-25 14:33        --------        d-----w-        c:\users\Tuan\AppData\Local\temp
2012-06-25 14:32 . 2012-06-25 14:32        --------        d-----w-        c:\users\Tran Trong Chinh\AppData\Local\temp
2012-06-25 14:32 . 2012-06-25 14:32        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-06-25 14:32 . 2012-06-25 14:32        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-06-25 14:32 . 2012-06-25 14:32        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-06-24 16:32 . 2012-06-24 17:13        --------        d-----w-        C:\_OTL
2012-06-22 14:23 . 2012-05-31 03:41        6762896        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{0D90C47D-611F-4D84-83AD-D4FD26510E7B}\mpengine.dll
2012-06-22 14:10 . 2012-06-02 22:19        53784        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-22 14:10 . 2012-06-02 22:19        45080        ----a-w-        c:\windows\system32\wups2.dll
2012-06-22 14:10 . 2012-06-02 22:12        2422272        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-22 14:10 . 2012-06-02 22:19        1933848        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-22 14:10 . 2012-06-02 22:19        35864        ----a-w-        c:\windows\system32\wups.dll
2012-06-22 14:10 . 2012-06-02 22:19        577048        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-22 14:10 . 2012-06-02 22:12        88576        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-22 14:10 . 2012-06-02 13:19        171904        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-22 14:10 . 2012-06-02 13:12        33792        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-19 21:16 . 2012-06-19 21:16        --------        d-----w-        c:\program files\ESET
2012-06-18 11:50 . 2012-06-18 11:50        421200        ----a-w-        c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-18 11:50 . 2012-06-18 11:50        770384        ----a-w-        c:\program files\Mozilla Firefox\msvcr100.dll
2012-06-15 16:10 . 2012-06-15 16:10        --------        d-----w-        c:\users\Tuan\AppData\Local\Macromedia
2012-06-14 14:08 . 2012-04-23 16:00        984064        ----a-w-        c:\windows\system32\crypt32.dll
2012-06-14 14:08 . 2012-04-23 16:00        98304        ----a-w-        c:\windows\system32\cryptnet.dll
2012-06-14 14:08 . 2012-04-23 16:00        133120        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-06-14 14:07 . 2012-05-01 14:03        180736        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-06-14 14:03 . 2012-05-15 19:51        2045440        ----a-w-        c:\windows\system32\win32k.sys
2012-06-13 13:27 . 2012-06-13 13:27        --------        d-----w-        c:\program files\iPod
2012-06-13 13:27 . 2012-06-13 13:29        --------        d-----w-        c:\program files\iTunes
2012-06-10 15:00 . 2012-06-10 15:01        --------        d-----w-        c:\users\Tuan\AppData\Local\Ubisoft Game Launcher
2012-06-05 16:54 . 2012-06-05 17:04        --------        d-----w-        c:\users\Tuan\AppData\Roaming\pdfforge
2012-06-05 16:54 . 2012-05-14 07:17        79360        ----a-w-        c:\windows\system32\pdfcmon.dll
2012-06-05 16:54 . 2004-03-08 23:00        662288        ----a-w-        c:\windows\system32\MSCOMCT2.OCX
2012-06-05 16:54 . 1998-06-23 23:00        137000        ----a-w-        c:\windows\system32\MSMAPI32.OCX
2012-06-05 16:54 . 2012-06-05 16:54        --------        d-----w-        c:\program files\PDFCreator
2012-06-05 16:54 . 1998-07-06 16:56        125712        ----a-w-        c:\windows\system32\VB6DE.DLL
2012-06-05 16:54 . 1998-07-06 16:55        158208        ----a-w-        c:\windows\system32\MSCMCDE.DLL
2012-06-05 16:54 . 1998-07-06 16:55        64512        ----a-w-        c:\windows\system32\MSCC2DE.DLL
2012-06-05 16:54 . 1998-07-05 23:00        23552        ----a-w-        c:\windows\system32\MSMPIDE.DLL
2012-06-01 18:11 . 2012-03-22 11:43        2557952        ----a-w-        c:\windows\system32\QtCore4.dll
2012-06-01 18:11 . 2012-05-22 13:47        405176        ----a-w-        c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-05-29 17:04 . 2012-06-01 18:33        --------        d-----w-        c:\users\Tuan\AppData\Roaming\redsn0w
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-24 14:03 . 2009-04-01 15:24        139048        ----a-w-        c:\windows\system32\drivers\PnkBstrK.sys
2012-06-24 14:02 . 2009-04-01 15:28        282296        ----a-w-        c:\windows\system32\PnkBstrB.xtr
2012-06-24 14:02 . 2009-04-01 15:24        282296        ----a-w-        c:\windows\system32\PnkBstrB.exe
2012-06-24 14:01 . 2009-04-01 15:24        280736        ----a-w-        c:\windows\system32\PnkBstrB.ex0
2012-06-24 13:13 . 2012-04-01 14:47        426184        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-06-24 13:13 . 2011-05-15 13:37        70344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-17 16:30 . 2009-04-01 15:23        76888        ----a-w-        c:\windows\system32\PnkBstrA.exe
2012-05-08 14:01 . 2011-10-14 17:02        83392        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-05-08 14:01 . 2011-10-14 17:02        137928        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-04-18 18:56 . 2012-04-18 18:56        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2012-04-18 18:56 . 2012-04-18 18:56        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2012-04-08 15:50 . 2011-03-28 16:36        19352        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-04-06 05:21 . 2012-04-06 05:21        9334784        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2012-04-06 02:22 . 2012-04-06 02:22        159744        ----a-w-        c:\windows\system32\atiapfxx.exe
2012-04-06 02:21 . 2010-09-17 10:04        909312        ----a-w-        c:\windows\system32\aticfx32.dll
2012-04-06 02:16 . 2012-04-06 02:16        442368        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2012-04-06 02:16 . 2012-04-06 02:16        451072        ----a-w-        c:\windows\system32\atieclxx.exe
2012-04-06 02:15 . 2012-04-06 02:15        217600        ----a-w-        c:\windows\system32\atiesrxx.exe
2012-04-06 02:14 . 2012-04-06 02:14        159744        ----a-w-        c:\windows\system32\atitmmxx.dll
2012-04-06 02:14 . 2012-04-06 02:14        20992        ----a-w-        c:\windows\system32\atimuixx.dll
2012-04-06 02:14 . 2012-04-06 02:14        43520        ----a-w-        c:\windows\system32\ati2edxx.dll
2012-04-06 02:13 . 2012-04-06 02:13        6800896        ----a-w-        c:\windows\system32\atidxx32.dll
2012-04-06 02:00 . 2010-09-17 10:05        52736        ----a-w-        c:\windows\system32\coinst.dll
2012-04-06 01:50 . 2012-04-06 01:50        19753984        ----a-w-        c:\windows\system32\atioglxx.dll
2012-04-06 01:34 . 2012-04-06 01:34        1831424        ----a-w-        c:\windows\system32\atiumdmv.dll
2012-04-06 01:34 . 2008-10-28 00:21        6203392        ----a-w-        c:\windows\system32\atiumdag.dll
2012-04-06 01:30 . 2012-04-06 01:30        46080        ----a-w-        c:\windows\system32\aticalrt.dll
2012-04-06 01:30 . 2012-04-06 01:30        44032        ----a-w-        c:\windows\system32\aticalcl.dll
2012-04-06 01:25 . 2012-04-06 01:25        13764096        ----a-w-        c:\windows\system32\aticaldd.dll
2012-04-06 01:22 . 2012-04-06 01:22        4795904        ----a-w-        c:\windows\system32\atiumdva.dll
2012-04-06 01:11 . 2012-04-06 01:11        360448        ----a-w-        c:\windows\system32\atiadlxx.dll
2012-04-06 01:11 . 2012-04-06 01:11        14848        ----a-w-        c:\windows\system32\atiglpxx.dll
2012-04-06 01:10 . 2012-04-06 01:10        33280        ----a-w-        c:\windows\system32\atigktxx.dll
2012-04-06 01:10 . 2012-04-06 01:10        275968        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2012-04-06 01:09 . 2012-04-06 01:09        41984        ----a-w-        c:\windows\system32\atiuxpag.dll
2012-04-06 01:09 . 2010-09-17 10:05        32256        ----a-w-        c:\windows\system32\atiu9pag.dll
2012-04-06 01:09 . 2010-09-17 10:05        37376        ----a-w-        c:\windows\system32\atitmpxx.dll
2012-04-06 01:09 . 2012-04-06 01:09        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2012-04-06 01:06 . 2012-04-06 01:06        53760        ----a-w-        c:\windows\system32\atimpc32.dll
2012-04-06 01:06 . 2012-04-06 01:06        53760        ----a-w-        c:\windows\system32\amdpcom32.dll
2012-04-05 20:34 . 2012-04-05 20:34        159232        ----a-w-        c:\windows\system32\clinfo.exe
2012-04-05 20:34 . 2012-04-05 20:34        64512        ----a-w-        c:\windows\system32\OpenVideo.dll
2012-04-05 20:33 . 2012-04-05 20:33        56320        ----a-w-        c:\windows\system32\OVDecode.dll
2012-04-05 20:32 . 2012-04-05 20:32        13007872        ----a-w-        c:\windows\system32\amdocl.dll
2012-04-04 13:56 . 2012-01-23 20:39        22344        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-04-03 08:16 . 2012-05-11 14:14        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16 . 2012-05-11 14:14        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-04-01 15:31 . 2010-05-07 14:34        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2012-03-30 12:39 . 2012-05-11 14:15        905600        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-06-18 11:50 . 2011-04-25 11:52        85472        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VX3000"="c:\windows\vVX3000.exe" [2009-06-26 757248]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118640]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-08 348624]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
c:\users\Tuan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.4.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2012-4-19 1199104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-4 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^Users^Tuan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\Tuan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08        1259376        ----a-w-        c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2011-03-07 13:33        89456        ----a-w-        c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-449065279-793341504-1815772316-1000]
"EnableNotificationsRef"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 250056]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 45195557
*Deregistered* - 45195557
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-06-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 13:13]
.
2012-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 18:36]
.
2012-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 18:36]
.
2012-05-29 c:\windows\Tasks\HPCeeScheduleForTuan.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-10-27 19:03]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://de.yahoo.com/?p=us
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
uInternet Settings,ProxyOverride = *.local
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: Free YouTube Download - c:\users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to iPhone Converter - c:\users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoiphoneconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://de.yahoo.com/
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-{980A182F-E0A2-4A40-94C1-AE0C1235902E} - c:\program files\Pando Networks\Media Booster\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-06-25 16:33
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\DVDPlay\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\SecuROM\License information*]
"datasecu"=hex:52,56,3d,c6,d7,d5,93,74,ba,a6,f6,e0,5f,08,79,62,29,8c,dc,eb,5e,
  eb,a0,21,1c,5d,56,7d,3e,57,68,0f,d0,45,be,32,e0,6d,51,69,5a,d2,94,74,aa,20,\
"rkeysecu"=hex:66,d5,3f,d0,e1,ce,5a,a9,17,2e,78,dc,1a,8f,57,7c
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(5688)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Zeit der Fertigstellung: 2012-06-25  16:37:21
ComboFix-quarantined-files.txt  2012-06-25 14:37
.
Vor Suchlauf: 16 Verzeichnis(se), 333.664.276.480 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 333.623.406.592 Bytes frei
.
- - End Of File - - C2C57F51C698F3DA6A8E1A039ABA9079

--- --- ---

cosinus 25.06.2012 19:13

Combofix - Scripten

1. Starte das Notepad (Start / Ausführen / notepad[Enter])

2. Jetzt füge mit copy/paste den ganzen Inhalt der untenstehenden Codebox in das Notepad Fenster ein.

Code:

Firefox::
FF - ProfilePath - c:\users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - http://de.yahoo.com/
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false

3. Speichere im Notepad als CFScript.txt auf dem Desktop.

4. Deaktivere den Guard Deines Antivirenprogramms und eine eventuell vorhandene Software Firewall.
(Auch Guards von Ad-, Spyware Programmen und den Tea Timer (wenn vorhanden) !)

5. Dann ziehe die CFScript.txt auf die cofi.exe, so wie es im unteren Bild zu sehen ist. Damit wird Combofix neu gestartet.

http://users.pandora.be/bluepatchy/m...s/CFScript.gif

6. Nach dem Neustart (es wird gefragt ob Du neustarten willst), poste bitte die folgenden Log Dateien:
Combofix.txt

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

Hajaku 26.06.2012 16:01

[code]
Combofix Logfile:
Code:

ComboFix 12-06-26.01 - Tuan 26.06.2012  16:33:36.1.4 - x86
Microsoft® Windows Vista™ Home Premium  6.0.6002.2.1252.49.1031.18.3070.1959 [GMT 2:00]
ausgeführt von:: c:\users\Tuan\Desktop\ComboFix.exe
Benutzte Befehlsschalter :: c:\users\Tuan\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2012-05-26 bis 2012-06-26  ))))))))))))))))))))))))))))))
.
.
2012-06-26 14:48 . 2012-06-26 14:48        --------        d-----w-        c:\users\Tuan\AppData\Local\temp
2012-06-26 14:48 . 2012-06-26 14:48        --------        d-----w-        c:\users\Tran Trong Chinh\AppData\Local\temp
2012-06-26 14:48 . 2012-06-26 14:48        --------        d-----w-        c:\users\Public\AppData\Local\temp
2012-06-26 14:48 . 2012-06-26 14:48        --------        d-----w-        c:\users\Gast\AppData\Local\temp
2012-06-26 14:48 . 2012-06-26 14:48        --------        d-----w-        c:\users\Default\AppData\Local\temp
2012-06-26 14:24 . 2012-05-31 03:41        6762896        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{8289125F-C0AD-4355-BCB1-DF26E5BC6A0D}\mpengine.dll
2012-06-24 16:32 . 2012-06-24 17:13        --------        d-----w-        C:\_OTL
2012-06-22 14:10 . 2012-06-02 22:19        53784        ----a-w-        c:\windows\system32\wuauclt.exe
2012-06-22 14:10 . 2012-06-02 22:19        45080        ----a-w-        c:\windows\system32\wups2.dll
2012-06-22 14:10 . 2012-06-02 22:12        2422272        ----a-w-        c:\windows\system32\wucltux.dll
2012-06-22 14:10 . 2012-06-02 22:19        1933848        ----a-w-        c:\windows\system32\wuaueng.dll
2012-06-22 14:10 . 2012-06-02 22:19        35864        ----a-w-        c:\windows\system32\wups.dll
2012-06-22 14:10 . 2012-06-02 22:19        577048        ----a-w-        c:\windows\system32\wuapi.dll
2012-06-22 14:10 . 2012-06-02 22:12        88576        ----a-w-        c:\windows\system32\wudriver.dll
2012-06-22 14:10 . 2012-06-02 13:19        171904        ----a-w-        c:\windows\system32\wuwebv.dll
2012-06-22 14:10 . 2012-06-02 13:12        33792        ----a-w-        c:\windows\system32\wuapp.exe
2012-06-19 21:16 . 2012-06-19 21:16        --------        d-----w-        c:\program files\ESET
2012-06-18 11:50 . 2012-06-18 11:50        421200        ----a-w-        c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-18 11:50 . 2012-06-18 11:50        770384        ----a-w-        c:\program files\Mozilla Firefox\msvcr100.dll
2012-06-15 16:10 . 2012-06-15 16:10        --------        d-----w-        c:\users\Tuan\AppData\Local\Macromedia
2012-06-14 14:08 . 2012-04-23 16:00        984064        ----a-w-        c:\windows\system32\crypt32.dll
2012-06-14 14:08 . 2012-04-23 16:00        98304        ----a-w-        c:\windows\system32\cryptnet.dll
2012-06-14 14:08 . 2012-04-23 16:00        133120        ----a-w-        c:\windows\system32\cryptsvc.dll
2012-06-14 14:07 . 2012-05-01 14:03        180736        ----a-w-        c:\windows\system32\drivers\rdpwd.sys
2012-06-14 14:03 . 2012-05-15 19:51        2045440        ----a-w-        c:\windows\system32\win32k.sys
2012-06-13 13:27 . 2012-06-13 13:27        --------        d-----w-        c:\program files\iPod
2012-06-13 13:27 . 2012-06-13 13:29        --------        d-----w-        c:\program files\iTunes
2012-06-10 15:00 . 2012-06-10 15:01        --------        d-----w-        c:\users\Tuan\AppData\Local\Ubisoft Game Launcher
2012-06-05 16:54 . 2012-06-05 17:04        --------        d-----w-        c:\users\Tuan\AppData\Roaming\pdfforge
2012-06-05 16:54 . 2012-05-14 07:17        79360        ----a-w-        c:\windows\system32\pdfcmon.dll
2012-06-05 16:54 . 2004-03-08 23:00        662288        ----a-w-        c:\windows\system32\MSCOMCT2.OCX
2012-06-05 16:54 . 1998-06-23 23:00        137000        ----a-w-        c:\windows\system32\MSMAPI32.OCX
2012-06-05 16:54 . 2012-06-05 16:54        --------        d-----w-        c:\program files\PDFCreator
2012-06-05 16:54 . 1998-07-06 16:56        125712        ----a-w-        c:\windows\system32\VB6DE.DLL
2012-06-05 16:54 . 1998-07-06 16:55        158208        ----a-w-        c:\windows\system32\MSCMCDE.DLL
2012-06-05 16:54 . 1998-07-06 16:55        64512        ----a-w-        c:\windows\system32\MSCC2DE.DLL
2012-06-05 16:54 . 1998-07-05 23:00        23552        ----a-w-        c:\windows\system32\MSMPIDE.DLL
2012-06-01 18:11 . 2012-03-22 11:43        2557952        ----a-w-        c:\windows\system32\QtCore4.dll
2012-06-01 18:11 . 2012-05-22 13:47        405176        ----a-w-        c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-05-29 17:04 . 2012-06-01 18:33        --------        d-----w-        c:\users\Tuan\AppData\Roaming\redsn0w
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-24 14:03 . 2009-04-01 15:24        139048        ----a-w-        c:\windows\system32\drivers\PnkBstrK.sys
2012-06-24 14:02 . 2009-04-01 15:28        282296        ----a-w-        c:\windows\system32\PnkBstrB.xtr
2012-06-24 14:02 . 2009-04-01 15:24        282296        ----a-w-        c:\windows\system32\PnkBstrB.exe
2012-06-24 14:01 . 2009-04-01 15:24        280736        ----a-w-        c:\windows\system32\PnkBstrB.ex0
2012-06-24 13:13 . 2012-04-01 14:47        426184        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2012-06-24 13:13 . 2011-05-15 13:37        70344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-17 16:30 . 2009-04-01 15:23        76888        ----a-w-        c:\windows\system32\PnkBstrA.exe
2012-05-08 14:01 . 2011-10-14 17:02        83392        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2012-05-08 14:01 . 2011-10-14 17:02        137928        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2012-04-18 18:56 . 2012-04-18 18:56        94208        ----a-w-        c:\windows\system32\QuickTimeVR.qtx
2012-04-18 18:56 . 2012-04-18 18:56        69632        ----a-w-        c:\windows\system32\QuickTime.qts
2012-04-08 15:50 . 2011-03-28 16:36        19352        ----a-w-        c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-04-06 05:21 . 2012-04-06 05:21        9334784        ----a-w-        c:\windows\system32\drivers\atikmdag.sys
2012-04-06 02:22 . 2012-04-06 02:22        159744        ----a-w-        c:\windows\system32\atiapfxx.exe
2012-04-06 02:21 . 2010-09-17 10:04        909312        ----a-w-        c:\windows\system32\aticfx32.dll
2012-04-06 02:16 . 2012-04-06 02:16        442368        ----a-w-        c:\windows\system32\ATIDEMGX.dll
2012-04-06 02:16 . 2012-04-06 02:16        451072        ----a-w-        c:\windows\system32\atieclxx.exe
2012-04-06 02:15 . 2012-04-06 02:15        217600        ----a-w-        c:\windows\system32\atiesrxx.exe
2012-04-06 02:14 . 2012-04-06 02:14        159744        ----a-w-        c:\windows\system32\atitmmxx.dll
2012-04-06 02:14 . 2012-04-06 02:14        20992        ----a-w-        c:\windows\system32\atimuixx.dll
2012-04-06 02:14 . 2012-04-06 02:14        43520        ----a-w-        c:\windows\system32\ati2edxx.dll
2012-04-06 02:13 . 2012-04-06 02:13        6800896        ----a-w-        c:\windows\system32\atidxx32.dll
2012-04-06 02:00 . 2010-09-17 10:05        52736        ----a-w-        c:\windows\system32\coinst.dll
2012-04-06 01:50 . 2012-04-06 01:50        19753984        ----a-w-        c:\windows\system32\atioglxx.dll
2012-04-06 01:34 . 2012-04-06 01:34        1831424        ----a-w-        c:\windows\system32\atiumdmv.dll
2012-04-06 01:34 . 2008-10-28 00:21        6203392        ----a-w-        c:\windows\system32\atiumdag.dll
2012-04-06 01:30 . 2012-04-06 01:30        46080        ----a-w-        c:\windows\system32\aticalrt.dll
2012-04-06 01:30 . 2012-04-06 01:30        44032        ----a-w-        c:\windows\system32\aticalcl.dll
2012-04-06 01:25 . 2012-04-06 01:25        13764096        ----a-w-        c:\windows\system32\aticaldd.dll
2012-04-06 01:22 . 2012-04-06 01:22        4795904        ----a-w-        c:\windows\system32\atiumdva.dll
2012-04-06 01:11 . 2012-04-06 01:11        360448        ----a-w-        c:\windows\system32\atiadlxx.dll
2012-04-06 01:11 . 2012-04-06 01:11        14848        ----a-w-        c:\windows\system32\atiglpxx.dll
2012-04-06 01:10 . 2012-04-06 01:10        33280        ----a-w-        c:\windows\system32\atigktxx.dll
2012-04-06 01:10 . 2012-04-06 01:10        275968        ----a-w-        c:\windows\system32\drivers\atikmpag.sys
2012-04-06 01:09 . 2012-04-06 01:09        41984        ----a-w-        c:\windows\system32\atiuxpag.dll
2012-04-06 01:09 . 2010-09-17 10:05        32256        ----a-w-        c:\windows\system32\atiu9pag.dll
2012-04-06 01:09 . 2010-09-17 10:05        37376        ----a-w-        c:\windows\system32\atitmpxx.dll
2012-04-06 01:09 . 2012-04-06 01:09        53248        ----a-w-        c:\windows\system32\drivers\ati2erec.dll
2012-04-06 01:06 . 2012-04-06 01:06        53760        ----a-w-        c:\windows\system32\atimpc32.dll
2012-04-06 01:06 . 2012-04-06 01:06        53760        ----a-w-        c:\windows\system32\amdpcom32.dll
2012-04-05 20:34 . 2012-04-05 20:34        159232        ----a-w-        c:\windows\system32\clinfo.exe
2012-04-05 20:34 . 2012-04-05 20:34        64512        ----a-w-        c:\windows\system32\OpenVideo.dll
2012-04-05 20:33 . 2012-04-05 20:33        56320        ----a-w-        c:\windows\system32\OVDecode.dll
2012-04-05 20:32 . 2012-04-05 20:32        13007872        ----a-w-        c:\windows\system32\amdocl.dll
2012-04-04 13:56 . 2012-01-23 20:39        22344        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-04-03 08:16 . 2012-05-11 14:14        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16 . 2012-05-11 14:14        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
2012-04-01 15:31 . 2010-05-07 14:34        472808        ----a-w-        c:\windows\system32\deployJava1.dll
2012-03-30 12:39 . 2012-05-11 14:15        905600        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2012-06-18 11:50 . 2011-04-25 11:52        85472        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VX3000"="c:\windows\vVX3000.exe" [2009-06-26 757248]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118640]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-08 348624]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-05 641664]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-4 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^Users^Tuan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\Tuan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08        1259376        ----a-w-        c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2011-03-07 13:33        89456        ----a-w-        c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-449065279-793341504-1815772316-1000]
"EnableNotificationsRef"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 250056]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
HPZ12        REG_MULTI_SZ          Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
Inhalt des "geplante Tasks" Ordners
.
2012-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 13:13]
.
2012-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 18:36]
.
2012-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-08 18:36]
.
2012-05-29 c:\windows\Tasks\HPCeeScheduleForTuan.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-10-27 19:03]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://de.yahoo.com/?p=us
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=84&bd=Pavilion&pf=cndt
uInternet Settings,ProxyOverride = *.local
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: Free YouTube Download - c:\users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to iPhone Converter - c:\users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoiphoneconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\Tuan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Tuan\AppData\Roaming\Mozilla\Firefox\Profiles\w97yn8xt.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-06-26 16:48
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\DVDPlay\000.fcl"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-449065279-793341504-1815772316-1000\Software\SecuROM\License information*]
"datasecu"=hex:52,56,3d,c6,d7,d5,93,74,ba,a6,f6,e0,5f,08,79,62,29,8c,dc,eb,5e,
  eb,a0,21,1c,5d,56,7d,3e,57,68,0f,d0,45,be,32,e0,6d,51,69,5a,d2,94,74,aa,20,\
"rkeysecu"=hex:66,d5,3f,d0,e1,ce,5a,a9,17,2e,78,dc,1a,8f,57,7c
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
.
- - - - - - - > 'Explorer.exe'(4124)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Zeit der Fertigstellung: 2012-06-26  16:50:55
ComboFix-quarantined-files.txt  2012-06-26 14:50
ComboFix2.txt  2012-06-25 14:37
.
Vor Suchlauf: 16 Verzeichnis(se), 334.229.594.112 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 334.204.600.320 Bytes frei
.
- - End Of File - - 85B8ED4F74C825A262BFB0C7D9C55EA2

--- --- ---

cosinus 26.06.2012 18:05

Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).



Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.

Hajaku 27.06.2012 15:59

Beim erstem Mal ist Gmer abgestürzt, haz aber beim zweitem Mal geklappt
[code]
GMER Logfile:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-06-27 15:43:14
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000059 WDC_WD64 rev.01.0
Running: w71gow08.exe; Driver: C:\Users\Tuan\AppData\Local\Temp\kwldipog.sys


---- Kernel code sections - GMER 1.0.15 ----

.text  C:\Windows\system32\DRIVERS\atikmdag.sys  section is writeable [0x8F803000, 0x3DBAA0, 0xE8000020]
.text  C:\Windows\system32\DRIVERS\atksgt.sys    section is writeable [0xA2E0F300, 0x3ACC8, 0xE8000020]
.text  C:\Windows\system32\DRIVERS\lirsgt.sys    section is writeable [0xA2E52300, 0x1B7E, 0xE8000020]
      C:\Program Files\HP\DVDPlay\000.fcl      entry point in "" section [0xA2F6A41C]
.clc  C:\Program Files\HP\DVDPlay\000.fcl      unknown last code section [0xA2F6B000, 0x1000, 0xE0000020]

---- EOF - GMER 1.0.15 ----

--- --- ---


Code:

OSAM Logfile:

       
Code:

       
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 15:50:47 on 27.06.2012

OS: Windows Vista Home Premium Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 13.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"HPCeeScheduleForTuan.job" - "Hewlett-Packard" - C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Adobe Flash Player Updater.job" - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"DivXControlPanelApplet.cpl" - "DivX, Inc." - C:\Windows\system32\DivXControlPanelApplet.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"PhysX.cpl" - "NVIDIA Corporation" - C:\Windows\system32\PhysX.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Pando" - ? - C:\Program Files\Pando Networks\Media Booster\PMB.cpl  (File not found)
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AODDriver4.01" (AODDriver4.01) - "Advanced Micro Devices" - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys
"AODDriver4.1" (AODDriver4.1) - "Advanced Micro Devices" - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys
"atksgt" (atksgt) - ? - C:\Windows\System32\DRIVERS\atksgt.sys  (File found, but it contains no detailed information)
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"avkmgr" (avkmgr) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avkmgr.sys
"catchme" (catchme) - ? - C:\Users\Tuan\AppData\Local\Temp\catchme.sys  (File not found)
"EagleNT" (EagleNT) - ? - C:\Windows\system32\drivers\EagleNT.sys  (File not found)
"ElbyCDIO Driver" (ElbyCDIO) - "Elaborate Bytes AG" - C:\Windows\System32\Drivers\ElbyCDIO.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"kwldipog" (kwldipog) - ? - C:\Users\Tuan\AppData\Local\Temp\kwldipog.sys  (Hidden registry entry, rootkit activity | File not found)
"lirsgt" (lirsgt) - ? - C:\Windows\System32\DRIVERS\lirsgt.sys  (File found, but it contains no detailed information)
"MBAMProtector" (MBAMProtector) - "Malwarebytes Corporation" - C:\Windows\system32\drivers\mbam.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys
"{22D78859-9CE9-4B77-BF18-AC83E81A9263}" ({22D78859-9CE9-4B77-BF18-AC83E81A9263}) - "Cyberlink Corp." - C:\Program Files\HP\DVDPlay\000.fcl

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} "Album Download IE Asynchronous Pluggable Protocol Interface" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{3D9F03FA-7A94-11D3-BE81-0050048385D1} "Data Page Pluggable Protocol mso-offdap Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} "IEProtocolHandler Class" - "Skype Technologies" - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
{828030A1-22C1-4009-854F-8E305202313F} "livecall" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
{828030A1-22C1-4009-854F-8E305202313F} "msnim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Messenger\msgrapp.dll
{03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" - "Microsoft Corporation" - C:\Program Files\Windows Live\Mail\mailcomm.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -   (File not found | COM-object registry key not found)
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -   (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -   (File not found | COM-object registry key not found)
{872A9397-E0D6-4e28-B64D-52B8D0A7EA35} "DisplayCplExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiamaxx.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -   (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -   (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{DC70C4A5-2044-4c59-B806-DEFB9AE0DF7C} "KbLogiExt Class" - "Logitech, Inc." - C:\Program Files\Logitech\SetPoint\kbcplext.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -   (File not found | COM-object registry key not found)
{B9B9F083-2B04-452A-8691-83694AC1037B} "LogiExt Class" - "Logitech, Inc." - C:\Program Files\Logitech\SetPoint\mcplext.dll
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -   (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{7F67036B-66F1-411A-AD85-759FB9C5B0DB} "ShellViewRTF" - "XSS" - C:\Windows\System32\ShellvRTF.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{B7056B8E-4F99-44f8-8CBD-282390FE5428} "VirtualCloneDrive Shell Extension" - "Elaborate Bytes AG" - C:\Program Files\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} "Windows Live Photo Gallery Autoplay Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} "Windows Live Photo Gallery Editor Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} "Windows Live Photo Gallery Editor Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F33137-EE26-412F-8D71-F84E4C2C6625} "Windows Live Photo Gallery Viewer Autoplay Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{00F374B7-B390-4884-B372-2FC349F2172B} "Windows Live Photo Gallery Viewer Drop Target" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} "Windows Live Photo Gallery Viewer Shim" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -   (File not found | COM-object registry key not found)
{B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" - "Alexander Roshal" - C:\Program Files\WinRAR\rarext.dll
{0563DB41-F538-4B37-A92D-4659049B7766} "WLMD Message Handler" - ? -   (File not found | COM-object registry key not found)
{06A2568A-CED6-4187-BB20-400B8C02BE5A} "{06A2568A-CED6-4187-BB20-400B8C02BE5A}" - "Microsoft Corporation" - C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
ITBar7Height "ITBar7Height" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -   (File not found | COM-object registry key not found)
<binary data> "ITBarLayout" - ? -   (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{784797A8-342D-4072-9486-03C8D0F2F0A1} "Battlefield Heroes Updater" - "EA Digital Illusions CE AB" - C:\Windows\Downloaded Program Files\BFHUpdater.dll / https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.31.0.cab
{C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} "Battlefield Play4Free Updater" - "EA Digital Illusions CE AB" - C:\Windows\Downloaded Program Files\BP4FUpdater.dll / https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.27.2.cab
{20A60F0D-9AFA-4515-A0FD-83BD84642501} "Checkers Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\msgrchkr.dll / hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_31" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_31.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} "MessengerStatsClient Class" - "Microsoft Corporation" - C:\Windows\Downloaded Program Files\MessengerStatsPAClient.dll / hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} "QuickTime Object" - "Apple Inc." - C:\Program Files\QuickTime\QTPlugin.ocx / hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
{5D6F45B3-9043-443D-A792-115447494D24} "UnoCtrl Class" - "Microsoft" - C:\Windows\Downloaded Program Files\GAME_UNO1.dll / hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} "{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" - ? -   (File not found | COM-object registry key not found) / hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} "{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" - ? -   (File not found | COM-object registry key not found) / hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{5F7B1267-94A9-47F5-98DB-E99415F33AEC} "@C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004" - "Microsoft Corporation" - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
{77BF5300-1474-4EC7-9980-D32B190E9B07} "ClsidExtension" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
{77BF5300-1474-4EC7-9980-D32B190E9B07} "Skype" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{326E768D-4182-46FD-9C16-1449A49795F4} "DivX Plus Web Player HTML5 <video>" - "DivX, LLC" - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "Java(tm) Plug-In SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} "Skype add-on (mastermind)" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} "Windows Live ID Sign-in Helper" - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Tuan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Logitech SetPoint.lnk" - "Logitech, Inc." - C:\Program Files\Logitech\SetPoint\SetPoint.exe  (Shortcut exists | File exists)
"Microsoft Office.lnk" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\Office10\OSA.EXE  (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Search Protection" - "Yahoo! Inc" - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Adobe ARM" - "Adobe Systems Incorporated" - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"APSDaemon" - "Apple Inc." - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"ATICustomerCare" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
"avgnt" - "Avira Operations GmbH & Co. KG" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"DivXUpdate" - ? - "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"HP Health Check Scheduler" - "Hewlett-Packard" - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
"hpsysdrv" - "Hewlett-Packard Company" - c:\hp\support\hpsysdrv.exe
"iTunesHelper" - "Apple Inc." - "C:\Program Files\iTunes\iTunesHelper.exe"
"KBD" - ? - C:\HP\KBD\KbdStub.EXE  (File found, but it contains no detailed information)
"LifeCam" - "Microsoft Corporation" - "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
"Malwarebytes' Anti-Malware" - "Malwarebytes Corporation" - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"QuickTime Task" - "Apple Inc." - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
"StartCCC" - "Advanced Micro Devices, Inc." - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"YSearchProtection" - "Yahoo! Inc" - "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"pdfcmon" - "pdfforge GbR" - C:\Windows\system32\pdfcmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Adobe Flash Player Update Service" (AdobeFlashPlayerUpdateSvc) - "Adobe Systems Incorporated" - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
"AMD FUEL Service" (AMD FUEL Service) - "Advanced Micro Devices, Inc." - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"ASP.NET-Zustandsdienst" (aspnet_state) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
"Avira Echtzeit Scanner" (AntiVirService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira Planer" (AntiVirSchedulerService) - "Avira Operations GmbH & Co. KG" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"AVK Tuner Service" (AVK Tuner Service) - ? - C:\Program Files\G DATA InternetSecurity TotalCare\AVKTuner\AVKTunerService.exe  (File not found)
"Dienst "Bonjour"" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"Easybits Shared Services for Windows" (ezSharedSvc) - "EasyBits Sofware AS" - C:\Windows\System32\ezsvc7.dll
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"HP Health Check Service" (HP Health Check Service) - "Hewlett-Packard" - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
"InstallDriver Table Manager" (IDriverT) - "Macrovision Corporation" - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
"iPod-Dienst" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"LightScribeService Direct Disc Labeling Service" (LightScribeService) - "Hewlett-Packard Company" - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
"Logitech Bluetooth Service" (LBTServ) - "Logitech, Inc." - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
"MBAMService" (MBAMService) - "Malwarebytes Corporation" - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"Mozilla Maintenance Service" (MozillaMaintenance) - "Mozilla Foundation" - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
"MSCamSvc" (MSCamSvc) - "Microsoft Corporation" - C:\Program Files\Microsoft LifeCam\MSCamS32.exe
"Net Driver HPZ12" (Net Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZinw12.dll
"Pml Driver HPZ12" (Pml Driver HPZ12) - "Hewlett-Packard" - C:\Windows\system32\HPZipm12.dll
"PnkBstrA" (PnkBstrA) - ? - C:\Windows\system32\PnkBstrA.exe  (File found, but it contains no detailed information)
"Steam Client Service" (Steam Client Service) - "Valve Corporation" - C:\Program Files\Common Files\Steam\SteamService.exe
"Windows Live ID Sign-in Assistant" (wlidsvc) - "Microsoft Corp." - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
"Yahoo! Updater" (YahooAUService) - "Yahoo! Inc." - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll

===[ Logfile end ]=========================================[ Logfile end ]===


--- --- ---

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-06-27 15:53:18
-----------------------------
15:53:18.942    OS Version: Windows 6.0.6002 Service Pack 2
15:53:18.942    Number of processors: 4 586 0x203
15:53:18.942    ComputerName: TUAN-PC  UserName: Tuan
15:53:21.048    Initialize success
15:54:25.282    AVAST engine defs: 12062700
15:55:27.043    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000059
15:55:27.059    Disk 0 Vendor: WDC_WD64 01.0 Size: 610480MB BusType: 8
15:55:27.464    Disk 0 MBR read successfully
15:55:27.464    Disk 0 MBR scan
15:55:27.464    Disk 0 unknown MBR code
15:55:27.589    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      597009 MB offset 63
15:55:27.698    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS        13468 MB offset 1222675020
15:55:28.135    Disk 0 scanning sectors +1250258625
15:55:29.102    Disk 0 scanning C:\Windows\system32\drivers
15:57:13.812    Service scanning
15:57:36.603    Modules scanning
15:59:42.762    Disk 0 trace - called modules:
15:59:42.887    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys dxgkrnl.sys atikmpag.sys atikmdag.sys watchdog.sys
15:59:42.903    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87245ac8]
15:59:42.903    3 CLASSPNP.SYS[8073b8b3] -> nt!IofCallDriver -> [0x861b3360]
15:59:42.903    5 acpi.sys[806176bc] -> nt!IofCallDriver -> \Device\00000059[0x861b8928]
15:59:44.244    AVAST engine scan C:\Windows
16:02:54.487    AVAST engine scan C:\Windows\system32
16:04:33.529    File: C:\Windows\system32\jureg.exe  **INFECTED** Win32:SMSSend-IG [Trj]
16:08:52.708    AVAST engine scan C:\Windows\system32\drivers
16:09:12.536    AVAST engine scan C:\Users\Tuan
16:50:49.116    AVAST engine scan C:\ProgramData
16:53:28.798    Scan finished successfully
16:54:40.090    Disk 0 MBR has been saved successfully to "C:\Users\Tuan\Desktop\MBR.dat"
16:54:40.090    The log file has been saved successfully to "C:\Users\Tuan\Desktop\aswMBR.txt"


cosinus 28.06.2012 09:53

Code:

C:\Windows\system32\jureg.exe
Bitte diese Datei bei Virustotal auswerten lassen und den Ergebnislink posten. Falls Du die Datei nicht siehst, musst Du sie evtl. vorher sichtbar machen.
Wenn die Datei schon ausgewertet sein sollte, bitte eine weitere Auswertung starten.

Hajaku 29.06.2012 14:15

so gemacht.
ich weiß nicht ob du was damit anfangen kannst, aber hier.
Code:

SHA256:        eadfe05a413aed21d31f051cd81daefef70d303e811a359a621795ca7351119c
SHA1:        9c6fe613d5b3353962d58fa8af82fbb06d4e5f9c
MD5:        4f89dd4ea74c66916e15a6e7d74a50b5
File size:        53.6 KB ( 54936 bytes )
File name:        jureg.exe
File type:        Win32 EXE
Detection ratio:        0 / 42
Analysis date:        2012-06-29 13:11:44 UTC ( 0 Minuten ago )

und additional information
Code:

ssdeep
768:PwyOzv3OyCIqkLJVJfS3VEgrB5li5ZnMTL35tb1:PwyKv367kLJVJWm6li5ZnMTD1
TrID
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
ExifTool

SubsystemVersion.........: 4.0
FileDescription..........: Java(TM) Platform SE binary
InitializedDataSize......: 24576
ImageVersion.............: 0.0
ProductName..............: Java(TM) Platform SE 6 U1
FileVersionNumber........: 6.0.10.7
LanguageCode.............: Neutral
FileFlagsMask............: 0x003f
FullVersion..............: 1.6.0_01-b07
CharacterSet.............: Unicode
LinkerVersion............: 7.1
OriginalFilename.........: jureg.exe
MIMEType.................: application/octet-stream
Subsystem................: Windows GUI
FileVersion..............: 6.0.10.7
TimeStamp................: 2007:04:07 10:12:47+02:00
FileType.................: Win32 EXE
PEType...................: PE32
InternalName.............: Java(TM) Update RegisterTask
ProductVersion...........: 6.0.10.7
UninitializedDataSize....: 0
OSVersion................: 4.0
FileOS...................: Win32
LegalCopyright...........: Copyright    2004
MachineType..............: Intel 386 or later, and compatibles
CompanyName..............: Sun Microsystems, Inc.
CodeSize.................: 24576
FileSubtype..............: 0
ProductVersionNumber.....: 6.0.10.7
EntryPoint...............: 0x16af
ObjectFileType...........: Executable application

Sigcheck

publisher................: Sun Microsystems, Inc.
product..................: Java(TM) Platform SE 6 U1
internal name............: Java(TM) Update RegisterTask
copyright................: Copyright (c) 2004
original name............: jureg.exe
signing date.............: 11:56 PM 4/6/2007
signers..................: Sun Microsystems, Inc.
              VeriSign Class 3 Code Signing 2004 CA
              Class 3 Public Primary Certification Authority
file version.............: 6.0.10.7
description..............: Java(TM) Platform SE binary

Portable Executable structural information

Compilation timedatestamp.....: 2007-04-07 08:12:47
Target machine................: 0x14C (Intel 386 or later processors and compatible processors)
Entry point address...........: 0x000016AF

PE Sections...................:

Name        Virtual Address  Virtual Size  Raw Size  Entropy  MD5
.text                  4096        21052    24576    6.09  9396df4bf3b53d52ea8148004e18630a
.rdata                28672          6816      8192    4.47  29493b378bbcc13fe9f4c418e0a53358
.data                36864          4540      4096    1.52  4949e527f08d12460bec8c96f89e313b
.rsrc                45056          4856      8192    3.18  a51ff8a51076dbac7d88ee6be23ee602

PE Imports....................:

KERNEL32.dll
        InterlockedExchange, GetACP, GetLocaleInfoA, GetVersionExA, InitializeCriticalSection, DeleteCriticalSection, GetLastError, CloseHandle, GetExitCodeProcess, CreateProcessA, lstrcatA, GetEnvironmentVariableA, GetSystemDirectoryA, lstrcpyA, GetCommandLineA, EnterCriticalSection, LeaveCriticalSection, GetSystemInfo, HeapFree, GetModuleHandleA, GetStartupInfoA, ExitProcess, HeapReAlloc, HeapAlloc, RtlUnwind, VirtualQuery, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, GetProcAddress, TerminateProcess, GetCurrentProcess, HeapSize, WriteFile, GetStdHandle, GetModuleFileNameA, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, TlsAlloc, SetLastError, GetCurrentThreadId, TlsFree, TlsSetValue, TlsGetValue, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, LoadLibraryA, GetOEMCP, GetCPInfo, LCMapStringA, MultiByteToWideChar, LCMapStringW, GetStringTypeA, GetStringTypeW, VirtualProtect

USER32.dll
        wsprintfA


PE Exports....................:


cosinus 29.06.2012 14:46

Das ist ein Fehlalarm von aswMBR die Datei hat was mit Java zu tun

Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.
Mach den Fix auch dann nicht, wenn du zB mit TrueCrypt oder anderen Verschlüsselungsprogrammen eine Vollverschlüsselung der Windowspartition bzw. gesamten Festplatte hast


Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehalalrm!

Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

Hajaku 02.07.2012 14:03

tut mir Leid für die verspätete Antwort.:zunge:
Ich kam in den letzten Tagen nicht an den Rechner ran.

Wie sichere ich mir die Daten?

cosinus 02.07.2012 14:30

Willst du mir jetzt echt erzählen, du hast noch nie deine wichtigen Dateien auf eine externe Platte oder ein anderem externes Medium kopiert? :balla:
Oder willst du wissen wie man möglichst ein gesamtes Backup (Image) seines Systems macht?

Hajaku 02.07.2012 18:51

Oh sehe schon, habe die Frage etwas schlecht formuliert^^
Natürlich habe ich schon mal wichtige Daten gesichert. Nur das war vor knapp 2 Jahren.
Ich wollte wissen, wie man ein gesamtes Backup eines Systems macht. Oder reichen schon die gesicherte Daten, die ich vor 2 Jahren gemacht hatte?
Ich meine aktuellere gesicherte Daten wären besser oder?

cosinus 03.07.2012 11:59

Da gibt es mehrere Möglichkeiten. Das einfachste wäre es wohl alle Dateien und wichtigen persönlichen Ordner auf eine ext. Platte zu kopieren. Dann hast du deine Daten gesichert, zB nach einem Systemcrash kannst du Windows dann manuell sauber neu installieren und die Daten aus der einfachen manuellen Backupmethode einfach wieder zurückkopieren

Man kann aber auch Abbilder eines gesamten System (besser gesagt der gesamten Platte oder von einzelnen oder auch mehreren Partitionen erstellen), Denkanstoß hier => http://www.trojaner-board.de/115678-...r-backups.html

Wenn du eine Festplatte von WesternDigital oder Seagate hast, bekommst du ein AcronisTrueImage für lau :) (das aber ohne SecureZone soweit ich weiß, ich empfehle aber eh Images auf externe Platten, diese sollten nur angesteckt sein wenn man das Backup braucht bzw. ein Backup erstellen muss!)

WesternDigtal => http://filepony.de/download-acronis_...ge_wd_edition/
Seagate => http://filepony.de/download-seagate_discwizard/

Mit Windows7 hat man auch ein Bordmitteln für die Imageerstellung zB hier => [Anleitung] Komplettes Image-Backup (Systemabbild) von Windows 7 erstellen - Anleitungen / Tutorials / FAQ (Windows 7)

Gibt auch andere Programme, wie zB Drive Snapshot - Disk Image Backup leicht gemacht

Hajaku 04.07.2012 13:49

So habe die Daten einfach auf einer CD gebrannt
Hier der Log von MBR
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-04 14:41:13
-----------------------------
14:41:13.329    OS Version: Windows 6.0.6002 Service Pack 2
14:41:13.329    Number of processors: 4 586 0x203
14:41:13.344    ComputerName: TUAN-PC  UserName: Tuan
14:41:15.154    Initialize success
14:41:23.890    AVAST engine defs: 12070400
14:41:40.950    Verifying
14:41:50.992    Disk 0 Windows 600 MBR fixed successfully
14:42:36.872    Disk 0 MBR has been saved successfully to "C:\Users\Tuan\Desktop\MBR.dat"
14:42:36.872    The log file has been saved successfully to "C:\Users\Tuan\Desktop\aswMBR1.txt"


cosinus 05.07.2012 08:56

Das ist nur das Fixlog. Du solltest neu starten und aswMBR auch neu scannen lassen - das Log wollte ich sehen

Hajaku 05.07.2012 19:06

Achso das meintest du :zunge:
Hier der Log
Code:

aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-05 19:26:55
-----------------------------
19:26:55.833    OS Version: Windows 6.0.6002 Service Pack 2
19:26:55.833    Number of processors: 4 586 0x203
19:26:55.833    ComputerName: TUAN-PC  UserName: Tuan
19:27:47.750    Initialize success
19:28:01.322    AVAST engine defs: 12070400
19:28:12.211    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000059
19:28:12.242    Disk 0 Vendor: WDC_WD64 01.0 Size: 610480MB BusType: 8
19:28:12.258    Disk 0 MBR read successfully
19:28:12.258    Disk 0 MBR scan
19:28:12.258    Disk 0 Windows VISTA default MBR code
19:28:12.273    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      597009 MB offset 63
19:28:12.304    Disk 0 Partition 2 00    07    HPFS/NTFS NTFS        13468 MB offset 1222675020
19:28:12.304    Disk 0 scanning sectors +1250258625
19:28:12.382    Disk 0 scanning C:\Windows\system32\drivers
19:28:22.725    Service scanning
19:28:44.269    Modules scanning
19:28:48.138    Disk 0 trace - called modules:
19:28:48.169    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys tcpip.sys NETIO.SYS
19:28:48.169    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87311780]
19:28:48.184    3 CLASSPNP.SYS[8072e8b3] -> nt!IofCallDriver -> [0x86651620]
19:28:48.200    5 acpi.sys[8060a6bc] -> nt!IofCallDriver -> \Device\00000059[0x86275990]
19:28:50.322    AVAST engine scan C:\Windows
19:28:54.939    AVAST engine scan C:\Windows\system32
19:29:44.048    File: C:\Windows\system32\jureg.exe  **INFECTED** Win32:SMSSend-IG [Trj]
19:32:22.092    AVAST engine scan C:\Windows\system32\drivers
19:32:37.754    AVAST engine scan C:\Users\Tuan
20:01:10.462    AVAST engine scan C:\ProgramData
20:04:03.435    Scan finished successfully
20:04:33.106    Disk 0 MBR has been saved successfully to "C:\Users\Tuan\Desktop\MBR.dat"
20:04:33.106    The log file has been saved successfully to "C:\Users\Tuan\Desktop\aswMBR2.txt"


cosinus 05.07.2012 20:25

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!

Hajaku 09.07.2012 13:39

Hier hast du schon mal das
Code:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Datenbank Version: v2012.07.06.09

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Tuan :: TUAN-PC [Administrator]

Schutz: Aktiviert

06.07.2012 19:01:07
mbam-log-2012-07-06 (19-01-07).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 486894
Laufzeit: 2 Stunde(n), 22 Minute(n), 30 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Den Log von SASW kriegst du heut Abend wenn ich das zeitlich noch schaffe :)

So hab es endlich geschafft
Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 07/09/2012 at 09:19 PM

Application Version : 5.5.1006

Core Rules Database Version : 8863
Trace Rules Database Version: 6675

Scan type      : Complete Scan
Total Scan Time : 01:23:54

Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User (Administrator User)

Memory items scanned      : 847
Memory threats detected  : 0
Registry items scanned    : 36466
Registry threats detected : 0
File items scanned        : 60514
File threats detected    : 27

Adware.Tracking Cookie
        C:\Users\Tuan\AppData\Roaming\Microsoft\Windows\Cookies\9PE13R2W.txt [ /mediaplex.com ]
        C:\Users\Tuan\AppData\Roaming\Microsoft\Windows\Cookies\XSMZSFX7.txt [ /apmebf.com ]
        C:\Users\Tuan\AppData\Roaming\Microsoft\Windows\Cookies\OZB2BXCE.txt [ /atdmt.com ]
        C:\USERS\GAST\AppData\Roaming\Microsoft\Windows\Cookies\Low\gast@doubleclick[1].txt [ Cookie:gast@doubleclick.net/ ]
        C:\USERS\GAST\AppData\Roaming\Microsoft\Windows\Cookies\Low\gast@tradedoubler[1].txt [ Cookie:gast@tradedoubler.com/ ]
        C:\USERS\GAST\AppData\Roaming\Microsoft\Windows\Cookies\Low\gast@advertising[1].txt [ Cookie:gast@advertising.com/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@tto2.traffictrack[2].txt [ Cookie:tran trong chinh@tto2.traffictrack.de/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@aolde.122.2o7[1].txt [ Cookie:tran trong chinh@aolde.122.2o7.net/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@2o7[2].txt [ Cookie:tran trong chinh@2o7.net/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@de.at.atwola[1].txt [ Cookie:tran trong chinh@de.at.atwola.com/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@fastclick[1].txt [ Cookie:tran trong chinh@fastclick.net/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@a6.adserver01[1].txt [ Cookie:tran trong chinh@a6.adserver01.de/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@apmebf[2].txt [ Cookie:tran trong chinh@apmebf.com/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@adtech[1].txt [ Cookie:tran trong chinh@adtech.de/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@de2.komtrack[2].txt [ Cookie:tran trong chinh@de2.komtrack.com/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@adfarm1.adition[1].txt [ Cookie:tran trong chinh@adfarm1.adition.com/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@ad.zanox[1].txt [ Cookie:tran trong chinh@ad.zanox.com/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@advertising[2].txt [ Cookie:tran trong chinh@advertising.com/ ]
        C:\USERS\TRAN TRONG CHINH\AppData\Roaming\Microsoft\Windows\Cookies\Low\tran_trong_chinh@doubleclick[1].txt [ Cookie:tran trong chinh@doubleclick.net/ ]
        C:\USERS\TUAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\5Z8RJHDA.txt [ Cookie:tuan@ad.yieldmanager.com/ ]
        C:\USERS\TUAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\GRKFMB74.txt [ Cookie:tuan@imrworldwide.com/cgi-bin ]
        C:\USERS\TUAN\AppData\Roaming\Microsoft\Windows\Cookies\Low\PSKX45PV.txt [ Cookie:tuan@statse.webtrendslive.com/ ]
        C:\USERS\TUAN\Cookies\9PE13R2W.txt [ Cookie:tuan@mediaplex.com/ ]
        C:\USERS\TUAN\Cookies\OZB2BXCE.txt [ Cookie:tuan@atdmt.com/ ]
        C:\USERS\GAST\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\GAST@DE.AT.ATWOLA[1].TXT [ /DE.AT.ATWOLA ]
        C:\USERS\TRAN TRONG CHINH\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\TRAN_TRONG_CHINH@TRACKING.QUISMA[1].TXT [ /TRACKING.QUISMA ]

Trojan.Agent/Gen-Injector
        C:\USERS\TUAN\DOWNLOADS\BORLAND\DELPHI5\PROJECTS\KASSE\KASSE.EXE


Hajaku 17.07.2012 13:17

glaube du hast meinen post übersehen, wollte nur nochmal darauf hinweisen.
Ist ja schon eine Woche her^^

cosinus 18.07.2012 11:36

Code:

Trojan.Agent/Gen-Injector
        C:\USERS\TUAN\DOWNLOADS\BORLAND\DELPHI5\PROJECTS\KASSE\KASSE.EXE

Das ist wohl ein Fehlalarm der Rest nur Cookies

Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )


Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller http://filepony.de/download-cookie_culler/
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ich halte es so, dass ich zum "wilden Surfen" den Opera-Browser oder Chromium unter meinem Linux verwende. Mein Hauptbrowser (Firefox) speichert nur die Cookies von den Sites die ich auch will, alles andere lehne ich manuell ab (der FF fragt mich immer) - die anderen Browser nehmen alles an Cookies zwar an, aber spätestens beim nächsten Start von Opera oder Chromium sind keine Cookies mehr da.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Hajaku 18.07.2012 18:49

Nein sonst ist alles in Ordnung
Vielen dank für die Super Hilfe:dankeschoen:

cosinus 19.07.2012 10:25

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. Mit Hilfe von OTL kannst du auch viele Tools entfernen:

Starte bitte OTL und klicke auf Bereinigung.
Dies wird die meisten Tools entfernen, die wir zur Bereinigung benötigt haben. Sollte etwas bestehen bleiben, bitte mit Rechtsklick --> Löschen entfernen.


Malwarebytes zu behalten ist zu empfehlen. Kannst ja 1x im Monat damit einen Vollscan machen, aber immer vorher ans Update denken.


Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks => Adobe Flash Player Distribution | Adobe

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 03:57 Uhr.

Copyright ©2000-2026, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132